The Hacker News
โœ”
151K subscribers
1.84K photos
10 videos
3 files
7.76K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: admin@thehackernews.com

๐ŸŒ Website: https://thehackernews.com
Download Telegram
Apple releases a security patch for 10-year-old macOS SUDO root privilege escalation vulnerability, tracked as CVE-2021-3156, and also called "Baron Samedit."

Read details โ€” https://thehackernews.com/2021/02/apple-patches-10-year-old-macos-sudo.html
Windows LodaRAT malware with credential-stealing and espionage capabilities has now expanded its scope to set its sights on users of Android devices.

Read more: https://thehackernews.com/2021/02/lodarat-windows-malware-now-also.html
๐Ÿ”ฅ A novel dependency confusion supply-chain attack allowed a security researcher to breach over 35 high-profile companiesโ€”including Microsoft, Apple, PayPal, Shopify, Netflix, Tesla, Uberโ€”and achieve remote code execution.

Details: https://thehackernews.com/2021/02/dependency-confusion-supply-chain.html
In its latest cyber espionage attacks, Iranian hackers utilize a legit remote access tool, called ScreenConnect, to spy on UAE and Kuwait government agencies.

Read details: https://thehackernews.com/2021/02/iranian-hackers-utilize-screenconnect.html
It turns out that poor #password security and outdated system lead to the recent cyberattack on Florida's water treatment facility, where an attacker tried to poison the water supply.

Read details here: https://thehackernews.com/2021/02/poor-password-security-lead-to-recent.html
A researcher discovered a privacy flaw in the Telegram messenger that left media files shared over the self-destructible secret chat feature.

https://thehackernews.com/2021/02/secret-chat-in-telegram-left-self.html

In a separate issue, Telegram's macOS app stored local passcodes in plaintext.
An Employee at Russia's leading technology company 'Yandex' caught selling unauthorized access to the users' mailboxes for personal gain.

Details: https://thehackernews.com/2021/02/yandex-employee-caught-selling-access.html

Yandex discloses 4,887 email accounts were compromised.
As a new privacy feature, Apple will proxy Safe Browsing requests to preserve iOS users' privacy and hide IP addresses from Google.

Read: https://thehackernews.com/2021/02/apple-will-proxy-safe-browsing-requests.html
A malicious sticker sent on the Telegram messaging app could have exposed your secret messages, photos, and videos to remote hackers.

Read more: https://thehackernews.com/2021/02/a-sticker-sent-on-telegram-could-have.html
In a 3-year-long stealthy cyber espionage operation, Russian hackers exploit IT monitoring tool 'Centreon' to target several French entities.

Read details: https://thehackernews.com/2021/02/hackers-exploit-it-monitoring-tool.html
๐Ÿ‘1
Researchers disclose multiple unpatched vulnerabilities affecting popular SHAREit app for Android that could be abused to leak a user's sensitive data, execute arbitrary code, and possibly lead to remote code execution.

https://thehackernews.com/2021/02/unpatched-shareit-android-app-flaw.html
Malvertisers exploited a zero-day vulnerability in WebKit-based browsers to inject malicious payloads that redirected users to fraudulent websites gift card scams.

Read details: https://t.co/em1xrNEYy8
Researchers warn of a new FUD office malware builder, called 'APOMacroSploit,' getting popular among cybercriminals and also unmasked the identity of hackers behind its development.

Read โ€” https://t.co/rc6wffiz8t
HACKERS WANTED BY THE FBI !!!

The United States has charged 3 North Korean military hackers to steal and extort over $1.3 billion in cash and cryptocurrencies from financial institutions and businesses.
https://thehackernews.com/2021/02/us-charges-3-north-korean-hackers-over.html
(New) Microsoft discloses that SolarWinds hackers stole source code for some of its Azure, Exchange, and Intune components.

Details: https://thehackernews.com/2021/02/solarwinds-hackers-stole-some-source.html
Masslogger, an infamous credential stealer trojan, has been updated to steal all your credentials from Microsoft Outlook, Google Chrome, and instant messenger apps.

Read details: https://thehackernews.com/2021/02/masslogger-trojan-upgraded-to-steal-all.html
๐Ÿ”ฅ WATCH OUT !!!

A new hack lets criminals bypass PIN for Mastercard contactless cards by tricking terminals into believing it to be a Visa card.
Read about 'Card Brand Mixup Attack' here โ€” https://thehackernews.com/2021/02/new-hack-lets-attackers-bypass.html
A privacy bug in Brave Browser exposes the Dark-Web browsing history of its users by sending queries for .onion domains to public internet DNS resolvers rather than routing them through Tor nodes.

https://thehackernews.com/2021/02/privacy-bug-in-brave-browser-exposes.html
Researchers disclose yet another malware that targets both Apple Macs running M1 and Intel processors, which has so far already infected nearly 30,000 systems.

Read details: https://thehackernews.com/2021/02/new-silver-sparrow-malware-infected.html