The Hacker News
โœ”
151K subscribers
1.85K photos
10 videos
3 files
7.76K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: admin@thehackernews.com

๐ŸŒ Website: https://thehackernews.com
Download Telegram
This year at Pwn2Own contest, hackers have hacked the following widely-used programs, resulting in up to $1.2 million in bounties.

โœ… Microsoft Exchange and Teams
โœ… Windows 10 and Ubuntu
โœ… Apple Safari, Google Chrome, Edge
โœ… Parallels Desktop
โœ… Zoom

https://thehackernews.com/2021/04/windows-ubuntu-zoom-safari-ms-exchange.html
๐Ÿ”ฅ WATCH OUT โ€” A new exploit has been released to the public for a $100,000 UNPATCHED security vulnerability affecting Google Chrome and other Chromium-based browsers like Microsoft Edge, Opera, and Brave.

Details: https://thehackernews.com/2021/04/rce-exploit-released-for-unpatched.html
Several malicious apps have been caught posing as #Android security scanners on the #Google Play Store

Read โ€” https://thehackernews.com/2021/04/brata-malware-poses-as-android-security.html
These apps trick users into installing fake versions of Chrome, WhatsApp, or PDF Reader, which can steal banking credentials.
As part of an ongoing campaign, attackers are making use of contact forms on websites to deliver malicious links to targeted businesses.



https://thehackernews.com/2021/04/hackers-using-websites-contact-forms-to.html
More than 100 million consumer and enterprise IoT devices are at risk due to 9 newly discovered vulnerabilities affecting 4 widely used TCP/IP stacks.

Read: https://thehackernews.com/2021/04/new-namewreck-vulnerabilities-impact.html
Attention: Google warns that a set of exploits for two new #Chrome flaws exist in the wild, making it possible for hackers to engage in active exploitations.

https://thehackernews.com/2021/04/2-new-chrome-0-days-under-attack-update.html
As new Chrome updates become available for Windows, Mac, Linux, make sure to install them ASAP!
Summary: Patch Tuesday โ€” April 2021

โœ… 114 new flaws, of which are 19 critical
โœ… Windows 0-day under active attack
โœ… 27 RCE flaws in Windows RPC
โœ… NSA uncovers new Exchange server flaws
โœ… FBI sanitized hacked Exchange servers
Details: https://lnkd.in/ebuuENd
๐Ÿ”ฅIMPORTANT: Unfortunately, Google Chrome users are still at risk of hacking even after installing the latest update released today.

Researcher pointed out that there's another bug in V8 engine that still hasn't been addressed in Chrome.
https://thehackernews.com/2021/04/2-new-chrome-0-days-under-attack-update.html
SMASH ATTACK โ€” Hackers can now use a new JavaScript exploit to trigger ๐Ÿ”จ Rowhammer attacks remotely on modern DDR4 RAM, despite the extensive mitigations over the past seven years.

Find details and demo here: https://thehackernews.com/2021/04/new-javascript-exploit-can-now-carry.html
๐Ÿ”ฅ A recently reported bug in WhatsApp messenger could have enabled attackers to hack into your phone remotely and even compromise encrypted communications.

Find details and demos here https://thehackernews.com/2021/04/new-whatsapp-bug-couldve-let-attackers.html
ALERT: Cybercriminals are flooding the web with thousands of web pages offering malicious PDF documents such as invoices, templates, questionnaires, and receipts as a ploy for luring business professionals to download a RAT capable of carrying out a wide range of attacks.

https://thehackernews.com/2021/04/yikes-cybercriminals-flood-intrenet.html
๐Ÿ”ฅ Experts find 1-CLICK code execution bugs in popular desktop apps for Windows, macOS & Linuxโ€”including Telegram, Nextcloud, VLC, Libre-/OpenOffice, Bitcoin/Dogecoin Wallets, Wireshark and more.

https://thehackernews.com/2021/04/1-click-hack-found-in-popular-desktop.html
If you're using any of them, make sure it's up-to-date.
๐Ÿ‘1
In retaliation for the SolarWinds cyberattack, which the United States has attributed with "high confidence" to the operatives working for the Russian intelligence service, the Biden administration today imposed sweeping sanctions on Russia and expelled 10 diplomats.

https://thehackernews.com/2021/04/us-sanctions-russia-and-expels-10.html
Researchers have found multiple severe vulnerabilities affecting OpENer EtherNet/IP stack used in industrial systems that could enable DoS, RCE, and memory leak attacks.

Read: https://thehackernews.com/2021/04/severe-bugs-reported-in-ethernetip.html
A simple crafted packet would be all that's needed to exploit these issues.
A Ukrainian hackerโ€”who worked as system administrator for the billion-dollar hacking group FIN7โ€”has been sentenced to 10 years in U.S. prison.

https://thehackernews.com/2021/04/sysadmin-of-billion-dollar-hacking.html
XCSSET macOS malware campaign that targeted Xcode developers has been updated to include support for Apple's new M1 chips and expand its capabilities to steal from cryptocurrency apps.

Read: https://thehackernews.com/2021/04/malware-spreads-via-xcode-projects-now.html
In recent spear-phishing attacks, North Korean Lazarus APT hackers are now using BMP images to hide RAT malware.

Read: https://thehackernews.com/2021/04/lazarus-apt-hackers-are-now-using-bmp.html
Watch Out! Researchers have spotted a new set of fraudulent Android appsโ€”with over 700,000 downloadsโ€”on the Google Play store that hijack SMS notifications for billing scams.

Check list here: https://thehackernews.com/2021/04/over-750000-users-download-new-billing.html
๐Ÿ”ฅ WARNING !!!

APT hackers are exploiting a new UNPATCHED 0-DAY critical authentication bypass vulnerability (CVE-2021-22893) in Pulse Connect Secure Gateway to breach organizations worldwide.
Details โ€” https://thehackernews.com/2021/04/warning-hackers-exploit-unpatched-pulse.html
Temporary mitigations currently available.
0-DAY ALERT โ€” Hackers have been exploiting 3 new flaws in #SonicWall Email Security appliances to penetrate corporate networks and "install a backdoor, access files and email, and move laterally on the victim's network."

Details: https://thehackernews.com/2021/04/3-zero-day-exploits-hit-sonicwall.html