The Hacker News
151K subscribers
1.84K photos
9 videos
3 files
7.75K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
A new academic study has highlighted a number of serious #privacy and security pitfalls associated with recycling mobile phone numbers that could be abused to stage a variety of attacks, including account takeovers, phishing, spam attacks.

Read: https://thehackernews.com/2021/05/new-study-warns-of-security-threats.html
🔥 Researchers have found a new variant of Spectre vulnerability that bypasses all current protections built into Intel & AMD processors, potentially putting BILLIONS of systems—desktops, laptops, cloud servers, smartphones—at risk of hacking.

https://thehackernews.com/2021/05/new-spectre-flaws-in-intel-and-amd-cpus.html
Newly discovered critical vulnerabilities in Cisco vManage and HyperFlex HX could allow hackers to remotely execute commands as root on affected devices or even create unauthorized administrators.

Read details: https://thehackernews.com/2021/05/critical-flaws-hit-cisco-sd-wan-vmanage.html
A newly discovered stealth ROOTKIT malware—active since at least 2018—has infiltrated the networks of several high-profile organizations, helping hackers gain control of remote hosts as well as facilitate lateral movement.

Read details: https://thehackernews.com/2021/05/new-stealthy-rootkit-infiltrated.html
TsuNAME — A new critical vulnerability affecting DNS resolvers could let attackers carry out reflection-based DDoS attacks to take down authoritative servers.

Find details here: https://thehackernews.com/2021/05/new-tsuname-flaw-could-let-attackers.html
A researcher has disclosed 6 unpatched 0-day vulnerabilities affecting the "RemoteMouse" app for Android (over 1 million installs) & iOS devices that could let remote hackers gain full RCE on connected computers without user interaction.

Read: https://thehackernews.com/2021/05/6-unpatched-flaws-disclosed-in-remote.html
Google this week announced 4 major privacy and security that everyone needs to know about:

— Two-factor authentication for all, by default.
— Privacy labels for Google Play apps
— Hardware-Enforced Exploit Protection for Chrome
— Cosign for signing and verifying container images
Read details here: https://thehackernews.com/2021/05/4-major-privacy-and-security-updates.html
Facebook has decided it won't deactivate WhatsApp accounts that don't agree with its latest controversial privacy policy by May 15, but will instead restrict some key features as a reminder.https://thehackernews.com/2021/05/facebook-will-limit-your-whatsapp.html
Four people have pleaded guilty to helping cyber criminals with bulletproof hosting used to spread malware such as Zeus, SpyEye, Citadel and Blackhole Exploit Kit.

Read: https://thehackernews.com/2021/05/four-plead-guilty-to-aiding-cyber.html
👍1
WARNING — Over 25% of Tor exit relays have been spying on users' dark web activity since an unknown threat actor managed to increase the number of servers and now control over 27% of the total Tor network exit capacity.

Details: https://thehackernews.com/2021/05/over-25-of-tor-exit-relays-are-spying.html
Experts warn of TeaBot, a new Android banking Trojan that hijacks users' credentials and SMS messages to enable fraudulent activity against users of more than 60 banks in Spain, Germany, Italy, Belgium and the Netherlands.


Read: https://thehackernews.com/2021/05/experts-warn-of-new-android-banking.html
US intelligence agencies are warning of weaknesses in the 5G network—such as inadequate deployments and supply chain threats—that cybercriminals and nation-state adversaries can exploit to gain valuable intelligence.

Read: https://thehackernews.com/2021/05/us-intelligence-agencies-warn-about-5g.html
Alert: Hackers Exploit Adobe Reader 0-Day Vulnerability in the Wild

Read: https://thehackernews.com/2021/05/alert-hackers-exploit-adobe-reader-0.html
Also receiving critical patches today are Adobe Experience Manager, InDesign, Illustrator, Magento, Creative Cloud, Media Encoder, After Effects, and Animate.
BABUK ransomware hacker gang leaked data from the Metropolitan Police Department after talks failed over $4 million ransom demand.

Read details: https://thehackernews.com/2021/05/ransomware-gang-leaks-metropolitan.html
Patch Tuesday (May 2021)

Microsoft has released the latest Windows updates to patch a dozen newly discovered vulnerabilities, one of the most critical of which is a wormable RCE (CVE-2021-31166) in the HTTP protocol stack.
Read details - https://thehackernews.com/2021/05/latest-microsoft-windows-updates-patch.html
🔥 Attention! A set of new vulnerabilities—dubbed FragAttacks—affects nearly all Wi-Fi devices shipped in the past 24 years.

https://thehackernews.com/2021/05/nearly-all-wifi-devices-are-vulnerable.html
These flaws could let hackers forge encrypted frames in various ways, enabling code execution and exfiltration of sensitive data.