The Hacker News
151K subscribers
1.82K photos
9 videos
3 files
7.74K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
APT41 hackers from #China are believed to be responsible for the data breach at SITA, which affected 4.5 million customers of Air India and millions of customers of other airlines.

Details: https://thehackernews.com/2021/06/chinese-hackers-believed-to-be-behind.html
A supply-chain attack on the Android emulator NoxPlayer is suspected to be the work of cyberespionage hackers from the group Gelsemium.

Details: https://thehackernews.com/2021/06/noxplayer-supply-chain-attack-is-likely.html
Google introduces client-side encryption at Workspace, giving enterprise customers control over encryption keys.

Details: https://thehackernews.com/2021/06/google-workspace-now-offers-client-side.html
Initially, it will be available for Google Drive, Docs, Sheets and Slides, with support for a wide range of files.
ALERT — Apple has confirmed that 2 zero-day vulnerabilities in iOS 12.5.3 have been actively exploited in the wild, and has shipped urgent out-of-band security patches to fix them.

Details: https://thehackernews.com/2021/06/apple-issues-urgent-patches-for-2-zero.html
Instagram has paid $30,000 bounty to a hacker who reported a security flaw that allowed anyone to see private account posts, archived posts, Stories, Reels and IGTV—without following them.

Read: https://thehackernews.com/2021/06/instagram-bug-allowed-anyone-to-view.html
Researchers uncover "distinctive" tactics, techniques and procedures (TTPs) used by Hades ransomware operators that set them apart from the rest of the pack, attributing it to a financially motivated threat group called GOLD WINTER.

https://thehackernews.com/2021/06/experts-shed-light-on-distinctive.html
CISA has issued an advisory warning #IoT manufacturers of a critical vulnerability — CVE-2021-32934 / CVSS score: 9.1 —in ThroughTek's P2P SDK that could be exploited by attackers to eavesdrop on connected cameras.

Read: https://thehackernews.com/2021/06/critical-throughtek-flaw-opens-millions.html
New research finds that ransomware attackers are increasingly shifting from using emails as an intrusion route to purchasing access from other cybercriminal enterprises that have already infiltrated major targets.

Read: https://thehackernews.com/2021/06/ransomware-attackers-partnering-with.html
Researchers have disclosed a new executable image tampering attack — dubbed "Process Ghosting" — that could be exploited by attackers to circumvent security measures and execute malware code on a Windows system.

Details: https://thehackernews.com/2021/06/researchers-uncover-process-ghosting.html
APT hacker group "TA402/Molerats" has resurfaced after a two-month hiatus to target government institutions in the Middle East and global government agencies linked to geopolitics in the region.

Details: https://thehackernews.com/2021/06/molerats-hackers-return-with-new.html
Russian communications regulator Roskomnadzor bans VyprVPN and Opera VPN services in the country for failing to comply with a blacklisting request, and it is likely that more services will be blocked in the near future.

Details: https://thehackernews.com/2021/06/russia-bans-vyprvpn-opera-vpn-services.html
As cyberattacks on the software supply-chain become a major concern, Google is introducing a new security framework—called SLSA—to ensure the integrity of packages and prevent unauthorized changes.

Details:
https://thehackernews.com/2021/06/google-releases-new-framework-to.html
Researchers warn of increased cyber-espionage activities by Chinese state-sponsored hackers in neighboring countries.

Cyberattacks on Central Asia, India and Pakistan were carried out by suspected hackers from the PLA's 69010 cyber offensive unit and affected India's largest energy company NTPC as well as BSNL, the national telecommunications company.

Read: https://thehackernews.com/2021/06/cyber-espionage-by-chinese-hackers-in.html
👍1
South Korea's Atomic Energy Research Institute has disclosed a hack of its internal network that, according to the Ministry of Science, could be the work of North Korean hackers exploiting a #vulnerability in an unnamed VPN software.

Read: https://thehackernews.com/2021/06/north-korea-exploited-vpn-flaw-to-hack.html
NVIDIA Jetson series chipsets have been found vulnerable to 26 new vulnerabilities, the most serious of which can enable attackers to escalate privileges, cause DoS, and steal information.

Details: https://thehackernews.com/2021/06/nvidia-jetson-chipsets-found-vulnerable.html