The Hacker News
151K subscribers
1.84K photos
9 videos
3 files
7.75K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
A new security patch update for Pulse Secure VPNs has been released to address an incomplete patch previously issued for a critical RCE vulnerability (CVE-2020-8260) that was under active exploitation.

Read: https://thehackernews.com/2021/08/pulse-secure-vpns-get-new-urgent-update.html
Watch Out!

A new Android malware campaign—distributing apps via Google Play Store and other marketplaces—hacking Facebook accounts of tens of hundreds of users.

Read details: https://thehackernews.com/2021/08/beware-new-android-malware-hacks.html
A serious vulnerability in the hardware random number generators (RNGs) affects almost all Internet of Things (IoT) devices worldwide, undermining security related to #cryptography, access control, and authentication.

Details: https://thehackernews.com/2021/08/a-critical-random-number-generator-flaw.html
Researchers warn of an ongoing hacking campaign targeting network routers, where attackers are exploiting a newly disclosed critical authentication bypass vulnerability in Arcadyan firmware.

Details: https://thehackernews.com/2021/08/hackers-exploiting-new-auth-bypass-bug.html
Researchers have traced a string of cyberattacks against Israeli government institutions and IT providers to a Chinese cyberespionage group.

Read: https://thehackernews.com/2021/08/experts-believe-chinese-hackers-are.html
Microsoft rolls out August 2021 Windows security updates to fix 44 newly discovered vulnerabilities, including one actively exploited zero-day.

Details: https://thehackernews.com/2021/08/microsoft-releases-windows-updates-to.html
Adobe releases update for Magento to fix several critical pre-authentication vulnerabilities affecting hundreds of thousands of e-commerce sites.

Read: https://thehackernews.com/2021/08/magento-update-released-fix-critical.html
In one of the largest heists of cryptocurrencies, hackers steal over 600 million worth of Binance Chain, Ethereum, and Polygon assets from Poly Network, a cross-chain decentralized financial platform (DeFi).

Details: https://thehackernews.com/2021/08/hacker-steal-over-600-million-worth-of.html
🔥1
Researchers have uncovered a new class of vulnerabilities affecting major managed DNS providers that could allow attackers to spy on massive amount of DNS traffic and exfiltrate sensitive information from corporate networks.

Read: https://thehackernews.com/2021/08/bugs-in-managed-dns-services-cloud-let.html
Microsoft warns of yet another UNPATCHED Windows Print Spooler vulnerability (CVE-2021-36958) allowing RCE attacks.

Read: https://thehackernews.com/2021/08/microsoft-security-bulletin-warns-of.html

Users are advised to stop and disable the Print Spooler service to prevent malicious actors from exploiting the vulnerability.
Global IT consultancy giant Accenture has become the latest company to be hit by the LockBit ransomware gang.

https://thehackernews.com/2021/08/it-giant-accenture-hit-by-lockbit.html

Cybercriminals are now threatening to publish the stolen data online.
New research sheds light on a new Russian malware-as-a-service being sold and distributed on underground forums.

Details: https://thehackernews.com/2021/08/experts-shed-light-on-new-russian.html

The malware is written in the Rust programming language and aims to steal passwords, crypto wallets and FTP client data.
Watch Out! Ransomware attackers are now actively exploiting vulnerabilities in Windows Print Spooler to compromise victims and spread laterally through the victim's network to distribute file-encrypting payloads to target systems.

Read: https://thehackernews.com/2021/08/ransomware-gangs-exploiting-windows.html
Hackers are actively hunting for Microsoft Exchange servers with unpatched ProxyShell, ProxyOracle, and ProxyLogon vulnerabilities.

Read details: https://thehackernews.com/2021/08/hackers-actively-searching-for.html
Microsoft has discovered #phishing campaigns in which attackers use Morse code and other #encryption techniques to avoid detection.

Read details: https://thehackernews.com/2021/08/hackers-spotted-using-morse-code-in.html
#Facebook is expanding end-to-end encryption (E2EE) for voice and video calls in Messenger, and is also testing an opt-in setting that will enable end-to-end encryption for Instagram direct messages.

Read Details: https://thehackernews.com/2021/08/facebook-adds-end-to-end-encryption-for.html
— Glowworm Attack —

Experts demonstrate a novel technique that uses the optical emanations from a device's power indicator LED to recover sounds from connected peripherals and spy on electronic conversations from up to 35 meters away.

Read: https://thehackernews.com/2021/08/new-glowworm-attack-recovers-devices.html
👍1
New AdLoad malware variant bypasses Apple's security defenses to target macOS systems.

Read: https://thehackernews.com/2021/08/new-adload-variant-bypasses-apples.html
Researchers discover dozens of STARTTLS #encryption related vulnerabilities affecting several popular email client software and services.

Details: https://thehackernews.com/2021/08/dozens-of-starttls-related-flaws-found.html

Apple Mail, Gmail, Mozilla Thunderbird, Claws Mail, Mutt, Exim, Samsung Email and Yandex are some of them.