The Hacker News
151K subscribers
1.84K photos
9 videos
3 files
7.75K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
Netgear Smart Switches are affected by a third critical bug – details and a proof-of-concept have been released.

Read: https://thehackernews.com/2021/09/third-critical-bug-affects-netgear.html
A serious security vulnerability has been discovered in Travis CI that exposed API keys, access tokens, and credentials, potentially putting organizations using public source code repositories to the risk of further attacks.

Read details: https://thehackernews.com/2021/09/travis-ci-flaw-exposes-secrets-of.html
Researchers have uncovered a malware attack on the aviation industry that has gone unnoticed for nearly two years.

Read details: https://thehackernews.com/2021/09/malware-attack-on-aviation-sector.html
Researchers have discovered a new malware strain that targets the Linux Subsystem built inside the Windows operating system before infecting the Windows system to launch stealthy attacks.

Read details: https://thehackernews.com/2021/09/new-malware-targets-windows-subsystem.html
A new banking trojan targeting Latin American users has been spotted storing its encrypted remote configuration on legitimate platforms such as YouTube and Pastebin.

Read: https://thehackernews.com/2021/09/numando-new-banking-trojan-targeting.html
An organized crime cell linked to the Italian Mafia that was involved in online fraud, money laundering, drug trafficking, and property crime has been disrupted by law enforcement agencies.

Read: https://thehackernews.com/2021/09/europol-busts-major-cybercrime-ring.html
A new #malware — codenamed "Capoae" — scans the web for vulnerable Linux machine and WordPress sites in order to install a backdoored plugin that runs a Golang-based crypto-mining software.

Read details: https://thehackernews.com/2021/09/new-capoae-malware-infiltrates.html
Cring Ransomware Gang Exploits 11-Year-Old ColdFusion Bug

Read: https://thehackernews.com/2021/09/cring-ransomware-gang-exploits-11-year.html
A new UNPATCHED high-severity vulnerability has been disclosed in macOS Finder on Apple machines running Big Sur and earlier versions, which could allow remote attackers to trick users into executing arbitrary commands.

Details: https://thehackernews.com/2021/09/unpatched-high-severity-vulnerability.html
VMWare warns of 19 new flaws affecting vCenter Server and Cloud Foundation appliances, the most serious of which is an arbitrary file upload vulnerability (CVE-2021-22005) that allows remote attackers to take control of affected systems.

https://thehackernews.com/2021/09/vmware-warns-of-critical-file-upload.html
A new high-severity remote code execution vulnerability has been discovered in several Netgear router models that could be exploited by MiTM attackers to take control of affected systems.

Read details: https://thehackernews.com/2021/09/high-severity-rce-flaw-disclosed-in.html
For the first time, the U.S. Treasury has announced sanctions against a cryptocurrency exchange (Russia's SUEX) for its role in laundering financial transactions for #ransomware attackers.

Read details — https://thehackernews.com/2021/09/us-sanctions-cryptocurrency-exchange.html
👍1
Researchers reported 11 new security vulnerabilities in Nagios network management systems that could lead to pre-authenticated remote code execution with the highest privileges, credential theft, and phishing attacks.

Read details: https://thehackernews.com/2021/09/new-nagios-software-bugs-could-let.html
👍1😁1
Microsoft reveals details of a large-scale phishing-as-a-service operation that is "responsible for many of the phishing campaigns that impact enterprises today."

https://thehackernews.com/2021/09/microsoft-warns-of-wide-scale-phishing.html

BulletProofLink offers phishing kits, email templates, hosting, and automated services.
A new insidious Android malware has been discovered targeting users in U.S. and Canada as part of a new campaign that leverages SMS text message baits linked to COVID19 rules & vaccine information to collect personal and financial data.

Read: https://thehackernews.com/2021/09/new-android-malware-targeting-us.html
A terabyte of data containing 5.5 million files was left exposed, exposing the personal and buying information of over 100,000 customers of a Colombian real estate company.

Read details: https://thehackernews.com/2021/09/colombian-real-estate-agency-leak.html
IMPORTANT — A newly disclosed unpatched weakness in all Microsoft Windows computers shipped since 2012 could allow attackers to bypass system defenses and install rootkit malware with ease.

Read details: https://thehackernews.com/2021/09/a-new-bug-in-microsoft-windows-could.html
👍1
A vulnerability in Microsoft Exchange's Autodiscover protocol exposed around 100,000 Windows domain credentials from various apps such as Outlook, mobile email clients, and others that interacted with the Exchange server.

Read details: https://thehackernews.com/2021/09/microsoft-exchange-bug-exposes-100000.html
Apple releases urgent updates for iOS and macOS to patch 3 new 0-day flaws actively exploited in the wild.

Attacks involve:

CVE-2021-30860 — maliciously crafted PDFs
CVE-2021-30858 — maliciously crafted web content
CVE-2021-30869 — malicious app

https://thehackernews.com/2021/09/urgent-apple-ios-and-macos-updates.html
Cisco has released security patches for three critical flaws in IOS XE network operating system, which remote attackers may exploit to run arbitrary code with administrative rights.

Read details: https://thehackernews.com/2021/09/cisco-releases-patches-3-new-critical.html