The Hacker News
152K subscribers
1.87K photos
10 videos
3 files
7.79K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
A new report reveals Emotet's latest malware delivery and evasion techniques used in recent cyberattacks.

Read: https://thehackernews.com/2022/10/new-report-uncovers-emotets-delivery.html
24👍16🔥6🤔5
Researchers have outlined the increasingly sophisticated malware tools employed by a cyber espionage group called "Earth Aughisky."

Read: https://thehackernews.com/2022/10/researchers-detail-malicious-tools-used.html
🔥32👍167😁6
Fortinet warns that the newly discovered critical vulnerability affecting its firewall and proxy products is being actively exploited in the wild.

Read: https://thehackernews.com/2022/10/fortinet-warns-of-active-exploitation.html
🔥33👍7👏6🤯4
Cyber criminals are using a previously undocumented phishing-as-a-service (PhaaS) toolkit called Caffeine to effectively scale their attacks and spread malicious payloads.

Read: https://thehackernews.com/2022/10/researchers-warn-of-new-phishing-as.html
🔥28🤯12👍11🤔6😁4
Researchers warn of a recently reported critical RCE vulnerability (CVE-2022-36067 / CVSS 10) in the popular vm2 JavaScript sandbox module that could be exploited by hackers to overcome security barriers and perform arbitrary operations.

Read: https://thehackernews.com/2022/10/researchers-detail-critical-rce-flaw.html
🔥27👍17🤯1
A new report shows how BazaCall callback phishing attack operators keep updating their social engineering tactics to deploy malware on targeted networks.

Read: https://thehackernews.com/2022/10/bazarcall-callback-phishing-attacks.html
👍18😁13🔥95😱2👏1🤔1
A critical vulnerability (CVE-2022-38465 / CVSS 9.3) in Siemens Simatic programmable logic controllers (PLCs) can enable attackers to access hard-coded private cryptographic keys and bypass access controls.

Read: https://thehackernews.com/2022/10/critical-bug-in-siemens-simatic-plcs.html
🤯30👍10🤔5😱4🔥2
Microsoft's Patch Tuesday updates this month fix 85 vulnerabilities, including an actively exploited Windows Zero Day vulnerability, but no patches yet for in-the-wild exploited Exchange Server vulnerabilities.

Read: https://thehackernews.com/2022/10/microsoft-patch-tuesday-fixes-new.html
🔥34👍13😁9😱86🤔6
Google is rolling out support for passkeys, the next-generation passwordless authentication standard, to both Android and Chrome.

Read: https://thehackernews.com/2022/10/google-rolling-out-passkey-passwordless.html
🔥42👍14🤔9😱5👏3😁1
Cyber criminals are resorting to voice phishing tactics (vishing) to trick their victims into installing Android banking malware on their devices.

Read: https://thehackernews.com/2022/10/hackers-using-vishing-tactics-to-trick.html
👍43🤯11😁9🔥8🤔7
Researchers uncover seven custom backdoors used by Polonium APT hackers in targeted attacks on Israeli entities to take screenshots, log keystrokes, spy via webcam, open reverse shells and exfiltrate files.

Read: https://thehackernews.com/2022/10/researchers-uncover-custom-backdoors.html
👍487🔥7
Watch Out! An unofficial modified version of the popular WhatsApp messaging app called "YoWhatsApp" has been caught infecting users' Android devices with the Triada malware.

Read: https://thehackernews.com/2022/10/modified-whatsapp-app-caught-infecting.html
👍65😁30😱11🤯10🔥71
Researchers have published technical details and a PoC exploit for a recently disclosed critical vulnerability (CVE-2022-40684) affecting Fortinet FortiOS, FortiProxy, and FortiSwitchManager.

Read: https://thehackernews.com/2022/10/poc-exploit-released-for-critical.html
👍50👏10🔥5😱5
Tata Power, India's largest integrated power company, has been hit by a cyberattack.

Read: https://thehackernews.com/2022/10/indian-energy-company-tata-powers-it.html
😱102👍39🔥1614😁14🤯9🤔7
Interpol has announced the arrest of 75 people as part of a coordinated global operation against an organized cybercrime syndicate called "Black Axe."

Read: https://thehackernews.com/2022/10/interpol-led-operation-takes-down-black.html
👍26😱17🤯16👏7😁52🔥1🤔1
Zimbra has finally released security patches for an actively exploited RCE vulnerability (CVE-2022-41352) in its Enterprise Collaboration Suite that could be used to upload arbitrary files to vulnerable instances.

Read: https://thehackernews.com/2022/10/zimbra-releases-patch-for-actively.html
🔥13👏9👍84
Microsoft warns about a newly discovered ransomware campaign called "Prestige" that targets companies in the transportation and related logistics industries in Ukraine and Poland.

Read: https://thehackernews.com/2022/10/new-prestige-ransomware-targeting.html
👍23🤯118😁3🔥2
New research has uncovered a security weakness in Microsoft 365 that could be exploited to determine the content of encrypted messages due to the use of a broken cryptographic algorithm.

Read: https://thehackernews.com/2022/10/researchers-claim-microsoft-office-365.html
👍35😱13😁9🤯9🤔6🔥5👏2
Hackers behind the Black Basta ransomware attacks have been observed using the Qakbot trojan to deploy the Brute Ratel C4 framework as a second-stage payload in recent attacks.

Read: https://thehackernews.com/2022/10/black-basta-ransomware-hackers.html
🔥27👍19🤔5😱42
Police in Europe have arrested members of a cybercrime ring that used a hacking tool to steal cars without a physical key fob.

Read: https://thehackernews.com/2022/10/european-police-arrest-gang-that-hacked.html
👍30🤯2410🔥9👏9😁7