The Hacker News
151K subscribers
1.85K photos
10 videos
3 files
7.76K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
Hackers are turning to malicious Excel add-in (.XLL) files as their initial attack vector, in response to Microsoft's decision to block VBA macros by default for Office files downloaded from the Internet .

https://thehackernews.com/2022/12/apt-hackers-turn-to-malicious-excel-add.html
👍39🤔21🔥12👏7🤯2
BitKeep, a decentralized multi-chain cryptocurrency wallet, has confirmed a cyberattack that led to the distribution of fraudulent versions of its Android app, resulting in the theft of an estimated $9.9 million worth of digital assets.

https://thehackernews.com/2022/12/bitkeep-confirms-cyber-attack-loses.html
😁30🤯30👍20🔥5
A new malvertising campaign has been discovered that targets people searching for popular #software. This campaign uses Google Ads to spread Trojanized variants that deploy malware, including Raccoon Stealer and Vidar.

Read: https://thehackernews.com/2022/12/new-malvertising-campaign-via-google.html
👍33😁83
Thousands of Citrix ADC and Gateway endpoints have not yet been patched for two critical vulnerabilities (CVE-2022-27510 and CVE-2022-27518), leaving several organisations vulnerable to potential cyberattacks.

https://thehackernews.com/2022/12/thousands-of-citrix-servers-still.html
🤔24👍16🔥136👏6😱1
CISA has added two-year-old vulnerabilities in TIBCO Software's JasperReports product to its KEV catalog after discovering evidence of active exploitation by cybercriminals.

Read: https://thehackernews.com/2022/12/cisa-warns-of-active-exploitation-of.html
👍37🤔11👏74🔥4
Google has agreed to pay $29.5 million to settle lawsuits brought by Indiana and Washington, D.C. over its "deceptive" location tracking practices.

Read: https://thehackernews.com/2023/01/google-to-pay-295-million-to-settle.html
🔥26👍20👏11😱10😁5🤯54
A new strain of Linux malware is targeting WordPress sites, taking advantage of vulnerabilities in various plugins and themes to infiltrate and compromise vulnerable systems.

Read: https://thehackernews.com/2023/01/wordpress-security-alert-new-linux.html
🤯32🔥18👍9😁9👏74😱1
PyTorch, a machine learning framework project, fell victim to a supply chain attack between Dec. 25 and Dec.30, 2022, involving a malicious dependency that affected users who downloaded the affected versions.

Read: https://thehackernews.com/2023/01/pytorch-machine-learning-framework.html
😱35😁13👍8🔥5🤯53👏3🤔1
Chinese international students in the U.K. have been facing persistent scams for over a year by Chinese-speaking fraudsters belonging to a group called RedZei (also known as RedThief).

Read: https://thehackernews.com/2023/01/redzei-chinese-scammers-targeting.html
👍28🤯7🔥63👏2🤔1
Raspberry Robin worm is targeting financial and insurance sectors in Europe, and has evolved its post-exploitation capabilities to resist analysis and collect more data from infected computers.

Read: https://thehackernews.com/2023/01/raspberry-robin-worm-evolves-to-attack.html
😱19👍13🔥6👏6🤯3😁1
Attention: A new malware campaign has been detected using sensitive information stolen from a bank to trick people into downloading a remote access trojan called BitRAT.

Read: https://thehackernews.com/2023/01/hackers-using-stolen-bank-information.html
🔥38👍13🤯11😱9👏5😁5
Synology has released security updates to address a critical RCE vulnerability (CVE-2022-43931) impacting VPN Plus Server that could be exploited to take over affected systems.

Read: https://thehackernews.com/2023/01/synology-releases-patch-for-critical.html
👍24🤯12🔥5🤔3👏1
Attention Linux users! There is a new malware that has been created using the Shell Script Compiler (shc) and it is deploying a cryptocurrency miner on infected systems.

Read: https://thehackernews.com/2023/01/new-shc-based-linux-malware-targeting.html
🤯52👍27😱13🔥11🤔10
Irish regulators have fined Meta a hefty $414 million for violating data protection laws by forcing Facebook and Instagram users to accept targeted ads.

Read: https://thehackernews.com/2023/01/irish-regulators-fine-facebook-414.html
👍40👏13🔥9😁9
Fortinet has identified a high-severity flaw in multiple versions of FortiADC.

Zoho also warns of an SQLi vulnerability affecting Access Manager Plus, PAM360 and Password Manager Pro.

Read details: https://thehackernews.com/2023/01/fortinet-and-zoho-urge-customers-to.html
👍23👏5🔥4😁2
Don't let Vidar malware take control of your device.

This sneaky stealer now uses throwaway accounts on social media platforms to retrieve the address of its C2 servers and steal information from compromised hosts.

Details: https://thehackernews.com/2023/01/the-evolving-tactics-of-vidar-stealer.html
🤯33👍14😁43🔥3👏2😱2
A new feature-rich version of SpyNote Android spyware has been detected targeting financial institutions, including HSBC UK, Deutsche Bank, Kotak Mahindra Bank and Nubank.

Read: https://thehackernews.com/2023/01/spynote-strikes-again-android-spyware.html
😱22👍6🔥6🤯5😁21
Alert: Bluebottle cybercrime group linked to targeted attacks on financial sector in French-speaking African countries.

Read: https://thehackernews.com/2023/01/bluebottle-cybercrime-group-preys-on.html

Symantec reports the group uses living-off-the-land & dual use tools, with no custom malware.
19👍17🔥10😁1🤔1
Alert: Financially motivated threat actor "Blind Eagle" has resurfaced with new tools and infection chain targeting organizations in Colombia and Ecuador.

Read: https://thehackernews.com/2023/01/blind-eagle-hackers-return-with-refined.html
👍30🔥7🤔5😁3
Stay connected no matter what!

WhatsApp has announced support for proxy servers on Android and iOS, allowing users to bypass censorship and Internet shutdowns.

Read: https://thehackernews.com/2023/01/whatsapp-introduces-proxy-support-to.html
🔥48👍20🤔15😁10👏6🤯2