The Hacker News
151K subscribers
1.85K photos
10 videos
3 files
7.76K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
Oracle releases EMERGENCY updates to patch a newly discovered critical RCE vulnerability (CVE-2019-2729) in the Oracle WebLogic Server that is actively being exploited in the wild by attackers

https://thehackernews.com/2019/06/oracle-weblogic-vulnerability.html
Tor Browser 8.5.2 Released — Users Should Immediately Update It to Patch the Newly Discovered Actively-Exploited Firefox RCE Vulnerability

https://thehackernews.com/2019/06/tor-browser-firefox-hack.html
MongoDB introduces an end-to-end Field Level Encryption (FLE) for online databases that would handle crypto operations on clients’ devices, preventing hackers and even administrators from accessing sensitive data in plaintext

Read more ➤ https://thehackernews.com/2019/06/mongodb-fle-data-encryption.html
Using Outlook for Android? — UPDATE it immediately.

Microsoft patches an important flaw in its popular email app [100+ million users] that could allow remote attackers to execute client-side scripts on the targeted app just by sending an email message.

https://thehackernews.com/2019/06/outlook-app-android.html
An important security vulnerability (CVE-2019-12280) in the Support Assistance Software—that comes pre-installed on most Dell computers—affects millions of users.

https://thehackernews.com/2019/06/dells-supportassist-hacking.html

Update Dell SupportAssist to version—
◆ 2.0.1 (for Business PCs)
◆ 3.2.2 (for Home PCs)
👍1
This is interesting ➤ Here's a new malware that first launches Linux Virtual Machine (VM) on Windows and macOS systems, and then automatically starts mining software within it... just to take the best of your CPU resources

Read more: https://thehackernews.com/2019/06/emulated-malware.html
Researcher today released PoC for a severe RCE vulnerability in "Outlook for Android" that Microsoft patched just this week—almost 6 month after the initial responsible disclosure.

Read more ➤ https://thehackernews.com/2019/06/microsoft-outlook-vulnerability.html
OpenSSH Adds Protection Against Side-Channel Attacks That Now Encrypts Secret SSH Keys in the System Memory

https://thehackernews.com/2019/06/openssh-side-channel-vulnerability.html
New macOS malware found exploiting the latest GateKeeper bypass vulnerability that was disclosed publicly last month after Apple left it unpatched for 90 days

https://thehackernews.com/2019/06/macos-malware-gatekeeper.html
👍1
Microsoft introduces "OneDrive Personal Vault"

A new password / 2FA-protected folder within users' online Cloud Storage accounts where they can store sensitive and personal files with an extra layer of authentication.

Read more ➤ https://thehackernews.com/2019/06/microsoft-onedrive-personal-vault.html
"Legit Apps Turned into Spyware" Targeting Android Users in Middle East

https://thehackernews.com/2019/06/android-malware-hacking.html
Account Takeover Vulnerability Found in the Popular EA Games' Origin Platform

https://thehackernews.com/2019/06/ea-origin-game-hacking.html

Checkout the video demonstration shared by CheckPoint researchers.
Exclusive — German police yesterday raided the house of OmniRAT developer and seized his computers and mobile phones.

https://thehackernews.com/2019/06/police-raid-omnirat-developer.html

OmniRAT is one of the popular remote administration tools that allows users to monitor Android, Windows, Linux, Mac devices remotely.
Starting with Firefox 68, the Mozilla browser will automatically trust system-installed CA Root certificates to fix certain TLS errors, often triggered when antivirus software installed on a system tries to intercept HTTPS connections.

https://thehackernews.com/2019/07/firefox-https-security.html
Google's latest Android July 2019 security update patches 33 new vulnerabilities, the most critical of which resides in the Media framework that could allow remote attackers to execute arbitrary code on targeted devices using a specially crafted file

https://thehackernews.com/2019/07/android-security-update.html
China's border guards have been caught secretly installing a surveillance app—called Feng Cai (蜂采) or BXAQ—on the tourists' phones that instantly extracts texts messages, call records, contacts, more, and also scan the device for 73,000 objected files

https://thehackernews.com/2019/07/xinjiang-fengcai-spyware.html
D-Link has agreed to implement a "comprehensive software security" program and undergo 10 years of biennial security audits to settle FTC charges over the security of its routers & IP cameras, and negligence in patching reported vulnerabilities

https://thehackernews.com/2019/07/ftc-d-link-router-security.html
23-Year-Old DDoS Attacker Who Ruined Gamers' Christmas Gets 27 Months in Prison

Read more — https://thehackernews.com/2019/07/christmas-ddos-attacks.html

He has also been ordered to pay $95,000 in damages to Daybreak Games, previously known as Sony Online Entertainment.
Beware ➤ 17-Year-Old weakness in Firefox browser could allow downloaded HTML files to access other sensitive files stored on a victim's computer and send data back to remote attackers.

https://thehackernews.com/2019/07/firefox-same-origin-policy-hacking.html

Researcher successfully weaponized the issue and demonstrated PoC.
Official GitHub account of Canonical—the company behind Ubuntu Linux project—gets hacked.

Read more ➤ https://thehackernews.com/2019/07/canonical-ubuntu-github-hacked.html