The Hacker News
151K subscribers
1.85K photos
10 videos
3 files
7.77K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
💻🔒 Beware of the latest phishing attack! Attackers are using Microsoft Word docs to spread malware like Agent Tesla, OriginBotnet, and RedLine Clipper.

Learn more about this threat: https://thehackernews.com/2023/09/sophisticated-phishing-campaign.html
🔥20🤯9👍3🤔3😁2
🚨 New GitHub Security Alert!

A race condition vulnerability in GitHub could have over 4,000 code packages to repojacking attacks! Learn how this threat could have impacted the open-source community.

Read: https://thehackernews.com/2023/09/critical-github-vulnerability-exposes.html
👍17😱13🔥8
Your SaaS apps could be a breeding ground for cyber threats.

Find out how CISOs and IT teams are prioritizing SaaS security in this comprehensive article.

Read: https://thehackernews.com/2023/09/7-steps-to-kickstart-your-saas-security.html
👍23👏2😁2🔥1
⚠️ Critical Security Update: Mozilla is urgently fixing a zero-day vulnerability (CVE-2023-4863), actively exploited in browsers. It can be triggered by tricking victims into opening a malicious WebP image.

Read: https://thehackernews.com/2023/09/mozilla-rushes-to-patch-webp-critical.html
😱24👍13😁9🤯6👏5
⚠️ Urgent: Adobe's September 2023 update addresses a new zero-day vulnerability (CVE-2023-26369) in Acrobat and Reader that attackers are exploiting in the wild.

Read: https://thehackernews.com/2023/09/update-adobe-acrobat-and-reader-to.html
🔥14🤯7👍4😁4
⚡️September 2023 Patch Tuesday — Microsoft addresses 59 bugs, including actively exploited zero-day flaws.

Read: https://thehackernews.com/2023/09/microsoft-releases-patch-for-two-new.html
👍1211🤯9🔥5😱2
Microsoft sounds the alarm on Storm-0324's tactics, luring its prey through Teams messages to breach corporate networks.

Read: https://thehackernews.com/2023/09/microsoft-warns-of-new-phishing.html
👍13😁4
The New Battlefield: Cyberattacks have transformed warfare, with nations like Russia, China, and North Korea wielding digital weapons. Explore the tactics, threats, and global implications of this evolving digital force.

Read: https://thehackernews.com/2023/09/how-cyberattacks-are-transforming.html
👍14😁82🔥2🤔1🤯1
A new ransomware, 3AM, has emerged! It's written in Rust and aims to encrypt files while deleting Volume Shadow copies.

Read: https://thehackernews.com/2023/09/rust-written-3am-ransomware-sneak-peek.html
🔥26👍8😁32
Microsoft Azure HDInsight service had 8 XSS vulnerabilities. Learn how they could lead to data breaches, session hijacking attacks, and impact your organization.

Read: https://thehackernews.com/2023/09/researchers-detail-8-vulnerabilities-in.html
👏9👍4🤔3🔥2😁1
Identity is the New Endpoint: Mastering SaaS Security in the Modern Age

Dive deep into the future of SaaS security with Maor Bin, CEO of Adaptive Shield. Discover why identity is the new endpoint.

Secure your spot now: https://thehackernews.com/2023/09/webinar-identity-threat-detection.html
👍17🤔9🔥4😁2🤯1
Russian journalist Galina Timchenko's iPhone was hacked with NSO Group's Pegasus spyware, using a zero-click exploit known as PWNYOURHOME.

Read: https://thehackernews.com/2023/09/russian-journalists-iphone-compromised.html
😱38😁14🤯13👍6👏64🔥4🤔2
A high-severity Time-of-Check to Time-of-Use (TOCTOU) (CVE-2023-27470) in N-Able's Take Control Agent could give hackers SYSTEM privileges.

Find out how it works: https://thehackernews.com/2023/09/n-ables-take-control-agent.html
🔥15👍9🤯4😱2😁1
🚨 Attention Linux and macOS users!

Critical vulnerabilities in the ncurses library have been discovered. Find out how threat actors could elevate privileges and run malicious code.

Details: https://thehackernews.com/2023/09/microsoft-uncovers-flaws-in-ncurses.html
🔥16👍7👏4😁4😱4
Linux Users Beware: A stealthy supply chain attack went undetected for 3+ years, stealing passwords and more.

Learn how a trusted "Free Download Manager" site turned malicious and distributed malware.

Read: https://thehackernews.com/2023/09/free-download-manager-site-compromised.html
🤯20👍10🔥10👏1😁1😱1
🔒 Secure offboarding is essential in today's IT landscape. Learn about common pitfalls and how to avoid them in this must-read article.

Read: https://thehackernews.com/2023/09/avoid-these-5-it-offboarding-pitfalls.html
👍10😁8🔥2
🚨 Critical security flaws discovered in Kubernetes could lead to remote code execution with elevated privileges on Windows endpoints within a cluster.

Learn more about CVE-2023-3676, CVE-2023-3893, and CVE-2023-3955: https://thehackernews.com/2023/09/alert-new-kubernetes-vulnerabilities.html
🔥21👍13🤯12😁7
Microsoft reveals Iranian nation-state actors' password spray attacks targeting the satellite, defense, and pharmaceutical sectors globally.

Learn more about this: https://thehackernews.com/2023/09/iranian-nation-state-actors-employ.html
😁2513👍12🤔7🤯4
Cybercriminals behind RedLine and Vidar info-stealers have shifted their focus towards ransomware, employing phishing campaigns and leveraging Extended Validation (EV) code signing certificates.

Read details: https://thehackernews.com/2023/09/cybercriminals-combine-phishing-and-ev.html
👍26👏5😁3🤔2
⚠️ Attention Facebook Business Users: Python-based NodeStealer #malware has returned. It now targets multiple web browsers to maliciously take over accounts.

Read: https://thehackernews.com/2023/09/nodestealer-malware-now-targets.html
👍17🤯9👏5😁4