The Hacker News
βœ”
151K subscribers
1.86K photos
10 videos
3 files
7.77K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
SaaS Security breaches often stem from misconfigured settings. Learn how 'SaaS Security on Tap' video series tackles the key concepts.

Watch them here: https://thehackernews.com/2023/10/the-fast-evolution-of-saas-security.html
πŸ‘9πŸ”₯5😁4⚑2
🚨 WinRAR users, be alert! Pro-Russian hackers exploited a recent vulnerability (CVE-2023-38831) in the software. Ensure your version is updated!

Read details: https://thehackernews.com/2023/10/pro-russian-hackers-exploiting-recent.html
πŸ‘36😁13😱6⚑3🀯1
🚨 Cisco alerts about a critical UNPATCHED zero-day security vulnerability (CVE-2023-20198) in its IOS XE software that's under active exploitation.

Learn more: https://thehackernews.com/2023/10/warning-unpatched-cisco-zero-day.html
πŸ‘21🀯6πŸ€”1
Ukraine's CERT-UA discovered threat actors targeting 11 telecom providers between May and September 2023. The attacks caused service interruptions, and they used programs called POEMGATE and POSEIDON to control telecom hosts.

Learn more: https://thehackernews.com/2023/10/cert-ua-reports-11-ukrainian-telecom.html
πŸ‘17πŸ€”7πŸ‘3😁2
🚨 Vulnerabilities Alert β€” Milesight's industrial routers risk unauthorized web interface access, while Titan MFT and Titan SFTP servers face remote superuser threats.

Find details here: https://thehackernews.com/2023/10/experts-warn-of-severe-flaws-affecting.html
πŸ‘19😁3
πŸ”’ Ransomware attacks are evolving rapidly.

From new evasion techniques to targeting high-income organizations, find out how they're adapting in Cyble's Q3 Ransomware Report:

Read: https://thehackernews.com/2023/10/ransomware-attacks-doubled-year-on-year.html
πŸ”₯16πŸ‘7😁1
🚨 Alert β€” Two critical vulnerabilities in open-source CasaOS personal cloud software could allow attackers to gain full control of your system.

Find details here: https://thehackernews.com/2023/10/critical-vulnerabilities-uncovered-in.html
⚑13πŸ‘9πŸ”₯8
πŸ•΅οΈβ€β™‚οΈ Nation-state hackers are turning to Discord. Discover how they're using this social platform for potential cyber-espionage and target critical infrastructure.

Read: https://thehackernews.com/2023/10/discord-playground-for-nation-state.html
πŸ‘30😱10😁4🀯1
D-Link confirms data breach. Low-sensitivity data exposed from an old system due to an employee falling for a phishing attack.

Find details here: https://thehackernews.com/2023/10/d-link-confirms-data-breach-employee.html
🀯13πŸ‘12⚑3😁1
A vulnerability in Synology's DSM has been revealed, allowing attackers to remotely hijack admin accounts.

Learn how to safeguard your data: https://thehackernews.com/2023/10/new-admin-takeover-vulnerability.html
😱14πŸ‘12🀯10πŸ‘3
πŸ€– A sophisticated campaign known as TetrisPhantom is targeting APAC government entities, covertly harvesting sensitive data via secure USB drives.

Read: https://thehackernews.com/2023/10/tetrisphantom-cyber-espionage-via.html

Kaspersky links the mysterious APT actor to attacks on Russian entities.
πŸ‘12⚑9πŸ€”3😁1
πŸ’° Financial data is a digital treasure trove, but it's also a prime target for cybercriminals. Join our cybersecurity webinar to learn how to secure your financial data and ensure compliance.

Reserve your spot nowβ€”it's free: https://thehackernews.com/2023/10/webinar-locking-down-financial-and.html
πŸ‘10πŸ‘3
⚠️ New cyber threat: Discover how Qubitstrike, linked to Tunisia, targets Jupyter Notebooks for cryptocurrency mining and cloud breaches while also employing a sophisticated rootkit malware.

Learn more: https://thehackernews.com/2023/10/qubitstrike-targets-jupyter-notebooks.html
πŸ‘10😁10πŸ€”3
πŸ” Explore 7 real-life attack paths and learn how to tackle them.

Ensure you don't miss out on crucial insights and the power of the Exposure Management Platform for protecting critical assets.

Read: https://thehackernews.com/2023/10/unraveling-real-life-attack-paths-key.html
πŸ‘14😱4
Citrix is warning of active exploitation of a recently disclosed critical security flaw in NetScaler ADC and Gateway appliances that can hijack sessions and bypass multi-factor authentication.

Learn more: https://thehackernews.com/2023/10/critical-citrix-netscaler-flaw.html

Patch immediately and terminate active sessions.
🀯16πŸ‘10
🚨 Korean hacking group Lazarus Group targets defense industry and nuclear engineers with fake job interviews, using trojanized VNC apps to steal data and execute commands.

Learn more: https://thehackernews.com/2023/10/lazarus-group-targeting-defense-experts.html
πŸ”₯30πŸ‘14😁8πŸ‘7⚑3
πŸ•΅οΈβ€β™‚οΈ ALERT: Google TAG security experts uncover Russian and Chinese state-backed threat actors exploiting WinRAR vulnerability (CVE-2023-38831) to infiltrate systems.

Get details here: https://thehackernews.com/2023/10/google-tag-detects-state-backed-threat.html
πŸ‘22😱12⚑2😁1
North Korean threat actors Diamond Sleet and Onyx Sleet are exploiting a critical vulnerability in JetBrains TeamCity to breach servers, deploy #malware, and potentially launch supply chain attacks.

Read: https://thehackernews.com/2023/10/microsoft-warns-of-north-korean-attacks.html
πŸ”₯17😁7πŸ‘6⚑2🀯1
Iran-linked threat actor, OilRig, launched an 8-month cyber campaign targeting a Middle East government. Passwords stolen, files compromised.

Learn more: https://thehackernews.com/2023/10/iran-linked-oilrig-targets-middle-east.html
😁18πŸ‘8⚑4🀯3πŸ”₯1
Google Play Protect now scans apps in real time to detect and block novel Android malware before you install them.

Learn more: https://thehackernews.com/2023/10/google-play-protect-introduces-real.html

This new feature is designed to protect users against polymorphic apps that leverage AI to avoid detection.
πŸ‘42πŸ”₯12πŸ€”9⚑4😁2🀯1