The Hacker News
βœ”
151K subscribers
1.84K photos
9 videos
3 files
7.75K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
What to consider when evaluating tools to help activate & keep up with CTEM?🧐

We got your answers right here⬇️

Check out XM Cyber Buyer’s Guide to Meeting & Maintaining CTEM & start building consistent, actionable exposure remediation plans.

Dowload now: https://thn.news/ctem-buyers-guide
πŸ‘10πŸ”₯2
UPDATE β€” Airbus CERT releases Python scripts to scan for the critical CrushFTP flaw (CVE-2024-4040) that allows remote code execution. The zero-day has been exploited in attacks against U.S. entities.

Check: https://thehackernews.com/2024/04/critical-update-crushftp-zero-day-flaw.html

#infosec
πŸ‘20🀯6😁2⚑1
New stealthy malware campaign exploits 2 ZERO-DAY flaws in Cisco devices, enabling covert data collection & reconnaissance by a state-sponsored actor.

Details: https://thehackernews.com/2024/04/state-sponsored-hackers-exploit-two.html

"Line Runner" and "Line Dancer" implants allow config changes and traffic capture.
πŸ‘16πŸ”₯10⚑1
U.S. Department of Justice arrested two founders of cryptocurrency mixer Samourai, seizing the service, for allegedly enabling over $2 billion in illegal transactions and laundering more than $100 million in criminal proceeds.

Learn more: https://thehackernews.com/2024/04/doj-arrests-founders-of-crypto-mixer.html
🀯18πŸ‘12πŸ€”8⚑1😁1
The new #YARA search tool from AnyRun helps you quickly find relevant threats.

πŸ” Scan the service's public malware database using your own YARA rules to identify matching files. Explore the findings further in the sandbox.

Learn more ➑️ https://thehackernews.uk/yara-malware-search
πŸ”₯17πŸ‘10😁4⚑1
North Korean hackers used fake job offers to deliver a new Trojan called Kaolin RAT. It can change file timestamps and load malware - a gateway to the dangerous FudModule rootkit.

Details here: https://thehackernews.com/2024/04/north-koreas-lazarus-group-deploys-new.html
🀯24πŸ‘11πŸ”₯8⚑1😁1
🚨 Attention WordPress users!

A critical SQL injection vulnerability (CVE-2024-27956) in the WP-Automatic plugin is being actively exploited. With a max severity of 9.9/10, this bug enables site takeovers and malicious activities.

Details: https://thehackernews.com/2024/04/hackers-exploiting-wp-automatic-plugin.html
πŸ‘19😁8🀯8πŸ”₯4⚑2
⚠️ Attention Android users!

A new malware called Brokewell is disguising itself as updates for popular apps like Google Chrome and Klarna. Don't fall for these fake updates.

Click to find out more: https://thehackernews.com/2024/04/new-brokewell-android-malware-spread.html
😁12πŸ‘7⚑2πŸ€”2😱1
πŸ†˜ Attention, Palo Alto Networks users!

A critical vulnerability (CVE-2024-3400) in PAN-OS could expose your systems to remote code execution attacks.

Good news: Hotfixes and remediation steps available.

Read full advisory: https://thehackernews.com/2024/04/palo-alto-networks-outlines-remediation.html
🀯16πŸ‘11πŸ€”3⚑1
πŸ›‘οΈ Did you know 70% of successful breaches begin at the endpoint? Unprotected devices are gateways for devastating cyberattacks.

This guide shares 10 must-know tips, from identifying vulnerabilities to implementing robust security solutions: https://thehackernews.com/2024/04/10-critical-endpoint-security-tips-you.html
πŸ‘13πŸ”₯6⚑1
Multiple severe vulnerabilities discovered in Brocade SANnav SAN management application.

From insecure root access to lack of authentication and encryption, one flaw even allows unauthenticated remote attackers to log in as root!

Read: https://thehackernews.com/2024/04/severe-flaws-disclosed-in-brocade.html
πŸ‘18⚑1
🚨 Developers Beware! A new social engineering scam is on the rise, luring software engineers with fake job interviews only to infect their systems with BeaverTail and InvisibleFerret backdoors malware.

https://thehackernews.com/2024/04/bogus-npm-packages-used-to-trick.html
πŸ€”25πŸ‘12πŸ”₯11😁3⚑1πŸ‘1
Cybersecurity researchers have uncovered a targeted cyber attack against Ukraine that leveraged a 7-year-old Microsoft Office flaw to deploy Cobalt Strike beacons on victims' systems.

Read: https://thehackernews.com/2024/04/ukraine-targeted-in-cyberattack.html
πŸ€”8⚑5πŸ”₯4πŸ‘3😁2
Heads up! Okta is sounding the alarm on an unprecedented spike in credential stuffing attacks targeting online services.

These attacks are powered by readily available tools and stolen credentials.

Details: https://thehackernews.com/2024/04/okta-warns-of-unprecedented-surge-in.html
πŸ‘15⚑8😁2πŸ”₯1
🚨 Multiple vulnerabilities have been discovered in the popular Judge0 online code execution system, putting users at risk of complete system compromise.

Get the details: https://thehackernews.com/2024/04/sandbox-escape-vulnerabilities-in.html
πŸ‘13⚑3πŸ”₯1
Learn how Exposure Management empowers organizations to prioritize the most critical exposures based on their potential impact and proactively strengthen cybersecurity posture.

Read the full article to discover the power of Exposure Management ➑️ https://thehackernews.com/2024/04/navigating-threat-landscape.html
πŸ‘14
πŸ‘¨β€πŸ’»πŸ” A new security vulnerability (CVE-2024-27322) has been discovered in the R programming language. It could allow attackers to execute arbitrary code through malicious RDS files, exposing your projects to supply chain attacks.

Read: https://thehackernews.com/2024/04/new-r-programming-vulnerability-exposes.html
πŸ”₯20πŸ‘11⚑2
🚨 NEW THREAT ALERT!

Cybersecurity researchers have uncovered "Muddling Meerkat" - a sophisticated Chinese threat actor abusing DNS for global reconnaissance since 2019.

Details: https://thehackernews.com/2024/04/china-linked-muddling-meerkat-hijacks.html
🀯16πŸ‘8πŸ€”4😁2⚑1
Just in! Google is tightening the screws on bad actors:

200K app submissions rejected
333K bad accounts blocked
2.28 million policy-violating apps prevented
31 SDKs impacting 790,000+ apps had data access limited
1.5 million outdated apps removed

https://thehackernews.com/2024/04/google-prevented-228-million-malicious.html
πŸ‘41πŸ‘30πŸ€”8πŸ”₯3⚑2
πŸ”’ Say goodbye to easily guessable passwords on your smart home devices!

The U.K.'s PSTI act prohibits DEFAULT PASSWORDS from April 2024 onwards. Manufacturers must up their security game or face hefty fines up to Β£10 MILLION.

Read: https://thehackernews.com/2024/04/new-uk-law-bans-default-passwords-on.html
πŸ‘13πŸ”₯13⚑6πŸ‘5😁2