The Hacker News
โœ”
151K subscribers
1.85K photos
10 videos
3 files
7.76K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: admin@thehackernews.com

๐ŸŒ Website: https://thehackernews.com
Download Telegram
Researchers found a vulnerability in AI-as-a-service provider "Replicate" that could allow unauthorized access to proprietary AI models and sensitive data.

Read: https://thehackernews.com/2024/05/experts-find-flaw-in-replicate-ai.html

The issue stemmed from the arbitrary code execution potential in AI model packaging.
๐Ÿ‘22๐Ÿ”ฅ10๐Ÿ˜7โšก5
Indian government, defense, and aerospace sectors targeted by Pakistan-nexus actor Transparent Tribe using cross-platform malware written in Python, Golang, and Rust.

Learn about the new set of attacks: https://thehackernews.com/2024/05/pakistan-linked-hackers-deploy-python.html
๐Ÿ”ฅ17โšก8๐Ÿ‘3๐Ÿ˜3๐Ÿคฏ3๐Ÿ‘1
๐Ÿšจ Experts have uncovered phishing campaigns using HTML smuggling, DNS tunneling, generative AI, PhaaS toolkits, malvertising, and Cloudflare Workers to serve malicious sites targeting Microsoft and Gmail credentials.

Find out more: https://thehackernews.com/2024/05/new-tricks-in-phishing-playbook.html
๐Ÿ”ฅ17๐Ÿ‘5
๐Ÿšจ Cyber Alert: #Microsoft highlights Morocco-based Storm-0539, stealing up to $100,000/day in gift card fraud.

๐Ÿ”— Discover the full story: https://thehackernews.com/2024/05/moroccan-cybercrime-group-steals-up-to.html
๐Ÿ˜11๐Ÿ”ฅ8๐Ÿ‘6๐Ÿ‘2โšก1
๐Ÿšจ 83% of organizations have fallen victim to phishing. Itโ€™s time to rethink our security strategies. Discover innovative solutions that inspect web sessions and neutralize threats in real-time.

Read the full report: https://thehackernews.com/2024/05/report-dark-side-of-phishing-protection.html
๐Ÿค”12๐Ÿ”ฅ9๐Ÿ‘6๐Ÿ˜3โšก1๐Ÿ‘1
๐Ÿšจ Critical Alert: TP-Link Archer C5400X ๐ŸŽฎ Gaming Router Vulnerability.

๐Ÿšฆ Severity: Maximum (CVSS 10.0)

๐Ÿ›ก๏ธ Impact: Remote code execution Patch available: Firmware version 1_1.1.7 Protect your network, update now!

Read more: https://thehackernews.com/2024/05/tp-link-gaming-router-vulnerability.html
๐Ÿ”ฅ18๐Ÿ˜ฑ10๐Ÿ˜6๐Ÿ‘5โšก2๐Ÿ‘2
Unknown threat actors are targeting WordPress sites with a new attack vector, using the Dessky Snippets plugin to insert malicious PHP code and harvest credit card data.

Read More ๐Ÿ‘‰ https://thehackernews.com/2024/05/wordpress-plugin-exploited-to-steal.html
๐Ÿ˜ฑ15โšก4๐Ÿ‘3
Dual Threat: CatDDoS & DNSBomb!

๐Ÿฑ CatDDoS botnet exploits 80+ vulnerabilities, targeting 300+ devices daily for DDoS attacks.

๐Ÿ’ฃ DNSBomb, a new attack technique, achieves a 20,000x amplification in PDoS attacks.

Read the full story: https://thehackernews.com/2024/05/researchers-warn-of-catddos-botnet-and.html
๐Ÿค”14๐Ÿคฏ10๐Ÿ‘6โšก3
Special deals from the ANYRUN interactive malware sandbox ๐ŸŽ

New and existing clients can receive:
โœ… 6 months of free service
โœ… Additional licenses for team members

Get it until May 31 โžก๏ธ https://thn.news/anyrun-sandbox
๐Ÿ‘12๐Ÿคฏ5๐Ÿ˜2๐Ÿ‘1
๐Ÿ”’ With endless cyber threats, the 'spray 'n pray' approach is costing you big time. Discover the secret to prioritizing your resources and efforts on what truly matters.

Donโ€™t miss out โ€“ read the full article now: https://thehackernews.com/2024/05/4-step-approach-to-mapping-and-securing.html
๐Ÿ”ฅ14๐Ÿ‘4๐Ÿค”1
๐Ÿ’ธ Indian national pleads guilty to stealing over $37M through fake Coinbase website.

In separate cases, a Ukrainian arrested for aiding North Korean IT workers; Vietnamese charged for helping Chinese remote IT workers commit wire fraud.

Read: https://thehackernews.com/2024/05/indian-national-pleads-guilty-to-37.html
๐Ÿคฏ23๐Ÿ˜7๐Ÿ‘5๐Ÿ˜ฑ5๐Ÿ”ฅ1
๐Ÿšจ BreachForums domain is back online just 2 weeks after a law enforcement takedown!

Trap or blunder?

Learn more: https://thehackernews.com/2024/05/breachforums-returns-just-weeks-after.html

It's now selling: 1.3 TB database with 560M Ticketmaster customers' data for $500K!
๐Ÿ‘27๐Ÿ˜7๐Ÿ”ฅ6โšก4๐Ÿค”2
Microsoft uncovers Moonstone Sleet, a new North Korean hacker group targeting various sectors with ransomware and custom malware, using fake companies and tools to infiltrate targets.

Details here: https://thehackernews.com/2024/05/microsoft-uncovers-moonstone-sleet-new.html
๐Ÿ‘11๐Ÿ”ฅ7๐Ÿ‘4
๐Ÿ’ป Malachi Mullings, a 31-year-old from Georgia, has been sentenced to 10 years for laundering $4.5 million through BEC and ๐Ÿ’” romance scams.

Learn how they pulled off the scam: https://thehackernews.com/2024/05/us-sentences-31-year-old-to-10-years.html
๐Ÿ˜15๐Ÿ‘9๐Ÿ”ฅ6๐Ÿ‘6
๐ŸŽ‰ Introducing GRC Mastery โ€” Cyber Security GRC Training for beginners.

๐Ÿ“ฝ๏ธ Video modules, assessments, quizzes.
๐Ÿ† Master risk management, audit, compliance, asset management.
๐Ÿ”ญ Capstone Project: NIST assessment.
๐ŸŽ“ Earn a certificate.

Check it out: https://grcmastery.com
๐Ÿ”ฅ14๐Ÿ‘11๐Ÿค”2๐Ÿ‘1
๐Ÿ‡ง๐Ÿ‡ท๐Ÿ’ฐ New campaign targets Brazilian banks with AllaSenha, a custom AllaKore RAT variant. The malware steals banking credentials and uses Azure cloud for C2.

Learn more: https://thehackernews.com/2024/05/brazilian-banks-targeted-by-new.html
๐Ÿ”ฅ15๐Ÿ‘2๐Ÿค”1
๐Ÿšจ Attention: Check Point discovers zero-day vulnerability CVE-2024-24919 in Network Security VPN gateway products, exploited in the wild.

Read more here: https://thehackernews.com/2024/05/check-point-warns-of-zero-day-attacks.html

๐Ÿ”ง Ensure your systems are patched with the latest hotfixes.
๐Ÿคฏ15๐Ÿ‘11๐Ÿ˜ฑ4๐Ÿค”2๐Ÿ˜1
Employee offboarding is crucial for security. 63% of businesses may have ex-employees with data access. Automate SaaS security to reduce risks.

Learn more at: https://thehackernews.com/2024/05/new-research-warns-about-weak.html
๐Ÿค”9๐Ÿ‘7๐Ÿ”ฅ2
A malicious Python package, pytoileur, has been found in PyPI, aiming at cryptocurrency theft. Downloaded 316 times and re-uploaded after removal, this highlights significant risks in open-source ecosystems.

Learn more: https://thehackernews.com/2024/05/cybercriminals-abuse-stackoverflow-to.html
๐Ÿคฏ13๐Ÿ‘12โšก4๐Ÿ˜ฑ4๐Ÿ˜1
๐Ÿšจ Warning: Okta warns of a vulnerability in the cross-origin authentication feature of their Customer Identity Cloud (CIC) that attackers are increasingly exploiting for credential stuffing attacks.

Learn more: https://thehackernews.com/2024/05/okta-warns-of-credential-stuffing.html
๐Ÿค”10๐Ÿ‘9๐Ÿคฏ2