The Hacker News
βœ”
151K subscribers
1.78K photos
9 videos
3 files
7.69K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
πŸ” Discover how dynamic malware analysis & real-time interactivity reveal hidden behaviors!

Tools like #AnyRun let #cybersecurity pros monitor DNS/HTTP traffic & export data for deeper analysis with Wireshark.

Learn more: https://thehackernews.com/2024/10/5-must-have-tools-for-effective-dynamic.html
πŸ‘9🀯3😁2
🚨 A critical vulnerability, CosmicSting (CVE-2024-34102), has hit 5% of Adobe Commerce & Magento stores.

7 hacker groups are injecting malicious scripts.

Details here: https://thehackernews.com/2024/10/alert-adobe-commerce-and-magento-stores.html

Patching isn’t enoughβ€”rotate your encryption keys now!
🀯8πŸ‘5πŸ€”4πŸ‘3
🚨 14 vulnerabilities found in DrayTek routers, including 2 critical (CVSS 10.0). These flaws allow attackers to take full control and infiltrate networks.

Read: https://thehackernews.com/2024/10/alert-over-700000-draytek-routers.html

With 704,000+ routers exposed online, the risk is massive. Patch now!
😁9πŸ‘4πŸ”₯3πŸ€”1
⚠️ πŸ” The Hidden Threat in Your Inbox!

A spear-phishing campaign is tricking recruiters into downloading a JavaScript backdoor called More_Eggs through fake resumes.

Learn how to protect your team and avoid costly breaches: https://thehackernews.com/2024/10/fake-job-applications-deliver-dangerous.html
😁11πŸ”₯4⚑2🀯2πŸ‘1
⚠️ New threat alert: CeranaKeeper is targeting Southeast Asia with massive data exfiltration!

Using tools like TONESHELL & PUBLOAD, it evades detection by abusing Dropbox & OneDrive.

Learn more: https://thehackernews.com/2024/10/china-linked-ceranakeeper-targeting.html
😁13πŸ”₯6⚑4πŸ‘1
A global fraud campaign is using fake trading apps like SBI-INT and FINANS INSIGHTS on the Apple & Google Play stores to scam users. These apps passed reviews, deceiving victims.

Read: https://thehackernews.com/2024/10/fake-trading-apps-target-victims.html

Stay alert and protect your funds!
πŸ‘14πŸ”₯4⚑3😁3
πŸ”₯ Critical SQL Injection vulnerability (CVE-2024-29824) in Ivanti EPM is actively exploited!

CVSS 9.6β€”unauthenticated attackers can execute code remotely. Federal agencies must patch by Oct 23.

Find details here: https://thehackernews.com/2024/10/ivanti-endpoint-manager-flaw-actively.html
πŸ€”10⚑7🀯1
Authorities arrested 4 linked to LockBit ransomware, including a suspected developer in France. Aleksandr Ryzhenkov, a high-ranking Evil Corp member and LockBit affiliate, was outed.

Read: https://thehackernews.com/2024/10/lockbit-ransomware-and-evil-corp.html

Operation also exposed Kremlin ties to cybercrime groups.
πŸ”₯16🀯8πŸ‘7πŸ€”4😱4⚑3
INTERPOL cracks down on phishing scams and romance fraud in West Africa under Operation Contender 2.0, emphasizing global cooperation in cybersecurity.

Learn more: https://thehackernews.com/2024/10/interpol-arrests-8-in-major-phishing.html
😁13πŸ‘10
⚠️ North Korean-backed APT37 (aka InkySquid) has been observed delivering a never-before-seen backdoor, VeilShell, as part of stealthy state-sponsored cyberattacks targeting Southeast Asia.

Find details here: https://thehackernews.com/2024/10/north-korean-hackers-using-new.html
😁8πŸ‘3😱3πŸ‘2
πŸ”΄ New stealthy #malware "Perfctl" is hitting Linux servers, running crypto miners & proxyjacking undetected. It exploits Polkit vulnerability (CVE-2021-4043) for privilege escalation & uses a rootkit to evade defense.

Details here: https://thehackernews.com/2024/10/new-perfctl-malware-targets-linux.html
πŸ”₯17πŸ‘3
As non-human identities outnumber human ones, they pose an escalating security risk. Learn why machine identity management is vital for modern cybersecurity.

Read: https://thehackernews.com/2024/10/the-secret-weakness-execs-are.html
πŸ‘9πŸ”₯5πŸ‘2
Google is enhancing Android 14 security on Pixel devices to prevent 2G attacks and protect against baseband exploits. Baseband vulnerabilities expose devices to remote attacks, potentially compromising sensitive data.

Read: https://thehackernews.com/2024/10/android-14-adds-new-security-features.html
πŸ‘33😁6⚑5πŸ‘4πŸ”₯1
A major #vulnerability (CVE-2024-47374) in the LiteSpeed Cache WordPress plugin could allow attackers to execute arbitrary #JavaScript and hijack accounts.

Find details here: https://thehackernews.com/2024/10/wordpress-litespeed-cache-plugin.html

Patch now to protect your site.
πŸ”₯14πŸ‘5😁2
The largest-ever DDoS attack just occurredβ€”3.8 Tbps in just 65 seconds!

Is your CPU capacity prepared to filter massive attack traffic? Attackers leveraged compromised ASUS routers, a serious reminder to address CVE-2024-3080 now.

Read: https://thehackernews.com/2024/10/cloudflare-thwarts-largest-ever-38-tbps.html
πŸ”₯28🀯21πŸ‘5⚑3😁3
The U.S. Department of Justice and #Microsoft have seized 107 domains used by Russia-linked COLDRIVER hackers to launch phishing attacks, frequently targeting experts in Russian affairs, #privacy advocates, and intelligence officials.

Read: https://thehackernews.com/2024/10/us-and-microsoft-seize-107-russian.html
πŸ”₯15😱6πŸ‘4⚑2🀯1
Continuous Threat Exposure Management (CTEM) enables continuous protection by helping you prioritize threats with real-time data.

πŸ”—Learn how CTEM fits into your cybersecurity framework: https://thehackernews.com/2024/10/how-to-get-going-with-ctem-when-you.html
πŸ”₯14πŸ‘9⚑2
Apple has released critical iOS and iPadOS updates addressing a vulnerability (CVE-2024-44204) that could expose your passwords via VoiceOver technology.

Read: https://thehackernews.com/2024/10/apple-releases-critical-ios-and-ipados.html

iPhone XS and later, plus iPads from the Pro, Air, and Mini series, are impacted.
πŸ”₯35πŸ‘11😁10🀯6⚑3πŸ‘3πŸ€”3
Meta hit hard as Europe’s top court restricts #Facebook’s use of personal data for targeted ads, even with user consent.

Read > https://thehackernews.com/2024/10/eu-court-limits-metas-use-of-personal.html

This ruling pushes all companies to adopt more transparent, privacy-first data practices.
πŸ‘43πŸ‘14πŸ”₯6⚑3
🚨 Just dropped the latest Cybersecurity Recap newsletter! Dive into:

β€”Record-breaking DDoS attacks 🌐
β€”Evil Corp & LockBit takedowns πŸ•΅οΈβ€β™‚οΈ
β€”New North Korean malware 🦠
β€”700K+ routers vulnerable to attack 🚨

Read: https://thehackernews.com/2024/10/thn-cybersecurity-recap-top-threats-and.html

Stay secure, stay informed!
πŸ”₯7⚑2πŸ‘1😁1🀯1