The Hacker News
βœ”
151K subscribers
1.78K photos
9 videos
3 files
7.7K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
⚠️ WARNING: Ivanti’s CSA is under attack! Three new zero-day vulnerabilities are being actively exploited in the wild.

These flaws, CVE-2024-9379, CVE-2024-9380, and CVE-2024-9381, allow attackers to bypass restrictions, execute arbitrary SQL, and gain remote code executionβ€”all with admin privileges.

Find details here: https://thehackernews.com/2024/10/zero-day-alert-three-critical-ivanti.html
😁12πŸ‘6πŸ€”5
⚠️ Microsoft warns of cyberattacks abusing OneDrive, SharePoint & Dropbox.

Hackers use β€œliving-off-trusted-sites” (LOTS) to bypass defenses. View-only files trick users into sharing 2FA tokens, leading to BEC & financial fraud.

Learn more: https://thehackernews.com/2024/10/microsoft-detects-growing-use-of-file.html
😱13πŸ‘10⚑1😁1
πŸ‘‰ Microsoft has released patches for 118 vulnerabilities, two of which (CVE-2024-43572 and CVE-2024-43573) are being actively exploited in the wild.

Find details here: https://thehackernews.com/2024/10/microsoft-issues-security-update-fixing.html

Ensure your systems are protectedβ€”apply these patches ASAP!
πŸ€”8πŸ”₯6πŸ‘5😁5πŸ‘4
New IoT regulations may force small manufacturers out of business, despite improving security. With 100+ new vulnerabilities daily, compliance costs are rising fast.

How will this impact cybersecurity? Read: https://thehackernews.com/expert-insights/2024/10/will-small-iot-device-oem-survive.html
😁10πŸ‘4
Social media security is crucial for protecting your brand and finances. Poor governance can lead to unauthorized access and costly mistakes.

Learn how SSPM tools can help safeguard against unauthorized access and financial risks.

Read: https://thehackernews.com/2024/10/social-media-accounts-weak-link-in.html
πŸ€”8πŸ‘5😁2
🚨 Developers Under Attack!

A North Korean campaign, "Contagious Interview," is tricking job seekers with fake offers, leading to malware disguised as coding tasks.

Hackers use fake video conferencing apps to target both Windows & macOS.

Read: https://thehackernews.com/2024/10/n-korean-hackers-use-fake-interviews-to.html
πŸ‘14πŸ”₯4πŸ€”4
⚠️ Multiple MMS protocol vulnerabilities pose a severe threat to industrial devices, potentially leading to crashes or remote code execution that could disrupt critical infrastructure.

Learn more: https://thehackernews.com/2024/10/researchers-uncover-major-security.html

#infosec
πŸ”₯9πŸ‘4πŸ€”2
Google partners with GASA and DNS RF to launch the Global Signal Exchange (GSE), providing real-time insights into scam patterns to protect businesses from cybercrime.

Read: https://thehackernews.com/2024/10/google-joins-forces-with-gasa-and-dns.html
πŸ€”10πŸ‘5πŸ‘1
🚨 Warning: A critical #vulnerability (CVE-2024-9680) in Firefox is being actively exploited.

Don’t waitβ€”ensure your browsers are updated now to protect against potential remote code execution.

Learn more: https://thehackernews.com/2024/10/mozilla-warns-of-active-exploitation-in.html
😱25πŸ‘13🀯6πŸ”₯3😁2πŸ‘1
⚠️ Cyber Alerts:

β€”Fortinet CVE-2024-23113 actively exploited, patch by Oct 30!
β€”Palo Alto Expedition vulnerable to SQL & OS injection.
β€”Cisco patches critical bug in Nexus Dashboard Fabric Controller.

Read: https://thehackernews.com/2024/10/cisa-warns-of-critical-fortinet-flaw-as.html

Critical systems must be patched immediately.
πŸ‘9⚑3πŸ”₯3πŸ€”2
🚨 New "Mongolian Skimmer" uses Unicode obfuscation to steal sensitive data from e-commerce sites!

It disables debugging tools & adapts to browsers, making it highly evasive.

Learn more: https://thehackernews.com/2024/10/cybercriminals-use-unicode-to-hide.html
πŸ‘10πŸ”₯4⚑3😁2🀯1
🧐 SOC Analyst burnout is surging, with 80.8% expecting stress to worsen. AI-driven triage and response can ease the burden, allowing analysts to focus on higher-value tasks.

Discover how AI can lighten the load for your team: https://thehackernews.com/2024/10/6-simple-steps-to-eliminate-soc-analyst.html
πŸ‘16πŸ€”8
A critical unpatched #vulnerability (CVE-2024-9441) in the Nice Linear eMerge E3 access controller has been uncovered, carrying a CVSS score of 9.8, with proof-of-concept exploits already circulating.

Learn more: https://thehackernews.com/2024/10/experts-warn-of-critical-unpatched.html
πŸ‘4😁4⚑1
πŸ‘©β€πŸ’» OpenAI disrupts 20+ global deceptive operations exploiting AI models for advanced cyber activities like phishing, influence operations, and even election interference.

Learn more: https://thehackernews.com/2024/10/openai-blocks-20-global-malicious.html
πŸ”₯9πŸ‘6😁5⚑2πŸ€”2
The digital landscape is shifting fastβ€”are you ready to keep up with the latest threats? 🌐⚑

Join us on October 17 as we break down the key findings from the 2024 Kaseya Cybersecurity Survey! Get insights into:

πŸš€ How AI is transforming cyberattacks
πŸ‘₯ The challenges of user behavior
πŸ›‘οΈ How network penetration testing secure your network
πŸ“ˆ What companies are doing to prepare for 2025

πŸ“… Date: October 17
⏰ Time: 1 PM EST / 10 AM PST
πŸ”— Save Your Spot: https://thn.news/cyber-survey-2024

Don’t miss this session to stay one step ahead in cybersecurity!
πŸ‘9πŸ”₯9⚑1
🌍 Dutch police have dismantled Bohemia and Cannabia, the largest darkweb markets for illegal goods and cybercrime. Arrests in the Netherlands and Ireland, with €8M in seized cryptocurrency, prove dark web anonymity is fading.

Read: https://thehackernews.com/2024/10/bohemia-and-cannabia-dark-web-markets.html
πŸ‘12πŸ‘10😱9πŸ”₯3⚑2🀯1
🚩 A critical security flaw in GitLab (CVE-2024-9164) could allow attackers to run CI/CD pipelines on unauthorized branches.

Find details here: https://thehackernews.com/2024/10/new-critical-gitlab-vulnerability-could.html

Update your instance ASAP to avoid becoming the next victim.
😁17πŸ‘11😱8πŸ”₯4⚑1πŸ€”1
πŸ’»πŸ”’ Cybercriminals are leveling up! Phishing campaigns now exploit GitHub links, Telegram bots, and even QR codes to bypass security and deliver malware.

Read: https://thehackernews.com/2024/10/github-telegram-bots-and-qr-codes.html
⚑20πŸ”₯9πŸ€”8πŸ‘5😁3
πŸ”₯ FBI created its own cryptocurrency token, NexFundAI, to bust widespread market manipulation. Several market makers are charged with wash trading and a pump-and-dump scheme.

Read: https://thehackernews.com/2024/10/fbi-creates-fake-cryptocurrency-to.html
😁54🀯9⚑8πŸ”₯7πŸ‘6πŸ‘5πŸ€”5
Iranian threat actor OilRig is exploiting a Windows Kernel #vulnerability (CVE-2024-30088) to gain SYSTEM privileges, enabling backdoor deployment and data theft.

Learn how to protect your systems now https://thehackernews.com/2024/10/oilrig-exploits-windows-kernel-flaw-in.html
πŸ‘28πŸ”₯10⚑8πŸ€”5😁3🀯2😱1