The Hacker News
βœ”
151K subscribers
1.82K photos
9 videos
3 files
7.73K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
Identity security is evolving from mere access management to a strategic business necessity.

Explore the critical state of identity security post-breach, highlighting risks and strategic insights for cybersecurity professionals.

Read: https://thehackernews.com/2024/10/permiso-state-of-identity-security-2024.html
πŸ‘5πŸ‘3⚑2🀯1
⚠️ New variants of Grandoreiro banking malware are evolving, targeting 1,700 financial institutions in 45 countries, and employing tactics like mouse tracking and CAPTCHA barriers, despite law enforcement efforts.

Read: https://thehackernews.com/2024/10/new-grandoreiro-banking-malware.html
😁15πŸ”₯3πŸ€”3⚑2πŸ‘1
🚨 Fortinet confirms a critical vulnerability (CVE-2024-47575 / CVSS 9.8) affecting FortiManager is being actively exploited!

It could allow unauthorized remote access, potentially compromising sensitive data & configurations.

https://thehackernews.com/2024/10/fortinet-warns-of-critical.html

Don't waitβ€”patch now.
πŸ‘17πŸ”₯6πŸ‘3😁1
North Korea's Lazarus Group exploits a zero-day #vulnerability (CVE-2024-4947) in Google Chrome to target the #cryptocurrency sector.

Exploitation strategy involved social media manipulation and fake game promotions.

Learn more: https://thehackernews.com/2024/10/lazarus-group-exploits-google-chrome.html
πŸ”₯15πŸ‘10🀯4
Cisco has patched CVE-2024-20481, a #vulnerability affecting its ASA and Firepower devices that could lead to a denial-of-service (DoS) for Remote Access VPNs.

Learn more: https://thehackernews.com/2024/10/cisco-issues-urgent-fix-for-asa-and-ftd.html
πŸ‘7πŸ”₯7πŸ‘3😁1
Researchers identified a #vulnerability in AWS CDK that may lead to account takeover, with over 1% of users at risk from predictable S3 bucket names.

The solution: update your CDK version and customize bucket names.

Read: https://thehackernews.com/2024/10/aws-cloud-development-kit-vulnerability.html
πŸ‘10πŸ€”5πŸ”₯4😁3
Generative AI is revolutionizing phishing attacks, posing new challenges for #cybersecurity professionals.

Discover how to combat this evolving threat.

Read β†’ https://thehackernews.com/2024/10/why-phishing-resistant-mfa-is-no-longer.html
😁10πŸ”₯6πŸ‘4πŸ€”4🀯3
A new advanced Qilin #ransomware variant, Qilin.B, features enhanced AES-256-CTR and RSA-4096 encryption, making recovery nearly impossible without the attackers' keys.

Read β†’ https://thehackernews.com/2024/10/new-qilinb-ransomware-variant-emerges.html
πŸ‘8πŸ”₯8⚑3πŸ‘3
βš–οΈ LinkedIn has been fined €310 million for breaching GDPR regulations concerning user #privacy.

DPC found #LinkedIn's processing lacked necessary user consent and transparency, which could set a precedent for other companies.

Read β†’ https://thehackernews.com/2024/10/irish-watchdog-imposes-record-310.html
πŸ‘24😁18πŸ‘9πŸ”₯8
The SEC penalizes four companiesβ€”Avaya, Check Point, Mimecast, and Unisysβ€”for misleading investors following the 2020 SolarWinds cyberattack.

Learn more: https://thehackernews.com/2024/10/sec-charges-4-companies-over-misleading.html
πŸ‘9πŸ‘9
πŸ”’ Apple has launched its Private Cloud Compute Virtual Research Environment (VRE) for security researchers to validate its #privacy and security claims.

It offers rewards between $50,000 and $1,000,000 for identifying flaws.

Read: https://thehackernews.com/2024/10/apple-opens-pcc-source-code-for.html
πŸ”₯19🀯10πŸ‘7πŸ‘4😱4😁3
Attention: CVE-2024-41992 #vulnerability in Wi-Fi Test Suite could give attackers full control over Arcadyan routers. The flaw allows for command injection, enabling full administrative access.

Find details here β†’ https://thehackernews.com/2024/10/researchers-discover-command-injection.html
🀯12😁10⚑3πŸ‘2
🚨 Four members of the notorious REvil ransomware gang have been sentenced in Russia, a rare conviction in the cybercrime world.

Read πŸ‘‰ https://thehackernews.com/2024/10/four-revil-ransomware-members-sentenced.html
πŸ”₯20🀯1
⚠️ CERT-UA warns of a sophisticated email attack using RDP files to breach sensitive systems in Ukraine.

Read: https://thehackernews.com/2024/10/cert-ua-identifies-malicious-rdp-files.html
πŸ”₯9πŸ‘6😁5
Explore the rise of AI impersonation fraud and its implications for cybersecurity.

Learn how to safeguard your organization against these emerging threats.

Read: https://thehackernews.com/2024/10/eliminating-ai-deepfake-threats-is-your.html
πŸ‘13πŸ”₯7
TeamTNT shifts tactics to target Docker environments for #cryptocurrency mining by exploiting exposed daemons to deploy malware and cryptominers.

Read: https://thehackernews.com/2024/10/notorious-hacker-group-teamtnt-launches.html
πŸ‘11πŸ€”7πŸ‘3
A new attack technique bypasses Microsoft's Driver Signature Enforcement on fully patched Windows systems, enabling attackers to load unsigned kernel drivers and compromising the integrity of OS security.

Learn more: https://thehackernews.com/2024/10/researchers-uncover-os-downgrade.html
πŸ”₯15😁12🀯10πŸ‘6πŸ‘2
A staggering 10-fold increase in phishing pages created with Webflow has been observed, targeting over 120 organizations globally.

Discover how to stay ahead of evolving threats: https://thehackernews.com/2024/10/cybercriminals-use-webflow-to-deceive.html
πŸ‘12πŸ”₯8πŸ‘2
πŸ¦Ήβ€β™‚οΈ AI manipulation, 🌩️ cloud storage flaws, and a major πŸ’£ AWS vulnerability - this week's cybersecurity recap is packed!

https://thehackernews.com/2024/10/thn-cybersecurity-recap-top-threats_28.html

Don't let your friends and colleagues fall victim to the latest cyber threats. Share this newsletter with them, it's a must-read!
πŸ‘12πŸ”₯5
⚠️ Alert for developers - Three packages found to contain the BeaverTail #malware linked to North Korean cyber campaigns.

Find details here: https://thehackernews.com/2024/10/beavertail-malware-resurfaces-in.html
πŸ”₯8⚑2πŸ‘2