The Hacker News
βœ”
151K subscribers
1.84K photos
10 videos
3 files
7.76K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🚨 Fortinet confirms a critical vulnerability (CVE-2024-47575 / CVSS 9.8) affecting FortiManager is being actively exploited!

It could allow unauthorized remote access, potentially compromising sensitive data & configurations.

https://thehackernews.com/2024/10/fortinet-warns-of-critical.html

Don't waitβ€”patch now.
πŸ‘17πŸ”₯6πŸ‘3😁1
North Korea's Lazarus Group exploits a zero-day #vulnerability (CVE-2024-4947) in Google Chrome to target the #cryptocurrency sector.

Exploitation strategy involved social media manipulation and fake game promotions.

Learn more: https://thehackernews.com/2024/10/lazarus-group-exploits-google-chrome.html
πŸ”₯15πŸ‘10🀯4
Cisco has patched CVE-2024-20481, a #vulnerability affecting its ASA and Firepower devices that could lead to a denial-of-service (DoS) for Remote Access VPNs.

Learn more: https://thehackernews.com/2024/10/cisco-issues-urgent-fix-for-asa-and-ftd.html
πŸ‘7πŸ”₯7πŸ‘3😁1
Researchers identified a #vulnerability in AWS CDK that may lead to account takeover, with over 1% of users at risk from predictable S3 bucket names.

The solution: update your CDK version and customize bucket names.

Read: https://thehackernews.com/2024/10/aws-cloud-development-kit-vulnerability.html
πŸ‘10πŸ€”5πŸ”₯4😁3
Generative AI is revolutionizing phishing attacks, posing new challenges for #cybersecurity professionals.

Discover how to combat this evolving threat.

Read β†’ https://thehackernews.com/2024/10/why-phishing-resistant-mfa-is-no-longer.html
😁10πŸ”₯6πŸ‘4πŸ€”4🀯3
A new advanced Qilin #ransomware variant, Qilin.B, features enhanced AES-256-CTR and RSA-4096 encryption, making recovery nearly impossible without the attackers' keys.

Read β†’ https://thehackernews.com/2024/10/new-qilinb-ransomware-variant-emerges.html
πŸ‘8πŸ”₯8⚑3πŸ‘3
βš–οΈ LinkedIn has been fined €310 million for breaching GDPR regulations concerning user #privacy.

DPC found #LinkedIn's processing lacked necessary user consent and transparency, which could set a precedent for other companies.

Read β†’ https://thehackernews.com/2024/10/irish-watchdog-imposes-record-310.html
πŸ‘24😁18πŸ‘9πŸ”₯8
The SEC penalizes four companiesβ€”Avaya, Check Point, Mimecast, and Unisysβ€”for misleading investors following the 2020 SolarWinds cyberattack.

Learn more: https://thehackernews.com/2024/10/sec-charges-4-companies-over-misleading.html
πŸ‘9πŸ‘9
πŸ”’ Apple has launched its Private Cloud Compute Virtual Research Environment (VRE) for security researchers to validate its #privacy and security claims.

It offers rewards between $50,000 and $1,000,000 for identifying flaws.

Read: https://thehackernews.com/2024/10/apple-opens-pcc-source-code-for.html
πŸ”₯19🀯10πŸ‘7πŸ‘4😱4😁3
Attention: CVE-2024-41992 #vulnerability in Wi-Fi Test Suite could give attackers full control over Arcadyan routers. The flaw allows for command injection, enabling full administrative access.

Find details here β†’ https://thehackernews.com/2024/10/researchers-discover-command-injection.html
🀯12😁10⚑3πŸ‘2
🚨 Four members of the notorious REvil ransomware gang have been sentenced in Russia, a rare conviction in the cybercrime world.

Read πŸ‘‰ https://thehackernews.com/2024/10/four-revil-ransomware-members-sentenced.html
πŸ”₯20🀯1
⚠️ CERT-UA warns of a sophisticated email attack using RDP files to breach sensitive systems in Ukraine.

Read: https://thehackernews.com/2024/10/cert-ua-identifies-malicious-rdp-files.html
πŸ”₯9πŸ‘6😁5
Explore the rise of AI impersonation fraud and its implications for cybersecurity.

Learn how to safeguard your organization against these emerging threats.

Read: https://thehackernews.com/2024/10/eliminating-ai-deepfake-threats-is-your.html
πŸ‘13πŸ”₯7
TeamTNT shifts tactics to target Docker environments for #cryptocurrency mining by exploiting exposed daemons to deploy malware and cryptominers.

Read: https://thehackernews.com/2024/10/notorious-hacker-group-teamtnt-launches.html
πŸ‘11πŸ€”7πŸ‘3
A new attack technique bypasses Microsoft's Driver Signature Enforcement on fully patched Windows systems, enabling attackers to load unsigned kernel drivers and compromising the integrity of OS security.

Learn more: https://thehackernews.com/2024/10/researchers-uncover-os-downgrade.html
πŸ”₯15😁12🀯10πŸ‘6πŸ‘2
A staggering 10-fold increase in phishing pages created with Webflow has been observed, targeting over 120 organizations globally.

Discover how to stay ahead of evolving threats: https://thehackernews.com/2024/10/cybercriminals-use-webflow-to-deceive.html
πŸ‘12πŸ”₯8πŸ‘2
πŸ¦Ήβ€β™‚οΈ AI manipulation, 🌩️ cloud storage flaws, and a major πŸ’£ AWS vulnerability - this week's cybersecurity recap is packed!

https://thehackernews.com/2024/10/thn-cybersecurity-recap-top-threats_28.html

Don't let your friends and colleagues fall victim to the latest cyber threats. Share this newsletter with them, it's a must-read!
πŸ‘12πŸ”₯5
⚠️ Alert for developers - Three packages found to contain the BeaverTail #malware linked to North Korean cyber campaigns.

Find details here: https://thehackernews.com/2024/10/beavertail-malware-resurfaces-in.html
πŸ”₯8⚑2πŸ‘2
⚠️ Russian espionage group UNC5812 is using Telegram to deliver #malware designed to undermine military recruitment in Ukraine.

Threats like SUNSPINNER and CraxsRAT exploit vulnerabilities in #Android and Windows.

Read: https://thehackernews.com/2024/10/russian-espionage-group-targets.html
πŸ‘12⚑5πŸ‘2
🚨 New OT security threats are emerging as ships and cranes become more digital.

Find out how SSH’s PrivX OT Edition can help tackle these challenges in marine and industrial operations.

Read: https://thehackernews.com/2024/10/sailing-seven-seas-securely-from-port.html
πŸ‘7πŸ”₯4