The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.76K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
πŸ’‘ Cyberattacks on SMBs are rising, but many can't afford full-time CISOs. The vCISO model offers a cost-effective solution.

πŸ“š The vCISO Academy by Cynomi equips MSPs & MSSPs with the skills to meet the growing demand.

Learn more: https://thehackernews.com/2024/11/the-vciso-academy-transforming-msps-and.html
πŸ‘13⚑9πŸ‘4
⚠️ Critical "potential" RCE vulnerability in PAN-OS could expose your network to cybercriminals.

Palo Alto Networks advises securing management interfaces ASAP.

πŸ”— Details here: https://thehackernews.com/2024/11/palo-alto-advises-securing-pan-os.html
πŸ‘16⚑12😁8🀯3😱1
⚠️ New phishing campaign spreading Remcos RAT via Excel attachments! It’s a fileless variant, making it even harder to detect.

Read: https://thehackernews.com/2024/11/cybercriminals-use-excel-exploit-to.html

πŸ”’ Update your defenses NOW!
πŸ”₯15πŸ‘6😁5⚑3
🚨 Critical Command Injection Flaws found in Aruba Networking Access Points!

Remote code execution is possibleβ€”CVE-2024-42509 & CVE-2024-47460 threaten your network’s security. Don't wait for an attack!

Read more: https://thehackernews.com/2024/11/hpe-issues-critical-security-patches.html

πŸ‘‰ Patch your devices NOW.
πŸ‘10⚑7😁3
πŸ›‘ Critical vulnerabilities discovered in popular open-source machine learning (ML) tools like Weave, ZenML, and Mage AI.

These flaws could lead to hijacked servers and compromised pipelines.

Read the full report here πŸ‘‰ https://thehackernews.com/2024/11/security-flaws-in-popular-ml-toolkits.html
😱12😁7πŸ‘3πŸ‘2
DTCC cuts breach risks by 11% with Automated Security Validation. Using Pentera, they boosted security, reduced costs, and freed up expert resourcesβ€”without adding staff.

Is your team ahead, or falling behind? πŸ€”

Read how DTCC is leading the way: https://thehackernews.com/2024/11/the-roi-of-security-investments-how.html
⚑5πŸ‘4
🚨 SEO poisoning attack alert! GootLoader malware spreads by exploiting searches like "Are Bengal Cats legal in Australia?"

Read more: https://thehackernews.com/2024/11/new-gootloader-campaign-targets-users.html
πŸ”₯7πŸ‘5😁3
πŸ” Imagine your banking app or car's software secretly turning on you...

This isn't a movie plotβ€”it's the world of cyber in 2024. Dive into this week’s wildest cyber threats and top defense tips in our latest weekly recap.

Read it here: https://thehackernews.com/2024/11/thn-recap-top-cybersecurity-threats_11.html
πŸ‘16πŸ”₯4πŸ‘4
A new ransomware, Ymir, uses advanced memory management tactics to execute malicious code stealthily.

It targeted a Colombian organization after credentials were stolen by RustyStealer.

Read: https://thehackernews.com/2024/11/new-ymir-ransomware-exploits-memory-for.html
πŸ‘12πŸ€”5πŸ”₯4😁2
πŸ›‘οΈ North Korean hackers are using Flutter apps to target macOS with malware, bypassing traditional Apple security through signed developer IDs. Cryptocurrency companies are at risk.

Learn more: https://thehackernews.com/2024/11/north-korean-hackers-target-macos-using.html
😁14🀯8πŸ”₯3πŸ‘1
πŸ”‘ Revolutionizing SOCs: Behavioral Analytics is Backβ€”Better than Ever!

Discover how behavioral analytics is transforming SOC incident response, improving speed and accuracy, and reducing resource costs.

Read: https://thehackernews.com/2024/11/5-ways-behavioral-analytics-is.html
πŸ”₯8πŸ‘2πŸ€”2
🚨 Cybercriminals have a new weapon: GoIssue, a tool that targets #GitHub developers with bulk phishing emails.

This method can steal credentials and compromise repositories. With prices slashed, attacks are now more scalable.

Read: https://thehackernews.com/2024/11/new-phishing-tool-goissue-targets.html
πŸ‘6πŸ”₯5😁2😱1
Researchers have identified a #vulnerability in Citrix Virtual Apps that allows unauthenticated RCE through improper deserialization.

Read more: https://thehackernews.com/2024/11/new-flaws-in-citrix-virtual-apps-enable.html

Patches are available, but many organizations may still be exposed if not updated.
πŸ”₯14πŸ‘1
Protect your organization with a Georgetown Master's in Cybersecurity Risk Management. Attend a sample class on November 19.

https://thn.news/cyber-risk-sample-class-ig
πŸ‘12πŸ”₯5⚑3πŸ€”3🀯3😁2πŸ‘1😱1
🚨 Microsoft warns of actively exploited flaws in NTLM (CVE-2024-43451) & Task Scheduler (CVE-2024-49039), allowing NTLMv2 hash disclosure and privilege escalation to restricted RPC functions.

Find details on the November Patch Tuesday update: https://thehackernews.com/2024/11/microsoft-fixes-90-new-vulnerabilities.html
πŸ”₯14πŸ‘5πŸ‘5
The β€œDream Job” campaign isn’t just a scamβ€”it’s a sophisticated cyberattack.

Iranian hacker group TA455 mimics North Korean tactics, using fake job offers to deploy malware in the aerospace sector.

Learn more: https://thehackernews.com/2024/11/iranian-hackers-use-dream-job-lures-to.html
😁11πŸ‘10πŸ”₯6
🚨 OvrC cloud platform’s critical security flaws (CVE up to 9.2) allow attackers to bypass firewalls, hijack devices, and execute arbitrary code on IoT systems, threatening critical infrastructure.

Learn more: https://thehackernews.com/2024/11/ovrc-platform-vulnerabilities-expose.html
πŸ‘11⚑3πŸ‘3😁3
Bitdefender has released a free decryptor for ShrinkLocker, a #ransomware that uses BitLocker to lock files, and can compromise entire networks in under 10 minutes.

Read: https://thehackernews.com/2024/11/free-decryptor-released-for-bitlocker.html
πŸ‘14⚑4πŸ‘3🀯3
🚨 90% of network traffic flows through browsers. This makes them a prime target for cybercriminals. Phishing, data leakage & credential theft are increasing threats.

Check out LayerX’s guide for CISOs on protecting your teams and data.

Read: https://thehackernews.com/2024/11/comprehensive-guide-to-building-strong.html
πŸ‘13⚑5😁1
On November 19, GigaOm Analyst, Paul Stringfellow and Sentra's Director of Product Marketing, David S., will share the latest insights from Gigaom’s recent DSPM report.

This session will spotlight critical factors in choosing a DSPM provider and reveal why DSPM is emerging as a distinct and essential component of modern data security.

Don’t miss this opportunity to learn directly from the experts!

Reserve your spot here πŸ‘‡ https://thn.news/dspm-webinar
πŸ‘13⚑2πŸ€”2🀯2😁1