The Hacker News
βœ”
151K subscribers
1.85K photos
10 videos
3 files
7.76K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
πŸ”‘ Revolutionizing SOCs: Behavioral Analytics is Backβ€”Better than Ever!

Discover how behavioral analytics is transforming SOC incident response, improving speed and accuracy, and reducing resource costs.

Read: https://thehackernews.com/2024/11/5-ways-behavioral-analytics-is.html
πŸ”₯8πŸ‘2πŸ€”2
🚨 Cybercriminals have a new weapon: GoIssue, a tool that targets #GitHub developers with bulk phishing emails.

This method can steal credentials and compromise repositories. With prices slashed, attacks are now more scalable.

Read: https://thehackernews.com/2024/11/new-phishing-tool-goissue-targets.html
πŸ‘6πŸ”₯5😁2😱1
Researchers have identified a #vulnerability in Citrix Virtual Apps that allows unauthenticated RCE through improper deserialization.

Read more: https://thehackernews.com/2024/11/new-flaws-in-citrix-virtual-apps-enable.html

Patches are available, but many organizations may still be exposed if not updated.
πŸ”₯14πŸ‘1
Protect your organization with a Georgetown Master's in Cybersecurity Risk Management. Attend a sample class on November 19.

https://thn.news/cyber-risk-sample-class-ig
πŸ‘12πŸ”₯5⚑3πŸ€”3🀯3😁2πŸ‘1😱1
🚨 Microsoft warns of actively exploited flaws in NTLM (CVE-2024-43451) & Task Scheduler (CVE-2024-49039), allowing NTLMv2 hash disclosure and privilege escalation to restricted RPC functions.

Find details on the November Patch Tuesday update: https://thehackernews.com/2024/11/microsoft-fixes-90-new-vulnerabilities.html
πŸ”₯14πŸ‘5πŸ‘5
The β€œDream Job” campaign isn’t just a scamβ€”it’s a sophisticated cyberattack.

Iranian hacker group TA455 mimics North Korean tactics, using fake job offers to deploy malware in the aerospace sector.

Learn more: https://thehackernews.com/2024/11/iranian-hackers-use-dream-job-lures-to.html
😁11πŸ‘10πŸ”₯6
🚨 OvrC cloud platform’s critical security flaws (CVE up to 9.2) allow attackers to bypass firewalls, hijack devices, and execute arbitrary code on IoT systems, threatening critical infrastructure.

Learn more: https://thehackernews.com/2024/11/ovrc-platform-vulnerabilities-expose.html
πŸ‘11⚑3πŸ‘3😁3
Bitdefender has released a free decryptor for ShrinkLocker, a #ransomware that uses BitLocker to lock files, and can compromise entire networks in under 10 minutes.

Read: https://thehackernews.com/2024/11/free-decryptor-released-for-bitlocker.html
πŸ‘14⚑4πŸ‘3🀯3
🚨 90% of network traffic flows through browsers. This makes them a prime target for cybercriminals. Phishing, data leakage & credential theft are increasing threats.

Check out LayerX’s guide for CISOs on protecting your teams and data.

Read: https://thehackernews.com/2024/11/comprehensive-guide-to-building-strong.html
πŸ‘13⚑5😁1
On November 19, GigaOm Analyst, Paul Stringfellow and Sentra's Director of Product Marketing, David S., will share the latest insights from Gigaom’s recent DSPM report.

This session will spotlight critical factors in choosing a DSPM provider and reveal why DSPM is emerging as a distinct and essential component of modern data security.

Don’t miss this opportunity to learn directly from the experts!

Reserve your spot here πŸ‘‡ https://thn.news/dspm-webinar
πŸ‘13⚑2πŸ€”2🀯2😁1
A threat group aligned with Hamas has expanded its cyber warfare beyond espionage, deploying new disruptive wipers and phishing campaigns targeting Israel.

Learn more: https://thehackernews.com/2024/11/hamas-affiliated-wirte-employs-samecoin.html
πŸ‘26🀯5πŸ€”4⚑3πŸ‘3πŸ”₯1
πŸ”’ Internal vs. External PenTesting: What IT Pros Need to Know!

Cyber threats are up 180% – is your network ready? Regular network pentesting is more important than ever, but do you know the difference between internal vs external pentesting? πŸ€”

β€’ Internal: Tests from the inside, catching insider threats.
β€’ External: Protects your public-facing assets from outside attacks.

Finding weaknesses first = saving $$$, staying compliant, and peace of mind. And with vPenTest, network pen testing is easier and more affordable than ever!

πŸ”— Read more: https://thn.news/network-penetration-testing
πŸ‘8😁7⚑5πŸ”₯2πŸ‘2πŸ€”1
Exploit alert: Russia-linked threat actors have actively exploited the CVE-2024-43451 #vulnerability to deploy Spark RAT, with the potential for significant damage through credential theft.

Read: https://thehackernews.com/2024/11/russian-hackers-exploit-new-ntlm-flaw.html
πŸ‘12πŸ”₯6πŸ‘3⚑2
πŸ›‘ North Korean hackers are back with a new malware campaign targeting macOS. "RustyAttr" leverages extended file attributes to stealthily deliver malicious payloads.

Learn more: https://thehackernews.com/2024/11/new-rustyattr-malware-targets-macos.html
πŸ‘19⚑4πŸ‘2πŸ€”2😁1
A misconfigured TikTok pixel nearly caused a costly GDPR violation for a global travel company, showing how simple oversights can lead to significant fines and reputational damage.

Learn more: https://thehackernews.com/2024/11/tiktok-pixel-privacy-nightmare-new-case.html
πŸ‘7⚑2😁2πŸ€”2😱1
Ransomware is evolvingβ€”targeting local backups & SaaS. Avoid 5 BCDR oversights that leave you exposed. Prioritize immutable backups, automated testing, & threat detection.

Read: https://thehackernews.com/2024/11/5-bcdr-oversights-that-leave-you-exposed-to-ransomware.html

Are you ready to recover?
πŸ‘7⚑3πŸ‘3
πŸ›‘ The rise of cloaking and deepfakes is shaking up cybersecurity.

Google warns that fraudsters are using cloaking tactics to impersonate legitimate sites, leading to scams and malware installs.

Read: https://thehackernews.com/2024/11/google-warns-of-rising-cloaking-scams.html

Stay alert to these evolving threats!
πŸ”₯13πŸ‘4πŸ‘2⚑1
Researchers reveal over 70,000 domains have been hijacked by cybercriminals using a stealthy technique called Sitting Ducks.

This attack targets DNS misconfigurations, making it nearly impossible to detect.

Read: https://thehackernews.com/2024/11/experts-uncover-70000-hijacked-domains.html
πŸ‘12πŸ”₯5⚑3😁3
🚨 Urgent : CISA warns of active exploitation of critical flaws in Palo Alto Networks Expedition OS and SQL services (CVEs 9463 & 9465).

Read: https://thehackernews.com/2024/11/cisa-flags-critical-palo-alto-network.html

These vulnerabilities could lead to severe breaches if not addressed promptly.
😁9πŸ‘8⚑4πŸ‘3
Ilya Lichtenstein sentenced to 5 years for masterminding the 2016 Bitfinex hack, stealing $10.5B in #Bitcoin.

His laundering tactics included crypto mixers and fake identities, highlighting the evolving threat in crypto security.

Read: https://thehackernews.com/2024/11/bitfinex-hacker-sentenced-to-5-years.html
πŸ‘19⚑6😁4πŸ”₯1🀯1