The Hacker News
βœ”
151K subscribers
1.83K photos
9 videos
3 files
7.74K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
Critical Unauthorized RCE Vulnerability (CVE-2020-5902 with CVSS Score 10/10) Affects F5's BIG-IP Application Security Servers Used in large Enterprises, Data Centers, and Cloud Computing Environments.

Details β€” https://thehackernews.com/2020/07/f5-big-ip-application-security.html

Apply Newly Released Patch Updates ASAP!
< Project Freta πŸ”₯ >

Microsoft launches a new free, cloud-based Linux forensics tool that analyzes virtual machine (VM) snapshots for evidence of sabotage β€” including rootkits, kernel-level compromises & other advanced malware.

Read Details: https://thehackernews.com/2020/07/microsoft-linux-forensics-rootkit.html
Citrix Releases Critical Software Patches for 11 New Security Vulnerabilities Affecting ADC, Gateway, and SD-WAN WANOP Appliances.

Read More: https://thehackernews.com/2020/07/citrix-software-security-update.html
WATCH OUT!

Eleven new innocent-looking Android apps loaded with 'billing fraud' Joker malware ONCE AGAIN bypass Google's security protections, aiming to infect millions via Play Store.

Read more: https://thehackernews.com/2020/07/joker-android-mobile-virus.html
Considering the broken state of certificate revocation process & related safety checks, Firefox has updated #Mozilla’s Root Store Policy to reduce the maximum lifetime of TLS certificates from 825 days to 398 days to protect HTTPS connections.

https://blog.mozilla.org/security/2020/07/09/reducing-tls-certificate-lifespans-to-398-days/
An unpatched critical zero-day arbitrary code execution vulnerability has been discovered in Zoom video conferencing software exploitable on Microsoft Windows 7 or older operating system.

Details: https://thehackernews.com/2020/07/zoom-windows-security.html
WARNING β€” Dear Indian TikTokers, if you now have an account on πŸ”₯ Chingari, THEN BEWARE! Anyone in seconds can HIJACK your Chingari account.

Details: https://thehackernews.com/2020/07/hack-chingari-app-account.html

Like the 'Mitron' app (another viral TikTok clone), Chingari also suffers from an auth bypass flaw.
A newly disclosed highly-critical vulnerability (CVE-2020-6287 with CVSS score 10 out of 10) residing in SAP's Java-based solutions could let attackers compromise affected corporate servers.

https://thehackernews.com/2020/07/sap-netweaver-vulnerability.html

Patches are now available.
Adobe is today rolling out its July 2020 set of critical security patches for 13 new software vulnerabilities affecting:

βœ… Creative Cloud Desktop App
βœ… Media Encoder
βœ… Genuine Service
βœ… ColdFusion
βœ… Download Manager

Story β€” https://thehackernews.com/2020/07/adobe-security-patch-july.html
WARNING πŸ”₯ CVE-2020-1350 (CVSS 10)

A critical 17-year-old 'wormable' RCE vulnerability affects Windows DNS Servers (2013 to 2019 editions) that could let unauthenticated hackers gain 'Domain Admin' privileges on the targeted servers.

Researchers confirm the new Windows vulnerability, dubbed 'SigRed,' is a wormable bug, allowing attackers to launch #malware attacks that can spread from one vulnerable computer to another without any human interaction.

Details β€” https://thehackernews.com/2020/07/windows-dns-server-hacking.html
Wait, we're not yet done with this month's Patch Tuesday!

Oracle releases critical updates for 443 new vulnerabilities affecting dozens of its software products, out of which at least 120 bugs have scored 8 or above out of 10 on the CVSS severity scale.

https://www.oracle.com/security-alerts/cpujul2020.html
Apache today released updated versions of Tomcat Server to patch two DoS vulnerabilities residing in the WebSocket (CVE-2020-13935) and HTTP/2 (CVE-2020-13934) implementations.

http://mail-archives.us.apache.org/mod_mbox/www-announce/202007.mbox/%3C39e4200c-6f4e-b85d-fe4b-a9c2bd5fdc3d%40apache.org%3E

http://mail-archives.us.apache.org/mod_mbox/www-announce/202007.mbox/%3Cad62f54e-8fd7-e326-25f1-3bdf1ffa3818%40apache.org%3E
⚑ Watch Out!

Local Brazilian hackers have upgraded at least 4 large banking malware families (Guildma, Javali, Melcoz, Grandoreiro) to rob users across the globe.

https://thehackernews.com/2020/07/brazilian-banking-trojan.html

New variants are modular, obfuscated, bypass detection, & use complex execution flow.
Cisco just released the latest security advisories describing 33 new vulnerabilities affecting multiple products, out of which:

βœ… 5 are CRITICAL (with CVSS score 9.8),
βœ… 12 are HIGH, and
βœ… 16 are important.

https://tools.cisco.com/security/center/publicationListing.x?product=Cisco&sort=-day_sir#~Vulnerabilities
Stay Calm, and Patch 'Em All!

βœ… Microsoft
βœ… Cisco
βœ… Juniper
βœ… Oracle
βœ… Zoom
βœ… Citrix
βœ… SAP
βœ… F5
βœ… Intel
βœ… Adobe
βœ… Jenkins
βœ… NVIDIA
βœ… Apache
βœ… Chrome
βœ… Android
βœ… VMware
βœ… Siemens
βœ… Rust Lang Crates
βœ… Go programming

Happy Patch Week, Everyone.
πŸ‘1
WATCH OUT β€” Many top cryptocurrency-related verified Twitter accounts got compromised and a few minutes ago simultaneously tweeted an identical "Crypto For Health" SCAM message.

Hacked people & organizations include Gemini, Binance, Binance's CEO, KuCoin, Coinbase, CoinDesk.
THE BIGGEST HACK IN TWITTER'S HISTORY

List of hacked accounts:

- Jeff Bezos
- Elon Musk
- Warren Buffett
- Barack Obama
- Michael Bloomberg
- Kanye West
- Wiz Khalifa
- Apple
- Uber
- JoeBiden
- Bitcoin
- Coinbase
- Binance
- Gemini
- Kucoin
- Coindesk
- Ripple
- Justin Sun
- Charlee Lee
- SatoshiLite

And more...
πŸ‘4
Apple releases:

βœ… iOS 13.6
βœ… iPadOS 13.6
βœ… macOS 10.15.6
βœ… tvOS 13.4.8
βœ… watchOS 6.2.8

Of course, with dozens of new security patches.

Details: https://support.apple.com/en-in/HT201222
πŸ‘1