The Hacker News
151K subscribers
1.84K photos
10 videos
3 files
7.76K links
Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

📨 Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🔥 Researchers detail a recently disclosed Windows MSRPC Printer Spooler Relay vulnerability that can be exploited remotely to execute code on the attacked machine.

Learn more about NTLM Relay to RCE attack: https://thehackernews.com/2021/01/experts-detail-recent-remotely.html
🔥 BEWARE —A new WORMABLE Android malware is spreading automatically through WhatsApp messages by abusing its quick reply functionality in the notifications.

Read details: https://thehackernews.com/2021/01/beware-new-wormable-android-malware.html
Researchers uncover a new privacy vulnerability in TikTok that could have allowed attackers to access users' profile details and private phone numbers associated with their account.

Details: https://thehackernews.com/2021/01/tiktok-bug-could-have-exposed-users.html
An evolving phishing campaign targets high-ranking company executives across manufacturing, real estate, finance, government, and technological sectors to obtain sensitive information.

Read: https://thehackernews.com/2021/01/targeted-phishing-attacks-target-high.html
iPhone Users, BEWARE!


Hackers have been found actively exploiting 3 zero-day security vulnerabilities—affecting iOS, iPadOS, and tvOS—in the wild.


Read details on THN: https://thehackernews.com/2021/01/apple-warns-of-3-ios-zero-day-security.html


Apple has urged its millions of users to update their devices to install the latest security patches.
Fire Watch Out! A new variant of NAT Slipstreaming attack—a technique to bypass routers and firewalls—now could let remote hackers target any device on an internal network from the Internet.

Read details and watch demo: https://thehackernews.com/2021/01/new-attack-could-let-remote-hackers.html
Researchers release PoC for an unpatched Microsoft Azure Function flaw that could let attackers escalate privileges and escape Docker container to the host.

https://thehackernews.com/2021/01/new-docker-container-escape-bug-affects.html
Company says the bug has no security impact as another defense boundary still protects the host.
The world's most dangerous botnet malware—Emotet—has finally been disrupted through a collective operation by law enforcement agencies from as many as 8 countries.

Read — https://thehackernews.com/2021/01/european-authorities-disrupt-emotet.html
Ukrainian police also arrested 2 individuals involved in the Emotet cyberattacks.
U.S. and Bulgarian authorities took control of the dark web infrastructure used by the NetWalker ransomware cybercrime group to publish data stolen from its victims.

Read: https://thehackernews.com/2021/01/authorities-seize-dark-web-site-linked.html
Italy CERT-AGID warns of a new Android malware family that hijacks targeted devices to steal user credentials for different services and can also record audio and video.

Read Details — https://thehackernews.com/2021/01/italy-cert-warns-of-new-credential.html
Lebanese Cedar APT hacker group—linked to Hezbollah Cyber Unit—broke into telecom, hosting providers, communication, IT, and applications companies worldwide.

Read more: https://thehackernews.com/2021/01/hezbollah-hacker-group-targeted.html
Security experts at Google uncover details of a new security feature that Apple quietly added to iOS 14 as a countermeasure to prevent attacks similar to those recently found to leverage zero-days in the messaging app.



https://thehackernews.com/2021/01/google-uncovers-new-ios-security.html
🔥 After early heads-up on a severe #vulnerability in GnuPG's encryption library Libgcrypt, an expert at Google releases details on the potential RCE affecting many projects using the vulnerable library version 1.9.0.

Read: https://thehackernews.com/2021/01/google-discloses-severe-bug-in.html
Watch Out, Sysadmins!

A new cryptojacking malware by Rocke hacking group is leveraging vulnerabilities in Apache ActiveMQ, Oracle WebLogic, and Redis web technologies to hijack cloud infrastructures.
Details: https://thehackernews.com/2021/02/new-cryptojacking-malware-targeting.html
~ Operation NightScout ~

A new software supply-chain attack distributed spyware to potentially millions of Android emulator users running Windows and macOS systems.
Details: https://thehackernews.com/2021/02/a-new-software-supplychain-attack.html
👍1
A critical zero-day vulnerability affecting SonicWall SMA 100 devices—access management gateways for small & mid-sized businesses—has finally been discovered that is actively being exploited in the wild.

Read: https://thehackernews.com/2021/02/hackers-exploiting-critical-zero-day.html
A new data breach exposes the personal information of more than 1.6 million Washington state residents who filed for unemployment claims in 2020.

Read: https://thehackernews.com/2021/02/data-breach-exposes-16-million-jobless.html
Security researchers today uncovered new delivery and evasion techniques adopted by AgentTesla remote access trojan (RAT) to get around defense barriers and monitor its victims.

Details: https://thehackernews.com/2021/02/agent-tesla-malware-spotted-using-new.html
👍1
A newly discovered Linux backdoor — dubbed "Kobalos" — targets high-performance computing clusters, allowing hackers to execute arbitrary commands remotely.



Details: https://thehackernews.com/2021/02/a-new-linux-malware-targeting-high.html