The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to [email protected]
- Microsoft Uncovers macOS Vulnerability CVE-2024-44243 Allowing Rootkit Installationby [email protected] (The Hacker News) on 14 January 2025 at 4:53 pm
Microsoft has shed light on a now-patched security flaw impacting Apple macOS that, if successfully exploited, could have allowed an attacker running as "root" to bypass the operating system's System Integrity Protection (SIP) and install malicious kernel drivers by loading third-party kernel extensions. The vulnerability in question is CVE-2024-44243 (CVSS score: 5.5), a medium-severity bug
- Google OAuth Vulnerability Exposes Millions via Failed Startup Domainsby [email protected] (The Hacker News) on 14 January 2025 at 4:38 pm
New research has pulled back the curtain on a "deficiency" in Google's "Sign in with Google" authentication flow that exploits a quirk in domain ownership to gain access to sensitive data. "Google's OAuth login doesn't protect against someone purchasing a failed startup's domain and using it to re-create email accounts for former employees," Truffle Security co-founder and CEO Dylan Ayrey said
- 4 Reasons Your SaaS Attack Surface Can No Longer be Ignoredby [email protected] (The Hacker News) on 14 January 2025 at 10:08 am
What do identity risks, data security risks and third-party risks all have in common? They are all made much worse by SaaS sprawl. Every new SaaS account adds a new identity to secure, a new place where sensitive data can end up, and a new source of third party risk. Learn how you can protect this sprawling attack surface in 2025. What do identity risks, data security risks and third-party
- Illicit HuiOne Telegram Market Surpasses Hydra, Hits $24 Billion in Crypto Transactionsby [email protected] (The Hacker News) on 14 January 2025 at 9:29 am
The Telegram-based online marketplace known as HuiOne Guarantee and its vendors have cumulatively received at least $24 billion in cryptocurrency, dwarfing the now-defunct Hydra to become the largest online illicit marketplace to have ever operated. The figures, released by blockchain analytics firm Elliptic, show that monthly inflows have increased by 51% since July 2024. Huione Guarantee, part
- Zero-Day Vulnerability Suspected in Attacks on Fortinet Firewalls with Exposed Interfacesby [email protected] (The Hacker News) on 14 January 2025 at 9:13 am
Threat hunters are calling attention to a new campaign that has targeted Fortinet FortiGate firewall devices with management interfaces exposed on the public internet. "The campaign involved unauthorized administrative logins on management interfaces of firewalls, creation of new accounts, SSL VPN authentication through those accounts, and various other configuration changes," cybersecurity firm