The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to admin@thehackernews.com

  • CISA and FDA Warn of Critical Backdoor in Contec CMS8000 Patient Monitors
    by info@thehackernews.com (The Hacker News) on January 31, 2025 at 1:10 pm

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) and the Food and Drug Administration (FDA) have issued alerts about the presence of hidden functionality in Contec CMS8000 patient monitors and Epsimed MN-120 patient monitors. The vulnerability, tracked as CVE-2025-0626, carries a CVSS v4 score of 7.7 on a scale of 10.0. The flaw, alongside two other issues, was reported to CISA

  • Top 5 AI-Powered Social Engineering Attacks
    by info@thehackernews.com (The Hacker News) on January 31, 2025 at 11:15 am

    Social engineering has long been an effective tactic because of how it focuses on human vulnerabilities. There’s no brute-force ‘spray and pray’ password guessing. No scouring systems for unpatched software. Instead, it simply relies on manipulating emotions such as trust, fear, and respect for authority, usually with the goal of gaining access to sensitive information or protected systems.

  • Italy Bans Chinese DeepSeek AI Over Data Privacy and Ethical Concerns
    by info@thehackernews.com (The Hacker News) on January 31, 2025 at 11:04 am

    Italy’s data protection watchdog has blocked Chinese artificial intelligence (AI) firm DeepSeek’s service within the country, citing a lack of information on its use of users’ personal data. The development comes days after the authority, the Garante, sent a series of questions to DeepSeek, asking about its data handling practices and where it obtained its training data. In particular, it wanted

  • Google Bans 158,000 Malicious Android App Developer Accounts in 2024
    by info@thehackernews.com (The Hacker News) on January 31, 2025 at 10:45 am

    Google said it blocked over 2.36 million policy-violating Android apps from being published to the Google Play app marketplace in 2024 and banned more than 158,000 bad developer accounts that attempted to publish such harmful apps. The tech giant also noted it prevented 1.3 million apps from getting excessive or unnecessary access to sensitive user data during the time period by working with

  • Broadcom Patches VMware Aria Flaws – Exploits May Lead to Credential Theft
    by info@thehackernews.com (The Hacker News) on January 31, 2025 at 5:49 am

    Broadcom has released security updates to patch five security flaws impacting VMware Aria Operations and Aria Operations for Logs, warning customers that attackers could exploit them to gain elevated access or obtain sensitive information. The list of identified flaws, which impact versions 8.x of the software, is below – CVE-2025-22218 (CVSS score: 8.5) – A malicious actor with View Only Admin


Threatpost The First Stop For Security News