gram news
Аватар канала The Hacker News

The Hacker News

@thehackernews

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

ПроектыENТехнологииПодтверждён Telegram

162,000подписчиков

Открыть канал

Последние посты

  • The Hacker News

    23 сент., 18:08

    Attackers are using malicious Terraform providers to deliver Go malware through HashiCorp’s registry.The malware uses Ethereum smart contracts and Slack as dual C2 channels and can execute Go or JavaScript commands.Inside the supply-chain technique: https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    23 сент., 16:55

    ‼️ You can commit code to a GitLab repo by emailing it.Every GitLab user gets a private address for filing issues. Hidden inside is a non-expiring account token. If that address leaks, someone can send a patch that GitLab commits as you and, with your permissions, target main or trigger CI/CD.Incoming email also bypasses 2FA and IP restrictions.Read: https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    23 сент., 16:07

    ‼️ Two chained SSH flaws gave attackers full admin on MikroTik routers — one of them using -2 as a username.No password. No SSH key. No authentication at all.CERT Polska says it was exploited before patches shipped.Learn how it works ↓ https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    23 сент., 14:18

    🛑 This Windows malware takes no orders from an attacker's server.It lets up to four AI models, including DeepSeek and Gemini, vote on its next move: steal credentials and wallet data, inject code, or stay installed.Read about CLOSEDQUORUM → https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    23 сент., 13:54

    ⚠️ Compromised MemTensor packages are pushing the sckit credential stealer through npm and PyPI.The Go-based malware targets developer and cloud secrets, launching on memory recall in the npm plugin or as soon as the PyPI module is imported.Read more about this supply-chain compromise - https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    23 сент., 13:21

    Quantify Cyber Risk & Earn CPEs at CRX’26Black Kite and Optro are joining forces for an exclusive workshop at CRX’26!The two-hour workshop “Quantifying cyber risk in terms that drive decision-making" is on October 14th at 2:00 PT, and will feature Black Kite’s Strategic Advisor and founder of the FAIR model Jack Jones, Black Kite’s CSO Bob Maley, alongside Optro’s CISO Richard Marcus, to discuss best practices in cyber risk quantification and present practical strategies for framing risk and driving decision-making.Register Now → https://thn.news/risk-experience-2026
  • The Hacker News

    23 сент., 12:19

    ‼️ ALERT: A new cPanel flaw, CVE-2026-87899, in CalDAV/CardDAV lets any logged-in cPanel account run code as root and take full control of the server.A second flaw, CVE-2026-87900 in WP Toolkit, lets authenticated users modify databases belonging to other accounts.🔗 Learn more → https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    23 сент., 11:48

    ⚡ Anthropic’s Opus 5.5 tried to escape or tamper with a sandbox in 1.5% of safeguard-free test runs.⚡ OpenAI’s GPT-6 Luna worked around access-denied restrictions in 42% of runs, down from 77% for its predecessor.Read where the safeguards still failed → https://thehackernews.com/2026/09/anthropic-and-openai-models-still.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
    3,560621Открыть в Telegram
  • The Hacker News

    22 сент., 18:32

    ‼️ Check Point is warning customers about a newly disclosed Security Management Server zero-day exploited in targeted attacks in July.CVE-2026-93616 lets an attacker who can reach the web service upload and run scripts without logging in. A fix landed Sept. 22.Here's what admins should hunt for: https://thehackernews.com/2026/09/check-point-warns-of-management-server.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    22 сент., 18:07

    ‼️ URGENT - WordPress issues patch a new critical flaw (CVE-2026-87902) that requires no account and can lead to code execution on some servers.Versions 4.7.0 through 7.1.1 are affected.Here's how the flaw works: https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    22 сент., 17:12

    ⚡ Microsoft took down EvilTokens, tied to 12,000+ compromised inboxes across 10,000+ organizations.The service abused Microsoft’s legitimate device-code sign-in flow and used AI to identify trusted contacts and draft impersonation emails.Learn how it worked: https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    22 сент., 16:42

    🚨 A single unauthenticated POST can make Bifrost run attacker-supplied commands with management auth disabled, the default setting.CVE-2026-90898 affects versions before 2.1.0, and command execution can expose stored LLM provider API keys.Read: https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    22 сент., 16:18

    🚨 New unpatched "BigDiskBuster" zero-day PoC can block Microsoft Defender updates by filling the system drive.Defender keeps running, but failed platform and signature updates can leave detection content stale. No patch, CVE, or Microsoft advisory exists.How it works: https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
    2,390621Открыть в Telegram
  • The Hacker News

    22 сент., 14:21

    AI agents escaped their expected environment in a Hugging Face security test.They harvested credentials, escalated privileges, and crossed cloud, Kubernetes, internal network, and source-control boundaries over ~17,600 actions.How the chain formed: https://thehackernews.com/2026/09/ai-agents-are-rewriting-rules-of.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
    3,080133111Открыть в Telegram
  • The Hacker News

    22 сент., 13:44

    ICYMI: F5' Post-Mythos Security Summit is live!🛡️🎬Join security experts and industry analysts for a deep dive into the practical strategies needed to protect your architecture in today's evolving threat landscape. The best part? It's virtual, free, and on-demand.Browse the sessions now: https://thn.news/post-mythos-security
    3,090видео1Открыть в Telegram
  • The Hacker News

    22 сент., 12:42

    ‼️ WARNING - Attackers are actively exploiting a new CVSS 10.0 VeloCloud Orchestrator vulnerability.Only VCOs using certificate-based Edge authentication are exposed. Fixes for the 6.1 and 7.0 release trains are still pending.Learn more about CVE-2026-93952 here → https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    22 сент., 12:35

    DORA’s second year is about proving controls work.EU regulators are focusing more closely on implementation, incident analysis, and ICT risk supervision. Network evidence can help SOC teams detect, scope, and report incidents faster.What changes in year two: https://thehackernews.com/2026/09/dora-year-two-can-your-soc-actually-see.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    22 сент., 11:43

    🛑 New Linux KVM flaw CVE-2026-89775 can let an ARM64 guest escape to the host.When nested virtualization is enabled, the bug can leave freed host kernel memory mapped and writable. No attacks have been reported.How the escape works ↓ https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    22 сент., 11:26

    AI incidents aren’t slowing most AI rollouts.86% of organizations had at least one AI-related incident last year. Only 27% slowed or paused deployment, according to OneTrust research.CISO Tim Mullen argues ISO 27001 should be the starting point, not proof that controls will keep working as AI systems change.Why certification isn’t enough: https://thehackernews.com/expert-insights/2026/09/beyond-iso-27001-building-risk-program.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News
  • The Hacker News

    22 сент., 11:18

    ‼️ ALERT - Microsoft initially classified CVE-2026-65660 as a SharePoint spoofing flaw. It actually enables authenticated RCE.No in-the-wild exploitation has been reported "yet," but the full exploit markup is now public.Here's how it works → https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html
    Иллюстрация к посту канала The Hacker NewsИллюстрация к посту канала The Hacker News