TGINSIGHT CHAT
The Hacker News
@thehackernews
Technologies⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com
Recent posts
Page 10 of 85 · 1,016 posts
Posted Apr 23
⚠️ A China-aligned APT, GopherWhisper, targeted Mongolian government systems. It uses Slack, Discord, Outlook, and file-io for control and data theft, deploying Go-based backdoors across at least 12 confirmed systems. 🔗 Details → https://thehackernews.com/2026/04/china-linked-gopherwhisper-infects-12.html
Posted Apr 23
🔥 Vercel found more compromised accounts, some predating the breach. Attackers used malware → Google Workspace → Vercel access, then mapped systems and decrypted environment variables. OAuth trust enabled lateral movement. 🔗 Details here → https://thehackernews.com/2026/04/vercel-finds-more-compromised-accounts.html
Posted Apr 23
⚡ Apple fixed an iOS bug where deleted notifications stayed stored on devices. The flaw let message data persist after apps like Signal were removed. It surfaced after forensic extraction. The patch now clears and prevents retention. 🔗 Details → https://thehackernews.com/2026/04/apple-patches-ios-flaw-that-stored.html
Posted Apr 22
⚠️ WARNING: Checkmarx KICS Docker repo breached—malicious images replaced trusted tags. The modified images could encrypt and exfiltrate scan data, risking exposure of credentials in IaC files. Related VS Code extensions also ran unverified remote code. 🔗 Details → https://thehackernews.com/2026/04/malicious-kics-docker-images-and-vs.html
Posted Apr 22
🛑 Supply chain attacks are stacking across npm, PyPI, and GitHub. CanisterSprawl worm steals npm tokens via postinstall scripts, republishes infected packages, and spreads across ecosystems. Other campaigns add backdoored packages, LLM proxy abuse, and GitHub Actions exploits. 🔗 Read → https://thehackernews.com/2026/04/self-propagating-supply-chain-worm.html
Posted Apr 22
🛑 A Linux backdoor is using Microsoft’s cloud to stay hidden. Harvester’s GoGra uses Outlook mailboxes as C2, executing commands via email, returning results, then deleting traces to evade detection. Targets likely include India and Afghanistan. 🔗 Read → https://thehackernews.com/2026/04/harvester-deploys-linux-gogra-backdoor.html
Posted Apr 22
Join 15+ SANS Institute instructors in a panel-style webinar to gain practical tools, proven tactics, and real-world tradecraft you can apply immediately. Detect threats sooner and respond with precision. 15+ Cybersecurity Experts. 1 Can't-Miss Webinar. Register → https://thn.news/sans-2026-secure-fortress
Posted Apr 22
Moltbook exposed 1.5M API tokens and 35,000 emails via an open database. Agents also stored internal tokens and third-party credentials together in plaintext, creating cross-app access paths no one reviewed. 🔗 How “toxic combinations” form across SaaS → https://thehackernews.com/2026/04/toxic-combinations-when-cross-app.html
Posted Apr 22
⚠️ Kaspersky found a new wiper targeting Venezuela’s energy sector. Lotus Wiper fully destroys systems—no ransom, no recovery. It uses scripts to disable defenses, then wipes drives, deletes backups, and erases files using native Windows tools. 🔗 Details → https://thehackernews.com/2026/04/lotus-wiper-malware-targets-venezuelan.html
Posted Apr 22
⚠️ Microsoft patched CVE-2026-40372 (CVSS 9.1) in ASP .NET Core enabling SYSTEM-level escalation. A crypto flaw let attackers forge payloads and decrypt auth data in apps using vulnerable Data Protection on Linux/macOS. 🔗 Read → https://thehackernews.com/2026/04/microsoft-patches-critical-aspnet-core.html
Posted Apr 22
🛑 China-linked APT targets India’s banks with updated malware. LOTUSLITE v1.1 uses phishing, signed executables, and DLL sideloading to gain access—focused on espionage, not theft. Shift from U.S. govt targets to Indian financial systems. 🔗 Details → https://thehackernews.com/2026/04/mustang-pandas-new-lotuslite-variant.html
Posted Apr 22
⚡ Security teams track MTTR as a metric. Leadership sees every hour of dwell time as risk. Delays rarely come from staffing—they come from disconnected threat intel, manual lookups, and tool switching that add up over time. 🔗 Learn why MTTR slows down inside most SOCs → https://thehackernews.com/2026/04/5-places-where-mature-socs-keep-mttr.html