TGINSIGHT CHAT
The Hacker News
@thehackernews
Technologies⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com
Recent posts
Page 11 of 85 · 1,016 posts
Posted Apr 22
⚠️ A Python sandbox for untrusted code has a 9.3 flaw (CVE-2026-5752). A Pyodide bug enables sandbox escape and root command execution. The project is unmaintained, so the issue remains UNPATCHED. 🔗 Learn more → https://thehackernews.com/2026/04/cohere-ai-terrarium-sandbox-flaw.html
Posted Apr 22
Many companies have backups but still can’t recover from ransomware. As Acronis’ Subramani Rao explains, backups often fail before encryption as attackers disable, delete, or corrupt them after gaining access. Recovery breaks down due to compromised systems and slow validation. 🔗 Why backup doesn’t equal recovery in real attacks → https://thehackernews.com/expert-insights/2026/04/why-your-backups-might-not-save-you.html
Posted Apr 21
🛑 A SystemBC-linked server exposed 1,570+ infected systems, mostly corporate. An affiliate of The Gentlemen #ransomware used the proxy malware for covert access and staging—not all were confirmed ransomware victims. 🔗 Read → https://thehackernews.com/2026/04/systembc-c2-server-reveals-1570-victims.html
Hashtags
Posted Apr 21
🚨 Researchers found 22 vulnerabilities in serial-to-IP converters, with ~20,000 devices exposed online. Exploitation can enable device takeover and tampering with data between legacy systems and IP networks, impacting industrial operations. 🔗 Read → https://thehackernews.com/2026/04/22-bridgebreak-flaws-expose-20000.html
Posted Apr 21
A 24-year-old linked to Scattered Spider pleaded guilty after stealing $8 million in digital assets from multiple companies. The campaign used SMS phishing to capture employee credentials, then SIM swapping to take over accounts across telecom, tech, and crypto firms. 🔗 Read → https://thehackernews.com/2026/04/weekly-recap-vercel-hack-push-fraud.html#:~:text=British%20National%20Pleads%20Guilty%20to%20Scattered%20Spider%20Campaign
Posted Apr 21
Over 99% of Mythos-discovered vulnerabilities remain unpatched. The Glasswing report lands in July. The window between patch publication and AI-powered weaponization is collapsing. Picus Security published 12 vendor-neutral recommendations for security teams preparing for what comes after. Get your copy now: https://thn.news/post-mythos-actions
Posted Apr 21
🚨 A ransomware negotiator worked with attackers while advising victims. Angelo Martino leaked client negotiation data to BlackCat, including insurance limits, helping raise ransom payouts while getting paid by both sides. 🔗 Read → https://thehackernews.com/2026/04/ransomware-negotiator-pleads-guilty-to.html
Posted Apr 21
Most breaches don’t start with exploits. Stolen credentials still dominate initial access. Attackers log in, move laterally, and escalate fast—often reaching ransomware within hours. AI is accelerating this pattern, not changing it. 🔗 Why identity attacks still lead breaches → https://thehackernews.com/2026/04/no-exploit-needed-how-attackers-walk.html
Posted Apr 21
99% of security leaders are confident in their ability to detect attacks. Yet nearly half of those who experienced one admit they detected it too late to prevent significant damage. 🤔 Something doesn't add up. Halcyon recently surveyed 100 CISOs and senior security leaders on #ransomware, and their findings show the confidence-vs-reality gap is bigger than it should be: ⚠️ 98% use EDR; only 25% actually trust it to defend against today's threats ⚠️#AI is giving attackers a 13:1 speed advantage over defenders ⚠️ 90% rate their security as sufficient - yet nearly half experienced moderate to significant disruption The problem isn't experience or awareness. It's that most tools in use today weren't purpose-built for ransomware - and attackers know it. The gap is real, it's measurable, and it's getting wider. 👉 Read the full report: https://thn.news/halcyon-survey-2026
Hashtags
Posted Apr 21
🛑 Android malware is hijacking NFC payments via a real app. Researchers found NGate abusing HandyPay to relay card data and steal PINs for ATM withdrawals. Spread via fake lottery sites and spoofed app pages, targeting Brazil since Nov 2025. 🔗 Read → https://thehackernews.com/2026/04/ngate-campaign-targets-brazil.html
Posted Apr 21
Google fixed an Antigravity IDE flaw that enabled arbitrary code execution via a search tool input. Attackers could inject commands, bypass sandbox controls, and run scripts automatically. Similar prompt injection flaws are now seen across AI dev tools. 🔗 Read → https://thehackernews.com/2026/04/google-patches-antigravity-ide-flaw.html
Posted Apr 21
96% of security teams can’t confirm if risks are exploitable. In this analysis, Jean-Philippe Salles of Filigran shows CTEM is failing at prioritization and validation, with 42% of SOC time wasted on low-value work. The gap is poor use of threat intelligence. 🔗 Why CTEM breaks without intel-driven context → https://thehackernews.com/expert-insights/2026/04/why-threat-intelligence-is-missing-link.html