TGINSIGHT CHAT
The Hacker News
@thehackernews
Technologies⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com
Recent posts
Page 12 of 85 · 1,016 posts
Posted Apr 21
⚠️ CISA added 8 actively exploited vulnerabilities to KEV across Cisco, Quest, PaperCut, TeamCity, Kentico, and Zimbra. Includes 3 Cisco SD-WAN flaws and a Quest KACE bug (CVSS 10.0) enabling user impersonation. Federal patch deadlines: April 23 (Cisco), May 4 (others). 🔗 Read → https://thehackernews.com/2026/04/cisa-adds-8-exploited-flaws-to-kev-sets.html
Posted Apr 20
⚠️ SGLang has a critical flaw enabling remote code execution (CVSS 9.8) via malicious GGUF model files. A crafted Jinja2 template runs when /v1/rerank is triggered, executing attacker code on the server. 🔗 How GGUF templates become an RCE path → https://thehackernews.com/2026/04/sglang-cve-2026-5760-cvss-98-enables.html
Posted Apr 20
This week didn’t break anything. It bent everything: ⚡ Vercel hacked 🌐 DDoS busted 🤖 PowMix botnet 📢 Push fraud 📝 Obsidian RAT ⬇️ CPUID trojan 🧩 Chrome spyware 🧠 AI cyber 💰 Vect ransomware 💬 Teams trap 🗂️ CGrabber steal 📧 Mail breach 🔑 Access trade 🛠️ Adaptix C2 🧬 Adware backdoor 💉 SQL attacks 🖥️ VM stealth 🎭 Fake installer 🔗 Scroll through the full recap → https://thehackernews.com/2026/04/weekly-recap-vercel-hack-push-fraud.html
Posted Apr 20
Stop using Spreadsheets & PDFs for Pentest Reporting. Move from static files to live findings, automate remediation, and prove risk reduction. 🔗 See it in action → https://thn.news/plextrac-pentest
Posted Apr 20
AI tools look flawless in demos—but break in real operations. Clean data and ideal prompts don’t exist in production. Messy inputs, latency, edge cases, and weak integrations quickly surface. 🔗 What breaks when AI leaves the demo → https://thehackernews.com/2026/04/why-most-ai-deployments-stall-after-demo.html
Posted Apr 20
🛑 A design flaw in Anthropic’s MCP allows remote command execution on AI systems. 150M+ downloads affected as unsafe STDIO defaults expose 7,000+ services, including tools like LangChain and Flowise. Anthropic calls the behavior “expected,” leaving the risk across the AI supply chain. 🔗 Read → https://thehackernews.com/2026/04/anthropic-mcp-design-vulnerability.html
Posted Apr 20
Researchers found OT malware targeting Israeli water systems. ZionSiphon alters chlorine and pressure controls, scanning Modbus/DNP3/S7comm and spreading via USB. It activates only inside Israeli IP ranges + OT setups, but current code is unfinished. 🔗 Read → https://thehackernews.com/2026/04/researchers-detect-zionsiphon-malware.html
Posted Apr 20
🔥 Vercel disclosed a BREACH after an attacker used a compromised 3rd-party AI tool to take over an employee account. Some internal systems, non-sensitive variables, and limited customer credentials were exposed. No evidence sensitive data was accessed. 🔗 Read → https://thehackernews.com/2026/04/vercel-breach-tied-to-context-ai-hack.html
Posted Apr 18
The EU says its age verification app is ready for rollout. Users can prove age with ID without sharing personal data. The system is anonymous, open source, and built to support child safety rules across platforms. 🔗 What the EU’s system actually does → https://thehackernews.com/2026/04/threatsday-bulletin-17-year-old-excel.html#anonymous-age-checks
Posted Apr 18
Sanctioned #cryptocurrency exchange Grinex is shutting down after a $13.74M hack. Stolen funds were quickly moved and swapped to avoid freezing. The platform is linked to Garantex, flagged for laundering over $100M. 🔗 Read → https://thehackernews.com/2026/04/1374m-hack-shuts-down-sanctioned-grinex.html
Hashtags
Posted Apr 18
Attackers are exploiting CVE-2024-3721 in TBK DVRs to deploy Mirai variant Nexcorium. It spreads via old exploits and default creds, persists on devices, and launches DDoS attacks. EoL TP-Link routers are also being targeted via known flaws. 🔗 Read → https://thehackernews.com/2026/04/mirai-variant-nexcorium-exploits-cve.html
Posted Apr 17
⚡ Researchers confirm exploitation of three Microsoft Defender flaws—one patched (CVE-2026-33825) , two unpatched. Attackers escalate privileges and can block Defender updates. 🔗 Learn how these flaws are used in attacks → https://thehackernews.com/2026/04/three-microsoft-defender-zero-days.html