TGINSIGHT CHAT
The Hacker News
@thehackernews
Technologies⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com
Recent posts
Page 20 of 85 · 1,016 posts
Posted Apr 3
🛑 China-linked TA416 is again targeting European governments, using OAuth redirect abuse and cloud-hosted malware to deliver PlugX. Activity expanded to the Middle East in 2026, tied to conflict-driven intelligence gathering. 🔗 Read → https://thehackernews.com/2026/04/china-linked-ta416-targets-european.html
Posted Apr 3
🛑 Attackers are using HTTP cookies to control PHP web shells on Linux servers. Malware stays inactive and runs only when specific cookie values are sent, blending into normal traffic. Cron jobs can also recreate it for persistence. 🔗 How cookie-triggered web shells evade detection → https://thehackernews.com/2026/04/microsoft-details-cookie-controlled-php.html
Posted Apr 3
SparkCat malware has reappeared on Apple and Google app stores, hiding inside everyday apps. It scans photos for crypto recovery phrases and sends them to attackers, using OCR to extract sensitive data from images. 🔗 Read → https://thehackernews.com/2026/04/new-sparkcat-variant-in-ios-android.html
Posted Apr 3
30% of breaches now involve third parties like vendors and SaaS. The perimeter has shifted outward, and regulations now require continuous oversight. Cynomi shows TPRM is now a core security function, not just compliance. 🔗 Why TPRM is becoming central to security → https://thehackernews.com/2026/04/why-third-party-risk-is-biggest-gap-in.html
Posted Apr 3
Apple is testing a safeguard against copy-paste attacks. macOS 26.4 adds Terminal paste warnings, targeting scams that trick users into running malicious commands. Users can still override. ClickFix-style attacks are now widely used. 🔗 Reads → https://thehackernews.com/2026/03/weekly-recap-telecom-sleeper-cells-llm.html#:~:text=Apple%20Tests%20Ways%20to%20Block%20Malicious%20Copy%2DPastes%20in%20macOS
Posted Apr 3
⚡ It turns out Axios npm was compromised via a targeted UNC1069 social engineering attack. Attackers used a fake Slack + Teams setup to install malware, steal npm credentials, and publish trojanized versions (1.14.1, 0.30.4). 🔗 Details here → https://thehackernews.com/2026/04/unc1069-social-engineering-of-axios.html
Posted Apr 3
⚠️ WARNING - Attackers are weaponizing the Claude Code leak. Fake GitHub repos now deploy Vidar Stealer and GhostSocks, using trojanized builds that look legitimate. 🔗 Read → https://thehackernews.com/2026/04/claude-code-tleaked-via-npm-packaging.html#fake-claude-code-repos-deploy-vidar-stealer-and-ghostsocks
Posted Apr 3
Drift Protocol lost $285M after attackers took over governance, not by breaking code but by abusing approvals. They used pre-signed transactions, social engineering, and a zero-timelock change to gain admin control, add a fake asset, and remove limits to drain funds. 🔗 How governance and multisig failures enabled the exploit → https://thehackernews.com/2026/04/drift-loses-285-million-in-durable.html
Posted Apr 2
⚠️ ALERT - A threat group exploited a Next.js flaw to compromise 766+ hosts and steal cloud credentials at scale. Using automated scripts, attackers extracted AWS secrets, SSH keys, and API tokens, all managed through a central dashboard for reuse. 🔗 Read → https://thehackernews.com/2026/04/hackers-exploit-cve-2025-55182-to.html
Posted Apr 2
🚨 Cisco fixed two critical flaws that allow full system takeover without login. CVSS 9.8 vulnerabilities let attackers reset admin passwords (IMC) or run commands as root (SSM On-Prem) using crafted requests. No workaround is available. Patching is required. 🔗 Read → https://thehackernews.com/2026/04/cisco-patches-98-cvss-imc-and-ssm-flaws.html
Posted Apr 2
⚠️ A cybercrime campaign since 2023 spreads malware via fake installers. REF1695 delivers RATs, crypto miners, and CNB Bot via ISO files, tricks users to bypass Windows protections, and uses GitHub to host payloads. 🔗 Key tactics, payloads, and earnings → https://thehackernews.com/2026/04/researchers-uncover-mining-operation.html
Posted Apr 2
🚨 From zero-days to mass infections — this week has it all... ⚠️ ShareFile pre-auth RCE 📱 Android rootkit at scale 🖼️ ImageMagick 0-days → RCE 🕵️ XLoader stealth upgrades 🎣 Mobile phishing surge 📦 Supply chain attacks ×14 📖 Read the full ThreatsDay Bulletin → https://thehackernews.com/2026/04/threatsday-bulletin-pre-auth-chains.html