TGINSIGHT CHAT
The Hacker News
@thehackernews
Technologies⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com
Recent posts
Page 22 of 85 · 1,016 posts
Posted Apr 1
⚠️ Google links the Axios npm compromise to North Korean group UNC1069. Attackers hijacked the maintainer account and pushed malicious versions that executed during install via a hidden dependency, deploying a cross-platform backdoor (Windows, macOS, Linux) and then removing traces. 🔗 Read → https://thehackernews.com/2026/04/google-attributes-axios-npm-supply.html
Posted Apr 1
🔥 Anthropic accidentally exposed 512,000 lines of Claude Code via an npm packaging error. The code reveals internal systems like multi-agent workflows, guardrails, and automation—giving attackers a clear map to study and exploit. 🔗 Read → https://thehackernews.com/2026/04/claude-code-tleaked-via-npm-packaging.html
Posted Mar 31
🔥 Google has opened Android verification to all developers. Developer verification is now live globally, letting devs confirm identity and register apps ahead of enforcement. From Sept 30, 2026, only verified apps install in select markets, expanding globally in 2027. 🔗 Timeline and what devs must do next → https://thehackernews.com/2026/03/android-developer-verification-rollout.html
Posted Mar 31
⚠️ A zero-day in TrueConf let attackers spread malware through its own update system. CVE-2026-3502 (CVSS 7.8) was exploited by compromising on-prem servers, pushing tampered updates to all connected clients in government networks across Southeast Asia. 🔗 How the TrueChaos campaign weaponized software updates → https://thehackernews.com/2026/03/trueconf-zero-day-exploited-in-attacks.html
Posted Mar 31
AI is redefining cyber roles, hiring, and skills. See where teams are rebuilding and where careers are heading by downloading your copy of 2026 Workforce Research Report. 🔗 Download → https://thn.news/sans-workforce-research
Posted Mar 31
AI is shrinking cyberattacks to hours. Threat actors use AI to automate phishing, find vulnerabilities, and chain exploits faster than human response. Traditional security is too slow. Defenders are moving to continuous AI-driven testing and fixes. 🔗 Why speed now defines cybersecurity → https://thehackernews.com/2026/03/the-ai-arms-race-why-unified-exposure.html
Posted Mar 31
⚠️ A flaw in Google Cloud Vertex AI could expose sensitive data across projects. Default service agent permissions allow attackers to steal credentials from AI agents, access storage buckets, and move inside cloud environments. 🔗 Details here → https://thehackernews.com/2026/03/vertex-ai-vulnerability-exposes-google.html
Posted Mar 31
Silver Fox is spreading AtlasCross RAT via fake Zoom, Signal, and Teams sites. Signed installers from typo domains bypass checks, disable security tools, and run the RAT in memory for remote access and data theft across Asia. 🔗 Full details → https://thehackernews.com/2026/03/silver-fox-expands-asia-cyber-campaign.html
Posted Mar 31
Most AppSec teams say they fix critical bugs. Data shows otherwise. In Semgrep's report, Braden Riggs finds top teams fix 63% of critical issues, while most fix just 13%. Same tools and alerts—the gap is execution, not detection. 🔗 What 50k repos reveal about real vulnerability fixes → https://thehackernews.com/expert-insights/2026/03/which-code-vulnerabilities-actually-get.html
Posted Mar 31
⚡ WARNING - Axios npm (83M weekly downloads) was compromised, turning installs into a malware delivery path. Versions 1.14.1 and 0.30.4 pulled a fake dependency that dropped a cross-platform RAT, then erased evidence. Published using stolen maintainer credentials. 🔗 What happened and how the attack worked → https://thehackernews.com/2026/03/axios-supply-chain-attack-pushes-cross.html
Posted Mar 30
🛑 Two OpenAI flaws showed how AI systems can expose sensitive data. 🔸 One allowed silent leaks via a DNS side channel in ChatGPT 🔸 Another enabled GitHub token theft via Codex injection 🔗 What these vulnerabilities exposed about AI security → https://thehackernews.com/2026/03/openai-patches-chatgpt-data.html
Posted Mar 30
Most Tier 1 delays start before the threat is even understood. Tool switching and static triage slow investigations and hide real behavior. Unified workflows and behavior-first analysis reduce friction, speed validation, and cut unnecessary escalations. 🔗 How SOC teams cut delays at Tier 1 → https://thehackernews.com/2026/03/3-soc-process-fixes-that-unlock-tier-1.html