TGTGInsighttelegram intelligenceLIVE / telegram public index
Back to channels
The Hacker News avatar

TGINSIGHT CHAT

The Hacker News

@thehackernews

Technologies

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com

Subscribers16.3万Current channel subscribers
Tracked posts1,016Indexed post count
Recent reach102,929Sum of recent post views
Recent posts

Recent posts

Page 30 of 85 · 1,016 posts

Posted Mar 18

Valid credentials now drive 30% of attacks, per IBM. As Ani Khachatryan explains, PAM controls access but can’t detect misuse after login. ITDR fills that gap with real-time monitoring and response, closing the identity attack loop. 🔗 Why identity defense now needs both layers → https://thehackernews.com/expert-insights/2026/03/a-unified-identity-defense-layer-why.html

8,740 views

Posted Mar 18

🚨 Apple patched a WebKit flaw that lets crafted pages bypass browser isolation. CVE-2026-20643 impacts iOS, iPadOS, and macOS. Fixes now ship via background updates, outside full OS releases. 🔗 Details here → https://thehackernews.com/2026/03/apple-fixes-webkit-vulnerability.html

8,280 views

Posted Mar 18

⚠️ WARNING - An unpatched critical telnetd bug (CVE-2026-32746) lets attackers gain full system access with no credentials. One connection to port 23 is enough to trigger memory corruption and execute code as root. No patch yet. Prior telnet flaw is already exploited in the wild. 🔗Read → https://thehackernews.com/2026/03/critical-telnetd-flaw-cve-2026-32746.html

8,700 views

Posted Mar 17

🛑 Amazon Bedrock, LangSmith, and SGLang flaws expose data leaks, token theft, and RCE risks across AI platforms. Bedrock allows DNS-based exfiltration, LangSmith had account takeover, and SGLang remains vulnerable—showing weak isolation in real-world AI systems. 🔗 Exploits and fixes explained → https://thehackernews.com/2026/03/ai-flaws-in-amazon-bedrock-langsmith.html

9,310 views

Posted Mar 17

⚠️ LeakNet drops access brokers for ClickFix compromised sites trick users into running msiexec commands via fake CAPTCHA. Lower cost, faster scale. Deno executes payloads in memory, then lateral movement and data theft follow. 🔗 Details here → https://thehackernews.com/2026/03/leaknet-ransomware-uses-clickfix-via.html

8,950 views

Posted Mar 17

The best security teams aren't just reactive. They're informed. Knowing what attackers are doing, how they operate, and where your gaps are isn't a nice-to-have, it's the foundation of a modern defense strategy. That's what Threat-Informed Defense delivers. This guide lays out a six-stage Threat-Informed Defense pipeline to help your team: ⦿ Cut through alert noise and focus on threats that matter ⦿ Test your people, processes, and technology against realistic attack scenarios ⦿ Put CTI to work operationally with tools like OpenCTI + OpenAEV ⦿ Turn detection and response into a continuous, self-improving cycle Download the guide today → https://thn.news/infosec-threat-guide

8,490 views

Posted Mar 17

AI agents don’t need prompts to turn rogue. They can coordinate attacks on their own. Tests show agents collaborating to escalate privileges, disable defenses, and steal data—even persuading each other to act. 🔗 Report details how agent-to-agent collusion bypasses controls → https://thehackernews.com/2026/03/weekly-recap-chrome-0-days-router.html#:~:text=Rogue%20AI%20Agents%20Can%20Work%20Together%20to%20Engage%20in%20Offensive%20Behaviors

7,890 views

Posted Mar 17

⚠️ A full Roundcube exploit kit tied to APT28 was found on a live server, targeting Ukrainian government email. It enables XSS takeover, mailbox exfiltration, hidden forwarding, and even 2FA secret theft. Includes a new CSS-based data exfiltration method. 🔗 Toolkit details → https://thehackernews.com/2026/03/weekly-recap-chrome-0-days-router.html#:~:text=Roundcube%20Exploitation%20Toolkit%20Discovered

7,840 views

Posted Mar 17

Most CISOs don’t know where AI runs in their own orgs. 67% lack visibility—0% have full oversight. AI is spread across cloud, apps, and identity, owned by no one. Risk can’t be measured, let alone controlled. 🔗 Data shows where AI security actually breaks → https://thehackernews.com/2026/03/ai-is-everywhere-but-cisos-are-still.html

8,029 views

Posted Mar 17

⚠️ A fake job notice triggered full compromise in a Konni campaign. The attack drops EndRAT, enabling remote control, persistence, and silent data theft, then spreads via KakaoTalk messages from the victim’s account. Trusted contacts become the attack path. 🔗 Read → https://thehackernews.com/2026/03/konni-deploys-endrat-through-spear.html

8,490 views

Posted Mar 17

Firewalls still see encrypted port 443 traffic, not what users actually do inside SaaS apps or AI tools. As Dedi Shindler (Red Access) notes, that blinds teams to prompts, data leaks, and session activity. The fix isn’t replacing firewalls—it’s adding session-level visibility. 🔗 Firewall-native SSE explained → https://thehackernews.com/expert-insights/2026/03/the-firewall-isnt-blind-it-just-needs.html

9,020 views

Posted Mar 17

⚠️ CISA flags CVE-2025-47813 in Wing FTP as actively exploited. It leaks server paths via cookie errors—low severity, high value. Attackers can pair it with a known RCE flaw already used to deploy malware. 🔗 How it enables real attack chains → https://thehackernews.com/2026/03/cisa-flags-actively-exploited-wing-ftp.html

9,190 views
12•••5•••10•••15•••20•••25•••2829303132•••35•••40•••45•••50•••55•••60•••65•••70•••75•••80•••8485