TGINSIGHT CHAT
The Hacker News
@thehackernews
Technologies⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com
Recent posts
Page 34 of 85 · 1,016 posts
Posted Mar 10
⚠️ Attackers are abusing FortiGate firewalls as entry points. A SentinelOne report says exploits and weak credentials let intruders extract configs holding Active Directory service account credentials, then enroll rogue machines and scan internal networks. 🔗 FortiGate breach chain and AD access details → https://thehackernews.com/2026/03/fortigate-devices-exploited-to-breach.html
Posted Mar 10
🛑 KadNap malware has infected 14,000+ devices since Aug 2025, mostly in the U.S. Targets Asus routers and hides C2 using a peer-to-peer DHT network. Infected devices are sold as residential proxies through the Doppelgänger service. 🔗 Details → https://thehackernews.com/2026/03/kadnap-malware-infects-14000-edge.html
Posted Mar 10
🚨 Researchers found 9 cross-tenant flaws in #Google Looker Studio that could let attackers run arbitrary SQL queries on connected databases and access cloud data. BigQuery, Sheets, #PostgreSQL, and other connectors were exposed. 🔗 Attack paths and affected services → https://thehackernews.com/2026/03/new-leakylooker-flaws-in-google-looker.html
Hashtags
Posted Mar 10
⚡ WEBINAR — AI agents now send emails, move data, and run tasks across company systems. Many operate as “invisible employees” with access security teams rarely track. Attackers exploit this by planting instructions that make agents leak sensitive data. 🔗 Learn how to secure AI agent workflows → https://thehackernews.com/2026/03/how-to-stop-ai-data-leaks-webinar-guide.html
Posted Mar 10
Serious vulnerabilities now get exploited within 24–48 hours of disclosure. Some forecasts say minutes by 2028. During the SharePoint ToolShell zero-day, thousands of servers were still exposed to the internet — many unnecessarily. 🔗 Why attack surface exposure gets missed → https://thehackernews.com/2026/03/the-zero-day-scramble-is-avoidable.html
Posted Mar 10
🛑 Russian state-linked hackers APT28 are spying on Ukrainian military targets using BEARDSHELL and a modified COVENANT framework. Active since April 2024, the operation hides command-and-control in cloud services like Icedrive and Filen. 🔗 Read → https://thehackernews.com/2026/03/apt28-uses-beardshell-and-covenant.html
Posted Mar 10
🛑Threat actors are mass-scanning #Salesforce Experience Cloud sites using AuraInspector. The tool probes the /s/sfsites/aura API and can extract CRM data if guest user permissions are too broad. Salesforce says the platform isn’t vulnerable—misconfiguration is the risk. 🔗 Read → https://thehackernews.com/2026/03/threat-actors-mass-scan-salesforce.html
Hashtags
Posted Mar 10
Security teams often prioritize fixes by CVSS. But CVSS measures technical severity, not actual risk. A 9.8 CVSS flaw in an isolated test system may be patched first, while a lower-scored bug in a public login API waits. Real risk depends on exposure, exploit paths, and business impact. 🔗 Why context changes vulnerability priorities → https://thehackernews.com/expert-insights/2026/03/why-cvss-scores-dont-tell-real-story-of.html
Posted Mar 10
⚠️ CISA added 3 actively exploited flaws to KEV. Most critical: SolarWinds Web Help Desk CVE-2025-26399 (CVSS 9.8) allowing remote command execution. Other KEV entries hit Omnissa Workspace One UEM and Ivanti Endpoint Manager. Federal agencies ordered to patch. 🔗 Details → https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html
Posted Mar 9
⚠️ A malicious npm package is spreading a full RAT malware disguised as an OpenClaw installer. It pulls a hidden second-stage payload and steals browser data, macOS Keychain entries, crypto wallets, and developer cloud credentials. 🔗 Read → https://thehackernews.com/2026/03/malicious-npm-package-posing-as.html
Posted Mar 9
🚨 North Korea’s UNC4899 breached a crypto firm via AirDrop from a develop’s device. A poisoned archive ran a fake Kubernetes CLI, opened a backdoor, pivoted into Google Cloud, exposed CI/CD tokens & reset accounts to steal millions. 🔗 Read → https://thehackernews.com/2026/03/unc4899-used-airdrop-file-transfer-and.html
Posted Mar 9
Supply-chain pressure is pushing mid-market firms to meet enterprise security standards. Partners now expect proof of resilience. A Bitdefender webinar explains how security platform consolidation helps lean IT teams cut complexity and show stronger security posture. 🔗 GravityZone platform approach → https://thehackernews.com/2026/03/can-security-platform-finally-deliver.html