TGTGInsighttelegram intelligenceLIVE / telegram public index
Back to channels
The Hacker News avatar

TGINSIGHT CHAT

The Hacker News

@thehackernews

Technologies

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com

Subscribers16.3万Current channel subscribers
Tracked posts1,016Indexed post count
Recent reach113,610Sum of recent post views
Recent posts

Recent posts

Page 34 of 85 · 1,016 posts

Posted Mar 10

⚠️ Attackers are abusing FortiGate firewalls as entry points. A SentinelOne report says exploits and weak credentials let intruders extract configs holding Active Directory service account credentials, then enroll rogue machines and scan internal networks. 🔗 FortiGate breach chain and AD access details → https://thehackernews.com/2026/03/fortigate-devices-exploited-to-breach.html

10,200 views

Posted Mar 10

🛑 KadNap malware has infected 14,000+ devices since Aug 2025, mostly in the U.S. Targets Asus routers and hides C2 using a peer-to-peer DHT network. Infected devices are sold as residential proxies through the Doppelgänger service. 🔗 Details → https://thehackernews.com/2026/03/kadnap-malware-infects-14000-edge.html

10,200 views

Posted Mar 10

🚨 Researchers found 9 cross-tenant flaws in #Google Looker Studio that could let attackers run arbitrary SQL queries on connected databases and access cloud data. BigQuery, Sheets, #PostgreSQL, and other connectors were exposed. 🔗 Attack paths and affected services → https://thehackernews.com/2026/03/new-leakylooker-flaws-in-google-looker.html

9,500 views

Posted Mar 10

⚡ WEBINAR — AI agents now send emails, move data, and run tasks across company systems. Many operate as “invisible employees” with access security teams rarely track. Attackers exploit this by planting instructions that make agents leak sensitive data. 🔗 Learn how to secure AI agent workflows → https://thehackernews.com/2026/03/how-to-stop-ai-data-leaks-webinar-guide.html

9,290 views

Posted Mar 10

Serious vulnerabilities now get exploited within 24–48 hours of disclosure. Some forecasts say minutes by 2028. During the SharePoint ToolShell zero-day, thousands of servers were still exposed to the internet — many unnecessarily. 🔗 Why attack surface exposure gets missed → https://thehackernews.com/2026/03/the-zero-day-scramble-is-avoidable.html

8,830 views

Posted Mar 10

🛑 Russian state-linked hackers APT28 are spying on Ukrainian military targets using BEARDSHELL and a modified COVENANT framework. Active since April 2024, the operation hides command-and-control in cloud services like Icedrive and Filen. 🔗 Read → https://thehackernews.com/2026/03/apt28-uses-beardshell-and-covenant.html

8,470 views

Posted Mar 10

🛑Threat actors are mass-scanning #Salesforce Experience Cloud sites using AuraInspector. The tool probes the /s/sfsites/aura API and can extract CRM data if guest user permissions are too broad. Salesforce says the platform isn’t vulnerable—misconfiguration is the risk. 🔗 Read → https://thehackernews.com/2026/03/threat-actors-mass-scan-salesforce.html

8,710 views

Hashtags

Posted Mar 10

Security teams often prioritize fixes by CVSS. But CVSS measures technical severity, not actual risk. A 9.8 CVSS flaw in an isolated test system may be patched first, while a lower-scored bug in a public login API waits. Real risk depends on exposure, exploit paths, and business impact. 🔗 Why context changes vulnerability priorities → https://thehackernews.com/expert-insights/2026/03/why-cvss-scores-dont-tell-real-story-of.html

8,990 views

Posted Mar 10

⚠️ CISA added 3 actively exploited flaws to KEV. Most critical: SolarWinds Web Help Desk CVE-2025-26399 (CVSS 9.8) allowing remote command execution. Other KEV entries hit Omnissa Workspace One UEM and Ivanti Endpoint Manager. Federal agencies ordered to patch. 🔗 Details → https://thehackernews.com/2026/03/cisa-flags-solarwinds-ivanti-and.html

9,230 views

Posted Mar 9

⚠️ A malicious npm package is spreading a full RAT malware disguised as an OpenClaw installer. It pulls a hidden second-stage payload and steals browser data, macOS Keychain entries, crypto wallets, and developer cloud credentials. 🔗 Read → https://thehackernews.com/2026/03/malicious-npm-package-posing-as.html

10,200 views

Posted Mar 9

🚨 North Korea’s UNC4899 breached a crypto firm via AirDrop from a develop’s device. A poisoned archive ran a fake Kubernetes CLI, opened a backdoor, pivoted into Google Cloud, exposed CI/CD tokens & reset accounts to steal millions. 🔗 Read → https://thehackernews.com/2026/03/unc4899-used-airdrop-file-transfer-and.html

10,400 views

Posted Mar 9

Supply-chain pressure is pushing mid-market firms to meet enterprise security standards. Partners now expect proof of resilience. A Bitdefender webinar explains how security platform consolidation helps lean IT teams cut complexity and show stronger security posture. 🔗 GravityZone platform approach → https://thehackernews.com/2026/03/can-security-platform-finally-deliver.html

9,590 views
12•••5•••10•••15•••20•••25•••30•••3233343536•••40•••45•••50•••55•••60•••65•••70•••75•••80•••8485