TGTGInsighttelegram intelligenceLIVE / telegram public index
Back to channels
The Hacker News avatar

TGINSIGHT CHAT

The Hacker News

@thehackernews

Technologies

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com

Subscribers16.3万Current channel subscribers
Tracked posts1,016Indexed post count
Recent reach123,020Sum of recent post views
Recent posts

Recent posts

Page 38 of 85 · 1,016 posts

Posted Mar 3

🚨 A new phishing suite called "Starkiller" proxies real login pages to bypass MFA. It runs headless Chrome in Docker, loads the legitimate site, and relays everything live. Keystrokes and session tokens pass through attacker infrastructure, enabling account takeover. 🔗 How the AitM setup works → https://thehackernews.com/2026/03/starkiller-phishing-suite-uses-aitm.html

10,400 views

Posted Mar 3

⚠️ A new phishing wave uses malicious OAuth apps to bypass email and browser defenses, #Microsoft warns. Victims click links tied to fake app scopes, get redirected through legitimate identity providers, and end up downloading ZIP files that trigger PowerShell, MSI installs, and DLL sideloading. 🔗 Read → https://thehackernews.com/2026/03/microsoft-warns-oauth-redirect-abuse.html

10,000 views

Hashtags

Posted Mar 3

AI is being sold as the fix for lean security teams. The reality is more nuanced. Small teams face rising threats and limited staff. AI can improve detection and triage, but it also demands integration, tuning, and oversight. Many tools add noise instead of clarity. For lean teams, the question is outcomes, not AI labels. 🔗 Inside: build vs MDR tradeoffs and Forrester’s findings → https://thehackernews.com/expert-insights/2026/03/ai-in-cybersecurity-is-it-worth-effort.html

9,120 views

Posted Mar 3

⚠️ Google says CVE-2026-21385 is being exploited in the wild. The high-severity flaw affects a Qualcomm graphics component in Android and involves a buffer over-read caused by an integer overflow. Activity appears limited and targeted. 🔗 Details → https://thehackernews.com/2026/03/google-confirms-cve-2026-21385-in.html

10,300 views

Posted Mar 3

A threat group known as SloppyLemming used Rust malware for the first time in attacks on Pakistani and Bangladeshi government and infrastructure networks. Arctic Wolf links the activity to spear-phishing, ClickOnce abuse, and a BurrowShell implant that masks traffic as Windows Update. 🔗 Details → https://thehackernews.com/2026/03/sloppylemming-targets-pakistan-and.html

9,450 views

Posted Mar 2

⚠️ A new Google Chrome flaw (CVE-2026-0628, CVSS 8.8) could let a malicious extension inject code into the Gemini side panel due to weak WebView policy enforcement. Successful exploitation enabled privilege escalation and potential access to the camera, microphone, screenshots, and local files. 🔗 Details → https://thehackernews.com/2026/03/new-chrome-vulnerability-let-malicious.html

10,600 views

Posted Mar 2

🔐 Chrome is testing Merkle Tree Certificates (MTCs) to prepare HTTPS for the post-quantum era. Instead of embedding post-quantum keys in bulky X.509 chains, a CA signs one “Tree Head” covering millions of certs. Browsers get a compact proof of inclusion, reducing TLS handshake data. 🔗 Read → https://thehackernews.com/2026/03/google-develops-merkle-tree.html

10,100 views

Posted Mar 2

Cloud, AI, SD-WAN, VPNs, developer tools, telecom, and critical sectors under strain. ⚠️ Zero-days exploited. 🤖 AI models scraped. ☁️ Cloud keys exposed. 🛰️ C2 hidden in trusted services. 🎯 Critical CVEs piling up. 📡 80K+ VPN scans in days. This week’s recap shows where risk is quietly expanding: https://thehackernews.com/2026/03/weekly-recap-sd-wan-0-day-critical-cves.html

9,950 views

Posted Mar 2

Strategic Framework for Communicating AI Security This free, editable template helps security leaders communicate AI risk, posture, and priorities in a way the board understands, using real metrics, risk narratives, and strategic framing. 🔗 Get the Template → https://thn.news/ai-board-template

10,100 views

Posted Mar 2

⚡ Bot traffic often looks legitimate. It’s HTTPS, well-formed, and hits your own APIs. SafeLine is a self-hosted reverse-proxy WAF built to detect business-logic abuse alongside SQLi and XSS. The vendor claims 99.45% detection accuracy, with rate limiting and anti-bot challenges built in. 🔗 Read → https://thehackernews.com/2026/03/how-to-protect-your-saas-from-bot.html

10,100 views

Posted Mar 2

🛑 Microsoft fixed CVE-2026-21513 (CVSS 8.8) in February after confirming zero-day exploitation in MSHTML. A flaw in ieframe.dll let attackers bypass Mark-of-the-Web and IE ESC, enabling potential code execution. Akamai linked a malicious LNK sample to infrastructure associated with APT28. 🔗 Read → https://thehackernews.com/2026/03/apt28-tied-to-cve-2026-21513-mshtml-0.html

11,400 views

Posted Mar 2

⚠️ Contagious Interview resurfaced with 26 malicious npm packages. They decode steganographic C2 data from Pastebin essays, then deploy VS Code persistence, keylogging, browser and crypto wallet theft, and a cross-platform RAT. Infrastructure spans 31 Vercel deployments. 🔗 Read → https://thehackernews.com/2026/03/north-korean-hackers-publish-26-npm.html

11,500 views
12•••5•••10•••15•••20•••25•••30•••353637383940•••45•••50•••55•••60•••65•••70•••75•••80•••8485