TGINSIGHT CHAT
The Hacker News
@thehackernews
Technologies⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com
Recent posts
Page 39 of 85 · 1,016 posts
Posted Feb 28
A malicious website could take over your OpenClaw AI agent without any click beyond visiting the page. Oasis Security's ClawJacked chain exploits localhost WebSocket trust: brute-force gateway password, silently pair as trusted device, gain admin control to interact, enumerate, exfil data. 🔗 Read → https://thehackernews.com/2026/02/clawjacked-flaw-lets-malicious-sites.html
Posted Feb 28
Researchers found 2,863 live Google API keys publicly exposed that could authenticate to Gemini endpoints once the API was enabled in a project. Keys meant for billing could access files, cached data, and run LLM calls, racking up charges. 🔗 Read → https://thehackernews.com/2026/02/thousands-of-public-google-cloud-api.html
Posted Feb 28
🤖 Anthropic refused mass domestic surveillance and autonomous weapons use of its AI. Days later, the Pentagon labeled it a national security supply chain risk Federal agencies now have six months to phase out its tech. Anthropic says the move is legally unsound and limited to Defense contracts. 🔗 Learn how this fight could reshape military AI deals → https://thehackernews.com/2026/02/pentagon-designates-anthropic-supply.html
Posted Feb 27
⚡ Federal authorities seized $61M in crypto tied to online investment scams. The DOJ says victims were lured into fake high-return platforms, and funds were routed through multiple wallets to hide the trail. Many schemes are linked to scam compounds in Southeast Asia. 🔗 Read → https://thehackernews.com/2026/02/doj-seizes-61-million-in-tether-linked.html
Posted Feb 27
🚨 WARNING: ~900 Sangoma FreePBX systems remain compromised via CVE-2025-64328, a command injection bug patched in 17.0.3. The flaw allows authenticated shell access. Fortinet links the activity to INJ3CTOR3 deploying EncystPHP. Patch and restrict admin access. 🔗 Read → https://thehackernews.com/2026/02/900-sangoma-freepbx-instances.html
Posted Feb 27
🔥 You can now ask Kali Linux tools in plain English — powered by Anthropic Sonnet 4.5. Through MCP, Claude SSHs into Kali to run tools like nmap, gobuster, nikto, hydra, sqlmap, metasploit, john, wpscan, enum4linux-ng, checks dependencies, and returns results in-app. 🔗 Read about it here → https://thehackernews.com/2026/02/threatsday-bulletin-kali-linux-claude.html#ai-powered-command-execution
Posted Feb 27
⚠️ A malicious Go package injected code into ssh/terminal/terminal.go to capture passwords. It posed as Go’s crypto library, stole secrets, loosened firewall rules, and deployed Rekoobe — a Linux trojan linked to APT31 as recently as 2023. 🔗 Read → https://thehackernews.com/2026/02/malicious-go-crypto-module-steals.html
Posted Feb 27
Five attacks. Five lessons. One goal: resilience. From Boeing to Ascension, cybersecurity experts from Halcyon examined #ransomware incidents that reshaped cyber strategy - and the takeaways defenders can apply today. Curious which decisions changed the outcome? Swipe → to see the high-level hits. Don’t wait for an incident to learn from one. Download the full guide: https://thn.news/5-attacks-lessons
Hashtags
Posted Feb 27
A new ScarCruft campaign shows how air-gapped networks are still reachable. Zscaler's December 2025 findings detail malware that spreads through removable media while pulling payloads from Zoho WorkDrive and other cloud services. The chain includes keylogging and audio/video capture modules. 🔗 Read → https://thehackernews.com/2026/02/scarcruft-uses-zoho-workdrive-and-usb.html
Posted Feb 27
⚠️ Microsoft warns of trojanized gaming tools spreading a Java-based RAT. Attackers use PowerShell and built-in tools like cmstp.exe for stealth, add Defender exclusions and scheduled tasks for persistence, then connect to a C2 server to steal data and deploy more payloads. 🔗 Read → https://thehackernews.com/2026/02/trojanized-gaming-tools-spread-java.html
Posted Feb 27
⚡ Meta is suing scam advertisers in Brazil, China, and Vietnam after uncovering celeb-bait and cloaking schemes on its platforms. It says it now protects 500,000+ celebrity images from repeated abuse and has suspended payments, disabled accounts, and blocked domains. 🔗 Read → https://thehackernews.com/2026/02/meta-files-lawsuits-against-brazil.html
Posted Feb 26
🛑 New botnet loader Aeternum uses Polygon smart contracts as its C2 channel. Commands go straight to the public blockchain—infected devices pull & execute them. No servers. No domains. No easy takedown. (Also: US investigators linked a 300-device proxy net to a Belarus seller.) 🔗 Details → https://thehackernews.com/2026/02/aeternum-c2-botnet-stores-encrypted.html