TGINSIGHT CHAT
The Hacker News
@thehackernews
Technologies⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com
Recent posts
Page 51 of 85 · 1,016 posts
Posted Feb 5
📦⚠️ Is your container adoption outpacing your security maturity? You’re not alone. ActiveState’s 2026 State of Vulnerability Management & Remediation Report found 82% of DevSecOps leaders experienced a container-related breach last year and 87% expect one in 2026. Learn how to close the “remediation gap” and the role AI will play in securing your stack by 2026. 📥 Download the report → https://thn.news/container-sec-guide
Posted Feb 5
⚠️ AI is everywhere in the enterprise — SaaS, browsers, copilots, shadow tools. Visibility is years behind adoption. Legacy controls miss real interaction points, leaving prompts, uploads, and agent workflows ungoverned. 🔗 Download guide link → https://thehackernews.com/2026/02/the-buyers-guide-to-ai-usage-control.html
Posted Feb 5
💻 Iran-linked APT Infy paused C2 ops during Iran’s Jan internet blackout — then rebuilt infrastructure as access returned. Timing ties activity to state network controls. Latest malware uses Telegram + HTTP for dual-channel C2. 🔗 Timeline, tooling evolution, infra rebuild → https://thehackernews.com/2026/02/infy-hackers-resume-operations-with-new.html
Posted Feb 5
Passwords are sliding into legacy status. Passkeys, AI governance, and verifiable credentials are scaling as identity shifts to real-time trust — per Rex Booth, SailPoint. 🔐 9 predictions reshaping identity security → https://thehackernews.com/expert-insights/2026/02/9-identity-security-predictions-for-2026.html
Posted Feb 5
⚠️ Critical RCE flaw in n8n (CVE-2026-25049, CVSS 9.4) lets authenticated users execute system commands via crafted workflow expressions. Public webhooks exposed → remote trigger, credential theft, server takeover. 🔗 Exploit path, affected versions, patch details → https://thehackernews.com/2026/02/critical-n8n-flaw-cve-2026-25049.html
Posted Feb 5
⚠️ Attackers are hijacking live web traffic by weaponizing NGINX configs linked to React2Shell exploitation. Rogue proxy rules silently reroute user sessions through attacker infrastructure—impacting 🏛️ gov, 🎓edu, and Asian 🌏 TLD sites. 🔗 Details → https://thehackernews.com/2026/02/hackers-exploit-react2shell-to-hijack.html
Posted Feb 4
☁️ Cloud attacks move fast. Evidence disappears faster. Context-aware cloud forensics host data automatically and uses AI to rebuild real attack timelines in minutes—not days. Practical investigation workflows included. 🎥 Join the live session... Telemetry model, AI analysis, response use cases → https://thehacker.news/forensics-reimagined
Posted Feb 4
⚡ Microsoft built a scanner to detect backdoors in open-weight LLMs 🧠 using 3 behavioral signals. It flags trigger attention spikes, memorized poisoning data leaks, and fuzzy trigger activation—no retraining required. Built to scan open models at scale. 🔗 Signals, detection method, limits, AI SDL shift → https://thehackernews.com/2026/02/microsoft-develops-scanner-to-detect.html
Posted Feb 4
Threat actors are delivering AsyncRAT via IPFS-hosted VHD files in DEAD#VAX. Phishing emails mount fake PDF drives that run obfuscated scripts and in-memory shellcode inside trusted Windows processes—minimal disk trace. 🧠 Fileless 🛰️ IPFS 🪟 Process injection 🔗Read → https://thehackernews.com/2026/02/deadvax-malware-campaign-deploys.html
Posted Feb 4
🇨🇳 China-linked Amaranth-Dragon targeted Southeast Asian government and law enforcement networks in 2025, with links to the APT41 ecosystem. Campaigns leveraged political lures and the WinRAR CVE-2025-8088 RCE flaw, using cloud delivery and geo-fenced infrastructure for stealth. 🔗 Read → https://thehackernews.com/2026/02/china-linked-amaranth-dragon-exploits.html
Posted Feb 4
🚨 All 24 GenAI models failed our security testing We put 24 leading GenAI models through comprehensive security testing. The results? Every single one demonstrated exploitable chatbot vulnerabilities, with attack success rates ranging from 1.13% to 64.13%. Key findings: - 24 frontier models tested - Hundreds of vulnerabilities discovered - Attack success rates up to 64% - 100% failure rate across all models What's in the report: ✅ Detailed security profiles of 24 GenAI models ✅ Analysis of the AI prevention gap ✅ Practical strategies for securing AI systems ✅ Compliance and risk management guidance As GenAI transforms industries, these findings underscore the critical need for continuous, automated security testing. Download the full report: https://thn.news/gen-ai-tg-report
Posted Feb 4
Identity risk now sits beyond IAM — inside apps, APIs, and service accounts. 🧩 Identity Dark Matter includes hardcoded credentials, orphaned accounts, and access paths outside identity providers — largely invisible to traditional tools. 🔗 Learn how Orchid uncovers Identity Dark Matter → https://thehackernews.com/2026/02/orchid-security-introduces-continuous.html