TGINSIGHT CHAT
The Hacker News
@thehackernews
Technologies⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com
Recent posts
Page 53 of 85 · 1,016 posts
Posted Feb 3
🤖 Mozilla will add 1-click Firefox setting to fully disable generative AI features. With Firefox 148, users can block all current and future AI features or manage them individually, keeping AI strictly opt-in as browsers add more automation. 🔗 Read → https://thehackernews.com/2026/02/mozilla-adds-one-click-option-to.html
Posted Feb 3
🚨 China-linked Lotus Blossom compromised Notepad++ hosting infrastructure to hijack update traffic and deliver the Chrysalis backdoor, Rapid7 reports. The issue affected older versions and was fixed with version 8.8.9 in December 2025. 🔗 Read → https://thehackernews.com/2026/02/notepad-hosting-breach-attributed-to.html
Posted Feb 2
⚡🤖 Researchers find 341 malicious ClawHub skills targeting OpenClaw users via fake install steps. The skills deploy Atomic Stealer on macOS and keylogging malware on Windows, abusing OpenClaw’s open marketplace model. 🔗 Read → https://thehackernews.com/2026/02/researchers-find-341-malicious-clawhub.html
Posted Feb 2
🔥 A high-severity RCE flaw in OpenClaw lets attackers take over the local agent with a single click. A crafted link can steal a gateway token via unvalidated WebSocket origins, enabling full command execution even on localhost-only setups through the user’s browser. 🔗 Details and attack chain → https://thehackernews.com/2026/02/openclaw-bug-enables-one-click-remote.html
Posted Feb 2
⚡ Microsoft will phase out NTLM in Windows through a three-step plan. Deprecated in June 2024, NTLM remains widely used despite known security flaws. NTLM will be disabled by default in a future Windows release, with Kerberos becoming the standard. 🔗 dtails → https://thehackernews.com/2026/02/microsoft-begins-ntlm-phase-out-with.html
Posted Feb 2
Latest edition of Cybersecurity recap worth reading: 🌐 Proxy botnet disrupted 🪟 Office zero-day exploited 🤖 AI endpoints hijacked ⚡ Power systems targeted 🧩 Malware in dev tools 📧 AWS creds abused 🗄️ Databases extorted 🔐 Enterprise flaws exploited 🔗 Full RECAP → https://thehackernews.com/2026/02/weekly-recap-proxy-botnet-office-zero.html
Posted Feb 2
What if the hardest vulnerability to patch… is self-doubt? ICS environments are unforgiving. Responders can’t afford hesitation—but they also can't ignore it. In ICS410, Justin Searle helps practitioners move from doubt to decisive action, grounded in technical precision and OT situational awareness. Register for ICS410 at SANS Surge 2026 (Feb 23–28) and train live with Justin: https://thn.news/sans-surge-26
Posted Feb 2
🛡️⚙️ Mid-market security fails when siloed tools drive up cost and alerts faster than teams can cope. Endpoint, email, and firewall tools run in isolation, weakening protection. The shift is toward single platforms across the full threat lifecycle to cut risk without extra overhead. 🔗 How lifecycle security works in practice → https://thehackernews.com/2026/02/securing-mid-market-across-complete.html
Posted Feb 2
Experts at CTM360 report brand impersonation has become a scaled fraud operation. Its findings show 30,000+ fake fashion stores across 80+ countries, using ads and real payment flows before disappearing. 🔗 How the FraudWear network operates at scale → https://thehackernews.com/expert-insights/2026/02/ctm360-research-reveals-30000-fake.html
Posted Feb 2
🛑 WARNING - Notepad++ confirmed state-sponsored attackers hijacked its update traffic via a compromised hosting provider. Selected users were redirected to malicious update servers. The activity ran for months. 🔗 Learn more → https://thehackernews.com/2026/02/notepad-official-update-mechanism.html
Posted Feb 2
⚠️ ALERT — eScan antivirus delivered a malicious update after its update system was compromised. During a two-hour window, attackers swapped a trusted file to stop updates and 🛠️ cleanup. The malware hid by faking update status and downloading more payloads. 🔗 Details → https://thehackernews.com/2026/02/escan-antivirus-update-servers.html
Posted Feb 2
⚠️ WARNING: A supply chain attack spread malware via trusted VS Code extensions on Open VSX. Attackers hijacked a real developer account and pushed GlassWorm through four existing tools. 22,000+ installs happened before removal. 🔗 Read → https://thehackernews.com/2026/02/open-vsx-supply-chain-attack-used.html