TGTGInsighttelegram intelligenceLIVE / telegram public index
Back to channels
The Hacker News avatar

TGINSIGHT CHAT

The Hacker News

@thehackernews

Technologies

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com

Subscribers16.3万Current channel subscribers
Tracked posts1,016Indexed post count
Recent reach109,050Sum of recent post views
Recent posts

Recent posts

Page 60 of 85 · 1,016 posts

Posted Jan 21

🚨 npm binary-parser flaw enables arbitrary JavaScript execution in some Node.js apps. Affects versions < 2.3.0 and only hits apps that build parsers from untrusted input via dynamic code generation. 🔗 Exploit path explained → https://thehackernews.com/2026/01/certcc-warns-binary-parser-bug-allows.html

9,020 views

Posted Jan 20

🇰🇵 North Korea–linked actors are luring developers with fake job repos. Simply opening a malicious VS Code project can auto-run hidden tasks that fetch JavaScript from Vercel and deploy a backdoor enabling remote code execution. 🔗 Learn how it works → https://thehackernews.com/2026/01/north-korea-linked-hackers-target.html

10,000 views

Posted Jan 20

Cybersecurity in 2026 isn't a knowledge problem. It's an execution problem. 📉 The big 3: • AI-driven attacks • Shadow agents • Identity abuse Stop reading, start executing! Full Forecast: https://thn.news/tech-security-outlook

9,880 views

Posted Jan 20

🚨 Anthropic’s official Git MCP server had three vulnerabilities enabling file read/delete and potential RCE. Researchers showed prompt injection—via AI-read content—can trigger the chain without direct system access. 🔗 Exploit chain and CVEs → https://thehackernews.com/2026/01/three-flaws-in-anthropic-mcp-git-server.html

8,750 views

Posted Jan 20

🚨 Researchers found a malware campaign abusing VS Code extensions to infect developers with Evelyn Stealer. It injects into a legit Windows process to quietly steal credentials, browser cookies, and crypto data. 🔗 Find how the extensions worked and what was stolen → https://thehackernews.com/2026/01/evelyn-stealer-malware-abuses-vs-code.html

8,620 views

Posted Jan 20

🚨 Uncharted: The AI Safety & Security Summit from Fuel iX 🚨 Hidden vulnerabilities and compliance challenges are emerging faster than ever. Access 9 expert-led sessions and a comprehensive report revealing risks in 24 generative AI models. 🔒 Uncover hidden dangers in frontier AI models ⚖️ Learn legal frameworks balancing innovation with responsibility 🛡️ Get proactive defense strategies from top CISOs 📄 Receive a detailed report on vulnerabilities and actionable strategies Access it now, on-demand: https://thn.news/uncharted-summit

8,290 views

Posted Jan 20

⚠️ Most enterprises have a hidden risk: orphan accounts. They still log in, but no one owns them. IAM only controls what’s connected. Service accounts, legacy apps, and AI agents are often missed. Inactive access stays active—and attackers use it. 🔗 How continuous identity audits close this gap → https://thehackernews.com/2026/01/the-hidden-risk-of-orphan-accounts.html

8,080 views

Posted Jan 20

Leaked API keys aren’t rare 🔑 The blind spot is where teams look. Intruder scanned 5M apps and found 42K+ exposed tokens embedded in JavaScript bundles—most in SPAs. Many scanners never load front-end assets, so these leaks go unseen 👀 🔗 How secrets slip past scanners → https://thehackernews.com/2026/01/why-secrets-in-javascript-bundles-are.html

8,350 views

Posted Jan 20

🚨 Cloudflare fixed a flaw in its ACME HTTP-01 handling that could conditionally disable WAF and allow requests to reach origin servers. The issue was missing checks that the token matched an active challenge for the hostname. 🔗 Learn more → https://thehackernews.com/2026/01/cloudflare-fixes-acme-validation-bug.html

8,560 views

Posted Jan 20

Thousands of fake banking sites are quietly pulling users in via Google. CTM360 tracked 11,000+ fake bank domains targeting the U.S. and UK, many ranking next to real institutions. These sites run full onboarding and fake approvals before charging “fees” via crypto or PayPal. 🔗 How SEO is weaponized for fraud → https://thehackernews.com/expert-insights/2026/01/ctm360-analysis-shows-how-fake-banks.html

9,190 views

Posted Jan 20

🚨 A major Telegram scam marketplace may be winding down. Elliptic reports Tudou Guarantee has largely halted transactions in its public channels after processing $12B+ in illicit activity. 🔗 Read → https://thehackernews.com/2026/01/tudou-guarantee-marketplace-halts.html

9,710 views

Posted Jan 19

🚨 Researchers found an indirect prompt injection flaw abusing Google Gemini via calendar invites. A hidden prompt in an event could trigger Gemini, when asked about a schedule, to summarize private meetings into a new calendar entry—visible to attackers in some enterprise setups. No user action required. 🔗 Read → https://thehackernews.com/2026/01/google-gemini-prompt-injection-flaw.html

10,600 views
12•••5•••10•••15•••20•••25•••30•••35•••40•••45•••50•••55•••5859606162•••65•••70•••75•••80•••8485