TGINSIGHT CHAT
The Hacker News
@thehackernews
Technologies⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: [email protected] 🌐 Website: https://thehackernews.com
Recent posts
Page 64 of 85 · 1,016 posts
Posted Jan 13
Researchers disclosed VoidLink, a modular Linux malware built for long-term, stealthy cloud access. It detects AWS, Azure, GCP, Docker, and Kubernetes, adapts its behavior, steals credentials, and enables lateral movement using rootkit-style techniques 🧩 🔗 Read here → https://thehackernews.com/2026/01/new-advanced-linux-voidlink-malware.html
Posted Jan 13
🚨 ServiceNow patched a critical AI Platform flaw enabling unauthenticated user impersonation and actions as the victim. CVE-2025-12420 (CVSS 9.3) affects Now Assist and Virtual Agent. Fixed Oct 30. No known exploitation. 🔗 Details here → https://thehackernews.com/2026/01/servicenow-patches-critical-ai-platform.html
Posted Jan 13
Annual pentests are too slow and narrow for today's threats. Stop chasing every vulnerability and start validating what’s actually exploitable. Exposure Validation filters your list down to the risks that matter most. Check out the guide: https://thn.news/exposure-validation-intro
Posted Jan 13
Researchers uncovered SHADOW#REACTOR, a multi-stage campaign delivering Remcos RAT. It starts with an obfuscated VBS launcher, moves through PowerShell, and rebuilds fragmented text payloads in memory. The defining trait is text-only stagers and LOLBin abuse to reduce detection. 🔗 Read → https://thehackernews.com/2026/01/new-malware-campaign-delivers-remcos.html
Posted Jan 13
🚨 CISA confirms active exploitation of a Gogs flaw now added to the KEV list. CVE-2025-8110 (CVSS 8.7) abuses symlink handling to write outside repositories, enabling code execution. Around 700 exposed instances are already compromised. 🔗 Read → https://thehackernews.com/2026/01/cisa-warns-of-active-exploitation-of.html
Posted Jan 12
🚨 Attackers uploaded fake n8n community nodes to npm to steal OAuth tokens from live workflows. The packages mimicked real integrations, ran with full n8n access, decrypted credentials during execution, and exfiltrated them. Eight were removed, but activity appears ongoing. 🔗 Read about it here → https://thehackernews.com/2026/01/n8n-supply-chain-attack-abuses.html
Posted Jan 12
🚨 This week’s cyber risk moved fast and wide. ⚙️ Automation abused 📱 Mobile botnets scaled 📡 Telecoms mapped 💸 Crypto crime surged 🧪 Exploits outpaced patches 🗂️ Crime forums leaked 🧩 AI chats stolen 🐛 Bugs weaponized 🇮🇳 Policy pushback 📩 Political inboxes hit One pattern. Many fronts. Here’s the full recap of what mattered most ↓ https://thehackernews.com/2026/01/weekly-recap-ai-automation-exploits.html
Posted Jan 12
➡️🛑 Pentesting in 2026 isn’t failing at testing. It’s failing at what happens after. In a new analysis, Dan DeCloss explains why static reports slow real progress—and why teams that actually reduce risk treat findings as living inputs to daily work, not PDFs that get forgotten. Why execution, not output, now defines pentest success → https://thehackernews.com/expert-insights/2026/01/the-2026-state-of-pentesting-how-modern.html
Posted Jan 12
🚨 New GoBruteforcer wave is hijacking crypto and blockchain databases to expand a password-brute-forcing botnet. Researchers link the spike to AI-generated setup guides and reused defaults in legacy stacks like XAMPP. These servers are easy to take over, stay online 24/7, and scale attacks fast. 🔗 Read → https://thehackernews.com/2026/01/gobruteforcer-botnet-targets-crypto.html
Posted Jan 12
🏥🤖 Anthropic just rolled out Claude for Healthcare. U.S. users can connect lab results and health records, get plain-English explanations, spot patterns, and prep for doctor visits. Data sharing is opt-in and not used for training 🔗 Read → https://thehackernews.com/2026/01/anthropic-launches-claude-ai-for.html
Posted Jan 12
⚠️ Chinese crime groups are running 🐷 pig-butchering scams like a startup. Researchers found $2,500 turnkey kits with fake trading sites, apps, hosting, and laundering—built to scale fast, no skills needed. 🔗 Read details here → https://thehackernews.com/2026/01/researchers-uncover-service-providers.html
Posted Jan 10
Europol says Spanish police arrested 34 suspects linked to Black Axe, a Nigeria-origin crime syndicate. The 🕵️♂️ group is tied to cyber fraud, trafficking, and violent crime worldwide. Investigators estimate €5.93M in fraud losses, with cash and bank funds seized in Spain. 🔗 Read → https://thehackernews.com/2026/01/europol-arrests-34-black-axe-members-in.html