tgindex
The Hacker News

The Hacker News

Статистика

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

Последний пост
15 авг.
Последнее чтение
12:59
Постов за неделю
43
Всего постов
133
Тип
открытый
Язык
английский
Категория
Новости и СМИ
В каталоге с
12 авг.
Подписчики
162 064
+8 за 4 дн.
Сутки
−31
−0,02%
Неделя
 
Месяц
 
Просмотров на пост
5 492
40 постов
Вовлечённость
3,4%
к подписчикам
Постов в день
6,1
всего 133
Упоминаний
15
каналов
Охват размещения
по 15 постам
1/24сутки в ленте
4 749
1/48двое суток
5 126
1/72трое суток
5 528

Медиана по постам, которые мы застали свежими и померили через сутки.

Посты

  • 15 авг.4 923619

    🚨 Exploitation attempts hit SAP just three days after the patch. CVE-2026-58231 is a CVSS 10.0 Commerce Cloud flaw that could let unauthenticated attackers execute arbitrary code. Inside the attacks: https://thehackernews.com/2026/08/sap-commerce-cloud-cve-2026-58231.html

  • 15 авг.4 45412

    An IAM audit can pass while access gaps stay hidden. Local accounts, service credentials, and legacy systems may sit outside centralized IAM visibility. Compliance means proving controls are enforced, not just documented. Read more: https://thehackernews.com/2026/08/iam-compliance-requirements-and-best.html

  • 15 авг.4 239312

    ⚡ UPDATE: GeoServer has patched the actively targeted SQL injection flaw. The issue affects PostGIS-backed deployments and is a regression of CVE-2023-25158. Update now: https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html

  • 15 авг.4 5781018

    ⚠️ Attackers are exploiting a macOS Screen Sharing flaw to install Monero miners. CVE-2026-65400 is being abused on multiple Macs exposing port 5900 to the internet. Apple patched the flaw in emergency macOS updates. What you need to know: https://thehackernews.com/2026/08/apple-macos-screen-sharing-flaw.html

  • 14 авг.5 7011218

    ‼️ Nearly $7 million spent buying expired domains for cybercrime. Experts say Sable Squirrel controls 10,000+ domains used across illegal streaming, gambling, and malware infrastructure. At least 31,000 malware samples have communicated with them. Read - https://thehackernews.com/2026/08/hackers-spend-nearly-7-million-on.html

  • 14 авг.6 008921

    🚨 CoolClient now uses a signed rootkit to hide at the Windows kernel level. The Mustang Panda-linked backdoor can hide its process, files, registry entries, and some C2 activity. Kaspersky found victims in Myanmar, Mongolia, Pakistan, and Russia, including government entities. Read more: https://thehackernews.com/2026/08/mustang-panda-adds-signed-windows.html

  • 14 авг.5 6891220

    Fake job interviews are stealing Google and Facebook credentials. CTM360 uncovered RecruitTrap across 3,000+ phishing URLs posing as recruiter and interview pages. Some fake logins relay MFA prompts in real time, letting attackers obtain an authenticated session. See how the attack works: https://thehackernews.com/2026/08/ctm360-uncovers-over-3000-recruitment.html

  • 14 авг.5 4921327

    🚨 Live Chrome and Edge sessions can be hijacked without cookie replay. Researchers show how CDP can be enabled inside an already-running Windows browser, letting an attacker use its existing authenticated state after gaining code execution. Read how it works: https://thehackernews.com/2026/08/chrome-devtools-technique-enables.html

  • 14 авг.5 1631515

    ⚠️ Mercenary spyware may have targeted users in 110 countries. Apple has sent a fresh round of high-confidence alerts to people it says were individually singled out. Journalists, activists, politicians, and diplomats are typical targets. Read the full story: https://thehackernews.com/2026/08/apple-warns-users-in-110-countries-they.html

  • 14 авг.5 5452726

    ‼️ U.S. firms could soon be authorized to hack foreign crime groups. A Trump memo directs the NCC to create a program for vetted companies to access data and disrupt, degrade, or destroy TCO systems under U.S. government approval. Read what it allows: https://thehackernews.com/2026/08/trump-memo-paves-way-for-us-firms-to.html

  • 14 авг.5 4951017

    ⚠️ China-linked Jewelbug runs espionage and crypto fraud from the same platform. XG-Web lets operators control browsers, steal credentials and cookies, and execute commands on Windows hosts. One espionage operation hit 15 government webmail tenants and collected over 580,000 cookies. Read how Jewelbug operates: https://thehackernews.com/2026/08/china-linked-jewelbug-uses-xg-web-for.html

  • 13 авг.6 3791126

    ‼️ Attackers are already probing an unpatched GeoServer zero-day. The SQL injection flaw drew hundreds of attempts within hours of disclosure and, under certain configurations, can lead to remote code execution. No patch is available yet. Read the details: https://thehackernews.com/2026/08/unpatched-geoserver-zero-day-targeted.html

  • 13 авг.5 8651214

    The threat doesn’t always break in. Sometimes it gets hired. North Korean IT workers can pass interviews, get legitimate credentials, and gain trusted access. A new investigation reveals the red flags CISOs should catch before a fraudulent hire gets inside. Read the findings: https://thehackernews.com/2026/08/north-korean-remote-workers-are.html

  • 13 авг.5 388412

    ⚡ This week’s threats came from everywhere. AI agents tricked through poisoned data. Cloud services exposed through guest access. Fake software dropping spyware. DDoS attacks getting bigger. New scams, malware tricks, security flaws, and fixes. #ThreatsDay Bulletin packs the stories you may have missed into one quick read. Read the full roundup: https://thehackernews.com/2026/08/threatsday-ghostjacking-ai-attacks.html

  • 13 авг.5 829715

    AI has fundamentally changed email attacks. See how attackers create convincing AI-powered phishing campaigns, why traditional email security struggles to stop them, and how AI-native detection catches malicious intent. Join Adaptive's live webinar on August 25 at 11am PT / 2pm ET: https://thn.news/rethinking-ai-security

  • 13 авг.5 5681421

    🛑 APT36-linked hackers target Afghan telecom and Indian networks with new backdoors. PATCHCORD spreads via fake telecom tools, while SHEETCORD uses Google Sheets for C2. See how it works: https://thehackernews.com/2026/08/new-patchcord-backdoor-targets-afghan.html

  • 13 авг.5 5701027

    ⚠️ AmnesiaStealer gives attackers live control of authenticated browser sessions. macOS ClickFix lure → paste command in Terminal → steals passwords & browser data → opens a hidden Chromium browser attackers can click, type, scroll & navigate in real time. Details: https://thehackernews.com/2026/08/amnesiastealer-hijacks-chromium.html

  • 13 авг.5 6921729

    🚨 WindRelay turns Android phones into live contactless payment proxies. Attackers use SpyNote access to silently install the NFC relay malware. When victims tap a physical card on the infected phone, WindRelay streams its NFC data in real time to a fraudster's device, enabling fraudulent payments. Read how it works: https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html

  • 13 авг.6 2091726

    🚨 737 Chrome VPN extensions routed browser traffic through threat actor-controlled servers. They drew 75,486 installs, with 274 impersonating 66 VPN and privacy brands. Most sent entire browser sessions through SOCKS5 proxies. Read: https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html Check if you installed one.

  • 13 авг.6 0491012

    AI assistants sometimes repeated attackers’ install steps. Island’s Alon Biran says its team found ~7,600 malicious GitHub repos, 800+ posing as AI Skills or MCP servers. In tests, assistants surfaced them and sometimes repeated the install steps as legitimate guidance. Read more: https://thehackernews.com/expert-insights/2026/08/agents-work-everywhere-now-governance.html