The Hacker News
описание
⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com
162 085
подписчиков
Охват к подписчикам
4,1%
ERR
Реакции к просмотрам
0,19%
553 на 50 постов
Пересылки к просмотрам
0,39%
1 102
Постов в день
7,6
всего 156
Где отзываются чаще
доля реакций к просмотрам- 17 авг.‼️Critical GitLab vulnerability could let unauthenticated attackers delete public projects. CVE-2026-19478 affects self-managed CE and EE under certain conditions. Fixes are in 19.2.4, 19.1.6, 19.0.8, and 18.11.11. What admins need to know: https://thehackernews.com/2026/08/critical-gitlab-graphql-flaw-could-let.html0,49%
- 17 авг.⚡ A VoLTE exploit chain can give attackers full Android kernel access. The Unisoc chain starts with modem RCE, then lets modem code modify Android kernel memory. It requires attacker-controlled 4G infrastructure and the victim to answer the video call. No patch is available. Details: https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html0,47%
- 14 авг.‼️ U.S. firms could soon be authorized to hack foreign crime groups. A Trump memo directs the NCC to create a program for vetted companies to access data and disrupt, degrade, or destroy TCO systems under U.S. government approval. Read what it allows: https://thehackernews.com/2026/08/trump-memo-paves-way-for-us-firms-to.html0,42%
- 14:11‼️ AI “mind viruses” can spread from one agent to another. Researchers showed self-propagating payloads can travel through persistent prompt files, survive 20-hop agent chains, and even trigger file deletion in controlled tests. Read how the technique works: https://thehackernews.com/2026/08/ai-mind-viruses-can-spread-between.html0,37%
- 12 авг.🚨 Lazarus-linked attacks exploit a Windows zero-day for SYSTEM access. Dream Job lures defense and aerospace targets with fake recruiter messages. One chain exploits CVE-2026-68820 for privilege escalation; another uses a trojanized PDF viewer to load the new Troy backdoor. See how the attacks work: https://thehackernews.com/2026/08/lazarus-exploits-windows-zero-day-to.html0,33%
- 13 авг.🚨 WindRelay turns Android phones into live contactless payment proxies. Attackers use SpyNote access to silently install the NFC relay malware. When victims tap a physical card on the infected phone, WindRelay streams its NFC data in real time to a fraudster's device, enabling fraudulent payments. Read how it works: https://thehackernews.com/2026/08/windrelay-android-malware-turns-victims.html0,30%
- 12 авг.🚨 Three Adobe flaws hit CVSS 10.0 and could enable code execution. Adobe patched the maximum-severity bugs in ColdFusion and Campaign Classic, plus a CVSS 9.1 Commerce flaw that could allow privilege escalation. No exploitation has been seen in the wild. Read: https://thehackernews.com/2026/08/adobe-patches-three-cvss-100-coldfusion.html0,29%
- 13 авг.🚨 737 Chrome VPN extensions routed browser traffic through threat actor-controlled servers. They drew 75,486 installs, with 274 impersonating 66 VPN and privacy brands. Most sent entire browser sessions through SOCKS5 proxies. Read: https://thehackernews.com/2026/08/737-chrome-vpn-extensions-caught.html Check if you installed one.0,28%
- 12 авг.‼️ Researchers found a way to make a weaker AI decode a stronger model's hidden reasoning. They extracted hidden traces from OpenAI, Anthropic, and Google APIs, recovering secret API keys and passwords, along with other credentials, in publicly shared agent logs. Read more: https://thehackernews.com/2026/08/openai-anthropic-google-api-flaw-let.html0,27%
- 17 авг.🚨 Evooo1Bot turns infected edge devices into SOCKS5 proxies. The Linux botnet exploits known flaws in routers, firewalls, cameras, and other internet-facing devices, adding credential sniffing, SSH brute forcing, DDoS attacks, and other capabilities to Mirai-based code. How it works: https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html0,27%
- 13 авг.🛑 Attackers are exploiting a SharePoint authentication bypass. CVE-2026-55040 lets unauthenticated attackers forge JWTs and impersonate any SharePoint site user, including administrators. Eight of 12 recorded exploit attempts occurred on August 12 and 13, after Rapid7 published a PoC. See how the exploit works: https://thehackernews.com/2026/08/attackers-exploit-sharepoint.html0,26%
- 14 авг.⚠️ Mercenary spyware may have targeted users in 110 countries. Apple has sent a fresh round of high-confidence alerts to people it says were individually singled out. Journalists, activists, politicians, and diplomats are typical targets. Read the full story: https://thehackernews.com/2026/08/apple-warns-users-in-110-countries-they.html0,25%