The Hacker News
⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com
إظهار المزيد📈 نظرة تحليلية على قناة تيليجرام The Hacker News
تُعد قناة The Hacker News (@thehackernews) في القطاع اللغوي الإنكليزية لاعباً نشطاً. يضم المجتمع حالياً 163 551 مشتركاً، محتلاً المرتبة 654 في فئة التكنولوجيات والتطبيقات والمرتبة 105 في منطقة الولايات المتحدة.
📊 مؤشرات الجمهور والحراك
منذ تأسيسه في невідомо، حقق المشروع نمواً سريعاً وجمع 163 551 مشتركاً.
بحسب آخر البيانات بتاريخ 04 أكتوبر, 2026، تحافظ القناة على نشاط مستقر. خلال آخر 30 يوماً تغيّر عدد الأعضاء بمقدار 1 420، وفي آخر 24 ساعة بمقدار -54، مع بقاء الوصول العام مرتفعاً.
- حالة التحقق: موثّقة (مؤكدة رسمياً من تيليجرام)
- معدل التفاعل (ER): يبلغ متوسط تفاعل الجمهور 4.25%. وخلال أول 24 ساعة من النشر يحصد المحتوى عادةً 2.87% من ردود الفعل نسبةً إلى إجمالي المشتركين.
- وصول المنشورات: يحصل كل منشور على متوسط 6 963 مشاهدة. وخلال اليوم الأول يجمع عادةً 4 699 مشاهدة.
- التفاعلات والاستجابة: يتفاعل الجمهور بانتظام؛ متوسط التفاعلات لكل منشور يبلغ 10.
- الاهتمامات الموضوعية: يركز المحتوى على مواضيع رئيسية مثل attack, credential, cve-2026, github, backdoor.
📝 الوصف وسياسة المحتوى
يصف المؤلف القناة بأنها مساحة للتعبير عن الآراء الذاتية:
“⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.
📨 Contact: admin@thehackernews.com
🌐 Website: https://thehackernews.com”
بفضل وتيرة التحديث المرتفعة (أحدث البيانات بتاريخ 05 أكتوبر, 2026) تحافظ القناة على حداثتها ومستوى وصول مرتفع. وتُظهر التحليلات تفاعلاً نشطاً من الجمهور، ما يجعلها نقطة تأثير مهمة ضمن فئة التكنولوجيات والتطبيقات.
جاري تحميل البيانات...
| التاريخ | نمو المشتركين | الإشارات | القنوات | |
| 05 أكتوبر | +1 | |||
| 04 أكتوبر | +20 | |||
| 03 أكتوبر | +11 | |||
| 02 أكتوبر | +6 | |||
| 01 أكتوبر | +27 |
| 2 | GitGuardian found 28.65 million new hardcoded secrets in public GitHub commits in 2025, up 34% year over year.
It also found 24,008 unique secrets in public MCP configuration files, including 2,117 verified as valid.
See how credentials are spreading across code, endpoints, and AI tooling: https://thehackernews.com/2026/10/the-credential-layer-is-expanding.html | 2 407 |
| 3 | 15 cyber stories worth 2 minutes of your attention:
• NetScaler + FortiMail 0-days
• Spectre v2 leaks root hashes
• CosmicPulse phishing
• NeedyMantis persistence
• RatHat + Gemini targeting
• 13K AI-leaked screenshots
• Ransomware arrests
• Microsoft X hijack
• WordPress credential theft
• PageBreak AI vuln hunting
• Milk Dragon phishing
• NodeStealer upgrades
• Direct Send bypass
• PaperCut exploitation
• AI models building exploits
• Plus a huge CVE pile
Full ThreatsDay recap: https://thehackernews.com/2026/10/weekly-recap-netscaler-and-fortimail-0.html | 2 928 |
| 4 | CJIS compliance starts with stronger authentication.
Weak passwords and inconsistent MFA enforcement can create compliance and security challenges for agencies and organizations that handle criminal justice information.
Download our practical guide to learn:
✅ Key CJIS password requirements
✅ MFA compliance best practices
✅ Common compliance gaps to avoid
✅ Steps to strengthen your security posture
Get the guide: https://thn.news/password-mfa-standards | 3 352 |
| 5 | 🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet.
Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html | 1 |
| 6 | 🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet.
Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html | 1 |
| 7 | 🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet.
Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html | 3 448 |
| 8 | ⚡ Apple is tightening macOS Full Disk Access, a permission that can let AI agents read files, mail, messages, browsing history, and more.
Future access will require explicit user action.
Here's what Apple is changing: https://thehackernews.com/2026/10/apple-plans-tighter-macos-full-disk.html | 3 760 |
| 9 | A financial app treated a GUID like proof of access.
In a penetration test described by Sygnia's Zach Mead, the AI-assisted onboarding flow could issue or restore an applicant token if another applicant’s GUID was obtained, potentially exposing sensitive personal and financial data.
How the trust failure worked: https://thehackernews.com/expert-insights/2026/10/when-ai-writes-code-who-owns-security.html | 3 718 |
| 10 | ⚠️ Attackers are targeting a Rejetto HFS flaw that enables forged admin sessions and remote code execution.
CVE-2026-61500 affects HFS 3.0.0–3.2.0. VulnCheck detected exploitation attempts against vulnerable U.S. hosts after a public PoC was released.
Read - https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html | 4 076 |
| 11 | An AI pentesting agent says it exploited a bug. Did it?
XRanges for AI watches from inside the target, recording exploit-chain progress, coverage, boundary violations, and whether the environment survives the run.
Inside the scoring: https://thehackernews.com/2026/09/545-hackers-tested-it-first-now-xranges.html | 4 381 |
| 12 | ‼️ Citrix has patched a new NetScaler zero-day exploited in targeted attacks.
CVE-2026-88779 affects certain SAML-configured deployments & can cause denial-of-service, with repeated triggering potentially leaving services unavailable.
Details - https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html | 4 535 |
| 13 | ‼️ A suspected #ShinyHunters member is reportedly helping the FBI identify others in the group.
Rey, also known as ReyXBF, was allegedly detained in Jordan on September 29. His cooperation is now feeding an ongoing effort to pursue more members.
Read: https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html | 7 152 |
| 14 | TA419 is targeting U.S. AI policy experts with Microsoft AitM phishing.
The China-aligned group waits for targets to reply, then sends a shortened link to a Frameless BitB page built to capture credentials and session cookies.
Read about the technique: https://thehackernews.com/2026/10/china-aligned-ta419-targets-us-ai.html | 6 209 |
| 15 | ⚡ MI5 named a Chinese institute an MSS front and said 100+ UK-linked academics helped fund its spy tech.
A 30 Sept alert says CGTRI exists to bankroll work that improves MSS capability: AI, cyber, covert comms, steganography. Some academics may not know who paid.
Beijing calls it fabricated.
Read: https://thehackernews.com/2026/10/mi5-says-chinas-mss-funded-research.html | 6 736 |
| 16 | ⚠️ Unpatched SharePoint is still getting orgs ransomed.
Warlock hit a water utility, a telecom, a government body, and a university in the last 2 months. They killed security tools on 40 hosts in ~2 hours, then used SYSVOL to push ransomware to 33 machines.
Read: https://thehackernews.com/2026/10/warlock-exploits-sharepoint-flaws-to.html | 6 359 |
| 17 | Visibility alone is no longer enough.
A new report brings together 10 security companies on what comes next: continuous identity governance, telemetry that can be reused, enforced remediation, and AI that accelerates investigations without replacing human judgment.
Full report: https://thehackernews.com/2026/10/the-state-of-cybersecurity-in-2026key.html | 5 806 |
| 18 | ⚠️ Antino turns Outlook and OneDrive into command-and-control channels.
China-nexus UAT-11587 is using the Rust backdoor in spear-phishing attacks targeting government and policy organizations across Asia.
How the attack chain works: https://thehackernews.com/2026/10/antino-backdoor-uses-outlook-and.html | 6 983 |
| 19 | ‼️ GitLab has patched a critical 9.9-rated flaw in its self-hosted AI Gateway that could let low-privileged Duo Agent users escape the prompt sandbox and execute commands on the underlying server.
Affected self-hosted deployments should update immediately.
Read: https://thehackernews.com/2026/10/gitlab-patches-critical-self-hosted-ai.html | 6 566 |
| 20 | 🛑 A Dell CSM flaw can give unauthenticated attackers admin control over storage infrastructure.
The six bugs include two CVSS 10.0 issues. Another can let a low-privilege attacker gain root on Kubernetes cluster nodes. Dell says there are no workarounds beyond updating.
Details: https://thehackernews.com/2026/10/dell-csm-flaws-enable-unauthenticated.html | 5 955 |
