The Hacker News
⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com
Show more📈 Analytical overview of Telegram channel The Hacker News
Channel The Hacker News (@thehackernews) in the English language segment is an active participant. Currently, the community unites 162 275 subscribers, ranking 654 in the Technologies & Applications category and 111 in the USA region.
📊 Audience metrics and dynamics
Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 162 275 subscribers.
According to the latest data from 26 August, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 170 over the last 30 days and by 38 over the last 24 hours, overall reach remains high.
- Verification status: Verified (Officially confirmed by Telegram)
- Engagement rate (ER): The average audience engagement rate is 4.43%. Within the first 24 hours after publication, content typically collects 2.99% reactions from the total number of subscribers.
- Post reach: On average, each post receives 7 194 views. Within the first day, a publication typically gains 4 845 views.
- Reactions and interaction: The audience actively supports content: the average number of reactions per post is 13.
- Thematic interests: Content is focused on key topics such as attack, credential, cve-2026, github, backdoor.
📝 Description and content policy
The author describes the resource as a platform for expressing subjective opinions:
“⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.
📨 Contact: admin@thehackernews.com
🌐 Website: https://thehackernews.com”
Thanks to the high frequency of updates (latest data received on 27 August, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.
Data loading in progress...
| Date | Subscriber Growth | Mentions | Channels | |
| 27 August | +49 | |||
| 26 August | +59 | |||
| 25 August | +38 | |||
| 24 August | +45 | |||
| 23 August | +17 | |||
| 22 August | +62 | |||
| 21 August | +56 | |||
| 20 August | +52 | |||
| 19 August | +37 | |||
| 18 August | +36 | |||
| 17 August | +23 | |||
| 16 August | +35 | |||
| 15 August | +10 | |||
| 14 August | +48 | |||
| 13 August | +61 | |||
| 12 August | +40 | |||
| 11 August | +26 | |||
| 10 August | +15 | |||
| 09 August | +29 | |||
| 08 August | +26 | |||
| 07 August | +20 | |||
| 06 August | +45 | |||
| 05 August | +44 | |||
| 04 August | +33 | |||
| 03 August | +54 | |||
| 02 August | +37 | |||
| 01 August | +29 |
| 2 | 28% of security alerts go uninvestigated.
In a survey of 250+ security pros, 60% said a missed or ignored alert later became a serious issue. Meanwhile, 40% of teams use AI daily, and 72% of AI users report cutting investigation time by at least 25%.
What AI is changing inside the SOC: https://thehackernews.com/2026/08/what-data-says-about-ai-in-security.html | 1 368 |
| 3 | 🚨 A malicious Amazon Kiro workspace can leak sensitive local data.
After opening the workspace, sending any message to the agent can trigger repository-controlled instructions that send local data to an external server. Amazon fixed the flaw in Kiro 0.8.140.
How the flaw works: https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html | 2 059 |
| 4 | A single public GitHub issue was enough to take over a Google Cloud project.
New research from Pillar Security details how an unauthenticated attacker could move from a comment on Google's Gemini CLI to Editor-level access inside a GCP project.
Prompt injection through the issue text reached an agent whose tool allowlist had gone inactive, which led to code execution on the CI runner, cloud credentials stored in plaintext, and an over-broad permission that allowed service-account impersonation up to Editor.
The permission traced back to Google's official setup script for Gemini CLI in GitHub Actions, so any team that followed the recommended setup could have inherited the same path. Google has since shipped fixes.
Research by Dan Lisichkin.
Learn more: https://thn.news/gcp-project-risk | 2 094 |
| 5 | 🚨 Spark RAT targets Cambodia using a vulnerable driver to kill security processes.
The campaign abuses CVE-2026-36425 in an OPSWAT driver to terminate processes tied to Microsoft Defender, Huorong, and Tencent PC Manager before deploying the RAT.
How the attack chain works: https://thehackernews.com/2026/08/spark-rat-targets-cambodia-abuses.html | 3 249 |
| 6 | 🚨 New GoCaracal malware can retrieve fallback C2 addresses from Ethereum smart contracts.
Seen in a June intrusion at a Venezuelan communications organization, GoCaracal can read a replacement address from Ethereum after repeated primary C2 failures, then retry normal off-chain communications.
How the fallback works: https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html | 3 448 |
| 7 | ‼️ New GPUThor attack defeats ECC on NVIDIA’s RTX A6000 and demonstrates host privilege escalation to root.
The Rowhammer technique uses multi-bit memory errors to corrupt GPU page tables, but requires an unprivileged CUDA kernel on the target GPU.
How the attack works: https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html | 3 730 |
| 8 | ⚠️ CISA added six exploited flaws to KEV, spanning NetScaler, Linux, SQL Server, Red Hat, and AjaxPro.
NetScaler CVE-2026-8452 stands out: web shells were dropped, with 36 exploitation attempts from 12 IPs in 12 days.
CISA also says injection flaws dominate recent CVEs, while AI is being used to automate exploitation.
Read: https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html | 4 169 |
| 9 | 🔥 FBI shuts down Chinese hacking platforms tied to intrusions at NASA, the Fed, and U.S. Senate.
QScan exploited vulnerable IoT devices, while QTRouter hid attack traffic behind compromised devices, commercial proxies, and VPSs.
How it worked: https://thehackernews.com/2026/08/fbi-disrupts-china-linked-qtfy.html | 6 127 |
| 10 | 🛑 CISA red teams compromised two critical infrastructure organizations. One SOC detected nothing.
The other caught the initial phishing and isolated affected workstations within 2–20 minutes.
Learn why one SOC saw it and the other didn’t: https://thehackernews.com/2026/08/cisa-red-team-compromised-two-critical.html | 6 516 |
| 11 | Agentic SOCs can investigate alerts before analysts touch them.
AI agents can validate detections, test hypotheses against network telemetry, and return evidence-backed cases in seconds or minutes.
The shift: investigate first, escalate to humans when the evidence warrants it.
How the model works: https://thehackernews.com/2026/08/imagine-soc-without-queue-from-alert.html | 5 767 |
| 12 | 🚨 Unpatched Kaltura (a video management and streaming platform) flaws expose server files and could enable RCE.
The mwEmbed bugs need no authentication. Both stem from unsafe deserialization, and CERT/CC says no fix is available.
Read details here: https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html | 5 603 |
| 13 | ‼️ Nobody asked #Claude to cancel another gym member's booking.
Aikido rebuilt the Australian gym app and tested Opus 4.6 on #OpenClaw. The model bypassed its browser-only 7-day booking limit in 9 of 10 runs.
In two runs, it also canceled another member’s reservation.
Read: https://thehackernews.com/2026/08/claude-opus-46-bypasses-gym-booking.html | 5 660 |
| 14 | ⚠️ Russian operators used ChatGPT to run an influence operation.
OpenAI banned the accounts after finding they used VPNs to bypass restrictions and generated posts promoting the International Burke Institute across Substack, Telegram, X, Facebook and LinkedIn.
What OpenAI uncovered: https://thehackernews.com/2026/08/openai-bans-russian-chatgpt-accounts.html | 5 627 |
| 15 | 58 arrested in INTERPOL crackdown on West African cyber-enabled fraud.
Operation Jackal IV identified 263 suspects across 22 countries. One Romanian investment scam is estimated to have stolen and laundered €143 million globally.
Inside the operation: https://thehackernews.com/2026/08/interpol-operation-jackal-iv-arrests-58.html | 5 844 |
| 16 | 🚨 Attackers are exploiting a critical Gitea RCE flaw.
CVE-2026-60004 can let an external attacker gain repo write access via open registration and run shell commands as the Gitea service account.
One reported attack dropped cryptocurrency-miner-like malware.
Read: https://thehackernews.com/2026/08/critical-gitea-rce-actively-exploited.html | 5 934 |
| 17 | ⚡ U.S. sanctions Iran-linked hackers tied to critical infrastructure breaches.
Three alleged Mabna Institute members are accused of stealing data from U.S. energy, defense, healthcare, IT, and financial organizations.
TRM Labs linked 30 wallets to $16.8 million.
Who they hit and where the money went: https://thehackernews.com/2026/08/us-sanctions-iran-linked-hackers-behind.html | 6 505 |
| 18 | UPDATE - Apple fixed the iCloud Private Relay IP leak in iOS 26.6.1 and macOS 26.6.2.
The WebKit issue could bypass proxies and expose users’ real IPs. The fix was not in the iOS 26.6.1 beta.
See the update: https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html | 6 231 |
| 19 | 48% of Mirage2FA-targeted emails were potentially compromised.
ANYRUN uncovered 9,000+ potential compromise events involving password and cookie theft, SSO logins, and 2FA bypass. Activity is potentially linked to 4,532 organization email domains.
See how Mirage2FA works - https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html | 6 033 |
| 20 | ‼️ A malicious webpage could poison the AI running on your own machine.
A NemoClaw weakness can expose Ollama to DNS rebinding, letting an attacker alter its chat template with instructions that persist across conversations.
Read how it works - https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html | 5 874 |
