en
Feedback
The Hacker News

The Hacker News

Open in Telegram

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

Show more

📈 Analytical overview of Telegram channel The Hacker News

Channel The Hacker News (@thehackernews) in the English language segment is an active participant. Currently, the community unites 164 871 subscribers, ranking 645 in the Technologies & Applications category and 106 in the USA region.

📊 Audience metrics and dynamics

Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 164 871 subscribers.

According to the latest data from 15 September, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 162 over the last 30 days and by -11 over the last 24 hours, overall reach remains high.

  • Verification status: Verified (Officially confirmed by Telegram)
  • Engagement rate (ER): The average audience engagement rate is 4.57%. Within the first 24 hours after publication, content typically collects 2.98% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 7 411 views. Within the first day, a publication typically gains 4 838 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 11.
  • Thematic interests: Content is focused on key topics such as attack, credential, cve-2026, github, backdoor.

📝 Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

Thanks to the high frequency of updates (latest data received on 16 September, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

164 871
Subscribers
-1124 hours
-737 days
+16230 days
Attracting Subscribers
September '26
September '26
+3 158
in 8 channels
August '26
+1 157
in 23 channels
Get PRO
July '26
+1 477
in 20 channels
Get PRO
June '26
+994
in 18 channels
Get PRO
May '26
+1 175
in 24 channels
Get PRO
April '26
+4 326
in 26 channels
Get PRO
March '26
+6 849
in 26 channels
Get PRO
February '26
+1 583
in 27 channels
Get PRO
January '26
+1 516
in 23 channels
Get PRO
December '25
+1 900
in 34 channels
Get PRO
November '25
+1 648
in 25 channels
Get PRO
October '25
+1 634
in 21 channels
Get PRO
September '25
+1 163
in 25 channels
Get PRO
August '25
+1 070
in 17 channels
Get PRO
July '25
+1 318
in 28 channels
Get PRO
June '25
+2 024
in 24 channels
Get PRO
May '25
+1 328
in 24 channels
Get PRO
April '25
+1 758
in 13 channels
Get PRO
March '25
+1 782
in 16 channels
Get PRO
February '25
+2 159
in 19 channels
Get PRO
January '25
+2 315
in 31 channels
Get PRO
December '24
+3 006
in 22 channels
Get PRO
November '24
+3 500
in 12 channels
Get PRO
October '24
+3 385
in 18 channels
Get PRO
September '24
+2 583
in 22 channels
Get PRO
August '24
+2 157
in 16 channels
Get PRO
July '24
+1 844
in 11 channels
Get PRO
June '24
+1 514
in 7 channels
Get PRO
May '24
+1 079
in 9 channels
Get PRO
April '24
+1 306
in 11 channels
Get PRO
March '24
+1 332
in 13 channels
Get PRO
February '24
+630
in 14 channels
Get PRO
January '24
+1 075
in 14 channels
Get PRO
December '23
+973
in 7 channels
Get PRO
November '23
+1 457
in 8 channels
Get PRO
October '23
+3 536
in 5 channels
Get PRO
September '23
+3 177
in 0 channels
Get PRO
August '23
+3 401
in 0 channels
Get PRO
July '23
+2 829
in 0 channels
Get PRO
June '23
+2 847
in 0 channels
Get PRO
May '23
+2 417
in 0 channels
Get PRO
April '23
+2 646
in 0 channels
Get PRO
March '23
+2 345
in 0 channels
Get PRO
February '23
+2 328
in 0 channels
Get PRO
January '23
+2 603
in 0 channels
Get PRO
December '22
+2 541
in 0 channels
Get PRO
November '22
+2 543
in 0 channels
Get PRO
October '22
+3 146
in 0 channels
Get PRO
September '22
+3 951
in 0 channels
Get PRO
August '22
+2 425
in 0 channels
Get PRO
July '22
+2 611
in 0 channels
Get PRO
June '22
+2 636
in 0 channels
Get PRO
May '22
+3 979
in 0 channels
Get PRO
April '22
+4 171
in 0 channels
Get PRO
March '22
+6 802
in 0 channels
Get PRO
February '22
+3 153
in 0 channels
Get PRO
January '22
+4 050
in 0 channels
Get PRO
December '21
+4 346
in 0 channels
Get PRO
November '21
+4 152
in 0 channels
Get PRO
October '21
+6 200
in 0 channels
Get PRO
September '21
+5 226
in 0 channels
Get PRO
August '21
+5 134
in 0 channels
Get PRO
July '21
+6 261
in 0 channels
Get PRO
June '21
+2 427
in 0 channels
Get PRO
May '21
+731
in 0 channels
Get PRO
April '21
+1 029
in 0 channels
Get PRO
March '21
+1 300
in 0 channels
Get PRO
February '21
+786
in 0 channels
Get PRO
January '21
+1 163
in 0 channels
Get PRO
December '20
+22 087
in 0 channels
Date
Subscriber Growth
Mentions
Channels
16 September+2 628
15 September+26
14 September+23
13 September+29
12 September+23
11 September+32
10 September+54
09 September+25
08 September+61
07 September+25
06 September+53
05 September+45
04 September+41
03 September+37
02 September+34
01 September+22
Channel Posts
⚠️ Acronis Backup flaw exploited in limited targeted attacks. CVE-2026-87886 lets a low-privileged attacker escalate permissi
⚠️ Acronis Backup flaw exploited in limited targeted attacks. CVE-2026-87886 lets a low-privileged attacker escalate permissions on affected Linux cPanel/WHM and Plesk deployments. Fixes are available. Which builds need updating → https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html

2
A unified security dashboard can still hide a broken incident workflow. Run one incident from detection to clean recovery. Co
A unified security dashboard can still hide a broken incident workflow. Run one incident from detection to clean recovery. Count every console switch, permission change, and ownership handoff. Six tests reveal whether consolidation actually reduces operational friction: https://thehackernews.com/expert-insights/2026/09/how-to-evaluate-unified-security.html
859
3
🚨 Attackers are exploiting a critical WooCommerce Wholesale Lead Capture flaw to plant PHP web shells. Wordfence has blocked
🚨 Attackers are exploiting a critical WooCommerce Wholesale Lead Capture flaw to plant PHP web shells. Wordfence has blocked over 100,000 exploit attempts since June against CVE-2026-27540, which affects versions through 2.0.3.1. Read: https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html
8 782
4
⚠️ Forged admin JWTs are being used in WSO2 API Manager exploitation attempts. CVE-2026-5430 lets unsupported JWT algorithms
⚠️ Forged admin JWTs are being used in WSO2 API Manager exploitation attempts. CVE-2026-5430 lets unsupported JWT algorithms bypass authentication and can lead to account takeover. Fixes are available. Read: https://thehackernews.com/2026/09/active-exploitation-attempts-target.html
2 750
5
🚨 KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials
🚨 KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials and session tokens. It also uses Ethereum smart contracts to rotate C2 and payload locations. How the attack chain works: https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html
4 738
6
‼️ Iran-attributed HEAVYGRAM, also tracked as CHOSEN BRICK, uses Telegram bots to spy on dissidents and journalists. A joint
‼️ Iran-attributed HEAVYGRAM, also tracked as CHOSEN BRICK, uses Telegram bots to spy on dissidents and journalists. A joint U.S.-U.K.-Dutch advisory says the Windows malware can steal messages and passwords, record audio, capture screenshots, and exfiltrate files. Details → https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html
4 978
7
🚨 BambooToken uses MQTT to control Windows and Linux hosts across Asia and South America. Lumen identified a dozen compromis
🚨 BambooToken uses MQTT to control Windows and Linux hosts across Asia and South America. Lumen identified a dozen compromised entities, with activity detected as recently as July 2026. Learn what's inside the malware’s MQTT command-and-control: https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html
4 789
8
✅ Your Business Continuity Management Checklist. Most resilience programs look complete on paper. Let's make sure yours holds
✅ Your Business Continuity Management Checklist. Most resilience programs look complete on paper. Let's make sure yours holds up when it matters most. Discover 6 ways to align your BCM program with operational reality. Get the checklist → https://thn.news/bcm-reality-check
4 893
9
Phishing puts financial SOCs under constant pressure. Cut the workload with ANY.RUN: faster analysis, fewer escalations, and
Phishing puts financial SOCs under constant pressure. Cut the workload with ANY.RUN: faster analysis, fewer escalations, and 21 min lower MTTR. → https://thn.news/phishing-soc-detection
4 791
10
🚨 A human attacker exploited Marimo’s pre-auth RCE and reached an SSH bastion in eight seconds. The operator used harvested
🚨 A human attacker exploited Marimo’s pre-auth RCE and reached an SSH bastion in eight seconds. The operator used harvested AWS credentials to fetch the private key from Secrets Manager and authenticate over SSH. No AI agent was involved. Read: https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html
4 231
11
One attack step can now decide what gets tested next. OpenAEV’s Attack Chaining feeds live findings like credentials, tokens,
One attack step can now decide what gets tested next. OpenAEV’s Attack Chaining feeds live findings like credentials, tokens, and open ports into the next stage, while XTM One can plan and adapt the path inside a defined scope. How the attack path builds: https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html
4 185
12
⚠️ Exposed Vite dev servers are being scanned for cloud credentials. Attackers are exploiting a Vite flaw to bypass file rest
⚠️ Exposed Vite dev servers are being scanned for cloud credentials. Attackers are exploiting a Vite flaw to bypass file restrictions and retrieve .env files, AWS and Azure credentials, and infrastructure state. How the bypass works: https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html
4 320
13
Cursor deleted a production database and its backups in nine seconds. The agent found an unrelated Railway API token with bla
Cursor deleted a production database and its backups in nine seconds. The agent found an unrelated Railway API token with blanket GraphQL permissions while handling a staging task. AI blast radius follows credential reach. Why access boundaries matter: https://thehackernews.com/expert-insights/2026/09/stop-trying-to-control-ai-behavior.html
5 401
14
‼️ Warning: LiteSpeed Enterprise before 6.3.7 can let low-privilege website users gain root on shared-hosting servers. It can
‼️ Warning: LiteSpeed Enterprise before 6.3.7 can let low-privilege website users gain root on shared-hosting servers. It can bypass CageFS isolation. No CVE is assigned, exploitation is unknown, and 6.3.7 may not auto-update immediately. Manual update may be required → https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html
4 914
15
‼️ Attackers are exploiting a Cisco Secure Email Gateway vulnerability that can let a crafted email trigger command execution
‼️ Attackers are exploiting a Cisco Secure Email Gateway vulnerability that can let a crafted email trigger command execution as root. Cisco has released fixes, and CISA added CVE-2026-76461 to its KEV catalog. How the attack works → https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
4 947
16
⚠️ Two China-linked threat actors exploited the same Chrome-Windows zero-day chain. UTA0560 used it to deploy the GRIMWEDGE b
⚠️ Two China-linked threat actors exploited the same Chrome-Windows zero-day chain. UTA0560 used it to deploy the GRIMWEDGE backdoor against NGOs. APT31 used it to install LONGTALE, a credential-stealing Chrome extension. How the shared exploit chain worked: https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html
4 992
17
🚨 Thai ISP 3BB attacker had root access and hid MeshCentral for persistence. Recovered tools sprayed passwords across 55+ in
🚨 Thai ISP 3BB attacker had root access and hid MeshCentral for persistence. Recovered tools sprayed passwords across 55+ internal systems and targeted subscriber login databases. How the attacker stayed in: https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html
5 869
18
‼️ A Telegram Desktop flaw could send messages from opened HTML exports to an attacker-controlled server. A bot message could
‼️ A Telegram Desktop flaw could send messages from opened HTML exports to an attacker-controlled server. A bot message could hide JavaScript in pre-fix exports, which ran when the file was opened in a browser with JavaScript enabled. Updating Telegram does not clean old export files. Read: https://thehackernews.com/2026/09/telegram-desktop-flaw-lets-hidden.html
5 641
19
‼️ Researchers broke Intel TDX’s confidential-computing protections with a $159 DDR5 interposer. New "DDRop" attack silently
‼️ Researchers broke Intel TDX’s confidential-computing protections with a $159 DDR5 interposer. New "DDRop" attack silently drops memory writes so the CPU trusts stale encrypted data. In lab tests, researchers read protected VM memory and forged attestation. No CVE. No patch. Full details here → https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html
5 129
20
‼️ Researchers broke Intel TDX’s confidential-computing protections with a $159 DDR5 interposer. New "DDRop" attack silently drops memory writes so the CPU trusts stale encrypted data. In lab tests, researchers read protected VM memory and forged attestation. No CVE. No patch. Full details here → https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html
1