en
Feedback
The Hacker News

The Hacker News

Open in Telegram

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

Show more

📈 Analytical overview of Telegram channel The Hacker News

Channel The Hacker News (@thehackernews) in the English language segment is an active participant. Currently, the community unites 163 483 subscribers, ranking 655 in the Technologies & Applications category and 106 in the USA region.

📊 Audience metrics and dynamics

Since its creation on невідомо, the project has demonstrated rapid growth, gathering an audience of 163 483 subscribers.

According to the latest data from 05 October, 2026, the channel demonstrates stable activity. Although there has been a change in the number of participants by 1 247 over the last 30 days and by -144 over the last 24 hours, overall reach remains high.

  • Verification status: Verified (Officially confirmed by Telegram)
  • Engagement rate (ER): The average audience engagement rate is 4.27%. Within the first 24 hours after publication, content typically collects 2.88% reactions from the total number of subscribers.
  • Post reach: On average, each post receives 6 987 views. Within the first day, a publication typically gains 4 705 views.
  • Reactions and interaction: The audience actively supports content: the average number of reactions per post is 10.
  • Thematic interests: Content is focused on key topics such as attack, credential, cve-2026, github, backdoor.

📝 Description and content policy

The author describes the resource as a platform for expressing subjective opinions:
“⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com”

Thanks to the high frequency of updates (latest data received on 06 October, 2026), the channel maintains relevance and a high level of publication reach. Analytics show that the audience actively interacts with content, making it an important point of influence in the Technologies & Applications category.

163 483
Subscribers
-14424 hours
-4467 days
+1 24730 days
Posts Archive
Nearly half of IT and security pros say they lack full visibility into employee AI use. Cristian Iordache of Bitdefender expl
Nearly half of IT and security pros say they lack full visibility into employee AI use. Cristian Iordache of Bitdefender explains how GravityZone maps 700+ AI tools and helps teams allow, review, restrict, or block risky activity. What AI security teams are missing: https://thehackernews.com/expert-insights/2026/10/your-employees-are-adopting-ai-faster.html

⚡ Google just paused product bug bounty rewards for some of its biggest open-source projects. It says automated submissions s
⚡ Google just paused product bug bounty rewards for some of its biggest open-source projects. It says automated submissions surged, and the vast majority were invalid. Go, Angular, Flutter, Bazel, and Protocol Buffers are among the affected projects. Supply chain rewards continue. Read: https://thehackernews.com/2026/10/google-pauses-oss-product-bug-bounty.html

‼️ A critical Atlassian vulnerability rated CVSS 9.3 affects 8 Data Center products. CVE-2026-21589 can let unauthenticated a
‼️ A critical Atlassian vulnerability rated CVSS 9.3 affects 8 Data Center products. CVE-2026-21589 can let unauthenticated attackers read specific files if they know the exact file path. Internet-facing instances should be upgraded or restricted. Details - https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html

‼️ A security patch wasn’t applied. Thousands of FBI employees had personal details stolen. The FBI has now removed an Accent
‼️ A security patch wasn’t applied. Thousands of FBI employees had personal details stolen. The FBI has now removed an Accenture contractor over the security failure tied to the ShinyHunters breach. Read the full report → https://thehackernews.com/2026/10/fbi-removes-accenture-contractor-after.html

⚠️ Denmark says unauthorized parties accessed names, addresses and CPR numbers for about 8.8 million people, roughly 4 in 5 r
⚠️ Denmark says unauthorized parties accessed names, addresses and CPR numbers for about 8.8 million people, roughly 4 in 5 records in its national register, via a private company’s lawful access. Automated lookups ran 10 days; police are investigating. Details → https://thehackernews.com/2026/10/denmark-says-attackers-accessed-cpr.html

🚨 ClickFix has a new trick... the malicious payload is already sitting in your browser cache before you paste the command. C
🚨 ClickFix has a new trick... the malicious payload is already sitting in your browser cache before you paste the command. Compromised sites preload scripts disguised as PNGs, letting pasted commands bypass Windows Run's ~260-character limit and launch a multi-stage malware chain. Read: https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html

‼️ ALERT - Exchange admins should review this now. CVE-2026-96940 can allow an authenticated attacker to access other users’
‼️ ALERT - Exchange admins should review this now. CVE-2026-96940 can allow an authenticated attacker to access other users’ mailboxes and read emails and attachments within the same organization. Microsoft has issued out-of-band fixes. Read: https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html

GitGuardian found 28.65 million new hardcoded secrets in public GitHub commits in 2025, up 34% year over year. It also found 24,008 unique secrets in public MCP configuration files, including 2,117 verified as valid. See how credentials are spreading across code, endpoints, and AI tooling: https://thehackernews.com/2026/10/the-credential-layer-is-expanding.html

15 cyber stories worth 2 minutes of your attention: • NetScaler + FortiMail 0-days • Spectre v2 leaks root hashes • CosmicPul
15 cyber stories worth 2 minutes of your attention: • NetScaler + FortiMail 0-days • Spectre v2 leaks root hashes • CosmicPulse phishing • NeedyMantis persistence • RatHat + Gemini targeting • 13K AI-leaked screenshots • Ransomware arrests • Microsoft X hijack • WordPress credential theft • PageBreak AI vuln hunting • Milk Dragon phishing • NodeStealer upgrades • Direct Send bypass • PaperCut exploitation • AI models building exploits • Plus a huge CVE pile Full ThreatsDay recap: https://thehackernews.com/2026/10/weekly-recap-netscaler-and-fortimail-0.html

CJIS compliance starts with stronger authentication. Weak passwords and inconsistent MFA enforcement can create compliance an
CJIS compliance starts with stronger authentication. Weak passwords and inconsistent MFA enforcement can create compliance and security challenges for agencies and organizations that handle criminal justice information. Download our practical guide to learn: ✅ Key CJIS password requirements ✅ MFA compliance best practices ✅ Common compliance gaps to avoid ✅ Steps to strengthen your security posture Get the guide: https://thn.news/password-mfa-standards

🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2
🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet. Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html

🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2
🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet. Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html

🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2
🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet. Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html

⚡ Apple is tightening macOS Full Disk Access, a permission that can let AI agents read files, mail, messages, browsing histor
⚡ Apple is tightening macOS Full Disk Access, a permission that can let AI agents read files, mail, messages, browsing history, and more. Future access will require explicit user action. Here's what Apple is changing: https://thehackernews.com/2026/10/apple-plans-tighter-macos-full-disk.html

A financial app treated a GUID like proof of access. In a penetration test described by Sygnia's Zach Mead, the AI-assisted o
A financial app treated a GUID like proof of access. In a penetration test described by Sygnia's Zach Mead, the AI-assisted onboarding flow could issue or restore an applicant token if another applicant’s GUID was obtained, potentially exposing sensitive personal and financial data. How the trust failure worked: https://thehackernews.com/expert-insights/2026/10/when-ai-writes-code-who-owns-security.html

⚠️ Attackers are targeting a Rejetto HFS flaw that enables forged admin sessions and remote code execution. CVE-2026-61500 af
⚠️ Attackers are targeting a Rejetto HFS flaw that enables forged admin sessions and remote code execution. CVE-2026-61500 affects HFS 3.0.0–3.2.0. VulnCheck detected exploitation attempts against vulnerable U.S. hosts after a public PoC was released. Read - https://thehackernews.com/2026/10/attackers-target-rejetto-hfs-flaw-that.html

An AI pentesting agent says it exploited a bug. Did it? XRanges for AI watches from inside the target, recording exploit-chai
An AI pentesting agent says it exploited a bug. Did it? XRanges for AI watches from inside the target, recording exploit-chain progress, coverage, boundary violations, and whether the environment survives the run. Inside the scoring: https://thehackernews.com/2026/09/545-hackers-tested-it-first-now-xranges.html

‼️ Citrix has patched a new NetScaler zero-day exploited in targeted attacks. CVE-2026-88779 affects certain SAML-configured
‼️ Citrix has patched a new NetScaler zero-day exploited in targeted attacks. CVE-2026-88779 affects certain SAML-configured deployments & can cause denial-of-service, with repeated triggering potentially leaving services unavailable. Details - https://thehackernews.com/2026/10/new-netscaler-zero-day-exploited-in.html

‼️ A suspected #ShinyHunters member is reportedly helping the FBI identify others in the group. Rey, also known as ReyXBF, wa
‼️ A suspected #ShinyHunters member is reportedly helping the FBI identify others in the group. Rey, also known as ReyXBF, was allegedly detained in Jordan on September 29. His cooperation is now feeding an ongoing effort to pursue more members. Read: https://thehackernews.com/2026/10/shinyhunters-suspect-rey-reportedly.html

TA419 is targeting U.S. AI policy experts with Microsoft AitM phishing. The China-aligned group waits for targets to reply, t
TA419 is targeting U.S. AI policy experts with Microsoft AitM phishing. The China-aligned group waits for targets to reply, then sends a shortened link to a Frameless BitB page built to capture credentials and session cookies. Read about the technique: https://thehackernews.com/2026/10/china-aligned-ta419-targets-us-ai.html