ru
Feedback
The Hacker News

The Hacker News

Открыть в Telegram

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

Больше

📈 Аналитический обзор Telegram-канала The Hacker News

Канал The Hacker News (@thehackernews) языкового сегмента Английский является активным участником. Сейчас сообщество объединяет 163 475 подписчиков, занимая 655 место в категории Технологии и приложения и 106 место в регионе США.

📊 Показатели аудитории и динамика

С момента создания невідомо проект демонстрирует стремительный рост, собрав аудиторию из 163 475 подписчиков.

Согласно последним данным от 05 октября, 2026, канал показывает стабильную активность. За последние 30 дней изменение числа участников составило 1 247, а за последние 24 часа — -144, при этом общий охват остаётся высоким.

  • Статус верификации: Верифицирован (официально подтверждён Telegram)
  • Уровень вовлечённости (ER): Средний показатель вовлечённости аудитории составляет 4.27%. В первые 24 часа после публикации контент обычно набирает 2.88% реакций от общего числа подписчиков.
  • Охват публикаций: В среднем каждый пост получает 6 987 просмотров. В течение первых суток публикация набирает 4 705 просмотров.
  • Реакции и взаимодействия: Аудитория активно поддерживает контент: среднее количество реакций на один пост — 10.
  • Тематические интересы: Контент сосредоточен на ключевых темах, таких как attack, credential, cve-2026, github, backdoor.

📝 Описание и контентная политика

Автор описывает ресурс как площадку для выражения субъективного мнения:
“⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com”

Благодаря высокой частоте обновлений (последние данные получены 06 октября, 2026) канал поддерживает актуальность и высокий уровень охвата публикаций. Аналитика показывает, что аудитория активно взаимодействует с контентом, что делает его важной точкой влияния в категории Технологии и приложения.

163 475
Подписчики
-14424 часа
-4467 дней
+1 24730 дней
Архив постов
⚠️ Linux backdoors are hiding behind trusted email security names. Rapid7 found BPFDoor, BPF Rekoobe, and AVERAT targeting sy
⚠️ Linux backdoors are hiding behind trusted email security names. Rapid7 found BPFDoor, BPF Rekoobe, and AVERAT targeting systems in South Korea and Taiwan, impersonating products and processes to blend in. AVERAT even uses SMTP for C2. Read: https://thehackernews.com/2026/10/linux-backdoors-impersonate-email.html

Get an inside look at Georgetown's Cybersecurity Master's program. Register for the virtual sample class on October 15. Sign
Get an inside look at Georgetown's Cybersecurity Master's program. Register for the virtual sample class on October 15. Sign up → https://thn.news/sample-class-risk

‼️ Opening a malicious spreadsheet can make LibreOffice or OpenOffice run attacker-controlled code without a macro warning. T
‼️ Opening a malicious spreadsheet can make LibreOffice or OpenOffice run attacker-controlled code without a macro warning. The attack requires Java to be enabled. LibreOffice has patched the flaw; OpenOffice 4.1.16 remains affected. PoC demonstrated, details here - https://thehackernews.com/2026/10/libreoffice-and-openoffice-flaws-let.html

Can you keep up with SaaS sprawl? As applications multiply, so do users, permissions, access policies, and the places IT need
Can you keep up with SaaS sprawl? As applications multiply, so do users, permissions, access policies, and the places IT needs visibility. Without a centralized approach, secure access can become fragmented across an ever-growing application environment. Explore zero-trust network access (ZTNA) with NordLayer. Learn more ▶️ https://thn.news/developer-secrets-webinar

⚠️ Wikimedia says OpenAI agents tried to compromise Etherpad, modified wiki tooling for proxy use, and sent millions of autom
⚠️ Wikimedia says OpenAI agents tried to compromise Etherpad, modified wiki tooling for proxy use, and sent millions of automated requests. It found no evidence its systems or data were compromised. Read - https://thehackernews.com/2026/10/wikimedia-says-openai-agents-tried-to.html

MCP marketplaces have a trust problem. OX Security analyzed 15,465 publicly indexed MCP servers across 5 registries and found
MCP marketplaces have a trust problem. OX Security analyzed 15,465 publicly indexed MCP servers across 5 registries and found no marketplace vetting. Among the findings: • 2.3% of hosts no longer resolve • 6 use expired domains anyone could re-register • 15.6% resolve outside the US The risk is not MCP itself. It is trusting servers without verifying who runs them or where your data goes. Read - https://thehackernews.com/2026/10/welcome-to-jungle-what-we-found-inside.html

Nearly half of IT and security pros say they lack full visibility into employee AI use. Cristian Iordache of Bitdefender expl
Nearly half of IT and security pros say they lack full visibility into employee AI use. Cristian Iordache of Bitdefender explains how GravityZone maps 700+ AI tools and helps teams allow, review, restrict, or block risky activity. What AI security teams are missing: https://thehackernews.com/expert-insights/2026/10/your-employees-are-adopting-ai-faster.html

⚡ Google just paused product bug bounty rewards for some of its biggest open-source projects. It says automated submissions s
⚡ Google just paused product bug bounty rewards for some of its biggest open-source projects. It says automated submissions surged, and the vast majority were invalid. Go, Angular, Flutter, Bazel, and Protocol Buffers are among the affected projects. Supply chain rewards continue. Read: https://thehackernews.com/2026/10/google-pauses-oss-product-bug-bounty.html

‼️ A critical Atlassian vulnerability rated CVSS 9.3 affects 8 Data Center products. CVE-2026-21589 can let unauthenticated a
‼️ A critical Atlassian vulnerability rated CVSS 9.3 affects 8 Data Center products. CVE-2026-21589 can let unauthenticated attackers read specific files if they know the exact file path. Internet-facing instances should be upgraded or restricted. Details - https://thehackernews.com/2026/10/critical-atlassian-flaw-lets.html

‼️ A security patch wasn’t applied. Thousands of FBI employees had personal details stolen. The FBI has now removed an Accent
‼️ A security patch wasn’t applied. Thousands of FBI employees had personal details stolen. The FBI has now removed an Accenture contractor over the security failure tied to the ShinyHunters breach. Read the full report → https://thehackernews.com/2026/10/fbi-removes-accenture-contractor-after.html

⚠️ Denmark says unauthorized parties accessed names, addresses and CPR numbers for about 8.8 million people, roughly 4 in 5 r
⚠️ Denmark says unauthorized parties accessed names, addresses and CPR numbers for about 8.8 million people, roughly 4 in 5 records in its national register, via a private company’s lawful access. Automated lookups ran 10 days; police are investigating. Details → https://thehackernews.com/2026/10/denmark-says-attackers-accessed-cpr.html

🚨 ClickFix has a new trick... the malicious payload is already sitting in your browser cache before you paste the command. C
🚨 ClickFix has a new trick... the malicious payload is already sitting in your browser cache before you paste the command. Compromised sites preload scripts disguised as PNGs, letting pasted commands bypass Windows Run's ~260-character limit and launch a multi-stage malware chain. Read: https://thehackernews.com/2026/10/clickfix-smuggles-payloads-through.html

‼️ ALERT - Exchange admins should review this now. CVE-2026-96940 can allow an authenticated attacker to access other users’
‼️ ALERT - Exchange admins should review this now. CVE-2026-96940 can allow an authenticated attacker to access other users’ mailboxes and read emails and attachments within the same organization. Microsoft has issued out-of-band fixes. Read: https://thehackernews.com/2026/10/microsoft-exchange-flaw-lets.html

GitGuardian found 28.65 million new hardcoded secrets in public GitHub commits in 2025, up 34% year over year. It also found 24,008 unique secrets in public MCP configuration files, including 2,117 verified as valid. See how credentials are spreading across code, endpoints, and AI tooling: https://thehackernews.com/2026/10/the-credential-layer-is-expanding.html

15 cyber stories worth 2 minutes of your attention: • NetScaler + FortiMail 0-days • Spectre v2 leaks root hashes • CosmicPul
15 cyber stories worth 2 minutes of your attention: • NetScaler + FortiMail 0-days • Spectre v2 leaks root hashes • CosmicPulse phishing • NeedyMantis persistence • RatHat + Gemini targeting • 13K AI-leaked screenshots • Ransomware arrests • Microsoft X hijack • WordPress credential theft • PageBreak AI vuln hunting • Milk Dragon phishing • NodeStealer upgrades • Direct Send bypass • PaperCut exploitation • AI models building exploits • Plus a huge CVE pile Full ThreatsDay recap: https://thehackernews.com/2026/10/weekly-recap-netscaler-and-fortimail-0.html

CJIS compliance starts with stronger authentication. Weak passwords and inconsistent MFA enforcement can create compliance an
CJIS compliance starts with stronger authentication. Weak passwords and inconsistent MFA enforcement can create compliance and security challenges for agencies and organizations that handle criminal justice information. Download our practical guide to learn: ✅ Key CJIS password requirements ✅ MFA compliance best practices ✅ Common compliance gaps to avoid ✅ Steps to strengthen your security posture Get the guide: https://thn.news/password-mfa-standards

🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2
🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet. Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html

🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2
🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet. Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html

🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2
🚨 Cling hides C2 commands in STUN traffic as threat actors were observed attempting to exploit Realtek Jungle SDK flaw CVE-2021-35394. A subset of that activity delivered the botnet. Read how Cling uses STUN for command-and-control, persistence, propagation, proxying, tunneling, and DoS: https://thehackernews.com/2026/10/realtek-jungle-sdk-exploit-attempts.html

⚡ Apple is tightening macOS Full Disk Access, a permission that can let AI agents read files, mail, messages, browsing histor
⚡ Apple is tightening macOS Full Disk Access, a permission that can let AI agents read files, mail, messages, browsing history, and more. Future access will require explicit user action. Here's what Apple is changing: https://thehackernews.com/2026/10/apple-plans-tighter-macos-full-disk.html