ru
Feedback
The Hacker News

The Hacker News

Открыть в Telegram

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

Больше

📈 Аналитический обзор Telegram-канала The Hacker News

Канал The Hacker News (@thehackernews) языкового сегмента Английский является активным участником. Сейчас сообщество объединяет 162 044 подписчиков, занимая 676 место в категории Технологии и приложения и 112 место в регионе США.

📊 Показатели аудитории и динамика

С момента создания невідомо проект демонстрирует стремительный рост, собрав аудиторию из 162 044 подписчиков.

Согласно последним данным от 24 июля, 2026, канал показывает стабильную активность. За последние 30 дней изменение числа участников составило 345, а за последние 24 часа — 35, при этом общий охват остаётся высоким.

  • Статус верификации: Верифицирован (официально подтверждён Telegram)
  • Уровень вовлечённости (ER): Средний показатель вовлечённости аудитории составляет 4.51%. В первые 24 часа после публикации контент обычно набирает 3.06% реакций от общего числа подписчиков.
  • Охват публикаций: В среднем каждый пост получает 7 312 просмотров. В течение первых суток публикация набирает 4 962 просмотров.
  • Реакции и взаимодействия: Аудитория активно поддерживает контент: среднее количество реакций на один пост — 12.
  • Тематические интересы: Контент сосредоточен на ключевых темах, таких как attack, credential, cve-2026, github, backdoor.

📝 Описание и контентная политика

Автор описывает ресурс как площадку для выражения субъективного мнения:
⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

Благодаря высокой частоте обновлений (последние данные получены 25 июля, 2026) канал поддерживает актуальность и высокий уровень охвата публикаций. Аналитика показывает, что аудитория активно взаимодействует с контентом, что делает его важной точкой влияния в категории Технологии и приложения.

162 044
Подписчики
+3524 часа
+1757 дней
+34530 день
Архив постов
🚨 Researchers say one short message let Claude Cowork escape its Linux VM and access files across the host Mac. The SharedRoot chain used CVE-2026-46331 to gain guest root, then crossed through Cowork’s read-write host mount. Read how it worked: https://thehackernews.com/2026/07/claude-cowork-flaw-could-let-ai-agent.html

‼️ Chaos Hid Its C2 Inside Chrome. Instead of connecting directly to its command server, Chaos #ransomware’s msaRAT launches
‼️ Chaos Hid Its C2 Inside Chrome. Instead of connecting directly to its command server, Chaos #ransomware’s msaRAT launches Chrome or Edge in hidden mode and uses the browser to send encrypted commands over WebRTC, making the malicious traffic look like normal browser activity. Read: https://thehackernews.com/2026/07/chaos-ransomware-uses-msarat-to-route.html

🛑 China-nexus JadeProx breached a Vietnamese hospital’s medical imaging server and targeted Malaysia’s foreign ministry with
🛑 China-nexus JadeProx breached a Vietnamese hospital’s medical imaging server and targeted Malaysia’s foreign ministry with a new Windows loader. The same operation also hid malware inside a fake Claude installer. How the campaign worked: https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html

Social engineering is now a margin game. Convincing lures cost 95% less to produce. Median time to click: 21 seconds. Doppel’
Social engineering is now a margin game. Convincing lures cost 95% less to produce. Median time to click: 21 seconds. Doppel’s Josh Bartolomie says defenders should stop chasing lures and make attacks too costly to scale. Learn how to break the economics: https://thehackernews.com/expert-insights/2026/07/how-to-make-social-engineering.html

🚨 Attackers turned GitHub-hosted runners into cPanel attack infrastructure. They planted 583 malicious workflows to target c
🚨 Attackers turned GitHub-hosted runners into cPanel attack infrastructure. They planted 583 malicious workflows to target cPanel and WHM servers exposed to CVE-2026-41940, hunting for cloud keys, API tokens, SSH data, and other secrets. How the campaign worked: https://thehackernews.com/2026/07/attackers-weaponize-github-actions.html

🔥 Google now lets users RECOVER LOCKED ACCOUNTS with a selfie video. Users save a face clip, then record another when they n
🔥 Google now lets users RECOVER LOCKED ACCOUNTS with a selfie video. Users save a face clip, then record another when they need to prove the account is theirs. An optional setting can expand how Google uses that data beyond sign-in. What is stored and how it may be used: https://thehackernews.com/2026/07/google-adds-selfie-video-recovery-for.html

🛑 A newly disclosed, 9-year-old #Linux flaw lets unprivileged users overwrite root-owned files and gain persistent root acce
🛑 A newly disclosed, 9-year-old #Linux flaw lets unprivileged users overwrite root-owned files and gain persistent root access. On affected XFS systems, the overwrite survives reboot without changing ownership, permissions, timestamps, or the setuid bit. Read: https://thehackernews.com/2026/07/nine-year-old-refluxfs-linux-flaw-gives.html

⚠️ Attackers are exploiting a Check Point SmartConsole flaw that can grant full administrative access. CVE-2026-16232 affects
⚠️ Attackers are exploiting a Check Point SmartConsole flaw that can grant full administrative access. CVE-2026-16232 affects management servers exposed directly to the internet under a specific configuration. Check Point says a small number of customers were targeted. Read: https://thehackernews.com/2026/07/check-point-patches-exploited.html

GitHub is cutting public bug bounty payouts by at least half. The reset comes as AI floods programs with low-effort reports w
GitHub is cutting public bug bounty payouts by at least half. The reset comes as AI floods programs with low-effort reports while helping skilled researchers find real bugs faster. Top rewards now move to an invite-only VIP tier. Read the full story: https://thehackernews.com/2026/07/github-cuts-public-bug-bounty-payouts.html

🚨 A flaw in Ubuntu’s snap-confine could turn local user access into root. CVE-2026-8933 chains FUSE and symlink race conditi
🚨 A flaw in Ubuntu’s snap-confine could turn local user access into root. CVE-2026-8933 chains FUSE and symlink race conditions to plant malicious udev rules and execute commands as root. Default Ubuntu #Linux Desktop 24.04, 25.10, and 26.04 installations are affected. Read how the exploit works: https://thehackernews.com/2026/07/ubuntu-snap-confine-flaw-could-give.html

⚡ AI is pushing code output up 10–50x. Security programs still assume humans can review what humans build. That model breaks
⚡ AI is pushing code output up 10–50x. Security programs still assume humans can review what humans build. That model breaks at machine speed. Learn how to govern AI-built software with secure-by-default architecture. Save your seat: https://thehacker.news/secure-ai-development

🛑 One visit to a malicious webpage could have been enough to expose your #WhatsApp Web chats. CVE-2026-48294 in Adobe Acroba
🛑 One visit to a malicious webpage could have been enough to expose your #WhatsApp Web chats. CVE-2026-48294 in Adobe Acrobat’s Chrome extension could read messages, contact names, chat previews, and profile data without malware, stolen credentials, or session cookies. The extension has over 314 million users. See how HermeticReader worked: https://thehackernews.com/2026/07/adobe-acrobat-extension-flaw-let.html

76% of employees now use AI at work. Most of those tools were never reviewed by security. When approval takes six weeks and a
76% of employees now use AI at work. Most of those tools were never reviewed by security. When approval takes six weeks and a workaround takes six minutes, AI use moves out of sight. How to make the secure path the faster one: https://thehackernews.com/2026/07/the-fastest-path-to-ai-adoption-runs.html

Windmill servers are under active attack. Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files
Windmill servers are under active attack. Experts say attackers are exploiting CVE-2026-29059 to read arbitrary server files without logging in. On some systems, the same flaw can lead to superadmin access and code execution. Full details: https://thehackernews.com/2026/07/hackers-exploit-windmill-flaw-to-read.html

Around 79% of attacks are malware-free, CrowdStrike estimates. Endpoint alerts alone can miss credential theft and lateral mo
Around 79% of attacks are malware-free, CrowdStrike estimates. Endpoint alerts alone can miss credential theft and lateral movement across identity and cloud systems. AI cannot connect what the SOC never captured. Why network evidence matters: https://thehackernews.com/2026/07/why-modern-socs-need-multi-layered.html

🛑 MFA didn’t stop Kratos. The phishing kit stole Microsoft 365 session cookies, letting attackers enter accounts without ano
🛑 MFA didn’t stop Kratos. The phishing kit stole Microsoft 365 session cookies, letting attackers enter accounts without another MFA check. Police took 200+ servers offline and arrested the alleged operator in Indonesia. But about 1,800 customers may still have the code. Read: https://thehackernews.com/2026/07/police-dismantle-kratos-phishing-kit.html

One extra “t” hid a package built to rig live betting results. Newtonsoftt.Json[.]Net worked as a normal JSON library for mos
One extra “t” hid a package built to rig live betting results. Newtonsoftt.Json[.]Net worked as a normal JSON library for most users, but targeted Digitain’s FG-Crash backend when the right conditions were present. Inside the selective attack: https://thehackernews.com/2026/07/trojanized-newtonsoftjson-fork-hides.html

⚠️ An attacker does not need the reviewer’s broader Azure DevOps permissions. In tests, one hidden PR comment steered the rev
⚠️ An attacker does not need the reviewer’s broader Azure DevOps permissions. In tests, one hidden PR comment steered the reviewer’s AI coding agent into other projects and leaked data the attacker could not access directly. How the missing MCP guardrail enables the chain: https://thehackernews.com/2026/07/microsoft-azure-devops-mcp-flaw-lets.html

🔥 OpenAI says its own AI models broke out of a sandbox, exploited a zero-day, and targeted Hugging Face’s production infrast
🔥 OpenAI says its own AI models broke out of a sandbox, exploited a zero-day, and targeted Hugging Face’s production infrastructure to cheat a security benchmark. The incident showed how long-running models can learn and work around approval-system blind spots. Read the full story: https://thehackernews.com/2026/07/openai-says-its-own-ai-models-escaped.html

Apple’s Hide My Email exposed the real address it was designed to hide. A flaw caused users’ personal email addresses to appe
Apple’s Hide My Email exposed the real address it was designed to hide. A flaw caused users’ personal email addresses to appear in mail logs when messages sent to an alias were rejected as spam. Apple fixed it on July 3, more than a year after disclosure. Read how the leak worked: https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html