uz
Feedback
The Hacker News

The Hacker News

Kanalga Telegram’da o‘tish

⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

Ko'proq ko'rsatish

📈 Telegram kanali The Hacker News analitikasi

The Hacker News (@thehackernews) Ingliz til segmentidagi kanali faol ishtirokchi. Hozirda hamjamiyat 164 871 obunachidan iborat bo'lib, Texnologiyalar & Aralashmalar toifasida 645-o'rinni va AQSH mintaqasida 106-o'rinni egallagan.

📊 Auditoriya ko‘rsatkichlari va dinamika

невідомо sanasidan buyon loyiha tez o‘sib, 164 871 obunachiga ega bo‘ldi.

15 Sentabr, 2026 dagi oxirgi ma’lumotlarga ko‘ra kanal barqaror faollikka ega. Oxirgi 30 kunda obunachilar soni 162 ga, so‘nggi 24 soatda esa -11 ga o‘zgardi va umumiy qamrov yuqori darajada qolmoqda.

  • Tasdiqlash holati: Tasdiqlangan (Telegram tomonidan rasmiy tasdiq)
  • Jalb etish (ER): Auditoriya o‘rtacha 4.57% darajada jalb etiladi. Nashrdan keyingi dastlabki 24 soatda kontent odatda umumiy obunachilar sonining 2.98% ini tashkil etuvchi reaksiyalarni to‘playdi.
  • Post qamrovi: Har bir post o‘rtacha 7 411 marta ko‘riladi; birinchi sutkada odatda 4 838 ta ko‘rish yig‘iladi.
  • Reaksiyalar va o‘zaro ta’sir: Auditoriya faol: har bir postga o‘rtacha 11 ta reaksiya keladi.
  • Tematik yo‘nalishlar: Kontent attack, credential, cve-2026, github, backdoor kabi asosiy mavzularga jamlangan.

📝 Tavsif va kontent siyosati

Muallif resursni shaxsiy fikrni ifoda etish maydoni sifatida ta’riflaydi:
⭐ Official THN Telegram Channel — A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking. 📨 Contact: admin@thehackernews.com 🌐 Website: https://thehackernews.com

Yuqori yangilanish chastotasi (oxirgi ma’lumot 16 Sentabr, 2026 da olingan) sababli kanal doimo dolzarb va katta qamrovli bo‘lib qoladi. Analitika auditoriya kontent bilan faol hamkorlik qilishini, uni Texnologiyalar & Aralashmalar toifasidagi muhim ta’sir nuqtasiga aylantirishini ko‘rsatadi.

164 871
Obunachilar
-1124 soatlar
-737 kun
+16230 kun
Obunachilarni jalb qilish
Sentabr '26
Sentabr '26
+3 158
8 kanalda
Avgust '26
+1 157
23 kanalda
Get PRO
Iyul '26
+1 477
20 kanalda
Get PRO
Iyun '26
+994
18 kanalda
Get PRO
May '26
+1 175
24 kanalda
Get PRO
Aprel '26
+4 326
26 kanalda
Get PRO
Mart '26
+6 849
26 kanalda
Get PRO
Fevral '26
+1 583
27 kanalda
Get PRO
Yanvar '26
+1 516
23 kanalda
Get PRO
Dekabr '25
+1 900
34 kanalda
Get PRO
Noyabr '25
+1 648
25 kanalda
Get PRO
Oktabr '25
+1 634
21 kanalda
Get PRO
Sentabr '25
+1 163
25 kanalda
Get PRO
Avgust '25
+1 070
17 kanalda
Get PRO
Iyul '25
+1 318
28 kanalda
Get PRO
Iyun '25
+2 024
24 kanalda
Get PRO
May '25
+1 328
24 kanalda
Get PRO
Aprel '25
+1 758
13 kanalda
Get PRO
Mart '25
+1 782
16 kanalda
Get PRO
Fevral '25
+2 159
19 kanalda
Get PRO
Yanvar '25
+2 315
31 kanalda
Get PRO
Dekabr '24
+3 006
22 kanalda
Get PRO
Noyabr '24
+3 500
12 kanalda
Get PRO
Oktabr '24
+3 385
18 kanalda
Get PRO
Sentabr '24
+2 583
22 kanalda
Get PRO
Avgust '24
+2 157
16 kanalda
Get PRO
Iyul '24
+1 844
11 kanalda
Get PRO
Iyun '24
+1 514
7 kanalda
Get PRO
May '24
+1 079
9 kanalda
Get PRO
Aprel '24
+1 306
11 kanalda
Get PRO
Mart '24
+1 332
13 kanalda
Get PRO
Fevral '24
+630
14 kanalda
Get PRO
Yanvar '24
+1 075
14 kanalda
Get PRO
Dekabr '23
+973
7 kanalda
Get PRO
Noyabr '23
+1 457
8 kanalda
Get PRO
Oktabr '23
+3 536
5 kanalda
Get PRO
Sentabr '23
+3 177
0 kanalda
Get PRO
Avgust '23
+3 401
0 kanalda
Get PRO
Iyul '23
+2 829
0 kanalda
Get PRO
Iyun '23
+2 847
0 kanalda
Get PRO
May '23
+2 417
0 kanalda
Get PRO
Aprel '23
+2 646
0 kanalda
Get PRO
Mart '23
+2 345
0 kanalda
Get PRO
Fevral '23
+2 328
0 kanalda
Get PRO
Yanvar '23
+2 603
0 kanalda
Get PRO
Dekabr '22
+2 541
0 kanalda
Get PRO
Noyabr '22
+2 543
0 kanalda
Get PRO
Oktabr '22
+3 146
0 kanalda
Get PRO
Sentabr '22
+3 951
0 kanalda
Get PRO
Avgust '22
+2 425
0 kanalda
Get PRO
Iyul '22
+2 611
0 kanalda
Get PRO
Iyun '22
+2 636
0 kanalda
Get PRO
May '22
+3 979
0 kanalda
Get PRO
Aprel '22
+4 171
0 kanalda
Get PRO
Mart '22
+6 802
0 kanalda
Get PRO
Fevral '22
+3 153
0 kanalda
Get PRO
Yanvar '22
+4 050
0 kanalda
Get PRO
Dekabr '21
+4 346
0 kanalda
Get PRO
Noyabr '21
+4 152
0 kanalda
Get PRO
Oktabr '21
+6 200
0 kanalda
Get PRO
Sentabr '21
+5 226
0 kanalda
Get PRO
Avgust '21
+5 134
0 kanalda
Get PRO
Iyul '21
+6 261
0 kanalda
Get PRO
Iyun '21
+2 427
0 kanalda
Get PRO
May '21
+731
0 kanalda
Get PRO
Aprel '21
+1 029
0 kanalda
Get PRO
Mart '21
+1 300
0 kanalda
Get PRO
Fevral '21
+786
0 kanalda
Get PRO
Yanvar '21
+1 163
0 kanalda
Get PRO
Dekabr '20
+22 087
0 kanalda
Sana
Obunachilarni jalb qilish
Esdaliklar
Kanallar
16 Sentabr+2 628
15 Sentabr+26
14 Sentabr+23
13 Sentabr+29
12 Sentabr+23
11 Sentabr+32
10 Sentabr+54
09 Sentabr+25
08 Sentabr+61
07 Sentabr+25
06 Sentabr+53
05 Sentabr+45
04 Sentabr+41
03 Sentabr+37
02 Sentabr+34
01 Sentabr+22
Kanal postlari
⚠️ Acronis Backup flaw exploited in limited targeted attacks. CVE-2026-87886 lets a low-privileged attacker escalate permissi
⚠️ Acronis Backup flaw exploited in limited targeted attacks. CVE-2026-87886 lets a low-privileged attacker escalate permissions on affected Linux cPanel/WHM and Plesk deployments. Fixes are available. Which builds need updating → https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html

2
A unified security dashboard can still hide a broken incident workflow. Run one incident from detection to clean recovery. Co
A unified security dashboard can still hide a broken incident workflow. Run one incident from detection to clean recovery. Count every console switch, permission change, and ownership handoff. Six tests reveal whether consolidation actually reduces operational friction: https://thehackernews.com/expert-insights/2026/09/how-to-evaluate-unified-security.html
859
3
🚨 Attackers are exploiting a critical WooCommerce Wholesale Lead Capture flaw to plant PHP web shells. Wordfence has blocked
🚨 Attackers are exploiting a critical WooCommerce Wholesale Lead Capture flaw to plant PHP web shells. Wordfence has blocked over 100,000 exploit attempts since June against CVE-2026-27540, which affects versions through 2.0.3.1. Read: https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html
8 782
4
⚠️ Forged admin JWTs are being used in WSO2 API Manager exploitation attempts. CVE-2026-5430 lets unsupported JWT algorithms
⚠️ Forged admin JWTs are being used in WSO2 API Manager exploitation attempts. CVE-2026-5430 lets unsupported JWT algorithms bypass authentication and can lead to account takeover. Fixes are available. Read: https://thehackernews.com/2026/09/active-exploitation-attempts-target.html
2 750
5
🚨 KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials
🚨 KREMLIN banking malware bypasses Chromium integrity checks to install a Chrome and Edge extension that steals credentials and session tokens. It also uses Ethereum smart contracts to rotate C2 and payload locations. How the attack chain works: https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html
4 738
6
‼️ Iran-attributed HEAVYGRAM, also tracked as CHOSEN BRICK, uses Telegram bots to spy on dissidents and journalists. A joint
‼️ Iran-attributed HEAVYGRAM, also tracked as CHOSEN BRICK, uses Telegram bots to spy on dissidents and journalists. A joint U.S.-U.K.-Dutch advisory says the Windows malware can steal messages and passwords, record audio, capture screenshots, and exfiltrate files. Details → https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html
4 978
7
🚨 BambooToken uses MQTT to control Windows and Linux hosts across Asia and South America. Lumen identified a dozen compromis
🚨 BambooToken uses MQTT to control Windows and Linux hosts across Asia and South America. Lumen identified a dozen compromised entities, with activity detected as recently as July 2026. Learn what's inside the malware’s MQTT command-and-control: https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html
4 789
8
✅ Your Business Continuity Management Checklist. Most resilience programs look complete on paper. Let's make sure yours holds
✅ Your Business Continuity Management Checklist. Most resilience programs look complete on paper. Let's make sure yours holds up when it matters most. Discover 6 ways to align your BCM program with operational reality. Get the checklist → https://thn.news/bcm-reality-check
4 893
9
Phishing puts financial SOCs under constant pressure. Cut the workload with ANY.RUN: faster analysis, fewer escalations, and
Phishing puts financial SOCs under constant pressure. Cut the workload with ANY.RUN: faster analysis, fewer escalations, and 21 min lower MTTR. → https://thn.news/phishing-soc-detection
4 791
10
🚨 A human attacker exploited Marimo’s pre-auth RCE and reached an SSH bastion in eight seconds. The operator used harvested
🚨 A human attacker exploited Marimo’s pre-auth RCE and reached an SSH bastion in eight seconds. The operator used harvested AWS credentials to fetch the private key from Secrets Manager and authenticate over SSH. No AI agent was involved. Read: https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html
4 231
11
One attack step can now decide what gets tested next. OpenAEV’s Attack Chaining feeds live findings like credentials, tokens,
One attack step can now decide what gets tested next. OpenAEV’s Attack Chaining feeds live findings like credentials, tokens, and open ports into the next stage, while XTM One can plan and adapt the path inside a defined scope. How the attack path builds: https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html
4 185
12
⚠️ Exposed Vite dev servers are being scanned for cloud credentials. Attackers are exploiting a Vite flaw to bypass file rest
⚠️ Exposed Vite dev servers are being scanned for cloud credentials. Attackers are exploiting a Vite flaw to bypass file restrictions and retrieve .env files, AWS and Azure credentials, and infrastructure state. How the bypass works: https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html
4 320
13
Cursor deleted a production database and its backups in nine seconds. The agent found an unrelated Railway API token with bla
Cursor deleted a production database and its backups in nine seconds. The agent found an unrelated Railway API token with blanket GraphQL permissions while handling a staging task. AI blast radius follows credential reach. Why access boundaries matter: https://thehackernews.com/expert-insights/2026/09/stop-trying-to-control-ai-behavior.html
5 401
14
‼️ Warning: LiteSpeed Enterprise before 6.3.7 can let low-privilege website users gain root on shared-hosting servers. It can
‼️ Warning: LiteSpeed Enterprise before 6.3.7 can let low-privilege website users gain root on shared-hosting servers. It can bypass CageFS isolation. No CVE is assigned, exploitation is unknown, and 6.3.7 may not auto-update immediately. Manual update may be required → https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html
4 914
15
‼️ Attackers are exploiting a Cisco Secure Email Gateway vulnerability that can let a crafted email trigger command execution
‼️ Attackers are exploiting a Cisco Secure Email Gateway vulnerability that can let a crafted email trigger command execution as root. Cisco has released fixes, and CISA added CVE-2026-76461 to its KEV catalog. How the attack works → https://thehackernews.com/2026/09/cisco-secure-email-gateway-flaw.html
4 947
16
⚠️ Two China-linked threat actors exploited the same Chrome-Windows zero-day chain. UTA0560 used it to deploy the GRIMWEDGE b
⚠️ Two China-linked threat actors exploited the same Chrome-Windows zero-day chain. UTA0560 used it to deploy the GRIMWEDGE backdoor against NGOs. APT31 used it to install LONGTALE, a credential-stealing Chrome extension. How the shared exploit chain worked: https://thehackernews.com/2026/09/china-linked-hackers-exploit-chrome.html
4 992
17
🚨 Thai ISP 3BB attacker had root access and hid MeshCentral for persistence. Recovered tools sprayed passwords across 55+ in
🚨 Thai ISP 3BB attacker had root access and hid MeshCentral for persistence. Recovered tools sprayed passwords across 55+ internal systems and targeted subscriber login databases. How the attacker stayed in: https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html
5 869
18
‼️ A Telegram Desktop flaw could send messages from opened HTML exports to an attacker-controlled server. A bot message could
‼️ A Telegram Desktop flaw could send messages from opened HTML exports to an attacker-controlled server. A bot message could hide JavaScript in pre-fix exports, which ran when the file was opened in a browser with JavaScript enabled. Updating Telegram does not clean old export files. Read: https://thehackernews.com/2026/09/telegram-desktop-flaw-lets-hidden.html
5 641
19
‼️ Researchers broke Intel TDX’s confidential-computing protections with a $159 DDR5 interposer. New "DDRop" attack silently
‼️ Researchers broke Intel TDX’s confidential-computing protections with a $159 DDR5 interposer. New "DDRop" attack silently drops memory writes so the CPU trusts stale encrypted data. In lab tests, researchers read protected VM memory and forged attestation. No CVE. No patch. Full details here → https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html
5 129
20
‼️ Researchers broke Intel TDX’s confidential-computing protections with a $159 DDR5 interposer. New "DDRop" attack silently drops memory writes so the CPU trusts stale encrypted data. In lab tests, researchers read protected VM memory and forged attestation. No CVE. No patch. Full details here → https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html
1