The Hacker News
βœ”
155K subscribers
2.27K photos
13 videos
3 files
8.19K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
🚨 A critical flaw in the vm2 Node.js library lets attackers escape the sandbox and run code on the host system.

Tracked as CVE-2026-22709 (CVSS 9.8), the issue stems from improper Promise handler sanitization.

πŸ”— How the flaw works β†’ https://thehackernews.com/2026/01/critical-vm2-nodejs-flaw-allows-sandbox.html
πŸ‘5πŸ‘1
πŸ€– AI didn’t replace SOC analysts. It fixed the scale gap.

Agentic AI investigates every alert first, then hands a verdict to humans.

🚫 No sampling. No skipped signals.
πŸ” Full context by default.

πŸ”— How triage really changes β†’ https://thehackernews.com/2026/01/from-triage-to-threat-hunts-how-ai.html
πŸ”₯9
Researchers find Russian-linked ELECTRUM targeted Poland’s ⚑ power infrastructure in December.

The coordinated attack hit wind, solar, and CHP sites, breaching OT systems and damaging some equipment beyond repair.

πŸ”— Read β†’ https://thehackernews.com/2026/01/russian-electrum-tied-to-december-2025.html
πŸ”₯9🀯7⚑1
🚨 Fake VS Code extension abused #Moltbot’s name to deliver remote access malware.

It posed as an AI assistant, despite Moltbot having no official VS Code plugin. Once installed, it auto-ran on IDE launch and dropped ScreenConnect for persistent remote control.

πŸ”— Read β†’ https://thehackernews.com/2026/01/fake-moltbot-ai-coding-assistant-on-vs.html
🀯21😁9⚑3
🚨 Container adoption has outpaced security.

82% of organizations suffered a container breach last year, and most now assume one will happen every year. Fast-moving containers and unchecked public images keep adding risk faster than teams can fix it.

πŸ”— Why container security prevention is failing in 2026 β†’ https://thehackernews.com/expert-insights/2026/01/the-great-container-disconnect-security.html
πŸ‘8⚑4😁3πŸ€”3πŸ‘1
πŸ’ͺ Google dismantles IPIDEA, a major residential proxy network.

GTIG says 550+ threat groups used it this month to hide espionage, cybercrime, and password-spray attacks by routing traffic through hijacked home devices worldwide.

πŸ”— Read β†’ https://thehackernews.com/2026/01/google-disrupts-ipidea-one-of-worlds.html
πŸ‘10πŸ”₯7😁2
🚨 SolarWinds patches unauthenticated RCE paths β†’ https://thehackernews.com/2026/01/solarwinds-fixes-four-critical-web-help.html

Four critical Web Help Desk bugs let attackers skip login, run code.

Deserialization + auth bypass chained. Update closes it.
πŸ”₯5πŸ‘4πŸ‘3
🚨 Fake ChatGPT Chrome add-on stole 459+ API keys: https://thehackernews.com/2026/01/weekly-recap-firewall-flaws-ai-built.html#:~:text=Malicious%20Chrome%20Extensions%20Steal%20OpenAI%20API%20Keys%20and%20User%20Prompts

Keys sent to Telegram after logout or chat delete.

Hidden Google access raised the real stakes.
😁11πŸ‘5😱5
πŸ“ŠπŸ›‘οΈ Poor threat intel drives downtime and analyst burnout in modern SOCs.

Fresh, validated feeds shorten MTTD/MTTR and reduce false positives at scale.

Full details: https://thehackernews.com/2026/01/3-decisions-cisos-need-to-make-to.html
πŸ‘9
πŸ”₯ This week’s ThreatsDay tracks exploits, ransomware trends, crypto laundering, and phishing operations.

Patterns point to scale and repetition, not one-off incidents, across platforms teams already trust.

Full details ➑️ https://thehackernews.com/2026/01/threatsday-bulletin-new-rces-darknet.html
πŸ”₯9
πŸ” Too many security tools. Not enough visibility.

If your asset inventory lives in spreadsheets πŸ“Š, alerts lack context 🚨, and remediation drags on ⏳, CTEM might be overdue.

This CTEM Readiness Checklist highlights 8 signs it’s time to move from firefighting to prevention with Axonius as the foundation for complete asset intelligence.

Worth a quick read if exposure management is on your radar πŸ‘€ β†’ https://thn.news/ctem-readiness-checklist
πŸ‘4
πŸ›‘οΈ OMICRON uncovers widespread OT vulnerabilities in substations and power plants.

Most issues surfaced within 30 minutes, showing systemic visibility and governance failures.

Detection at network level is now baseline, not optional.

Full details: https://thehackernews.com/2026/01/survey-of-100-energy-systems-reveals.html
πŸ‘6
⚠️ Researchers map 175K publicly exposed Ollama LLM servers worldwide.

Tool-calling turns exposed AI into a highest-severity execution risk.

Full details: https://thehackernews.com/2026/01/researchers-find-175000-publicly.html
πŸ”₯13⚑2
πŸ” WARNING: Ivanti fixes exploited EPMM zero-days with CVSS 9.8 severity.

Exploits enable code execution, persistence, and access to sensitive device data.

Federal agencies face KEV deadlines; temporary patches don’t persist across upgrades.

Read β†’ https://thehackernews.com/2026/01/two-ivanti-epmm-zero-day-rce-flaws.html
πŸ‘5⚑4
⚠️ SmarterMail fixed a critical unauthenticated RCE in its email server software.

The flaw, CVE-2026-24423 (CVSS 9.3), lets attackers execute OS commands via a crafted remote server. It affects builds before 9511.

πŸ”— Fixed builds and attack mechanics β†’ https://thehackernews.com/2026/01/smartermail-fixes-critical.html
πŸ‘3
A U.S. jury convicted a former Google engineer of stealing AI trade secrets for China.

Prosecutors said 2,000+ internal documents were taken to help build a China-based startup while he was still employed.

The case shows how AI infrastructure is now treated as a national security issue.

πŸ”— Details β†’ https://thehackernews.com/2026/01/ex-google-engineer-convicted-for.html
⚑6πŸ”₯6😁2πŸ€”1
The FBI has seized the RAMP cybercrime forum, shutting down its Tor site and clearnet domain with DOJ coordination.

Threat actors are already migrating to other platforms, underscoring how fast the underground re-forms after takedowns.

πŸ”— Read β†’ https://thehackernews.com/2026/01/threatsday-bulletin-new-rces-darknet.html#major-cybercrime-forum-takedown
πŸ‘9😱9πŸ”₯3
🌍 Cybercrime enforcement follows clear patterns. A new analysis maps 418 confirmed actions worldwide from 2021–2025, showing where arrests, takedowns, and sanctions are focused.

The U.S. and Europe lead, with private companies playing a growing support role.

πŸ”— How cybercrime is being targeted worldwide β†’ https://thehackernews.com/2026/01/badges-bytes-and-blackmail.html