The Hacker News
βœ”
155K subscribers
2.48K photos
16 videos
4 files
8.41K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
⚠️ Multiple infostealers β€” Arkanix, NovaStealer, DarkCloud, MawaStealer and others β€” are active in the wild.

Researchers say Arkanix was likely built with LLM assistance, speeding malware development. Stolen logs are filtered and sold to brokers seeking corporate network access.

πŸ”— Read β†’ https://thehackernews.com/2026/03/weekly-recap-sd-wan-0-day-critical-cves.html#:~:text=Multiple%20Stealer%20Malware%20Families%20Detected
😁3🀯3⚑2πŸ”₯1
Human-led. Rules-based. LLM-powered agentic systems. Each promises efficiency. Each has limits.

The real advantage? Knowing when, and how, to use them together.

The teams pulling ahead aren’t betting on a single model. They’re architecting a custom mix of all three.

On March 12th, join Tines for Workflow clarity: Where AI fits in modern automation. You'll learn how to harness AI with clarity and control, and determine the right combination of workflows for you.

πŸ”— Register and learn more here: https://thn.news/modern-automation-ai
πŸ€”5⚑2πŸ‘1
πŸ›‘ Hacktivists launched 149 DDoS attacks targeting 110 organizations in 16 countries after the U.S.–Israel strikes on Iran, security researchers report.

Most attacks hit government systems in the Middle East, with Kuwait, Israel, and Jordan seeing the highest activity.

πŸ”— Read β†’ https://thehackernews.com/2026/03/149-hacktivist-ddos-attacks-hit-110.html
⚑14πŸ‘11😁7πŸ€”6πŸ”₯4
Authorities have seized #LeakBase, a cybercrime forum used to trade stolen databases and infostealer logs.

Site had 142k+ members and hosted hundreds of millions of stolen credentials & financial records used for account takeovers and fraud.

πŸ”— Read β†’ https://thehackernews.com/2026/03/fbi-and-europol-seize-leakbase-forum.html
πŸ‘9πŸ”₯2
⚑ Authorities dismantled Tycoon 2FA, a major phishing-as-a-service toolkit used to bypass MFA.

The platform sent tens of millions of phishing emails monthly and enabled access to nearly 100,000 organizations by stealing credentials, MFA codes, and session cookies.

πŸ”— Read β†’ https://thehackernews.com/2026/03/europol-led-operation-takes-down-tycoon.html
πŸ‘8πŸ‘3πŸ”₯2
⚠️ Most encrypted web traffic relies on ECDHE, the TLS key exchange that lets browsers and servers derive a shared secret.

Quantum computers could break the elliptic-curve math behind it. The industry is moving to hybrid exchanges combining ECDHE with post-quantum ML-KEM.

πŸ”— Learn how hybrid key exchange protects data from future quantum attacks β†’ https://thehackernews.com/expert-insights/2026/03/demystifying-key-exchange-from.html
πŸ‘9πŸ”₯4
🚨 Russian-linked hackers are using BadPaw and MeowMeow malware to target Ukrainian entities.

Phishing emails deliver a ZIP with an HTA lure. Code hidden in a PNG loads a .NET dropper that installs a backdoor capable of running PowerShell commands and manipulating files.

πŸ”— Details β†’ https://thehackernews.com/2026/03/apt28-linked-campaign-deploys-badpaw.html
😁12🀯4πŸ‘2πŸ”₯2😱1
πŸ›‘ Suspected Iran-linked hackers targeted Iraqi officials by impersonating the foreign ministry and delivering malware.

Tracked as Dust Specter, the campaign deploys SPLITDROP, TWINTASK, TWINTALK, and GHOSTFORM via password-protected archives and DLL sideloading.

πŸ”— Read β†’ https://thehackernews.com/2026/03/dust-specter-targets-iraqi-officials.html
🀯9πŸ‘4😁4πŸ”₯1πŸ‘1πŸ€”1😱1
πŸ”₯ ActiveState Launches World's Largest Secure OSS Catalog With 79M Components.

ActiveState has launched the world’s largest secure open-source catalog, uniting 79M components across 12+ languages (Java, Python, Rust, etc.). It cuts CVE exposure by 99% via SLSA-3 builds and reclaims 30% of engineering time by automating manual maintenance and governance.

πŸ”— Read the release: https://thn.news/open-source-catalog
πŸ‘6
🚨 DDR5 bot scalping, Telegram cybercrime hubs, and new malware campaigns.

This week’s #ThreatsDay Bulletin breaks down the biggest security threats and tactics shaping the threat landscape right now.

πŸ”— Read β†’ https://thehackernews.com/2026/03/threatsday-bulletin-redis-rce-ddr5-bot.html
🀯6πŸ‘5
⚠️ Cisco confirms active exploitation of two Catalyst SD-WAN Manager flaws.

β–Ά CVE-2026-20122 enables arbitrary file overwrite via API credentials.
β–ΆCVE-2026-20128 can expose data and grant DCA privileges after login.

πŸ”— Read β†’ https://thehackernews.com/2026/03/cisco-confirms-active-exploitation-of.html

Patches are out across multiple releases.
πŸ”₯10πŸ‘4🀯4⚑1πŸ‘1