The Hacker News
βœ”
162K subscribers
3.25K photos
21 videos
4 files
9.21K links
⭐ Official THN Telegram Channel β€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

πŸ“¨ Contact: admin@thehackernews.com

🌐 Website: https://thehackernews.com
Download Telegram
πŸ›‘ Malicious Trivy images (0.69.4–0.69.6) confirm a supply chain breach using a compromised service account token.

Attackers pushed trojanized builds, spread an npm worm, defaced 44 repos in minutes, and deployed Kubernetes wiper payloads.

πŸ”—Read β†’ https://thehackernews.com/2026/03/trivy-hack-spreads-infostealer-via.html
πŸ”₯14πŸ‘11
Microsoft says tax-season phishing now deploys RMM tools like ScreenConnect, moving beyond credential theft.

A Feb. 10 campaign hit 29,000+ users across 10,000 orgs, using IRS lures to gain persistent system access.

πŸ”— IRS themes, QR tricks, and full attack chain β†’ https://thehackernews.com/2026/03/microsoft-warns-irs-phishing-hits-29000.html
πŸ”₯14πŸ‘4
Biggest security stories this week πŸ‘‡

πŸ”₯ Trivy backdoor β€” CI/CD worm
πŸ€– 4 DDoS botnets down
πŸ“± iOS DarkSword β€” 6 vulns
🦠 Android malware in IPTV apps
πŸ”“ Cisco FMC 0-day exploited
⚑ Langflow RCE in 20h
πŸ•΅οΈ FBI buys location data
🌐 WhatsApp testing usernames
🐻 APT28 toolkit leak
πŸ’€ 373K domains seized
🎯 Phishing hits Pakistan energy
🧠 VoidStealer bypasses Chrome ABE
πŸ’° Beast ransomware leak
πŸ“¦ Malicious npm account hijack
🎣 OpenClaw devs crypto phishing
πŸ‡¨πŸ‡³ China PQC standards
🚨 25+ critical CVEs exploited

Full cybersecurity recap β†’ https://thehackernews.com/2026/03/weekly-recap-cicd-backdoor-fbi-buys.html
πŸ”₯12πŸ‘4
XM Cyber mapped 8 AWS Bedrock attack paths targeting permissions and integrations, not the model itself.

One over-privileged identity can redirect logs, hijack agents, poison prompts, and pivot into connected enterprise systems.

πŸ”— The 8 paths from Bedrock access to infrastructure risk β†’ https://thehackernews.com/2026/03/we-found-eight-attack-vectors-inside.html
πŸ”₯8πŸ‘7
m
πŸ€”80😁30🀯19πŸ”₯13πŸ‘12😱11πŸ‘4⚑3
As AI reshapes the cyber workforce, leaders need clarity and practitioners need direction. Download the 2026 Cybersecurity Workforce Report.

πŸ”— Download β†’ https://thn.news/sans-workforce-2026
πŸ”₯9⚑6πŸ‘6🀯3
⚠️ North Korea’s Contagious Interview campaign now uses malicious VS Code projects to deploy StoatWaffle.

Opening the folder can auto-run tasks.json, install Node.js if missing, and fetch stealer or RAT payloads on developer systems.

πŸ”— Read β†’ https://thehackernews.com/2026/03/north-korean-hackers-abuse-vs-code-auto.html
😁8⚑5🀯4πŸ”₯2πŸ‘2
⚠️ Citrix patched a critical NetScaler flaw (CVSS 9.3) enabling unauthenticated memory leaks.

The issue exposes sensitive appliance data when SAML IDP is enabled, alongside a second bug that can mix user sessions in gateway or AAA setups.

πŸ”— Read β†’ https://thehackernews.com/2026/03/citrix-urges-patching-critical.html
πŸ‘5πŸ”₯4πŸ‘2
πŸ›‘ A Russian access broker was sentenced to 81 months in U.S. prison for fueling ransomware attacks.

He sold network access to groups like Yanluowang, enabling dozens of intrusions and over $9M in confirmed losses across U.S. organizations.

πŸ”— Read β†’ https://thehackernews.com/2026/03/us-sentences-russian-hacker-to-675.html
πŸ”₯7πŸ‘6😱4πŸ‘3😁3
Telegram blocked 43M+ channels in 2025, yet threat actors stayed.

Yochai Corem shows they adaptedβ€”rebuilding in days, gating access, and shifting sensitive comms off-platform while keeping Telegram for scale.

πŸ”— How criminals evolved despite Telegram’s crackdown β†’ https://thehackernews.com/expert-insights/2026/03/telegrams-crackdown-changed-how-threat.html
😁15πŸ‘9πŸ‘4πŸ”₯3⚑2πŸ€”2
🚨 TeamPCP expanded its supply chain attack to Checkmarx GitHub Actions, deploying the same CI credential stealer used in the Trivy breach.

Stolen tokens are reused to push malicious commits into other repos, enabling a cascading compromise across CI workflows.

πŸ”— Read β†’ https://thehackernews.com/2026/03/teampcp-hacks-checkmarx-github-actions.html
πŸ”₯10πŸ‘4⚑2
ActiveState Curated Catalog: Secure Open Source Built From Source.

Introducing the ActiveState Curated Catalog: a vetted source of truth for open-source. Instead of pulling from public registries, your team accesses a private catalog of rebuilt-from-source packages to ensure security and compliance from the start.

Start Free Course: https://thn.news/ai-code-catalogs
πŸ€”5πŸ”₯4πŸ‘2
This media is not supported in your browser
VIEW IN TELEGRAM
Security teams are using more toolsβ€”but still struggling to prioritize real risk.

Focus is shifting to exposure validation and business impact, not just alerts and scans, as highlighted at Gartner’s first event.

πŸ”— 5 key learnings shaping modern security β†’ https://thehackernews.com/2026/03/5-learnings-from-first-ever-gartner.html
πŸ‘5πŸ”₯3πŸ‘2
⚠️ ALERT: Fake resumes are infecting enterprise systems and the full attack runs in ~25 seconds.

Obfuscated VBScript deploys credential stealers and a Monero miner, using Dropbox, #WordPress C2, and SMTP for exfiltration. It selectively targets domain-joined machines.

πŸ”— Read β†’ https://thehackernews.com/2026/03/hackers-use-fake-resumes-to-steal.html
😁10🀯8πŸ€”5πŸ‘1
⚑ Cybersecurity tools improved, but teams still struggle with basics.

Missing understanding of their own systems leads to wrong priorities, poor tool choices, and weak risk focus. More tools do not fix this.

πŸ”— Why security still breaks without strong foundations β†’ https://thehackernews.com/2026/03/the-hidden-cost-of-cybersecurity.html
πŸ”₯7πŸ‘4😁2
🚨 A malvertising campaign uses tax searches to deliver kernel-level EDR killers via rogue ScreenConnect installers.

Cloaking hides payloads; a signed Huawei driver is abused via BYOVD to disable Defender, Kaspersky, and SentinelOne before credential theft and lateral movement.

πŸ”— Read β†’ https://thehackernews.com/2026/03/tax-search-ads-deliver-screenconnect.html
😁8⚑4πŸ”₯4πŸ‘1
🚨 Attackers are abusing npm and GitHub to deliver malware disguised as dev tools.

Sudo password phishing during install triggers a multi-stage chain that deploys a RAT, stealing crypto wallets, credentials, SSH keys, and tokens.

πŸ”— Read β†’ https://thehackernews.com/2026/03/ghost-campaign-uses-7-npm-packages-to.html
🀯8😁6⚑5πŸ”₯2
πŸ›‘ Malicious LiteLLM versions 1.82.7–1.82.8 deploy credential theft, Kubernetes lateral movement, and a persistent backdoor.

Linked to the Trivy CI/CD compromise, the payload runs on import or via .pth at Python startup, spreads across nodes, and installs a systemd service.

πŸ”— Full story β†’ https://thehackernews.com/2026/03/teampcp-backdoors-litellm-versions.html
🀯12πŸ”₯10⚑3😁3πŸ‘1
πŸ”₯ The FCC is banning new foreign-made consumer routers from U.S. markets over security risks.

Officials say these devices expose supply chain weaknesses and have been used in espionage and attacks on critical infrastructure.

πŸ”— Read β†’ https://thehackernews.com/2026/03/fcc-bans-new-foreign-made-routers-over.html
😁22πŸ€”6πŸ‘4😱4πŸ”₯1πŸ‘1🀯1
Universities run complex identity systems.

As Robert Kraczek (@OneIdentity) explains, high turnover and hybrid AD + Entra ID gaps leave orphaned accounts and excess access that attackers exploit.

πŸ”— Where higher ed identity security breaks down β†’ https://thehackernews.com/expert-insights/2026/03/why-institutions-of-higher-education.html
πŸ”₯5πŸ‘2πŸ‘1
πŸ›‘ A device code phishing campaign is hitting 340+ Microsoft 365 orgs using OAuth abuse.

Victims enter codes on real Microsoft pages, generating access and refresh tokens attackers reuseβ€”even after password resets.

πŸ”— Read β†’ https://thehackernews.com/2026/03/device-code-phishing-hits-340-microsoft.html
😁8πŸ”₯6⚑5πŸ‘3