The Hacker News
โœ”
161K subscribers
2.74K photos
18 videos
4 files
8.68K links
โญ Official THN Telegram Channel โ€” A trusted, widely read, independent source for breaking news and tech coverage about cybersecurity and hacking.

๐Ÿ“จ Contact: admin@thehackernews.com

๐ŸŒ Website: https://thehackernews.com
Download Telegram
๐Ÿ›‘ 108 Chrome extensions with 20,000 installs were tied to one backend stealing user data.

They captured Google accounts, hijacked Telegram sessions, and injected scripts into every pageโ€”while posing as games and utilities.

๐Ÿ”—Read โ†’ https://thehackernews.com/2026/04/108-malicious-chrome-extensions-steal.html
๐Ÿ˜15๐Ÿ‘6๐Ÿ”ฅ4
Android trojan Mirax is spreading via Meta ads, hitting 220K+ accounts with fake streaming apps.

It gives attackers full device control and turns phones into proxy nodes to mask fraud using real IPs.

๐Ÿ”— How RAT + proxy is reshaping mobile attacks โ†’ https://thehackernews.com/2026/04/mirax-android-rat-turns-devices-into.html
๐Ÿ”ฅ13โšก3๐Ÿ‘3๐Ÿ‘2๐Ÿ˜ฑ1
MFA protects login. Not the session.

As Alicia Townsend explains, session cookies become the real credential after authentication. If stolen, attackers get access with no password, no MFA, no alerts.

๐Ÿ”— How session hijacking bypasses MFA โ†’ https://thehackernews.com/expert-insights/2026/04/session-cookie-theft-you-showed-your-id.html
๐Ÿ‘21๐Ÿ‘4๐Ÿค”4๐Ÿ˜2๐Ÿ”ฅ1
Effective DDoS testing requires more than generating traffic.

It requires:
๐Ÿ”ถ Precise attack modeling
๐Ÿ”ถ Deep understanding of mitigation layers
๐Ÿ”ถ Controlled execution against production-like environments

Otherwise, youโ€™re measuring system behaviorโ€”not resilience to real world attacks.

Hereโ€™s how the main DDoS testing approaches stack up in 2026: https://thn.news/ddos-automation-testing
๐Ÿ‘2๐Ÿ˜1
Security alerts rose 52%, but critical risk jumped ~400%.

OX Security shows AI-driven development is scaling high-impact flaws faster than teams can fix them, while business context now outweighs CVSS in real risk.

๐Ÿ”— Read โ†’ https://thehackernews.com/2026/04/analysis-of-216m-security-findings.html
๐Ÿ‘3๐Ÿ˜1
๐Ÿ”ฅ Google put Rust in Pixel 10โ€™s modem DNS parser, cutting off a major class of memory bugs.

DNS powers core cellular functions, and unsafe parsing has enabled exploits like buffer overflows. This move reduces attack surface at one of the most exposed layers.

๐Ÿ”— Read โ†’ https://thehackernews.com/2026/04/google-adds-rust-based-dns-parser-into.html
๐Ÿ”ฅ7๐Ÿคฏ5๐Ÿ‘2๐Ÿ˜2
2026 Gartnerยฎ Magic Quadrantโ„ข for Third-Party Risk Management Tools for Assurance Leaders

As organizations grow increasingly reliant on third parties and their technologies, the range of associated risks expands as well. Third-party risk is a slippery slope, which is why itโ€™s even more important to have a trusted solution that best supports your team.

โœจ Optro has been named a Leader in the 2026 Gartnerยฎ Magic Quadrantโ„ข for Third-Party Risk Management for Assurance Leaders!

Download your complimentary copy for unbiased recommendations and in-depth analyses of TPRM software: https://thn.news/2026-tprm-magic-quadrant
๐Ÿ‘3๐Ÿ˜1
โšก U.K. moves to jail tech execs over failure to remove non-consensual intimate images.

New bill amendments also criminalize incest porn and adults roleplaying as children, expanding platform liability.

๐Ÿ”— What the law changes for platforms and execs โ†’ https://thehackernews.com/2026/04/weekly-recap-fiber-optic-spying-windows.html#:~:text=U.K.%20Government%20Threatens%20Tech%20Execs%20with%20Jail%20Time
๐Ÿ‘10๐Ÿ˜ฑ4๐Ÿ‘2๐Ÿ”ฅ2๐Ÿ˜1๐Ÿค”1๐Ÿคฏ1
A new ad fraud campaign used AI-written news to enter Google Discover and trick users.

Pushpaganda drove 240M ad requests in a week by forcing notification opt-ins, then pushing scam alerts and redirecting to ad sites.

๐Ÿ”— Read โ†’ https://thehackernews.com/2026/04/ai-driven-pushpaganda-scam-exploits.html
๐Ÿ‘4๐Ÿ”ฅ2๐Ÿ˜1
โš ๏ธ ALERT - Composer disclosed two command injection flaws (CVE-2026-40176 and CVE-2026-40261) with up to CVSS 8.8 severity.

Malicious composer.json or crafted source refs can execute arbitrary commandsโ€”even without Perforce installed. Affects multiple 2.x versions; patches released and metadata disabled as a precaution.

๐Ÿ”— Read โ†’ https://thehackernews.com/2026/04/new-php-composer-flaws-enable-arbitrary.html
๐Ÿค”5๐Ÿ‘3๐Ÿ”ฅ2๐Ÿ˜2
๐Ÿ”ฅ OpenAI launched GPT-5.4-Cyber, a model built for security teams to find and fix bugs faster.

3,000+ vulnerabilities already fixed using its Codex Security tools, with access expanding to thousands of defenders.

But the same AI can be misused to find exploits.

๐Ÿ”— Read โ†’ https://thehackernews.com/2026/04/openai-launches-gpt-54-cyber-with.html
๐Ÿ”ฅ22๐Ÿ‘8๐Ÿ˜ฑ7๐Ÿ˜5๐Ÿ‘2๐Ÿค”1
โšก Microsoft patched 169 vulnerabilities, including an actively exploited SharePoint zero-day.

It lets attackers spoof trusted content. 93 flaws are privilege escalation, and a critical IKEv2 bug (CVSS 9.8) enables remote code execution with no user action.

๐Ÿ”— Full Patch Tuesday risks and fixes โ†’ https://thehackernews.com/2026/04/microsoft-issues-patches-for-sharepoint.html
๐Ÿ”ฅ12๐Ÿ‘7โšก2๐Ÿคฏ2
๐Ÿ›‘ April Patch Tuesday spans SAP, Adobe, Microsoft, Fortinetโ€”and core vendors like Apple, Google, Cisco, VMware, Palo Alto, AWS, and Linux.

SAP (CVSS 9.9) enables SQL execution. Adobe Reader and SharePoint flaws are already exploited.

๐Ÿ”— Read โ†’ https://thehackernews.com/2026/04/april-patch-tuesday-fixes-critical.html
๐Ÿ‘3โšก1๐Ÿ”ฅ1
๐Ÿšจ A critical nginx-ui flaw is now exploited in the wild.

CVE-2026-33032 (9.8) allows auth bypass via the /mcp_message endpoint, letting attackers take full control of Nginx with two HTTP requests due to an โ€œallow-allโ€ default.

๐Ÿ”— Details here โ†’ https://thehackernews.com/2026/04/critical-nginx-ui-vulnerability-cve.html
๐Ÿ˜ฑ5๐Ÿ‘2๐Ÿ”ฅ1
๐Ÿค– AI is now embedded across security teams. 100% of CISOs report active use.

Agentic testing adds variability, so results change between runs and break repeatability. Hybrid models keep tests consistent while using AI to adapt.

๐Ÿ”— Learn why hybrid AI models are replacing agentic security testing โ†’ https://thehackernews.com/2026/04/deterministic-agentic-ai-architecture.html
๐Ÿ‘2๐Ÿ”ฅ1