У GitHub проблема с вредоносным ПО Злоумышленники используют страницу трендов GitHub, создавая репозитории с благозвучными названиями и покупая фейковые звезды, чтобы заманить разработчиков и заставить их скачать вредоносное ПО. Исследователи создали программу Star Scout, которая за шесть лет просканировала метаданные GitHub и выявила более 6 миллионов подозрительных фейковых звезд https://www.youtube.com/watch?v=w…

Channel
Hacker news - новости из мира хакинга и IT-технологий!
@Hackme_news
On this record: Topic · Growth · Engagement · Posts · Telegram's recommendations · Cite this entry
2,073subscribers
-15 since we began measuring on 6 August 2026
Risers and fallers across the register · movement among entries of 1,000–3,162.
Register entry
| Telegram ID | -1001402497123 |
|---|---|
| Type | Channel |
| Username | @Hackme_news |
| Created | Between 1 November 2018 and 31 October 2021 — estimated from Telegram’s id allocation, not measured. How this range is calculated. |
| First recorded | 6 August 2026 |
| Last confirmed live | 6 October 2026 |
| Measurements held | 15 |
| Confirmed unchanged | 1 time, most recently 6 October 2026 |
| On Telegram | t.me/Hackme_news |
Topic
Hacking & security — a classification, not a measurement. An on-box language model (Qwen3.6-35B-A3B-FP8, prompt version 1) read this channel’s own recent posts on 16 September 2026 and assigned it the closest of 31 fixed categories, at 98% confidence. This is a model’s judgement about what the channel is likely to be about, not a fact this register measured the way a subscriber count or a view count is measured — it can be revised on a later pass, and it carries no weight anywhere else on this page. How this classification works, and why it has no browse page of its own yet.
Growth
| Measured (UTC) | Subscribers | Change |
|---|---|---|
| 6 Oct 2026, 14:18 | 2,073 | -6 |
| 29 Sept 2026, 03:56 | 2,079 | +1 |
| 19 Sept 2026, 00:01 | 2,078 | +1 |
| 14 Sept 2026, 04:41 | 2,077 | -1 |
| 10 Sept 2026, 18:40 | 2,078 | -1 |
| 5 Sept 2026, 11:00 | 2,079 | +1 |
| 1 Sept 2026, 14:17 | 2,078 | +3 |
| 29 Aug 2026, 21:17 | 2,075 | -1 |
| 26 Aug 2026, 14:48 | 2,076 | -6 |
| 24 Aug 2026, 00:08 | 2,082 | -2 |
| 19 Aug 2026, 23:58 | 2,084 | -2 |
| 17 Aug 2026, 10:23 | 2,086 | -2 |
| 13 Aug 2026, 18:09 | 2,088 | -1 |
| 7 Aug 2026, 19:21 | 2,089 | +1 |
| 6 Aug 2026, 23:46 | 2,088 | first reading |
Engagement
20 posts held, back to 11 October 2024 — the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 2 pages of Telegram’s post history, 20 posts per page.
Nothing published in the last 30 days. ERR and ER are rolling 30-day measures, so there is nothing to compute — we hold 20 posts for this entry, the most recent from 12 April 2026. An engagement rate over an empty window would be a number about nothing.
Recent posts
🚨Хакеры взламывают Proofpoint + Bitly, чтобы обойти защиту электронной почты и украсть учётные данные Microsoft 365. Фишинговые ссылки выглядят настоящими — зашифрованные, сокращённые и отправленные с доверенных учётных записей. Даже «защищённые» письма теперь используются как оружие. https://thehackernews.com/2025/07/experts-detect-multi-layer-redirect.html
DreamWalkers (чтение за 8 минут) Рефлективная загрузка модулей — это метод сокрытия вредоносных данных, внедряемых через шелл-код. https://maxdcb.github.io/DreamWalkers
Хакеры активно используют критический RCE в теме WordPress Alone (чтение 2 минуты) Компания Wordfence, занимающаяся безопасностью WordPress, сообщила об активно эксплуатируемой критической уязвимости, связанной с произвольной загрузкой файлов без аутентификации, в премиум-теме WordPress «Alone». Уязвимость связана с функцией alone_import_pack_install_plugin() темы, в которой отсутствуют проверки одноразовых кодов, ра…
ВНИМАНИЕ → Такие приложения, как ChatGPT и Trello, могут получить доступ ко всему вашему облаку OneDrive через File Picker от Microsoft, даже если вы загружаете только один файл. https://thehackernews.com/2025/05/microsoft-onedrive-file-picker-flaw.html
🛑Думаете, что дешевый телефон Android — выгодная сделка? Он может быть загружен Triada — мощным вредоносным ПО, предустановленным на поддельных устройствах. 👀2600+ жертв всего за две недели; и хакеры украли 💰более 270 тыс. долларов в криптовалюте. «С новой версией Triada столкнулись более 2600 пользователей в разных странах, большинство — в России», — говорится в отчете «Лаборатории Касперского». Заражения были за…
Недавно обнаруженная уязвимость безопасности, влияющая на Apache Tomcat, подверглась активной эксплуатации после публикации публичного доказательства концепции (PoC) всего через 30 часов после публичного раскрытия информации. Уязвимость, обозначенная как CVE-2025-24813 , затрагивает следующие версии: Apache Tomcat 11.0.0-M1 до 11.0.2 Apache Tomcat 10.1.0-M1 до 10.1.34 Apache Tomcat 9.0.0-M1 до 9.0.98 https://theha…
CISA предупреждает об активной эксплуатации уязвимости цепочки поставок GitHub Action Агентство по кибербезопасности и безопасности инфраструктуры США (CISA) во вторник добавило уязвимость, связанную с компрометацией цепочки поставок GitHub Action, tj-actions/changed-files, в свой каталог известных эксплуатируемых уязвимостей (KEV). Уязвимость высокой степени серьезности, обозначенная как CVE-2025-30066 (оценка CVS…
Исследователи кибербезопасности обнаружили новый бэкдор, использующий Telegram для командования и контроля (C2). 🛠Вредоносное ПО на основе Golang скрывается на виду, имитируя системные файлы. 📲API Telegram Bot используется для удаленной отправки и получения команд. 🔄Функции скрытности позволяют вредоносному ПО перезагружать себя после завершения. https://www.netskope.com/blog/telegram-abused-as-c2-channel-for-new-…
⚠️Исследователи обнаружили две вредоносные модели машинного обучения на Hugging Face, использующие новый метод атаки — «сломанные» файлы pickle — для обхода обнаружения. https://www.reversinglabs.com/blog/rl-identifies-malware-ml-model-hosted-on-hugging-face
🛑Приложение DeepSeek для iOS передает конфиденциальные пользовательские данные без шифрования на облачную платформу, связанную с ByteDance (TikTok), оставляя ее открытой для хакеров. https://www.nowsecure.com/blog/2025/02/06/nowsecure-uncovers-multiple-security-and-privacy-flaws-in-deepseek-ios-mobile-app/
Раскрыта база данных DeepSeek AI: более 1 миллиона строк журнала и секретные ключи https://www.wiz.io/blog/wiz-research-uncovers-exposed-deepseek-database-leak
Showing the 12 most recent of 20 posts we hold for @Hackme_news. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.
Appears in Telegram’s recommendations for other channels
The reverse of the list above, and a different kind of signal. This does not require this channel to have ever been asked about directly — each row below is a channel we DID ask Telegram about, whose Telegram-generated list happened to include this one. A channel can appear here with an empty list above it, because being named by someone else’s query is independent of having been queried itself.
@i_odmin_book · 18,737
Telegram ranks this channel #81 of 83 here — alongside 82 others — read 5 October 2026
This channel appears in 1 seed channel's Telegram-generated recommendation list in total. Each is Telegram’s list for THAT channel, not this one — see how this is measured.
Cite this entry
A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 6 October 2026 — this entry's latest reading, not the date you are reading this.
“Hacker news - новости из мира хакинга и IT-технологий!” (@Hackme_news), 2,073 subscribers as measured 6 October 2026. Telegram Register, tgregister.com/channel/Hackme_news.
Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.