🟡 Metabase SQLi zero-day exploited in customer data-theft attacks #BleepingComputerNews "A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft attacks, known to impact Framework and Tally. Metabase disclosed the attacks on Thursday, warning that its Metabase Cloud SaaS platform was compromised through a previously unknown vulnerability affecting …

Channel
News Vulnerability Management and more
@avleonovnews
On this record: Growth · Engagement · Posts · Telegram's recommendations · Cite this entry
1,407subscribers
+43 since we began measuring on 7 August 2026
Risers and fallers across the register · movement among entries of 1,000–3,162.
Register entry
| Telegram ID | -1001450293378 |
|---|---|
| Type | Channel |
| Username | @avleonovnews |
| Created | Between 1 April 2019 and 31 October 2021 — estimated from Telegram’s id allocation, not measured. How this range is calculated. |
| First recorded | 7 August 2026 |
| Last confirmed live | 11 September 2026 |
| Measurements held | 12 |
| Confirmed unchanged | 1 time, most recently 11 September 2026 |
| On Telegram | t.me/avleonovnews |
Growth
| Measured (UTC) | Subscribers | Change |
|---|---|---|
| 11 Sept 2026, 14:58 | 1,407 | +8 |
| 6 Sept 2026, 23:17 | 1,399 | +10 |
| 2 Sept 2026, 03:33 | 1,389 | +6 |
| 30 Aug 2026, 11:26 | 1,383 | +5 |
| 27 Aug 2026, 04:46 | 1,378 | +5 |
| 24 Aug 2026, 05:19 | 1,373 | +8 |
| 20 Aug 2026, 13:07 | 1,365 | +2 |
| 17 Aug 2026, 18:16 | 1,363 | +1 |
| 14 Aug 2026, 08:27 | 1,362 | -1 |
| 11 Aug 2026, 10:05 | 1,363 | -1 |
| 7 Aug 2026, 22:20 | 1,364 | no change |
| 7 Aug 2026, 14:59 | 1,364 | first reading |
Engagement
20 posts held, back to 6 August 2026 — the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 1 page of Telegram’s post history, 20 posts per page.
Nothing published in the last 30 days. ERR and ER are rolling 30-day measures, so there is nothing to compute — we hold 20 posts for this entry, the most recent from 7 August 2026. An engagement rate over an empty window would be a number about nothing.
Recent posts
🟢 Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer #TheHackersNews "A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a pow…
🔵 Other News Digest #TheRegisterNews 1. MIT boffins' TONTOU attack slips through Spectre defenses on Intel and AMD CPUs 2. N-able God mode flaw: Vendor confirms attackers reached customer networks as second hotfix lands #BleepingComputerNews 1. Levi Strauss & Co. says hackers stole corporate data in cyberattack #InfosecurityMagazineNews 1. Healthcare and Victim Support Charities Affected by Beacon Cyber Incident #…
🟢 Ransomware attacks spike as world distracted by AI #TheRegisterNews "MOST POPULAR AI - AI and ML How the famed USENIX Security conf is managing a flood of papers in the AI era AI usage is evident but isn't yet a serious problem - AI and ML AMD acquires AI chip startup Taalas to boost inference performance by etching models into silicon Early tech demos show model-specific integrated circuits churning out up to 17,…
🔴 Rapid7 Analysis: Unauthenticated Remote Code Execution in JetBrains TeamCity (CVE-2026-63077) #Rapid7Blog "## Overview On July 27, 2026, JetBrains published a security advisory for CVE-2026-63077, a critical unsafe deserialization vulnerability affecting JetBrains TeamCity. An attacker who can reach a TeamCity server over HTTP or HTTPS can exploit the agent polling protocol without credentials and execute operatin…
🔵 Other News Digest #BleepingComputerNews 1. Real emails, hijacked payments: Two H1 2026 attack chains 2. North Carolina Ports confirms cyberattack disrupting operations #TheHackersNews 1. Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails 2. TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign 3. Growing Up The Hard Way #TheRecordNews 1. French rugby c…
🔴 New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP #TheHackersNews "WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-64638 (CVSS score: 8.9), the High-severity vulnerabi…
🟡 Agentic AI for Cyber Defenders: What Security Teams Built at Black Hat USA 2026 #TenableBlog "Agentic AI armed attackers first, but it also put real building power in defenders’ hands. Here’s what security practitioners built in two days at Black Hat USA 2026, and how the CyberAgents Exchange keeps that work compounding long after the event. ## Key takeaways 1. Building defensive cybersecurity tooling no longer r…
🟡 18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers #TheHackersNews "A use-after-free bug in Linux's SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3…
🟢 AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day #TheHackersNews "PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate attack vectors. PortSwigger said a separate human-guided discovery cascade also exposed a zero-day in Apache Tr…
🔵 Other News Digest #TheRecordNews 1. State Department says Trump raised cyber scam compound issue with Xi #KasperskyBlog 1. Dangerous email attachments: the files you should never open | Kaspersky official blog #BleepingComputerNews 1. OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it #SecurityWeeklyVideo 1. Computers Inside Your Computers #KrebsOnSecurityBlog 1. Canadian Man Pleads Guilty i…
🟡 New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables #TheHackersNews "Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026, the research found affected behavior ac…
Showing the 12 most recent of 20 posts we hold for @avleonovnews. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.
Appears in Telegram’s recommendations for other channels
The reverse of the list above, and a different kind of signal. This does not require this channel to have ever been asked about directly — each row below is a channel we DID ask Telegram about, whose Telegram-generated list happened to include this one. A channel can appear here with an empty list above it, because being named by someone else’s query is independent of having been queried itself.
@sarkari_jobs_exam_result · 57,615
Telegram ranks this channel #24 of 68 here — alongside 67 others — read 23 August 2026
@cibsecurity · 27,941
Telegram ranks this channel #47 of 58 here — alongside 57 others — read 10 September 2026
@techlucker · 43,579
Telegram ranks this channel #55 of 79 here — alongside 78 others — read 28 August 2026
This channel appears in 3 seed channels' Telegram-generated recommendation lists in total. Each is Telegram’s list for THAT channel, not this one — see how this is measured.
Cite this entry
A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 11 September 2026 — this entry's latest reading, not the date you are reading this.
“News Vulnerability Management and more” (@avleonovnews), 1,407 subscribers as measured 11 September 2026. Telegram Register, tgregister.com/channel/avleonovnews.
Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.