APT37 is back with NarwhalRAT, using spearphishing, malicious LNK files, and a dual C2 setup for keylogging, screen capture, USB data collection, and remote execution. #NorthKorea #APT37 #NarwhalRAT ➡️ https://www.hendryadrian.com/apt37-strikes-again-this-time-with-narwhalrat/

Channel
Cybersecurity News Everyday
@cybernotif
On this record: Topic · Growth · Engagement · Posts · Cite this entry
1,650subscribers
+121 since we began measuring on 7 August 2026
Risers and fallers across the register · movement among entries of 1,000–3,162.
Register entry
| Telegram ID | -1002097886698 |
|---|---|
| Type | Channel |
| Username | @cybernotif |
| Created | Between 1 November 2023 and 31 May 2024 — estimated from Telegram’s id allocation, not measured. How this range is calculated. |
| First recorded | 7 August 2026 |
| Last confirmed live | 18 September 2026 |
| Measurements held | 14 |
| Confirmed unchanged | 1 time, most recently 18 September 2026 |
| On Telegram | t.me/cybernotif |
Topic
Hacking & security — a classification, not a measurement. An on-box language model (Qwen3.6-35B-A3B-FP8, prompt version 1) read this channel’s own recent posts on 17 September 2026 and assigned it the closest of 31 fixed categories, at 99% confidence. This is a model’s judgement about what the channel is likely to be about, not a fact this register measured the way a subscriber count or a view count is measured — it can be revised on a later pass, and it carries no weight anywhere else on this page. How this classification works, and why it has no browse page of its own yet.
Growth
| Measured (UTC) | Subscribers | Change |
|---|---|---|
| 18 Sept 2026, 01:58 | 1,650 | +8 |
| 14 Sept 2026, 05:16 | 1,642 | +11 |
| 10 Sept 2026, 22:36 | 1,631 | +16 |
| 5 Sept 2026, 18:17 | 1,615 | +1 |
| 2 Sept 2026, 01:07 | 1,614 | +5 |
| 30 Aug 2026, 06:28 | 1,609 | +7 |
| 27 Aug 2026, 00:56 | 1,602 | +10 |
| 24 Aug 2026, 00:54 | 1,592 | +13 |
| 20 Aug 2026, 10:32 | 1,579 | +20 |
| 17 Aug 2026, 15:26 | 1,559 | +10 |
| 14 Aug 2026, 09:48 | 1,549 | +9 |
| 11 Aug 2026, 06:12 | 1,540 | +11 |
| 7 Aug 2026, 21:33 | 1,529 | no change |
| 7 Aug 2026, 19:16 | 1,529 | first reading |
Engagement
20 posts held, back to 7 August 2026 — the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 1 page of Telegram’s post history, 20 posts per page.
Nothing published in the last 30 days. ERR and ER are rolling 30-day measures, so there is nothing to compute — we hold 20 posts for this entry, the most recent from 7 August 2026. An engagement rate over an empty window would be a number about nothing.
Recent posts
BlackNevas ransomware claims OTEGROUP, a major Oman-based business group with automotive, electronics, appliances, and industrial polymer operations, was targeted in an alleged attack. #Oman #OTEGROUP #Ransomware ➡️ https://www.hendryadrian.com/ransom-otegroup-aug-2026/
Space bears reportedly targeted Hitech Distribuzione Informatica S.r.l. (HTDI), a Rome-based Italian IT solutions provider, in a ransomware claim affecting corporate infrastructure services. #Italy #HTDI #Ransomware ➡️ https://www.hendryadrian.com/ransom-hitech-distribuzione-informatica-s-r-l-htdi-aug-2026/
New 1Password research found ChatGPT 5.5 and Claude Opus 4.8 fully patched less than half of six high-impact CVEs, sometimes fixing only part of the flaw or adding new bugs. Human review remains essential. #ChatGPT #ClaudeOpus #1Password ➡️ https://www.hendryadrian.com/more-than-half-of-ai-generated-patches-are-broken/
Phishing campaign impersonates trusted app updates, including Google Meet, Microsoft Store, Apple App Store, Zoom, and more, to deliver unauthorized ScreenConnect installs via reused infrastructure and cloud hosts. #ScreenConnect #Phishing ➡️ https://www.hendryadrian.com/beyond-fake-updates-from-application-store-themed-phishing-to-large-scale-distribution-of-screenconnect/
Levi Strauss says hackers used social engineering on three employees to steal corporate data from company computers. The breach was contained quickly, and no consumer data was impacted. #LeviStrauss #DataBreach #SEC ➡️ https://www.hendryadrian.com/levi-strauss-co-says-hackers-stole-corporate-data-in-cyberattack/
Frey Wille, the Austrian jewelry retailer, disclosed an August cyberattack that exposed customer contact, contract, communication, and billing data. Authorities and forensic experts are involved. #FreyWille #Austria #Phishing ➡️ https://www.hendryadrian.com/cyberattack-on-frey-wille-jewellery-retailer/
OpenAI shut down Cambodia scam accounts, Amgen confirmed cloud data theft, and Apple moved to curb AI-generated bug bounty noise amid attacks on ports, Wall Street, and supply chains. #OpenAI #Cambodia #Apple ➡️ https://www.hendryadrian.com/in-other-news-ai-slop-limits-apple-bounties-north-carolina-port-attacks-hackers-target-wall-street/
WordPress 7.0.3 patches CVE-2026-64638, a pre-auth reflected XSS in the login screen that can chain to PHP code execution under certain conditions. #WordPress #CVE202664638 #XSS2Shell ➡️ https://www.hendryadrian.com/new-wordpress-pre-auth-xss-could-lead-to-php-code-execution-patch-asap/
Open source is entering a tougher era: enterprises will rely on projects that prove they are maintained, reachable, and accountable, while vendor support layers and stewardship models reshape regulated use. #OpenSource #SupplyChain #OSSGovernance ➡️ https://www.hendryadrian.com/growing-up-the-hard-way/
Zero-click abuse and prompt exposure are hitting AI browsers and assistants, while active exploits target Langflow, N-central, and Tomcat. Supply-chain risks also grow with router backdoors and macOS lures. #Claude #ChatGPTAtlas #Langflow ➡️ https://www.hendryadrian.com/cybersecurity-news-daily-recap-06-aug-2026/
Two H1 2026 attack chains abused trusted systems: hijacked mailboxes, browser and proxy tampering, clipboard theft, and blockchain-based C2 to steal banking sessions in Europe and crypto payments. #Europe #XWorm #RemcosRAT ➡️ https://www.hendryadrian.com/real-emails-hijacked-payments-two-h1-2026-attack-chains/
Showing the 12 most recent of 20 posts we hold for @cybernotif. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.
Cite this entry
A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 18 September 2026 — this entry's latest reading, not the date you are reading this.
“Cybersecurity News Everyday” (@cybernotif), 1,650 subscribers as measured 18 September 2026. Telegram Register, tgregister.com/channel/cybernotif.
Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.