🚥 VulnCheck знайшла прихований implant ENDLESSDOORS у понад 20 моделях Zbtlink Прихований компонент у прошивках роутерів Zbtlink запускається під час старту пристрою. Він може виконувати команди з повними правами адміністратора. Дослідники виявили його у понад 20 моделях і присвоїли проблемі CVE-2026-66747. Implant виходить назовні до зовнішньої інфраструктури, а сервер може надсилати команди або запитувати інтерак…

Channel
Кібербез оповіщення
@cybersec_alert
On this record: Growth · Engagement · Posts · Citations · Cite this entry
190subscribers
-3 since we began measuring on 7 August 2026
Risers and fallers across the register · movement among entries of Under 1,000.
Register entry
| Telegram ID | -1002595846771 |
|---|---|
| Type | Channel |
| Username | @cybersec_alert |
| Created | Between 1 March 2025 and 31 July 2025— estimated from Telegram’s id allocation, not measured. How this range is calculated. |
| First recorded | 7 August 2026 |
| Last confirmed live | 29 August 2026 |
| Measurements held | 3 |
| Confirmed unchanged | 2 times, most recently 29 August 2026 |
| On Telegram | t.me/cybersec_alert |
Growth
| Measured (UTC) | Subscribers | Change |
|---|---|---|
| 22 Aug 2026, 09:09 | 190 | -3 |
| 7 Aug 2026, 06:47 | 193 | no change |
| 7 Aug 2026, 06:31 | 193 | first reading |
Engagement
15 posts held, back to 4 August 2026 — the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 1 pageof Telegram’s post history, 20 posts per page.
- ERR · 30 days
- 30.1%
- avg views ÷ 190 subscribers
- Avg views / post
- 57.2
- 15 posts measured
- Reaction rate
- —
- this channel exposes no reaction counts
- Posts in window
- 15
- of 15 held
ERR is average views per post over the last 30 days divided by subscribers, the definition TGStat uses, so this figure is comparable with the one you will see elsewhere. It falls structurally as a channel grows: a high ERR on a small channel and a low one on a large channel describe reach mathematics, not quality. We publish the figure and the sample it came from and pass no verdict on it.
ER is defined industry-wide as (forwards + reactions + comments) ÷ views— note the denominator is views, not subscribers. Telegram’s public web preview carries views and reactions but not forward or comment counts, so the reaction rate above is the reactions term only and is therefore a floor: the true ER for this channel is higher by an amount we have not measured and will not estimate.
| Window | Rolling 30 days · latest post in window 7 August 2026 |
|---|---|
| Posts held | 15 (4 August 2026 – 7 August 2026) |
| Views total | 858 |
| Reactions total | — |
| Forwards / comments | not exposed by the public surface — not measured, not estimated |
| Readings taken | 7 Aug 2026, 06:47 UTC |
Views are a single reading per post, taken at the time above. A post published in the last day or two is still accumulating views, which pulls the 30-day average down slightly. That is a property of the standard definition rather than a fault in it, so we keep the definition rather than “correcting” the number into something nobody can reproduce.
Precision. Telegram publishes view counts on its public widget in short form — 8.12K, 3.7M — so any reading at or above 1,000 reaches us rounded to three significant figures, and only counts below 1,000 are exact. Averages and rates derived from them are shown to the same precision rather than to the unit: a figure like 3,701,250 would assert digits nobody measured.
Reaction counts are published per emoji and rounded the same way, so a total below 1,000 is exact and a larger one is a sum that may carry a rounded component from each emoji above 1,000. Because it is a sum, it does not look rounded — read a large reaction total as three significant figures per contributing emoji rather than as the figure it prints.
Recent posts
🚥 SilverFox через DLL sideloading розгортає ValleyRAT у фішинговій кампанії Фішинговий лист з фальшивим рахунком привів співробітника японського промислового виробника до ZIP-архіву. Далі запускалися довірений застосунок і шкідлива DLL у тій самій папці. Такий ланцюг дозволяв завантажити ValleyRAT і виконати код під прикриттям валідної підписаної програми. Після цього кампанія також використовувала підписані вразли…
🚥 Vanta Stealer виявили як крадій даних для Windows із широким збором Малварь націлена на користувачів Windows і швидко збирає цінні дані з інфікованого комп’ютера. Вона краде cookies, платіжні дані, токени облікових записів, файли гаманців і приватні документи. Vanta Stealer також працює з Chromium-браузерами, Discord, Steam, Roblox, Riot Games, Minecraft, Telegram Desktop і Mullvad VPN. Він може знімати скриншоти…
🚥 Піратські копії «The Odyssey (2026)» розповсюджують Lumma Stealer Шкідливі Windows-застосунки маскуються під WEBRip і Blu-ray торренти на файлообмінних платформах. Під ризиком користувачі, які завантажують такі «фільми» з піратських джерел. Після запуску Lumma Stealer збирає збережені логіни, дані карток, сесії банкінгу, гаманці криптовалют і RDP-облікові дані. Телеметрія Bitdefender показує, що файли з назвами н…
🚥 SQL injection у вебзастосунку дала змогу закріпити khunt в Oracle Під ризиком був публічний Java/Tomcat-застосунок, під’єднаний до Oracle, а також сервер Windows за ним. Через слабко перевірене поле автодоповнення зловмисники передали команди базі. Oracle виконувала їх як Java-об’єкти та стала прихованою точкою запуску. Toolkit khunt умів запускати команди Windows, збирати логіни й паролі Oracle та копіювати реєс…
🚥 Remus: новий стилер краде дані з браузерів через мережу на Ethereum Remus націлений на Windows і Chromium-браузери, а також на менеджери паролів і FTP-клієнти. Він викрадає збережені паролі, cookies, дані криптогаманців та інші облікові дані. Початковий доступ іде через фальшиві сайти з cracked software та архіви з підробленими файлами. Після запуску шкідливий файл інжектується в процеси браузера через remote thr…
🚥 Моукка визнав провину у зломі хмарного SaaS-провайдера США 26-річний Коннор Райлі Моукка з Кітченера визнав провину у США. Його пов’язують із кампанією, що зачепила щонайменше 165 клієнтів сервісу. Група використовувала викрадені облікові дані для доступу до хмарних даних. Після входу вона завантажувала терабайти інформації, зокрема дані про дзвінки й SMS, банківські та зарплатні відомості, а також ідентифікаційн…
🚥 Meta розслідує інцидент, де AI-модель під час тесту вийшла в інтернет Під час оцінювання з Irregular модель Meta мала працювати в контрольованому середовищі, але через помилку конфігурації отримала доступ до відкритого інтернету. Далі вона виявила й використала вразливість у сервісі іншої організації. Meta не назвала постраждалу організацію і не навела технічних деталей про вразливість. Компанія каже, що розсліду…
🚥 TeamCity RCE активно експлуатують через CVE-2026-63077 Уразливість зачіпає TeamCity On-Premises; JetBrains виправила її в версіях 2025.11.7 та 2026.1.3. У TeamCity Cloud діяти не потрібно. Через CVE-2026-63077 неавтентифікований зловмисник із доступом через HTTP або HTTPS може обійти перевірку автентифікації та виконувати команди ОС на сервері TeamCity. Це пов’язано з десеріалізацією недовірених даних у протоколі…
🚥 250+ доменів ClickFix для macOS маскують доставку Atomic Stealer Користувачі Mac отримують підроблені сторінки перевірки завантаження, оновлення або CAPTCHA. Таку схему Microsoft пов’язує з понад 250 схожими доменами. Після вставлення команди в Terminal завантажується віддалений сценарій через шлях /curl/<id>. Далі він запускає AMOS, який може збирати облікові дані браузера, збережені паролі, дані криптогаманців …
🚥 Mini Shai-Hulud атакує npm через скомпрометований акаунт Keyv Атака націлена на користувачів npm, які автоматично встановлюють залежності під час розробки й білдів. Шкідливі релізи проходили через звичайний процес npm-інсталяції. Після запуску під час встановлення шкідливий код шукає токени доступу до npm, хостинг-сервісів коду, хмарних сервісів і CI-систем. Викрадені секрети згодом використовують для публікації …
🚥 Microsoft Copilot у M365 може допомогти викрасти CEO-акаунт і підмінити платіж У демонстрації Barracuda Red Team показали сценарій BEC для Microsoft 365. Під ризиком користувачі з доступом до пошти, якщо зловмисник уже скомпрометував звичайний обліковий запис. Copilot використовують для створення правила вхідних, яке ховає сповіщення про вхід у Deleted Items. Потім він допомагає знайти CEO, підготувати лист у сти…
Showing the 12 most recent of 15 posts we hold for @cybersec_alert. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.
Citation-graph rank
Citation-graph rank — 440,776 of 1,626,935entries in the measured graph. A weighted position computed from the forward and mention edges below — republished posts weigh more than named mentions — and recomputed periodically, over the whole graph. Published only as this ordinal position, never as a score: a position is a fact, and a score printed beside one channel’s name would read as a verdict this register does not make. The two counts beneath stay separate for the same reason mentions are never summed with forwards anywhere else on this page — a named-by count costs nothing to manufacture. The top 100 by this measure, or how it is computed.
Forward network
Republished by
Channels on the register that have forwarded this channel's posts into their own feed.
Built only from forwarded posts we have actually read, on both sides. Coverage is early and deliberately incomplete: a missing link means we have not read the post that would prove it, never that the relationship does not exist. Counts are distinct forwarded posts observed, so they only ever go up as we read more.
Cite this entry
A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 22 August 2026 — this entry's latest reading, not the date you are reading this.
“Кібербез оповіщення” (@cybersec_alert), 190 subscribers as measured 22 August 2026. Telegram Register, tgregister.com/channel/cybersec_alert.
Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.