North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts needed to build AI into its malware.South Korean security firm Genians says it uncovered the via The Hacker News https…

Channel
Newshell Exploit Alert
@newshell
On this record: Growth · Engagement · Posts · Cite this entry
44subscribers
+1 since we began measuring on 7 August 2026
Risers and fallers across the register · movement among entries of Under 1,000.
Register entry
| Telegram ID | -1001099564306 |
|---|---|
| Type | Channel |
| Username | @newshell |
| Created | Between 1 October 2016 and 30 November 2017— estimated from Telegram’s id allocation, not measured. How this range is calculated. |
| First recorded | 10 August 2026 |
| Last confirmed live | 22 August 2026 |
| Measurements held | 4 |
| Confirmed unchanged | 1 time, most recently 22 August 2026 |
| On Telegram | t.me/newshell |
Growth
| Measured (UTC) | Subscribers | Change |
|---|---|---|
| 22 Aug 2026, 00:17 | 44 | -1 |
| 15 Aug 2026, 11:53 | 45 | +2 |
| 10 Aug 2026, 16:31 | 43 | no change |
| 7 Aug 2026, 14:07 | 43 | first reading |
Engagement
20 posts held, back to 7 August 2026 — the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 1 pageof Telegram’s post history, 20 posts per page.
- ERR · 30 days
- 5.91%
- avg views ÷ 44 subscribers
- Avg views / post
- 2.6
- 20 posts measured
- Reaction rate
- —
- this channel exposes no reaction counts
- Posts in window
- 20
- of 20 held
ERR is average views per post over the last 30 days divided by subscribers, the definition TGStat uses, so this figure is comparable with the one you will see elsewhere. It falls structurally as a channel grows: a high ERR on a small channel and a low one on a large channel describe reach mathematics, not quality. We publish the figure and the sample it came from and pass no verdict on it.
ER is defined industry-wide as (forwards + reactions + comments) ÷ views— note the denominator is views, not subscribers. Telegram’s public web preview carries views and reactions but not forward or comment counts, so the reaction rate above is the reactions term only and is therefore a floor: the true ER for this channel is higher by an amount we have not measured and will not estimate.
| Window | Rolling 30 days · latest post in window 10 August 2026 |
|---|---|
| Posts held | 20 (7 August 2026 – 10 August 2026) |
| Views total | 52 |
| Reactions total | — |
| Forwards / comments | not exposed by the public surface — not measured, not estimated |
| Readings taken | 10 Aug 2026, 16:31 UTC |
Views are a single reading per post, taken at the time above. A post published in the last day or two is still accumulating views, which pulls the 30-day average down slightly. That is a property of the standard definition rather than a fault in it, so we keep the definition rather than “correcting” the number into something nobody can reproduce.
Precision. Telegram publishes view counts on its public widget in short form — 8.12K, 3.7M — so any reading at or above 1,000 reaches us rounded to three significant figures, and only counts below 1,000 are exact. Averages and rates derived from them are shown to the same precision rather than to the unit: a figure like 3,701,250 would assert digits nobody measured.
Reaction counts are published per emoji and rounded the same way, so a total below 1,000 is exact and a larger one is a sum that may carry a rounded component from each emoji above 1,000. Because it is a sum, it does not look rounded — read a large reaction total as three significant figures per contributing emoji rather than as the figure it prints.
Recent posts
Disponibile un Proof of Concept (PoC) per la vulnerabilità identificata dalla CVE-2026-64638, già sanata dal vendor, che interessa il noto CMS WordPress. via RSS Csirt Italia https://ift.tt/dtoaFig
Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on.Passkeys are designed to replace reusable passwords and resist phishing. The attacks instead reused signed authentication material that Windows had exposed, abused a cloud-synced passkey system from malware already on the victim's machine, and used a via The Hacker News https://ift…
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed.When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is keeping security from becoming the bottleneck, or worse, losing control of what gets shipped. via The Hacker News https:…
The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, IT, and software development sectors.Russian cybersecurity vendor Kaspersky said it detected the attacks in July 2026.The activity involves exploiting a vulnerability chain via The Hacker News https:/…
Proseguono le campagne malware che sfruttano tecniche di ingegneria sociale per indurre gli utenti ad eseguire codice malevolo sui propri sistemi tramite la funzione “incolla” via RSS Csirt Italia https://ift.tt/U7rfMbp
Aggiornamenti di sicurezza Cisco sanano 7 vulnerabilità con gravità "alta" presenti in ClamAV, software open source per l'analisi antivirus. Tra queste si evidenziano le CVE-2026-20337 e CVE-2026-20338 per le quali il vendor conferma la presenza di Proof of Concept (PoC) disponibili in rete. via RSS Csirt Italia https://ift.tt/8lZp7cH
Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer.The names of the extensions are below - helper-beeps.solidity-pro web3devtoolsx.solidity-proAlthough neither of the extensions is now available on Open VSX, the GitHub repository via The Hacker News https://if…
OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity.In response to the discovery, the AI upstart said it's implementing security controls for higher-capability models and associated activities, such as isolated via The Hacker News ht…
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License. via SANS Internet Storm Center, InfoCON: green https://ift.tt/1zBVND8
Attacker-controlled instructions can make Atlassian's Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed.PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was via The Hacker News ht…
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email.PortSwigger researcher Gareth via The Hacker News https://…
Showing the 12 most recent of 20 posts we hold for @newshell. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.
Cite this entry
A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 22 August 2026 — this entry's latest reading, not the date you are reading this.
“Newshell Exploit Alert” (@newshell), 44 subscribers as measured 22 August 2026. Telegram Register, tgregister.com/channel/newshell.
Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.