AI Token Jacking: Stolen API Keys Fueled Nearly $1M Bills Unit 42 says criminals are feeding stolen AI API keys into gray-market proxy services within minutes of obtaining them. In one incident-response case, the unauthorized traffic generated nearly $1 million in charges before the victim contained it. A sudden usage spike is therefore an incident to stop immediately, not a billing problem to investigate… https://…

Channel
Latest Cyber-Attack News
@topcybersecurity
On this record: Topic · Growth · Engagement · Posts · Telegram's recommendations · Cite this entry
2,941subscribers
+45 since we began measuring on 7 August 2026
Risers and fallers across the register · movement among entries of 1,000–3,162.
Register entry
| Telegram ID | -1001749533937 |
|---|---|
| Type | Channel |
| Username | @topcybersecurity |
| Created | Between 1 December 2021 and 30 April 2023 — estimated from Telegram’s id allocation, not measured. How this range is calculated. |
| First recorded | 7 August 2026 |
| Last confirmed live | 16 September 2026 |
| Measurements held | 12 |
| Confirmed unchanged | 1 time, most recently 16 September 2026 |
| On Telegram | t.me/topcybersecurity |
Topic
Hacking & security — a classification, not a measurement. An on-box language model (Qwen3.6-35B-A3B-FP8, prompt version 1) read this channel’s own recent posts on 15 September 2026 and assigned it the closest of 31 fixed categories, at 86% confidence. This is a model’s judgement about what the channel is likely to be about, not a fact this register measured the way a subscriber count or a view count is measured — it can be revised on a later pass, and it carries no weight anywhere else on this page. How this classification works, and why it has no browse page of its own yet.
Growth
| Measured (UTC) | Subscribers | Change |
|---|---|---|
| 16 Sept 2026, 08:59 | 2,941 | +11 |
| 12 Sept 2026, 04:16 | 2,930 | +15 |
| 7 Sept 2026, 20:20 | 2,915 | +3 |
| 2 Sept 2026, 21:04 | 2,912 | +3 |
| 30 Aug 2026, 10:34 | 2,909 | +6 |
| 27 Aug 2026, 20:45 | 2,903 | +3 |
| 24 Aug 2026, 17:17 | 2,900 | +9 |
| 14 Aug 2026, 21:48 | 2,891 | +4 |
| 11 Aug 2026, 07:46 | 2,887 | -5 |
| 7 Aug 2026, 23:01 | 2,892 | -4 |
| 7 Aug 2026, 13:31 | 2,896 | no change |
| 7 Aug 2026, 12:29 | 2,896 | first reading |
Engagement
20 posts held, back to 29 July 2026 — the reader has not yet reached the start of this channel’s public history, so older posts may sit further back, unread. Read across 1 page of Telegram’s post history, 20 posts per page.
Nothing published in the last 30 days. ERR and ER are rolling 30-day measures, so there is nothing to compute — we hold 20 posts for this entry, the most recent from 6 August 2026. An engagement rate over an empty window would be a number about nothing.
Recent posts
ENDLESSDOORS Backdoor in Zbtlink Routers: 20 Models to Replace VulnCheck has found a root-control implant, named ENDLESSDOORS and tracked as CVE-2026-66747, inside firmware for 20 tested Zbtlink router models also sold under the Wiflyer name. The component starts at boot, calls an external command server from inside the network, and can accept shell commands as root. There is no… https://blog.gridinsoft.com/endless…
QuickFox FDMTP Backdoor: Check the Trojanized Windows Installer QuickFox users should update the Windows app to a clean current build and check for FDMTP backdoor artifacts if they installed or updated QuickFox between mid-2025 and August 2026. Fortinet says a trojanized QuickFox Windows installer used a modified Electron HTML file to download JavaScript from a fake QuickFox-looking domain, profile selected Windows …
Leaked n8n API Tokens Exposed 321 Live Instances GitGuardian found 321 reachable n8n instances still accepting API tokens exposed in public GitHub commits. The accepted keys could reveal workflows, executions, variables, data tables, and information about stored credentials. This was not a software exploit: a valid leaked key was enough to cross the API boundary. The researchers identified 4,576 unique n8n API… ht…
Keyv npm Worm Poisoned 444 Packages: Check Before Rotating Tokens An active npm supply-chain worm that surfaced through keyv and cacheable poisoned hundreds of package names on August 4, 2026. SafeDep recorded 2,234 malicious versions across 444 packages between 09:35 and 13:18 UTC, while Socket and Aikido independently tracked the initial Keyv-family compromise [1][2][3]. If a developer machine or CI… https://blo…
Pass-ta-key Attack Lets Malware Hijack Google Passkeys Palo Alto Networks Unit 42 has demonstrated three ways that malware already running on a Windows computer can abuse Google Password Manager’s synced passkey workflow. In the strongest scenario, the malware can recover the secret that protects synchronized passkeys and use them from the attacker’s own system. The research does not break passkey cryptography… htt…
N-central CVE-2026-18577: Patch and Hunt for Cloudflared N-able has released N-central build 2026.3.1.7 after attackers used an authentication bypass to obtain remote administrative access and reach systems managed through compromised servers. The important correction is that simply upgrading to N-central 2026.3 is not enough: CVE-2026-18577 covers builds before the emergency hotfix, including 2026.3.0. Organization…
Finance Department Secure Document Email Virus: ScreenConnect ZIP Check Quick answer: treat the Finance Department Secure Document email as malicious if it sends you to a fake document portal and asks you to download Adobe_Acrobat_Reader_en_Install.zip. Public reports describe that ZIP as a delivery path for a trojanized ScreenConnect remote-access client. If you only saw the email, report and… https://trojan-kille…
Arch Freezes AUR Pushes After Malware Wave: Check Your System Arch Linux temporarily disabled all pushes to the Arch User Repository (AUR) on August 1 after first blocking package adoption during a new wave of malicious takeovers. The confirmed current case starts with openconnect-sso, whose poisoned build path delivered a Linux loader followed by an infostealer, remote-access trojan, and SSH worm. AUR… https://blo…
Rails CVE-2026-66066: Patch Active Storage and Rotate Secrets Ruby on Rails has patched CVE-2026-66066, a critical Active Storage flaw that can let an unauthenticated attacker read files available to the application process and use exposed secrets for remote code execution or lateral movement. An app is in the confirmed risk path when it uses libvips for Active Storage image processing and accepts… https://blog.gri…
Coldcard Seed Flaw: Update Firmware and Move Funds Coinkite has fixed a Coldcard seed-generation flaw across Mk3, Mk4, Mk5, and Q release tracks, but installing the new firmware does not repair a seed that was already created on an affected version. Coldcard owners should first identify the model, firmware track, and how the seed was generated. If the affected seed did not… https://blog.gridinsoft.com/coldcard-seed…
Adform Script Swapped Crypto Wallet Addresses on Websites A compromised Adform tracking script could replace Bitcoin, Ethereum, and Tron wallet addresses while a website page was open. Adform says it detected and removed the malicious code on July 27, 2026. The company found no evidence that it installed software or persisted after the page closed. Anyone who used cryptocurrency on an affected… https://blog.gridins…
Showing the 12 most recent of 20 posts we hold for @topcybersecurity. View and reaction counts are the latest single reading for each post, not a live figure, and a recent post is still accumulating both. A view count marked ≈ was rounded by Telegram before we ever saw it — t.me prints views in full below 1,000 and to three significant figures above, so ≈1,200,000 means somewhere between 1,150,000 and 1,249,999. Unmarked counts are exact. Text is reproduced from the public post preview and truncated for length.
Appears in Telegram’s recommendations for other channels
The reverse of the list above, and a different kind of signal. This does not require this channel to have ever been asked about directly — each row below is a channel we DID ask Telegram about, whose Telegram-generated list happened to include this one. A channel can appear here with an empty list above it, because being named by someone else’s query is independent of having been queried itself.
@Marudhara_Academy · 66,793
Telegram ranks this channel #60 of 64 here — alongside 63 others — read 21 August 2026
@MPSCEnglish · 54,418
Telegram ranks this channel #61 of 76 here — alongside 75 others — read 23 August 2026
This channel appears in 2 seed channels' Telegram-generated recommendation lists in total. Each is Telegram’s list for THAT channel, not this one — see how this is measured.
Cite this entry
A live page changes as we take new readings, so a citation should name the measurement it is based on, not just the URL. The line below cites the subscriber count as measured 16 September 2026 — this entry's latest reading, not the date you are reading this.
“Latest Cyber-Attack News” (@topcybersecurity), 2,941 subscribers as measured 16 September 2026. Telegram Register, tgregister.com/channel/topcybersecurity.
Full measurement history, CC BY 4.0. Every reading this register holds for this entry, not just the latest one, as a dated, downloadable record: CSV · JSON. Free to use with attribution to tgregister.com. Each file carries its own generation timestamp, which is the figure to cite for exactly when the data was retrieved.