Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 1,796articles · 365d
- 1+ day agolatest article
- Sep 14, 2025earliest in window
- 20%with images
- 353avg words
- security 1,624
- cybersecurity 1,613
- malware 1,071
- cyber security news 1,017
- vulnerability 772
- cyber security 752
- artificial intelligence 595
- technology 543
- ai 471
- network security 435
- computer security 431
- cybercrime 427
- vulnerabilities 371
- windows 332
- software 313
- data breach 291
- phishing 270
- linux 257
- microsoft 233
- cloud security 228
- Science & Technology 1,179
- Software 933
- Computers & Electronics 923
- Conflict, War & Peace 510
- News 430
- Software Dev. 377
- Crime & Law 360
- Internet & Telecom 255
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
2+ day, 12+ hour ago (271+ words) A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An…...
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
2+ day, 18+ hour ago (903+ words) Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not…...
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
2+ day, 19+ hour ago (471+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities…...
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
4+ day, 1+ hour ago (245+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in…...
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
4+ day, 18+ hour ago (1041+ words) A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who…...
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
5+ day, 15+ hour ago (299+ words) Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that…...
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
5+ day, 18+ hour ago (838+ words) A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed…...
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
5+ day, 21+ hour ago (737+ words) Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix…...
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
6+ day, 20+ hour ago (390+ words) Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least…...
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
1+ week, 14+ hour ago (339+ words) Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that…...