Website profile

The Hacker News

The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.

  • 1,797articles · 365d
  • 17+ hour agolatest article
  • Sep 14, 2025earliest in window
  • 20%with images
  • 353avg words
articles per day
Categories
  • Science & Technology 1,179
  • Software 933
  • Computers & Electronics 923
  • Conflict, War & Peace 511
  • News 430
  • Software Dev. 377
  • Crime & Law 361
  • Internet & Telecom 256

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

The Hacker News
thehackernews.com > 2026 > 09 > attackers-use-passkey-phishing-to.html

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

17+ hour, 6+ min ago   (734+ words) Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. Evidence indicates that the operators behind the campaign…...

The Hacker News
thehackernews.com > 2026 > 09 > google-play-early-access-abused-to-push.html

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

3+ day, 12+ hour ago   (467+ words) Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. "The same feature that shields developers from unfair criticism also strips users of the earliest warning…...

The Hacker News
thehackernews.com > 2026 > 09 > infostealer-logs-expose-replayable-ai.html

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

4+ day, 12+ hour ago   (883+ words) Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to…...

The Hacker News
thehackernews.com > 2026 > 09 > webinar-learn-how-to-answer-are-we.html

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

4+ day, 15+ hour ago   (366+ words) A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build…...

The Hacker News
thehackernews.com > 2026 > 09 > chrome-v8-zero-day-exploited-in-wild.html

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

4+ day, 17+ hour ago   (321+ words) Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's…...

The Hacker News
thehackernews.com > 2026 > 09 > n-able-n-central-pre-auth-rce-flaw.html

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

4+ day, 22+ hour ago   (245+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in…...

The Hacker News
thehackernews.com > 2026 > 09 > wechat-zero-click-worm-took-over.html

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

5+ day, 15+ hour ago   (733+ words) Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their…...

thehackernews.com
thehackernews.com > 2026 > 09 > peep-turns-chrome-and-edge-into-post.html

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

6+ day, 8+ hour ago   (36+ words) PEEP uses Chrome and Edge as a post-compromise backdoor for credential theft and host command execution....

thehackernews.com
thehackernews.com > 2026 > 09 > attackers-exploit-papercut-flaws-to.html

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

1+ week, 1+ day ago   (246+ words) Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass…...

thehackernews.com
thehackernews.com > 2026 > 09 > gpt-6-astra-scores-100-on-exploitbench.html

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

1+ week, 2+ day ago   (546+ words) OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its…...