Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 1,796articles · 365d
- 1+ day agolatest article
- Sep 14, 2025earliest in window
- 20%with images
- 353avg words
- security 1,624
- cybersecurity 1,613
- malware 1,071
- cyber security news 1,017
- vulnerability 772
- cyber security 752
- artificial intelligence 595
- technology 543
- ai 471
- network security 435
- computer security 431
- cybercrime 427
- vulnerabilities 371
- windows 332
- software 313
- data breach 291
- phishing 270
- linux 257
- microsoft 233
- cloud security 228
- Science & Technology 1,179
- Software 933
- Computers & Electronics 923
- Conflict, War & Peace 510
- News 430
- Software Dev. 377
- Crime & Law 360
- Internet & Telecom 255
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands
2+ week, 4+ day ago (708+ words) Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services…...
ThreatsDay: GhostJacking AI Attacks, EtherHiding ClickFix, Cursor CLI Flaw + 17 More Stories
4+ week, 2+ day ago (208+ words) Some weeks have one big security story. Others bring many smaller updates that are easy to miss but still matter. This week has plenty of them, covering cloud services, AI tools, malware, data breaches, scams, and new attack methods. The…...
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
1+ mon, 2+ day ago (695+ words) North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession,…...
Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackers
1+ mon, 4+ day ago (1050+ words) PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was enough to make the assistant gather internal data and send it out through a URL request, with no separate approval step. The…...
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
1+ mon, 1+ week ago (443+ words) One such service, Poison Claude, claims to offer access to Anthropic's large language models (LLMs), including Opus 4.8, Opus 4.7, Opus 4.6, and Sonnet 4.6. "The service plainly states on its website that: 'We add those accounts to our pool, your request is routed…...
Hackers Poison Adform Script to Swap Crypto Wallet Addresses Across Customer Sites
1+ mon, 1+ week ago (512+ words) Attackers modified a JavaScript file served by advertising technology company Adform, turning it into a browser-side tool that rewrites cryptocurrency wallet addresses. Adform detected the incident on July 27, 2026, removed the malicious code, notified affected clients, and reported it to authorities....
Amazon Links Debug and Chalk npm Hijack to North Korea’s Sapphire Sleet
1+ mon, 2+ week ago (870+ words) Amazon has tied the September 2025 hijack of the npm packages debug and chalk to North Korea. For ten months, the incident sat in the public record as crypto theft: a maintainer phished through a lookalike npm domain and a wallet-draining…...
OpenAI Agent Used Exposed Credentials Across Four Services During Hugging Face Breach
1+ mon, 2+ week ago (883+ words) OpenAI on Tuesday revealed the rogue artificial intelligence (AI) agent that escaped its sealed evaluation environment and broke into Hugging Face's production environment, and also hacked multiple third-party accounts and services as part of the attack. The latest disclosure shows…...
Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In
1+ mon, 2+ week ago (333+ words) JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution. The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises…...
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
1+ mon, 2+ week ago (829+ words) The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered…...