Website profile

The Hacker News

The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.

  • 1,797articles · 365d
  • 1+ day agolatest article
  • Sep 13, 2025earliest in window
  • 20%with images
  • 353avg words
articles per day
Categories
  • Science & Technology 1,179
  • Software 933
  • Computers & Electronics 923
  • Conflict, War & Peace 511
  • News 431
  • Software Dev. 377
  • Crime & Law 361
  • Internet & Telecom 255

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

The Hacker News
thehackernews.com > 2026 > 09 > threatsday-200-android-flaws-browser.html

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

2+ day, 9+ hour ago   (271+ words) A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An…...

The Hacker News
thehackernews.com > 2026 > 09 > infostealer-logs-expose-replayable-ai.html

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

3+ day, 13+ hour ago   (883+ words) Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to…...

The Hacker News
thehackernews.com > 2026 > 09 > autonomous-ai-agents-compromise.html

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

4+ day, 13+ hour ago   (530+ words) Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group…...

The Hacker News
thehackernews.com > 2026 > 09 > bengalseo-poisons-bing-search-results.html

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

4+ day, 19+ hour ago   (1052+ words) Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has…...

thehackernews.com
thehackernews.com > 2026 > 09 > peep-turns-chrome-and-edge-into-post.html

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

5+ day, 9+ hour ago   (36+ words) PEEP uses Chrome and Edge as a post-compromise backdoor for credential theft and host command execution....

The Hacker News
thehackernews.com > 2026 > 09 > microsoft-365-attackers-use-help-desk.html

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

5+ day, 11+ hour ago   (360+ words) The activity, which mainly singles out directors, vice presidents, and other executive staff, is being tracked by Arctic Wolf under the moniker PREY-0058, adding it shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls UNC6671. It also…...

The Hacker News
thehackernews.com > 2026 > 09 > weekly-recap-chrome-0-day-router.html

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

5+ day, 13+ hour ago   (299+ words) Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that…...

thehackernews.com
thehackernews.com > 2026 > 09 > attackers-exploit-papercut-flaws-to.html

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

1+ week, 20+ hour ago   (246+ words) Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass…...

The Hacker News
thehackernews.com > 2026 > 09 > geonetwork-fixes-unauthenticated-rce.html

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

1+ week, 3+ day ago   (379+ words) Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the…...

Google News
thehackernews.com > 2026 > 09 > authorities-turn-salitys-p2p-network.html

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

1+ week, 3+ day ago   (937+ words) The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. "Cybercriminals, botnets, and malware are a clear and present danger to our nation's security…...