Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 1,797articles · 365d
- 16+ hour agolatest article
- Sep 14, 2025earliest in window
- 20%with images
- 353avg words
- security 1,625
- cybersecurity 1,614
- malware 1,072
- cyber security news 1,018
- vulnerability 772
- cyber security 752
- artificial intelligence 596
- technology 543
- ai 471
- network security 435
- computer security 431
- cybercrime 428
- vulnerabilities 371
- windows 332
- software 313
- data breach 291
- phishing 270
- linux 257
- microsoft 235
- cloud security 229
- Science & Technology 1,179
- Software 933
- Computers & Electronics 923
- Conflict, War & Peace 511
- News 430
- Software Dev. 377
- Crime & Law 361
- Internet & Telecom 256
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
16+ hour, 2+ min ago (734+ words) Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. Evidence indicates that the operators behind the campaign…...
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
4+ day, 11+ hour ago (883+ words) Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to…...
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
4+ day, 16+ hour ago (321+ words) Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's…...
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
4+ day, 21+ hour ago (245+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in…...
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
5+ day, 14+ hour ago (733+ words) Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their…...
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
6+ day, 7+ hour ago (36+ words) PEEP uses Chrome and Edge as a post-compromise backdoor for credential theft and host command execution....
Malicious.git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
1+ week, 4+ day ago (983+ words) Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command…...
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
1+ week, 4+ day ago (827+ words) Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a…...
Claude Opus 4.6 Bypasses Gym Booking Limit, Cancels Other Users' Reservations in Tests
2+ week, 4+ day ago (728+ words) Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by…...
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
2+ week, 6+ day ago (763+ words) Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China,…...