Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 1,797articles · 365d
- 17+ hour agolatest article
- Sep 14, 2025earliest in window
- 20%with images
- 353avg words
- security 1,625
- cybersecurity 1,614
- malware 1,072
- cyber security news 1,018
- vulnerability 772
- cyber security 752
- artificial intelligence 596
- technology 543
- ai 471
- network security 435
- computer security 431
- cybercrime 428
- vulnerabilities 371
- windows 332
- software 313
- data breach 291
- phishing 270
- linux 257
- microsoft 235
- cloud security 229
- Science & Technology 1,179
- Software 933
- Computers & Electronics 923
- Conflict, War & Peace 511
- News 430
- Software Dev. 377
- Crime & Law 361
- Internet & Telecom 256
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
4+ day, 12+ hour ago (883+ words) Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to…...
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
5+ day, 13+ hour ago (530+ words) Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group…...
What It Took to Reach 1 Billion Build Manifests
5+ day, 15+ hour ago (361+ words) Let’s be precise about what we're counting. How do we define a “build manifest”? Think of it as every time the Chainguard Factory produces a new, verifiable artifact: a fresh image for go:1.26.5, a rebuild of nginx triggered by a…...
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
6+ day, 13+ hour ago (299+ words) Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that…...
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
1+ week, 1+ day ago (246+ words) Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass…...
Malicious.git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
1+ week, 4+ day ago (983+ words) Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command…...
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
1+ week, 5+ day ago (767+ words) The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access…...
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
1+ week, 5+ day ago (594+ words) METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external…...
Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance
1+ week, 6+ day ago (1432+ words) Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger…...
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning
2+ week, 6+ day ago (428+ words) Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that…...