Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 174articles · 30d
- 16+ hour agolatest article
- Aug 15, 2026earliest in window
- 10%with images
- 353avg words
- security 162
- cybersecurity 142
- malware 108
- vulnerability 98
- cyber security news 88
- artificial intelligence 70
- cyber security 62
- cybercrime 59
- technology 58
- ai 52
- vulnerabilities 52
- cloud security 39
- windows 35
- network security 33
- remote code execution 33
- linux 30
- enterprise security 29
- microsoft 29
- infosec 28
- cisa 27
- Science & Technology 118
- Software 98
- Computers & Electronics 84
- Conflict, War & Peace 47
- News 37
- Crime & Law 35
- Software Dev. 30
- Internet & Telecom 29
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
16+ hour, 54+ min ago (734+ words) Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. Evidence indicates that the operators behind the campaign…...
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
2+ day, 11+ hour ago (461+ words) Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers…...
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
3+ day, 9+ hour ago (271+ words) A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An…...
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
3+ day, 16+ hour ago (471+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities…...
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
4+ day, 15+ hour ago (366+ words) A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build…...
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
4+ day, 19+ hour ago (887+ words) Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances…...
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
4+ day, 22+ hour ago (245+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in…...
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
5+ day, 12+ hour ago (636+ words) Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token…...
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
6+ day, 11+ hour ago (360+ words) The activity, which mainly singles out directors, vice presidents, and other executive staff, is being tracked by Arctic Wolf under the moniker PREY-0058, adding it shares significant tradecraft similarities with a data extortion group that Google-owned Mandiant calls UNC6671. It also…...
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
6+ day, 12+ hour ago (299+ words) Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that…...