Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 175articles · 30d
- 5+ hour agolatest article
- Aug 14, 2026earliest in window
- 11%with images
- 353avg words
- security 163
- cybersecurity 143
- malware 109
- vulnerability 98
- cyber security news 89
- artificial intelligence 70
- cyber security 63
- cybercrime 60
- technology 59
- ai 52
- vulnerabilities 52
- cloud security 39
- windows 35
- network security 34
- remote code execution 33
- infosec 30
- linux 30
- enterprise security 29
- microsoft 29
- cisa 27
- Science & Technology 119
- Software 98
- Computers & Electronics 84
- Conflict, War & Peace 47
- News 37
- Crime & Law 36
- Internet & Telecom 30
- Software Dev. 30
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
5+ hour, 50+ min ago (734+ words) Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. Evidence indicates that the operators behind the campaign…...
Your Critical Vulnerabilities Might Not Be Your Biggest Risk
2+ day, 4+ hour ago (1309+ words) Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a…...
Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
1+ day, 23+ hour ago (461+ words) Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers…...
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
2+ day, 22+ hour ago (271+ words) A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An…...
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
3+ day, 1+ hour ago (467+ words) Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. "The same feature that shields developers from unfair criticism also strips users of the earliest warning…...
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
3+ day, 4+ hour ago (903+ words) Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not…...
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
3+ day, 4+ hour ago (772+ words) A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports…...
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
3+ day, 4+ hour ago (921+ words) A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That split hides the trojan from the banking app's own malware checks, Group-IB…...
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
3+ day, 5+ hour ago (471+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities…...
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key
3+ day, 8+ hour ago (1179+ words) Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications…...