Website profile

The Hacker News

The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.

  • 172articles · 30d
  • 1+ day agolatest article
  • Aug 17, 2026earliest in window
  • 10%with images
  • 353avg words
articles per day
Categories
  • Science & Technology 116
  • Software 96
  • Computers & Electronics 83
  • Conflict, War & Peace 47
  • News 36
  • Crime & Law 35
  • Software Dev. 30
  • Internet & Telecom 29

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News


thehackernews.com > 2026 > 09 > attackers-use-passkey-phishing-to.html

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

1+ day, 4+ hour ago   (734+ words) Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. Evidence indicates that the operators behind the campaign…...


thehackernews.com > 2026 > 09 > infostealer-logs-expose-replayable-ai.html

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

4+ day, 23+ hour ago   (883+ words) Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to…...


thehackernews.com > 2026 > 09 > slim-spider-steals-crypto-custody.html

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

5+ day, 22+ hour ago   (686+ words) A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. Slim Spider has been observed orchestrating…...


thehackernews.com > 2026 > 09 > bengalseo-poisons-bing-search-results.html

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

6+ day, 5+ hour ago   (1052+ words) Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has…...


thehackernews.com > 2026 > 09 > malicious-apache-modules-hijack.html

Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages

1+ week, 5+ day ago   (693+ words) A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports…...


thehackernews.com > 2026 > 09 > researchers-use-claude-to-port-pre-auth.html

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

1+ week, 5+ day ago   (827+ words) Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a…...


thehackernews.com > 2026 > 09 > authorities-turn-salitys-p2p-network.html

Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads

1+ week, 5+ day ago   (937+ words) The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. "Cybercriminals, botnets, and malware are a clear and present danger to our nation's security…...


thehackernews.com > 2026 > 09 > breeze-comet-executes-hundreds-of.html

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

1+ week, 5+ day ago   (466+ words) Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating payment systems…...


thehackernews.com > 2026 > 09 > attackers-steal-metr-api-key-and.html

Attackers Steal METR API Key and Consume AI Credits Worth About $600,000

1+ week, 6+ day ago   (594+ words) METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external…...


thehackernews.com > 2026 > 09 > threat-actors-dont-want-better-attacks.html

Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones

1+ week, 6+ day ago   (1263+ words) The most common way into a company last year was to ask. What happens next is just as ordinary. When Bitdefender analyzed 700,000 security incidents, 84% of the high-severity ones involved binaries that were already on the machine - the same administrative tools…...