Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 172articles · 30d
- 1+ day agolatest article
- Aug 17, 2026earliest in window
- 10%with images
- 353avg words
- security 160
- cybersecurity 140
- malware 106
- vulnerability 96
- cyber security news 87
- artificial intelligence 70
- cyber security 61
- cybercrime 58
- technology 58
- ai 52
- vulnerabilities 51
- cloud security 37
- windows 34
- network security 33
- remote code execution 32
- linux 30
- enterprise security 28
- infosec 28
- microsoft 28
- cisa 25
- Science & Technology 116
- Software 96
- Computers & Electronics 83
- Conflict, War & Peace 47
- News 36
- Crime & Law 35
- Software Dev. 30
- Internet & Telecom 29
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
1+ day, 4+ hour ago (734+ words) Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. Evidence indicates that the operators behind the campaign…...
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
4+ day, 23+ hour ago (883+ words) Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to…...
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
5+ day, 22+ hour ago (686+ words) A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. Slim Spider has been observed orchestrating…...
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
6+ day, 5+ hour ago (1052+ words) Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has…...
Malicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting Pages
1+ week, 5+ day ago (693+ words) A Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting online gambling and sports…...
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
1+ week, 5+ day ago (827+ words) Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a…...
Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
1+ week, 5+ day ago (937+ words) The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. "Cybercriminals, botnets, and malware are a clear and present danger to our nation's security…...
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
1+ week, 5+ day ago (466+ words) Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating payment systems…...
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
1+ week, 6+ day ago (594+ words) METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external…...
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
1+ week, 6+ day ago (1263+ words) The most common way into a company last year was to ask. What happens next is just as ordinary. When Bitdefender analyzed 700,000 security incidents, 84% of the high-severity ones involved binaries that were already on the machine - the same administrative tools…...