Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 172articles · 30d
- 1+ day agolatest article
- Aug 17, 2026earliest in window
- 10%with images
- 353avg words
- security 160
- cybersecurity 140
- malware 106
- vulnerability 96
- cyber security news 87
- artificial intelligence 70
- cyber security 61
- cybercrime 58
- technology 58
- ai 52
- vulnerabilities 51
- cloud security 37
- windows 34
- network security 33
- remote code execution 32
- linux 30
- enterprise security 28
- infosec 28
- microsoft 28
- cisa 25
- Science & Technology 116
- Software 96
- Computers & Electronics 83
- Conflict, War & Peace 47
- News 36
- Crime & Law 35
- Software Dev. 30
- Internet & Telecom 29
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P
3+ week, 4+ day ago (663+ words) Users of affected Dahua products are advised to install the corresponding fix software or newer firmware...attributed the 14,530-plus total to three attack paths - The two 2021 flaws are authentication-bypass vulnerabilities...National Vulnerability Database (NVD) currently assigns each a CVSS score…...
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
3+ week, 6+ day ago (624+ words) The privilege-escalation vulnerability is classified as CWE-1189, Improper Isolation of Shared Resources...Running the complete chain requires a modem-level foothold from the March 2026 RCE vulnerability first...The researchers built their proof-of-concept environment using an open-source 4G core network, a software-defined...
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
1+ week, 5+ day ago (466+ words) Mandiant teams described the threat actor as "specializing in manipulating payment systems and banking software...Alternatively, the group has targeted vulnerable JBoss AS servers to deploy web shells, which are then...actor's primary targets are organizations with permission to conduct…...
StopAndProtect Uses Nearly 2,000 Hacked WordPress Sites to Spread Malware and Steal Data
3+ week, 4+ day ago (823+ words) "The operation doesn't rely on a single piece of malware, but on a whole toolkit of criminal software...for instance, runs a WordPress version from 2021, making it susceptible to roughly 40 different vulnerabilities...
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
1+ week, 1+ day ago (473+ words) Holborn said the software supply chain attack highlights the need for organizations to have complete..."The Trezor breach was the result of a supply chain attack beginning with a zero-day vulnerability,"...
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
5+ day, 21+ hour ago (530+ words) Google noted that the integration of AI-assisted coding tools has not only accelerated software development...The integration of AI is said to have allowed the system to autonomously manage the vulnerability scanning...
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another
1+ week, 5+ day ago (827+ words) to enable deep lateral movement in operational technology (OT) networks, exploiting multiple vulnerabilities...Manual review "suggested that this may be a separate, previously unidentified, vulnerability," Forescout...
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
1+ week, 6+ day ago (594+ words) However, the "vibe-coded app" suffered from a "fail-open vulnerability" that silently disabled authentication...
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
5+ day, 20+ hour ago (636+ words) SideSwap said a bug in Elements had created the L-BTC used in that withdrawal, the software Liquid runs...
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
1+ week, 6+ day ago (1263+ words) Verizon’s most recent Data Breach Investigations Report makes the exploitation of vulnerabilities “the...