Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 1,797articles · 365d
- 2+ hour agolatest article
- Sep 14, 2025earliest in window
- 20%with images
- 353avg words
- security 1,625
- cybersecurity 1,614
- malware 1,072
- cyber security news 1,018
- vulnerability 772
- cyber security 752
- artificial intelligence 596
- technology 543
- ai 471
- network security 435
- computer security 431
- cybercrime 428
- vulnerabilities 371
- windows 332
- software 313
- data breach 291
- phishing 270
- linux 257
- microsoft 235
- cloud security 229
- Science & Technology 1,179
- Software 933
- Computers & Electronics 923
- Conflict, War & Peace 511
- News 430
- Software Dev. 377
- Crime & Law 361
- Internet & Telecom 256
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
3+ day, 1+ hour ago (921+ words) A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That split hides the trojan from the banking app's own malware checks, Group-IB…...
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
3+ day, 19+ hour ago (594+ words) The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026. "Within days, several other espionage-motivated clusters began using BlueMoon,…...
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
3+ day, 22+ hour ago (883+ words) Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to…...
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
4+ day, 50+ min ago (366+ words) A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build…...
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
4+ day, 5+ hour ago (887+ words) Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances…...
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
4+ day, 22+ hour ago (530+ words) Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group…...
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
5+ day, 4+ hour ago (1052+ words) Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has…...
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
5+ day, 23+ hour ago (384+ words) According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form lure, to activate a four-stage VBScript chain that…...
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
6+ day, 1+ hour ago (838+ words) A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed…...
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
6+ day, 4+ hour ago (737+ words) Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix…...