Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 1,797articles · 365d
- 1+ day agolatest article
- Sep 13, 2025earliest in window
- 20%with images
- 353avg words
- security 1,625
- cybersecurity 1,614
- malware 1,071
- cyber security news 1,017
- vulnerability 772
- cyber security 752
- artificial intelligence 595
- technology 544
- ai 471
- network security 435
- computer security 432
- cybercrime 427
- vulnerabilities 371
- windows 332
- software 313
- data breach 292
- phishing 271
- linux 257
- microsoft 233
- cloud security 228
- Science & Technology 1,179
- Software 933
- Computers & Electronics 923
- Conflict, War & Peace 511
- News 431
- Software Dev. 377
- Crime & Law 361
- Internet & Telecom 255
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
2+ day, 7+ hour ago (271+ words) A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An…...
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
3+ day, 8+ hour ago (594+ words) The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026. "Within days, several other espionage-motivated clusters began using BlueMoon,…...
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
3+ day, 13+ hour ago (366+ words) A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build…...
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
6+ day, 16+ hour ago (912+ words) Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running…...
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
1+ week, 4+ day ago (376+ words) Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access…...
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
1+ week, 4+ day ago (767+ words) The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access…...
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
1+ week, 4+ day ago (510+ words) Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea,…...
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
1+ week, 5+ day ago (884+ words) Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and…...
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
1+ week, 6+ day ago (372+ words) Microsoft has disclosed details of a new ClickFix variant, dubbed TerminalFix, that aims to trick users into running a malicious command in Windows Terminal or PowerShell. "While traditional ClickFix campaigns direct victims to the Windows Run dialog, TerminalFix campaigns apply…...
CISA Red Team Compromised Two Critical Infrastructure Orgs, One Detected Nothing
2+ week, 3+ day ago (580+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. Both organizations were…...