Website profile

The Hacker News

The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.

  • 1,797articles · 365d
  • 1+ day agolatest article
  • Sep 13, 2025earliest in window
  • 20%with images
  • 353avg words
articles per day
Categories
  • Science & Technology 1,179
  • Software 933
  • Computers & Electronics 923
  • Conflict, War & Peace 511
  • News 431
  • Software Dev. 377
  • Crime & Law 361
  • Internet & Telecom 255

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

The Hacker News
thehackernews.com > 2026 > 09 > check-point-discloses-two-98-rated-vpn.html

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

2+ day, 14+ hour ago   (903+ words) Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not…...

The Hacker News
thehackernews.com > 2026 > 09 > papercut-attacker-uses-hundreds-of-ai.html

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

2+ day, 14+ hour ago   (772+ words) A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports…...

Google News
thehackernews.com > 2026 > 09 > cisa-flags-exploited-cisco-citrix.html

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

2+ day, 16+ hour ago   (471+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities…...

The Hacker News
thehackernews.com > 2026 > 09 > webinar-learn-how-to-answer-are-we.html

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

3+ day, 14+ hour ago   (366+ words) A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build…...

thehackernews.com
thehackernews.com > 2026 > 09 > new-cpanel-flaw-lets-hosting-account.html

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

3+ day, 17+ hour ago   (742+ words) cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there,…...

The Hacker News
thehackernews.com > 2026 > 09 > sap-patches-cvss-100-kernel-flaw.html

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

3+ day, 20+ hour ago   (526+ words) SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS…...

The Hacker News
thehackernews.com > 2026 > 09 > n-able-n-central-pre-auth-rce-flaw.html

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

3+ day, 21+ hour ago   (245+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in…...

The Hacker News
thehackernews.com > 2026 > 09 > autonomous-ai-agents-compromise.html

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

4+ day, 12+ hour ago   (530+ words) Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group…...

The Hacker News
thehackernews.com > 2026 > 09 > freeipa-flaw-chain-lets-anonymous.html

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

4+ day, 14+ hour ago   (1041+ words) A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who…...

thehackernews.com
thehackernews.com > 2026 > 09 > peep-turns-chrome-and-edge-into-post.html

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

5+ day, 8+ hour ago   (36+ words) PEEP uses Chrome and Edge as a post-compromise backdoor for credential theft and host command execution....