Website profile

The Hacker News

The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.

  • 174articles · 30d
  • 16+ hour agolatest article
  • Aug 15, 2026earliest in window
  • 10%with images
  • 353avg words
articles per day
Categories
  • Science & Technology 118
  • Software 98
  • Computers & Electronics 84
  • Conflict, War & Peace 47
  • News 37
  • Crime & Law 35
  • Software Dev. 30
  • Internet & Telecom 29

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

The Hacker News
thehackernews.com > 2026 > 09 > attackers-use-passkey-phishing-to.html

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

16+ hour, 27+ min ago   (734+ words) Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. Evidence indicates that the operators behind the campaign…...

thehackernews.com
thehackernews.com > 2026 > 09 > anthropic-says-seven-china-based-ai.html

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

2+ day, 10+ hour ago   (461+ words) Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers…...

The Hacker News
thehackernews.com > 2026 > 09 > check-point-discloses-two-98-rated-vpn.html

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

3+ day, 14+ hour ago   (903+ words) Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not…...

The Hacker News
thehackernews.com > 2026 > 09 > papercut-attacker-uses-hundreds-of-ai.html

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

3+ day, 15+ hour ago   (772+ words) A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports…...

The Hacker News
thehackernews.com > 2026 > 09 > gigabud-creates-android-work-profiles.html

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

3+ day, 15+ hour ago   (921+ words) A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That split hides the trojan from the banking app's own malware checks, Group-IB…...

Google News
thehackernews.com > 2026 > 09 > cisa-flags-exploited-cisco-citrix.html

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

3+ day, 16+ hour ago   (471+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities…...

thehackernews.com
thehackernews.com > 2026 > 09 > new-cpanel-flaw-lets-hosting-account.html

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

4+ day, 17+ hour ago   (742+ words) cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there,…...

thehackernews.com
thehackernews.com > 2026 > 09 > f5-big-ip-apm-malware-injects-php-web.html

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

4+ day, 19+ hour ago   (887+ words) Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances…...

The Hacker News
thehackernews.com > 2026 > 09 > sap-patches-cvss-100-kernel-flaw.html

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

4+ day, 20+ hour ago   (526+ words) SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS…...

The Hacker News
thehackernews.com > 2026 > 09 > n-able-n-central-pre-auth-rce-flaw.html

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

4+ day, 22+ hour ago   (245+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in…...