Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 179articles · 30d
- 1+ day agolatest article
- Aug 14, 2026earliest in window
- 11%with images
- 353avg words
- security 167
- cybersecurity 146
- malware 111
- vulnerability 100
- cyber security news 91
- artificial intelligence 70
- cyber security 65
- cybercrime 62
- technology 61
- ai 52
- vulnerabilities 52
- cloud security 38
- windows 36
- network security 35
- remote code execution 33
- infosec 31
- linux 31
- enterprise security 28
- microsoft 28
- cisa 27
- Science & Technology 122
- Software 100
- Computers & Electronics 86
- Conflict, War & Peace 47
- News 39
- Crime & Law 37
- Software Dev. 31
- Internet & Telecom 29
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
2+ day, 17+ hour ago (921+ words) A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That split hides the trojan from the banking app's own malware checks, Group-IB…...
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
2+ day, 18+ hour ago (471+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities…...
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
3+ day, 11+ hour ago (594+ words) The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026. "Within days, several other espionage-motivated clusters began using BlueMoon,…...
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
3+ day, 13+ hour ago (883+ words) Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to…...
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
3+ day, 18+ hour ago (321+ words) Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's…...
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
3+ day, 21+ hour ago (356+ words) The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher…...
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
4+ day, 1+ min ago (602+ words) Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. September's record-setting security updates come after Microsoft patched 457 vulnerabilities in August,…...
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
4+ day, 1+ min ago (245+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in…...
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
4+ day, 16+ hour ago (733+ words) Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their…...
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
4+ day, 19+ hour ago (281+ words) Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by…...