Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 1,797articles · 365d
- 1+ day agolatest article
- Sep 13, 2025earliest in window
- 20%with images
- 353avg words
- security 1,625
- cybersecurity 1,614
- malware 1,071
- cyber security news 1,017
- vulnerability 772
- cyber security 752
- artificial intelligence 595
- technology 544
- ai 471
- network security 435
- computer security 432
- cybercrime 427
- vulnerabilities 371
- windows 332
- software 313
- data breach 292
- phishing 271
- linux 257
- microsoft 233
- cloud security 228
- Science & Technology 1,179
- Software 933
- Computers & Electronics 923
- Conflict, War & Peace 511
- News 431
- Software Dev. 377
- Crime & Law 361
- Internet & Telecom 255
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
3+ day, 10+ hour ago (594+ words) The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026. "Within days, several other espionage-motivated clusters began using BlueMoon,…...
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
3+ day, 12+ hour ago (883+ words) Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to…...
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
3+ day, 20+ hour ago (356+ words) The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher…...
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
4+ day, 13+ hour ago (530+ words) Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group…...
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
5+ day, 13+ hour ago (299+ words) Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that…...
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
6+ day, 19+ hour ago (912+ words) Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running…...
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
1+ week, 10+ hour ago (509+ words) JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke…...
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
1+ week, 20+ hour ago (246+ words) Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass…...
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
1+ week, 2+ day ago (665+ words) Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put…...
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
1+ week, 3+ day ago (599+ words) An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. The websites observed as part of the campaign are hosted on the.com.cn and.hl.cn infrastructure and use Chinese-language lure content…...