Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 1,797articles · 365d
- 1+ day agolatest article
- Sep 14, 2025earliest in window
- 20%with images
- 353avg words
- security 1,625
- cybersecurity 1,614
- malware 1,072
- cyber security news 1,018
- vulnerability 772
- cyber security 752
- artificial intelligence 596
- technology 543
- ai 471
- network security 435
- computer security 431
- cybercrime 428
- vulnerabilities 371
- windows 332
- software 313
- data breach 291
- phishing 270
- linux 257
- microsoft 235
- cloud security 229
- Science & Technology 1,179
- Software 933
- Computers & Electronics 923
- Conflict, War & Peace 511
- News 430
- Software Dev. 377
- Crime & Law 361
- Internet & Telecom 256
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
4+ day, 1+ hour ago (471+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities…...
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week
4+ day, 19+ hour ago (594+ words) The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026. "Within days, several other espionage-motivated clusters began using BlueMoon,…...
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
6+ day, 3+ hour ago (1052+ words) Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has…...
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
1+ week, 4+ hour ago (494+ words) Malvertising campaigns distributing the malware make use of two ZIP archives delivered via PowerShell: one containing the Node.js runtime and the other containing the main payload and other auxiliary components. As recently as last month, ad security platform Confiant…...
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
1+ week, 1+ day ago (509+ words) JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke…...
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
1+ week, 4+ day ago (665+ words) Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put…...
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
1+ week, 4+ day ago (322+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - As for CVE-2026-48710, a report from Horizon3.ai in June…...
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
1+ week, 4+ day ago (599+ words) An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. The websites observed as part of the campaign are hosted on the.com.cn and.hl.cn infrastructure and use Chinese-language lure content…...
Malicious.git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
1+ week, 4+ day ago (983+ words) Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command…...
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
1+ week, 5+ day ago (379+ words) Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the…...