Website profile

The Hacker News

The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.

  • 145articles · 30d
  • 22+ hour agolatest article
  • Aug 15, 2026earliest in window
  • 10%with images
  • 352avg words
articles per day
Categories
  • Science & Technology 100
  • Software 83
  • Computers & Electronics 67
  • Conflict, War & Peace 37
  • News 34
  • Crime & Law 30
  • Internet & Telecom 24
  • Software Dev. 24

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

The Hacker News
thehackernews.com > 2026 > 09 > chrome-v8-zero-day-exploited-in-wild.html

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

4+ day, 22+ hour ago   (321+ words) Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's…...

thehackernews.com
thehackernews.com > 2026 > 09 > new-cpanel-flaw-lets-hosting-account.html

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

4+ day, 23+ hour ago   (742+ words) cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there,…...

The Hacker News
thehackernews.com > 2026 > 09 > sap-patches-cvss-100-kernel-flaw.html

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

5+ day, 2+ hour ago   (526+ words) SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS…...

The Hacker News
thehackernews.com > 2026 > 09 > freeipa-flaw-chain-lets-anonymous.html

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

5+ day, 21+ hour ago   (1041+ words) A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who…...

The Hacker News
thehackernews.com > 2026 > 09 > bengalseo-poisons-bing-search-results.html

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

5+ day, 23+ hour ago   (1052+ words) Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has…...

The Hacker News
thehackernews.com > 2026 > 09 > jsceal-malware-can-bypass-google.html

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

1+ week, 46+ min ago   (494+ words) Malvertising campaigns distributing the malware make use of two ZIP archives delivered via PowerShell: one containing the Node.js runtime and the other containing the main payload and other auxiliary components. As recently as last month, ad security platform Confiant…...

The Hacker News
thehackernews.com > 2026 > 09 > attackers-hijack-mikrotik-routers.html

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

1+ week, 23+ hour ago   (390+ words) Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least…...

The Hacker News
thehackernews.com > 2026 > 09 > four-revstealer-linked-modules-disable.html

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

1+ week, 1+ day ago   (912+ words) Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running…...

The Hacker News
thehackernews.com > 2026 > 09 > attackers-breached-jetbrains-cadence.html

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

1+ week, 1+ day ago   (509+ words) JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke…...

The Hacker News
thehackernews.com > 2026 > 09 > critical-vmware-workstation-and-fusion.html

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

1+ week, 1+ day ago   (339+ words) Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that…...