Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 145articles · 30d
- 22+ hour agolatest article
- Aug 15, 2026earliest in window
- 10%with images
- 352avg words
- security 135
- cybersecurity 120
- malware 90
- vulnerability 83
- cyber security news 72
- artificial intelligence 60
- cybercrime 49
- technology 49
- cyber security 48
- ai 44
- vulnerabilities 42
- cloud security 34
- windows 29
- network security 28
- remote code execution 28
- microsoft 27
- enterprise security 25
- infosec 25
- linux 24
- cisa 23
- Science & Technology 100
- Software 83
- Computers & Electronics 67
- Conflict, War & Peace 37
- News 34
- Crime & Law 30
- Internet & Telecom 24
- Software Dev. 24
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
4+ day, 22+ hour ago (321+ words) Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's…...
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
4+ day, 23+ hour ago (742+ words) cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there,…...
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
5+ day, 2+ hour ago (526+ words) SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS…...
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
5+ day, 21+ hour ago (1041+ words) A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who…...
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
5+ day, 23+ hour ago (1052+ words) Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has…...
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
1+ week, 46+ min ago (494+ words) Malvertising campaigns distributing the malware make use of two ZIP archives delivered via PowerShell: one containing the Node.js runtime and the other containing the main payload and other auxiliary components. As recently as last month, ad security platform Confiant…...
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
1+ week, 23+ hour ago (390+ words) Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least…...
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
1+ week, 1+ day ago (912+ words) Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running…...
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
1+ week, 1+ day ago (509+ words) JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke…...
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
1+ week, 1+ day ago (339+ words) Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that…...