Website profile

The Hacker News

The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.

  • 145articles · 30d
  • 22+ hour agolatest article
  • Aug 15, 2026earliest in window
  • 10%with images
  • 352avg words
articles per day
Categories
  • Science & Technology 100
  • Software 83
  • Computers & Electronics 67
  • Conflict, War & Peace 37
  • News 34
  • Crime & Law 30
  • Internet & Telecom 24
  • Software Dev. 24

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

Google News
thehackernews.com > 2026 > 09 > cisa-flags-exploited-cisco-citrix.html

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

3+ day, 22+ hour ago   (471+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities…...

The Hacker News
thehackernews.com > 2026 > 09 > four-spy-groups-used-same-chrome-and.html

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

4+ day, 15+ hour ago   (594+ words) The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026. "Within days, several other espionage-motivated clusters began using BlueMoon,…...

The Hacker News
thehackernews.com > 2026 > 09 > infostealer-logs-expose-replayable-ai.html

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

4+ day, 17+ hour ago   (883+ words) Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to…...

thehackernews.com
thehackernews.com > 2026 > 09 > f5-big-ip-apm-malware-injects-php-web.html

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

5+ day, 1+ hour ago   (887+ words) Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances…...

The Hacker News
thehackernews.com > 2026 > 09 > n-able-n-central-pre-auth-rce-flaw.html

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

5+ day, 4+ hour ago   (245+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in…...

The Hacker News
thehackernews.com > 2026 > 09 > freeipa-flaw-chain-lets-anonymous.html

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

5+ day, 21+ hour ago   (1041+ words) A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who…...

The Hacker News
thehackernews.com > 2026 > 09 > adobe-patches-magento-zero-day.html

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

5+ day, 23+ hour ago   (281+ words) Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by…...

thehackernews.com
thehackernews.com > 2026 > 09 > peep-turns-chrome-and-edge-into-post.html

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

6+ day, 14+ hour ago   (36+ words) PEEP uses Chrome and Edge as a post-compromise backdoor for credential theft and host command execution....

The Hacker News
thehackernews.com > 2026 > 09 > rogue-screenconnect-clients-spread-four.html

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

6+ day, 19+ hour ago   (384+ words) According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form lure, to activate a four-stage VBScript chain that…...

thehackernews.com
thehackernews.com > 2026 > 09 > unpatched-magento-and-adobe-commerce.html

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

1+ week, 1+ day ago   (1468+ words) Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September…...