Install
The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.
- 174articles · 30d
- 20+ hour agolatest article
- Aug 15, 2026earliest in window
- 10%with images
- 353avg words
- security 162
- cybersecurity 142
- malware 108
- vulnerability 98
- cyber security news 88
- artificial intelligence 70
- cyber security 62
- cybercrime 59
- technology 58
- ai 52
- vulnerabilities 52
- cloud security 39
- windows 35
- network security 33
- remote code execution 33
- linux 30
- enterprise security 29
- microsoft 29
- infosec 28
- cisa 27
- Science & Technology 118
- Software 98
- Computers & Electronics 84
- Conflict, War & Peace 47
- News 37
- Crime & Law 35
- Software Dev. 30
- Internet & Telecom 29
- cyber security news
- cyber news
- cyber security news today
- cyber security updates
- cyber updates
- hacker news
- hacking news
- software vulnerability
- cyber attacks
- data breach
- ransomware malware
- how to hack
- network security
- information security
- the hacker news
- computer security
- top cybersecurity threats
- ⚡ thn weekly recap
Please confirm you are human
This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.
A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.
News
Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data
20+ hour, 17+ min ago (734+ words) Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. Evidence indicates that the operators behind the campaign…...
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
3+ day, 18+ hour ago (903+ words) Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not…...
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
5+ day, 5+ min ago (526+ words) SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS…...
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
5+ day, 1+ hour ago (245+ words) The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in…...
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
5+ day, 18+ hour ago (1041+ words) A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who…...
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
6+ day, 19+ hour ago (838+ words) A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed…...
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
6+ day, 21+ hour ago (737+ words) Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix…...
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
1+ week, 1+ day ago (1468+ words) Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September…...
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
1+ week, 1+ day ago (339+ words) Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that…...
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
1+ week, 4+ day ago (487+ words) The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the office malicious macros remediation in…...