Website profile

The Hacker News

The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.

  • 1,797articles · 365d
  • 1+ day agolatest article
  • Sep 13, 2025earliest in window
  • 20%with images
  • 353avg words
articles per day
Categories
  • Science & Technology 1,179
  • Software 933
  • Computers & Electronics 923
  • Conflict, War & Peace 511
  • News 431
  • Software Dev. 377
  • Crime & Law 361
  • Internet & Telecom 255

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

thehackernews.com
thehackernews.com > 2026 > 09 > your-critical-vulnerabilities-might-not.html

Your Critical Vulnerabilities Might Not Be Your Biggest Risk

1+ day, 15+ hour ago   (1309+ words) Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a…...

thehackernews.com
thehackernews.com > 2026 > 09 > anthropic-says-seven-china-based-ai.html

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

1+ day, 11+ hour ago   (461+ words) Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers…...

The Hacker News
thehackernews.com > 2026 > 09 > threatsday-200-android-flaws-browser.html

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

2+ day, 9+ hour ago   (271+ words) A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An…...

The Hacker News
thehackernews.com > 2026 > 09 > papercut-attacker-uses-hundreds-of-ai.html

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

2+ day, 15+ hour ago   (772+ words) A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports…...

The Hacker News
thehackernews.com > 2026 > 09 > anthropic-ai-models-breached-real.html

Anthropic AI Models Breached Real Systems After Test Misconfiguration

2+ day, 19+ hour ago   (813+ words) Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI…...

The Hacker News
thehackernews.com > 2026 > 09 > infostealer-logs-expose-replayable-ai.html

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

3+ day, 12+ hour ago   (883+ words) Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to…...

The Hacker News
thehackernews.com > 2026 > 09 > webinar-learn-how-to-answer-are-we.html

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

3+ day, 15+ hour ago   (366+ words) A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build…...

The Hacker News
thehackernews.com > 2026 > 09 > deepseek-harness-flaw-let-ai-agents.html

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

3+ day, 15+ hour ago   (1039+ words) A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox,…...

The Hacker News
thehackernews.com > 2026 > 09 > alby-hub-critical-flaw-could-let.html

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

3+ day, 16+ hour ago   (798+ words) Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet....

The Hacker News
thehackernews.com > 2026 > 09 > chrome-v8-zero-day-exploited-in-wild.html

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

3+ day, 17+ hour ago   (321+ words) Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's…...