Website profile

The Hacker News

The Hacker News is the most trusted and popular cybersecurity publication for information security professionals seeking breaking news, actionable insights and analysis.

  • 174articles · 30d
  • 16+ hour agolatest article
  • Aug 15, 2026earliest in window
  • 10%with images
  • 353avg words
articles per day
Categories
  • Science & Technology 118
  • Software 98
  • Computers & Electronics 84
  • Conflict, War & Peace 47
  • News 37
  • Crime & Law 35
  • Software Dev. 30
  • Internet & Telecom 29

Please confirm you are human

This browser or connection looks automated. Press and continuously hold the control for 3 seconds to enable Google-hosted web results and, when separately allowed, AI-assisted answers.

A successful check enables 100 search requests. Interactive access does not authorize scraping, systematic collection, or reuse of search output.

Hold with a pointer, or hold Space or Enter.

News

The Hacker News
thehackernews.com > 2026 > 09 > four-spy-groups-used-same-chrome-and.html

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

4+ day, 10+ hour ago   (594+ words) The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, PerplexedGoblin, RedBravo, TA412, Tide Castle, and Violet Typhoon) on August 28, 2026. "Within days, several other espionage-motivated clusters began using BlueMoon,…...

The Hacker News
thehackernews.com > 2026 > 09 > webinar-learn-how-to-answer-are-we.html

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

4+ day, 15+ hour ago   (366+ words) A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build…...

thehackernews.com
thehackernews.com > 2026 > 09 > f5-big-ip-apm-malware-injects-php-web.html

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

4+ day, 19+ hour ago   (887+ words) Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances…...

The Hacker News
thehackernews.com > 2026 > 09 > researcher-drops-new-microsoft-defender.html

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

4+ day, 20+ hour ago   (356+ words) The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher…...

The Hacker News
thehackernews.com > 2026 > 09 > microsoft-patches-record-974-flaws.html

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

4+ day, 22+ hour ago   (602+ words) Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. September's record-setting security updates come after Microsoft patched 457 vulnerabilities in August,…...

The Hacker News
thehackernews.com > 2026 > 09 > adobe-patches-magento-zero-day.html

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

5+ day, 17+ hour ago   (281+ words) Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by…...

thehackernews.com
thehackernews.com > 2026 > 09 > peep-turns-chrome-and-edge-into-post.html

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

6+ day, 8+ hour ago   (36+ words) PEEP uses Chrome and Edge as a post-compromise backdoor for credential theft and host command execution....

The Hacker News
thehackernews.com > 2026 > 09 > rogue-screenconnect-clients-spread-four.html

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

6+ day, 13+ hour ago   (384+ words) According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake Geek Squad refund form lure, to activate a four-stage VBScript chain that…...

The Hacker News
thehackernews.com > 2026 > 09 > n-able-issues-fourth-n-central-hotfix.html

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

6+ day, 18+ hour ago   (737+ words) Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix…...

The Hacker News
thehackernews.com > 2026 > 09 > jsceal-malware-can-bypass-google.html

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

6+ day, 19+ hour ago   (494+ words) Malvertising campaigns distributing the malware make use of two ZIP archives delivered via PowerShell: one containing the Node.js runtime and the other containing the main payload and other auxiliary components. As recently as last month, ad security platform Confiant…...