The Hacker News
Coverage by The Hacker News as tracked by Newsylist.
AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day
Apple's ‘Private Relay’ Is Exposing Users’ Real IP Addresses
Anthropic and OpenAI models tried to trick humans into poisoning code during safety testing
Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts
Hijacked Hotel Wi-Fi Pushes Fake Updates to Deliver Surveillance Malware
5 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
Beware: attackers now using real Microsoft sign-in screen for phishing
7 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
Google says it fixed more Chrome bugs in June than over the past two years, thanks to AI
Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update
A coordinated campaign dubbed Operation BlueDash is using fraudulent Microsoft Teams updates to install remote access tools on corporate systems.
Hugging Face wants $100mn of compute from OpenAI
6 news sources are covering this Business story right now — Newsylist is tracking how fast it spreads.
Microsoft touts cost-saving AI model for cybersecurity
Claude Cowork escaped sandbox on Mac, gain full access to all files
Security experts have identified a vulnerability allowing the Claude Cowork AI agent to bypass virtual machine isolation and access local files on Mac systems.
Nvidia, Microsoft launch open AI security alliance
7 news sources are covering this Business story right now — Newsylist is tracking how fast it spreads.
AI innovation is outpacing governance, leaving companies exposed, EqualAI warns
EqualAI warns that rapid AI innovation is leaving companies exposed as corporate governance fails to keep pace with technological adoption.
Chaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and Edge
5 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes
Security agencies report a Russian-backed group is utilizing a zero-day exploit in Zimbra software to compromise email accounts and capture 2FA codes.
Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs
A long-standing security vulnerability in the Linux XFS file system, identified as RefluXFS, allows local users to escalate privileges to root access.
Google now lets you sign in to your account using a selfie video
Google has introduced a new account authentication feature that allows users to sign in using a recorded selfie video.
Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication
OpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat Benchmark
4 news sources are covering this Business story right now — Newsylist is tracking how fast it spreads.
Critical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoC
10 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
Hugging Face breach: OpenAI claims its models were responsible
Hugging Face reports a breach of internal datasets and credentials, while OpenAI states its models were involved in the autonomous cyber attack.
Google launches a cheaper alternative to large AI security models like Mythos
Apple Fixes Hide My Email Vulnerability After 404 Media Coverage
Apple has patched a vulnerability in its Hide My Email service following reporting by 404 Media.
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
A supply chain attack dubbed SleeperGem is utilizing compromised RubyGems packages to drop persistent backdoors on developer machines.
Hackers are exploiting recently patched WordPress bugs, putting millions of websites at risk
A vulnerability identified as 'WP2Shell' is facilitating remote takeovers of millions of WordPress sites, drawing urgent warnings from security researchers.
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
E.U. Orders Google to Open Android Mic, Camera and Screen to Rival AI Assistants
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code
A critical remote code execution flaw dubbed 'wp2shell' allows unauthenticated attackers to run code within WordPress Core via SQL injection.
Zoom warns of critical account takeover vulnerability
Zoom warns of critical Windows vulnerability enabling account takeover
CrashStealer Malware Impersonates Apple Tool to Steal Mac Passwords and Crypto
New malware impersonates Apple tool to steal Mac passwords and crypto
Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws
7 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday
5 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
CISA warns admins to patch actively exploited SharePoint flaws
New phishing kits target Microsoft 365 accounts, evade MFA
9 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now
SonicWall is urging users of its SMA1000 series appliances to apply patches immediately following reports of active zero-day exploits.
Microsoft’s Secure Boot has been broken for a decade and no one noticed until now
Research has revealed that decade-old Microsoft-signed UEFI shims can be used to bypass Secure Boot protections.
Microsoft July 2026 Patch Tuesday fixes massive 570 flaws, 3 zero-days
Microsoft's July 2026 Patch Tuesday addresses 570 vulnerabilities, including three zero-day flaws.
New CrashStealer malware poses as Apple crash reporting tool
14 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory
7 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
Security News This Week: AI Found a Root Bug in Linux That Everyone Missed for 15 Years
AI has uncovered a 15-year-old Linux kernel flaw known as "GhostLock" that allows root access and container escapes.
Windows Is Tracking You? What You Missed in Cybersecurity This Week
A hacker's arrest has exposed how Microsoft uses Windows telemetry GDIDs to identify and track users, according to recent court filings.
Study of 281 Free Android VPN Apps Finds Traffic Leaks, Unencrypted Data, and Tracking
A study of 281 free Android VPN apps reveals critical security flaws, including unencrypted data transfers and massive user data leaks.
Backdoor Found in the Firmware for These Wi-Fi Routers. And There's No Patch
6 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
Microsoft Patches RoguePlanet Defender Flaw That Can Grant SYSTEM Privileges
6 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
Meta AI now lets people make deepfakes from public Instagram photos without explicit consent
4 news sources are covering this Business story right now — Newsylist is tracking how fast it spreads.
Ubiquiti warns of new max severity UniFi OS vulnerability
Ubiquiti has issued patches for 25 security vulnerabilities within the UniFi ecosystem, including a flaw identified with a maximum severity score.
New Januscape Linux flaw allows VM escape on Intel, AMD devices
5 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
Threat Actors Probe Gitea Docker Flaw CVE-2026-20896 13 Days After Disclosure
5 news sources are covering this Technology story right now — Newsylist is tracking how fast it spreads.
JadePuffer ransomware used AI agent to automate entire attack
The emergence of JadePuffer marks the first known instance of 'agentic ransomware' using an AI agent to automate a full cyber attack.
New "Bad Epoll" Linux Kernel Flaw Lets Unprivileged Users Gain Root, Hits Android
A critical Linux kernel vulnerability known as "Bad Epoll" or "DirtyClone" allows unprivileged users to gain root access on servers and Android devices.
Somebody told DeepSeek to build in-browser ransomware and it gleefully complied
Newly discovered PamStealer isn’t your typical macOS malware
A new Rust-based macOS malware called PamStealer is masquerading as a clipboard manager to steal and validate user login information.
Anthropic Restores Claude Fable 5 After U.S. Lifts Jailbreak-Linked Export Controls
Azure CLI Password Spray Hits at Least 78 Microsoft Accounts in 81M+ Attempts
CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451)
Citrix has released patches for six NetScaler flaws, including a pre-auth memory overread vulnerability reminiscent of the CitrixBleed exploit.