The Hacker News
Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals.
- Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCsby info@thehackernews.com (The Hacker News) on July 21, 2026 at 11:58 am
An Android app that can draw over other windows and write to shared storage can slip instructions to the AI agent driving that phone, in text no human eye will ever see. Two more steps, and the same app is running commands on the PC driving the agent. Researchers demonstrated that chain, plus six other attacks, against five open-source mobile agent frameworks: AppAgent, AppAgentX,
- N-day is Becoming N-Hour. Patching Faster Won’t Save You.by info@thehackernews.com (The Hacker News) on July 21, 2026 at 11:42 am
Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn’t updated yet. This is N-day exploitation, and it’s always been a race: the vendor patches, the clock starts, and defenders try to deploy
- New Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an Exploitby info@thehackernews.com (The Hacker News) on July 21, 2026 at 11:24 am
A cloud tenant using nothing but ordinary GPU access can push a data center’s power draw up and down fast enough to threaten the grid it runs on, with no exploit and no break-in. That is the claim behind Bit2Watt, described by three Zhejiang University researchers in a paper accepted to CHES 2026, the IACR’s hardware-security conference, and the evidence splits in two: they measured the power
- WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanningby info@thehackernews.com (The Hacker News) on July 21, 2026 at 8:59 am
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have been codenamed wp2shell. “By the early hours of Saturday morning (UTC), successful exploitation was already well
- New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attackby info@thehackernews.com (The Hacker News) on July 21, 2026 at 7:34 am
Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model weights, vector indexes, training datasets, and other AI infrastructure files across the host filesystem. The entry
Security Magazine
Security magazine provides security industry news and trends on video surveillance, cyber security, physical security, security guards, access management and more for security executives and the security industry.
- Eye on the Sky: SkySafe Named 2026 Golden Eagle Award Winneron July 21, 2026 at 9:00 am
This year Security Magazine partnered with The National Center for Spectator Sports Safety and Security (NCS4) to present the Golden Eagle Award to SkySafe as the 2026 Golden Eagle Award winner for its case study submission, “University of Illinois Sets the Standard for Campus Drone Security.”
- Cyberattack Halts Coca-Cola’s Fairlife Productionson July 21, 2026 at 5:00 am
A company owned by Coca-Cola paused operations following a cyberattack.
- Hugging Face Confirms Data Breach Caused by Autonomous AI Agenton July 20, 2026 at 4:16 pm
A host platform for AI models and datasets confirmed it had experienced a data breach.
- Security’s 2026 Women in Securityon July 20, 2026 at 1:30 pm
Recognized for their achievements and influence, this year’s honorees drive progress throughout their organizations.
- Dr. Jazma Mekelle Parker — Women in Security 2026on July 20, 2026 at 9:00 am
Dr. Jazma Mekelle Parker began her security career as a contract background investigator for the U.S. Office of Personnel Management (OPM).
Threatpost
The first stop for security news.
- Student Loan Breach Exposes 2.5M Recordsby Nate Nelson on August 31, 2022 at 12:57 pm
2.5 million people were affected, in a breach that could spell more trouble down the line.
- Watering Hole Attacks Push ScanBox Keyloggerby Nate Nelson on August 30, 2022 at 4:00 pm
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
- Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firmsby Nate Nelson on August 29, 2022 at 2:56 pm
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
- Ransomware Attacks are on the Riseby Nate Nelson on August 26, 2022 at 4:44 pm
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
- Cybercriminals Are Selling Access to Chinese Surveillance Camerasby Nate Nelson on August 25, 2022 at 6:47 pm
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Security Weekly
Connecting the Security Industry with the Security Community















