The Hacker News
Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals.
- Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flawsby info@thehackernews.com (The Hacker News) on September 19, 2026 at 6:36 pm
Three researchers at the security firm Hacktron used Anthropic’s Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI’s public help forum and moved through a weakness in OpenAI’s own login system. This was security research,
- Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinarby info@thehackernews.com (The Hacker News) on September 19, 2026 at 1:28 pm
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is
- Identity Visibility in 2026: The Foundation of Identity Securityby info@thehackernews.com (The Hacker News) on September 19, 2026 at 1:28 pm
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon’s annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in
- SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCEby info@thehackernews.com (The Hacker News) on September 19, 2026 at 9:31 am
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior. “SolarWinds
- Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wildby info@thehackernews.com (The Hacker News) on September 19, 2026 at 8:18 am
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. “Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote
Security Magazine
Security magazine provides security industry news and trends on video surveillance, cyber security, physical security, security guards, access management and more for security executives and the security industry.
- Edge Processing Is Quietly Changing Physical Security — Here’s Why It Matterson September 18, 2026 at 4:00 pm
Examining edge and cloud processing in detail, including the benefits and trade-offs of each.
- The Best Way to Thank Security Officers Is to Give Them the Support They Deserveon September 18, 2026 at 1:05 pm
National Security Officer Appreciation Week is about more than recognition. It’s about giving officers the tools and support they need to succeed.
- Beyond 1999: The Case for AI-Augmented Vulnerability Orchestrationon September 18, 2026 at 9:00 am
Threat actors use AI and automation to weaponize flaws in milliseconds. Meanwhile, defensive teams remain shackled to spreadsheets, ticket chains, and 30-day approval cycles.
- Mobile Security Can’t Move at App Release Speed Anymoreon September 17, 2026 at 4:00 pm
Mobile security still assumes protection can wait for the next release. But like a burst pipe, it’s something we can’t afford to wait on.
- 8 Places AI Is Quietly Entering Your Enterpriseon September 16, 2026 at 11:00 am
Do you know where AI is entering your organization?
Threatpost
The first stop for security news.
- Student Loan Breach Exposes 2.5M Recordsby Nate Nelson on August 31, 2022 at 12:57 pm
2.5 million people were affected, in a breach that could spell more trouble down the line.
- Watering Hole Attacks Push ScanBox Keyloggerby Nate Nelson on August 30, 2022 at 4:00 pm
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
- Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firmsby Nate Nelson on August 29, 2022 at 2:56 pm
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
- Ransomware Attacks are on the Riseby Nate Nelson on August 26, 2022 at 4:44 pm
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
- Cybercriminals Are Selling Access to Chinese Surveillance Camerasby Nate Nelson on August 25, 2022 at 6:47 pm
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Security Weekly
Connecting the Security Industry with the Security Community















