The Hacker News
Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals.
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoorby info@thehackernews.com (The Hacker News) on August 12, 2026 at 5:39 pm
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have Oneby info@thehackernews.com (The Hacker News) on August 12, 2026 at 2:09 pm
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66
- OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoningby info@thehackernews.com (The Hacker News) on August 12, 2026 at 11:47 am
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers’ reasoning APIs, where a block created in one session could be replayed into another and, during testing,
- Enterprise Defenses Recovered at the Edge and Collapsed Insideby info@thehackernews.com (The Hacker News) on August 12, 2026 at 11:41 am
Enterprise defenses are tuned to catch the attacks that make noise. This year’s data shows attackers winning by making none. According to Picus Labs’ new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of 2026, defenses are having one of their strongest years yet. Average prevention effectiveness
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flawsby info@thehackernews.com (The Hacker News) on August 12, 2026 at 11:13 am
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below – CVE-2026-48362 (CVSS score: 10.0) – An operating system command injection vulnerability in ColdFusion that could
Security Magazine
Security magazine provides security industry news and trends on video surveillance, cyber security, physical security, security guards, access management and more for security executives and the security industry.
- Can Organizations Trust Their Own AI?on August 12, 2026 at 4:00 pm
Security magazine talks with Brent Johnson, CISO at Bluefin, about strategies organizations can adopt to protect themselves and their data.
- Enhancing Residential Building Securityon August 12, 2026 at 1:00 pm
Apartment complex management companies and property owners have a duty to maintain safe premises for their tenants and their guests.
- A Dive into the Royalmount Mall’s Securityon August 12, 2026 at 9:00 am
The Royalmount Mall in Quebec faces unique security challenges, and so it approaches protection in a distinct way.
- Film Festival Data Leak Exposes A-List Directors, Actors, Celebritieson August 11, 2026 at 4:00 pm
Records associated with Tribeca Film Festival were exposed.
- Mass Kidnapping Increased 154% from 2020 to 2025on August 11, 2026 at 5:00 am
2026 will see an increase in kidnaps-for-ransom.
Threatpost
The first stop for security news.
- Student Loan Breach Exposes 2.5M Recordsby Nate Nelson on August 31, 2022 at 12:57 pm
2.5 million people were affected, in a breach that could spell more trouble down the line.
- Watering Hole Attacks Push ScanBox Keyloggerby Nate Nelson on August 30, 2022 at 4:00 pm
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
- Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firmsby Nate Nelson on August 29, 2022 at 2:56 pm
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
- Ransomware Attacks are on the Riseby Nate Nelson on August 26, 2022 at 4:44 pm
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
- Cybercriminals Are Selling Access to Chinese Surveillance Camerasby Nate Nelson on August 25, 2022 at 6:47 pm
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Security Weekly
Connecting the Security Industry with the Security Community















