The Hacker News
Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals.
- OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Faceby info@thehackernews.com (The Hacker News) on August 27, 2026 at 6:36 pm
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly fueled by what it described as a “highly capable
- Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCEby info@thehackernews.com (The Hacker News) on August 27, 2026 at 3:13 pm
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path traversal, tracked as CVE-2026-75604&
- ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Storiesby info@thehackernews.com (The Hacker News) on August 27, 2026 at 3:12 pm
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned, and exploit windows shrinking again. Different
- Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powersby info@thehackernews.com (The Hacker News) on August 27, 2026 at 1:39 pm
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on Windows, according to Mindguard. The latest version of
- Learn How to Build Security Operations Ready for AI-Powered Attacksby info@thehackernews.com (The Hacker News) on August 27, 2026 at 11:56 am
Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processes were built to handle. The challenge is no longer just finding another vulnerability or
Security Magazine
Security magazine provides security industry news and trends on video surveillance, cyber security, physical security, security guards, access management and more for security executives and the security industry.
- Report Finds AI Security Fails to Match AI Usageon August 28, 2026 at 4:00 am
A report by Guardrail Technologies analyzed how S&P 500 companies document their AI usage alongside their AI cybersecurity measures.
- LAX Security Guard Found With 24 Pounds of Fentanyl, Facing Chargeson August 27, 2026 at 5:00 pm
A security guard was allegedly caught with fentanyl in the LAX restroom.
- DOJ, NASA, Others Among Victims of Chinese State-Sponsored Hackon August 27, 2026 at 4:00 pm
The DOJ and other federal entities were targeted by a Chinese state-sponsored actor.
- 12.9M Exposed by Carhartt Data Breachon August 27, 2026 at 12:03 pm
More than 50 gigabytes of documents were reportedly stolen.
- Medical Device Manufacturer Boston Scientific Faces Cyberattackon August 27, 2026 at 4:00 am
Boston Scientific, a U.S. medical device manufacturer, announced a cyberattack affecting their global operations.
Threatpost
The first stop for security news.
- Student Loan Breach Exposes 2.5M Recordsby Nate Nelson on August 31, 2022 at 12:57 pm
2.5 million people were affected, in a breach that could spell more trouble down the line.
- Watering Hole Attacks Push ScanBox Keyloggerby Nate Nelson on August 30, 2022 at 4:00 pm
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
- Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firmsby Nate Nelson on August 29, 2022 at 2:56 pm
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
- Ransomware Attacks are on the Riseby Nate Nelson on August 26, 2022 at 4:44 pm
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
- Cybercriminals Are Selling Access to Chinese Surveillance Camerasby Nate Nelson on August 25, 2022 at 6:47 pm
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Security Weekly
Connecting the Security Industry with the Security Community










.webp?t=1787774213)




