The Hacker News
Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals.
- OpenAI’s Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pauseby info@thehackernews.com (The Hacker News) on August 10, 2026 at 5:50 am
OpenAI has announced that it’s pausing some “internal activities” involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding and cybersecurity. In response to the discovery, the AI upstart said it’s implementing security controls for higher-capability models and associated activities, such as isolated
- Atlassian Rovo Can Be Tricked Into Sending Jira and Confluence Data to Attackersby info@thehackernews.com (The Hacker News) on August 8, 2026 at 8:54 am
Attacker-controlled instructions can make Atlassian’s Rovo assistant collect Jira or Confluence data that a signed-in user can access, then send it to an outside server. Two security firms found that behavior independently, by different routes. Only one of those routes is confirmed closed. PromptArmor, an AI security firm, hid the instructions in content Rovo reads. It said an uploaded file was
- New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokensby info@thehackernews.com (The Hacker News) on August 8, 2026 at 8:03 am
New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party accounts, leak tokens, hijack trusted UI actions, and manipulate AI tools that read email. PortSwigger researcher Gareth
- Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authenticationby info@thehackernews.com (The Hacker News) on August 8, 2026 at 6:58 am
Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthenticated remote attacker to inject arbitrary SQL into the Metabase application database, enabling them to gain
- N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persistby info@thehackernews.com (The Hacker News) on August 8, 2026 at 6:57 am
N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. “We are proactively expanding protections in response to ongoing monitoring of threat actors as they evolve their attack techniques,” the company said. “This is not a duplicate of our
Security Magazine
Security magazine provides security industry news and trends on video surveillance, cyber security, physical security, security guards, access management and more for security executives and the security industry.
- Modern Wireless-First Security Solutions Deliver Multiple Benefits for Mixed-Use Propertieson August 10, 2026 at 7:00 am
The most common longstanding security and safety challenges of mixed-use properties generally fall into 4 categories.
- Stop, Drop, and Rollon August 7, 2026 at 9:00 am
Insights from national fire prevention standards for active shooter prevention.
- As AI Outpaces Regulation, Trust is at Riskon August 7, 2026 at 5:00 am
AI will continue to outpace regulation. The question is not whether the gap exists, every CISO already knows it does. The question is who owns it.
- Building Trust in AI Starts with Trustworthy Dataon August 6, 2026 at 3:00 pm
Enterprise AI is transitioning from the “does it work” phase to the “how can we adopt it safely” phase, creating an unprecedented and complex mix of opportunities and challenges for business leaders.
- The State of National Securityon August 6, 2026 at 9:00 am
Former FBI Deputy Director Paul Abbate discusses the state of National Security today.
Threatpost
The first stop for security news.
- Student Loan Breach Exposes 2.5M Recordsby Nate Nelson on August 31, 2022 at 12:57 pm
2.5 million people were affected, in a breach that could spell more trouble down the line.
- Watering Hole Attacks Push ScanBox Keyloggerby Nate Nelson on August 30, 2022 at 4:00 pm
Researchers uncover a watering hole attack likely carried out by APT TA423, which attempts to plant the ScanBox JavaScript-based reconnaissance tool.
- Tentacles of ‘0ktapus’ Threat Group Victimize 130 Firmsby Nate Nelson on August 29, 2022 at 2:56 pm
Over 130 companies tangled in sprawling phishing campaign that spoofed a multi-factor authentication system.
- Ransomware Attacks are on the Riseby Nate Nelson on August 26, 2022 at 4:44 pm
Lockbit is by far this summer’s most prolific ransomware group, trailed by two offshoots of the Conti group.
- Cybercriminals Are Selling Access to Chinese Surveillance Camerasby Nate Nelson on August 25, 2022 at 6:47 pm
Tens of thousands of cameras have failed to patch a critical, 11-month-old CVE, leaving thousands of organizations exposed.
Security Weekly
Connecting the Security Industry with the Security Community















