Skip to content

company

The Hacker News

The Hacker News (thehackernews.com) is a widely read cybersecurity news outlet covering data breaches, vulnerabilities, malware, and threat intelligence.

Known aliases

  • thehackernews.com
  • THN

Relationships

No evidence-backed relationships are recorded.

Current stories

security4 publishers

Attackers move the ClickFix paste into Windows Terminal to land a multi-stage intrusion chain

Microsoft's TerminalFix writeup shows the same fake CAPTCHA lure now feeding multi-line PowerShell into Windows Terminal, where it sideloads a signed binary, pulls payloads out of PNG files and leaves a reverse tunnel behind.

Perspective Coverage

4 publishers
Builder
Builder 20%
Operator
Operator 75%
Investor
Investor 5%

Reality

Evidence65
Adoption
Insufficient
Hype gap+20
Incentives30
Confidence65

Earlier coverage

  1. Verizon's 43-day median patch time, against a five-day weaponization clock

    Security · September 17, 2026 · 1 publisher

  2. N0va captures refresh tokens from sign-ins the identity provider itself approved

    Security · September 16, 2026 · 1 publisher

  3. KREMLIN installers forge Chrome's Secure Preferences HMACs to register a stealer extension

    Security · September 15, 2026 · 1 publisher

  4. Exploitation catalogues logged 495 of the 35,853 CVEs published in the first half of 2026

    Security · September 15, 2026 · 1 publisher

  5. An attacker kept root inside Thai broadband provider 3BB with a hidden MeshCentral install

    Security · September 14, 2026 · 1 publisher

  6. Check Point ships this week's VPN fix as a live patch for three versions and an upgrade for the rest

    Build · September 14, 2026 · 1 publisher

  7. An attacker's Markdown playbooks drove a six-hour credential harvest from inside the victim's cloud

    Build · September 12, 2026 · 1 publisher

  8. SecurityBridge's co-founder makes the SAP agent case on one survey and two prior incidents

    Leadership · September 10, 2026 · 1 publisher

  9. cPanel patches an EmailTrack injection that carries a mail-privileged tenant to root

    Security · September 9, 2026 · 1 publisher

  10. Bitdefender counts 55.2% of breached practitioners asked to keep the incident quiet

    Security · September 8, 2026 · 1 publisher

  11. September 11 puts a 24-hour clock on knowing what software actually shipped

    Product · September 3, 2026 · 1 publisher

  12. GitGuardian finds a Shai-Hulud variant sweeping 469 credential paths across CI/CD and AI configs

    Security · September 3, 2026 · 1 publisher

  13. Approving one coding agent doesn't cover what's installed inside it

    Security · September 2, 2026 · 1 publisher

  14. Attackers ran ClickFix into 47% of the initial access Microsoft logged last year

    Security · September 1, 2026 · 1 publisher

  15. The CRA's 24-hour exploitation clock starts 456 days before its engineering rules do

    Security · September 1, 2026 · 1 publisher

  16. Anthropic's Compliance API now logs the Claude Code sessions running on inherited developer credentials

    Security · August 31, 2026 · 1 publisher

  17. DoJ rewrites its QTFY seizure release to move seven agencies from victims to targets

    Security · August 31, 2026 · 1 publisher

  18. ZBT router firmware ships two factory implants that beacon out on UDP/10000

    Security · August 28, 2026 · 1 publisher

  19. A survey of 250-plus SOC practitioners puts 135 minutes between an alert firing and an answer

    Security · August 27, 2026 · 1 publisher

  20. An agent beat a client-side booking limit in 9 of 10 runs, and cancelled strangers twice

    Security · August 26, 2026 · 1 publisher

  21. Kaltura's unpatched player bugs arrive with a coordinator that could not reach the vendor

    Security · August 26, 2026 · 1 publisher

  22. Time to revoke: the two timestamps a closed ticket cannot give you

    Build · August 26, 2026 · 1 publisher

  23. Mirage2FA: 4,532 domains later, "we have MFA" is not an answer to the auditor

    Security · August 25, 2026 · 1 publisher

  24. QUICSILVER runs its C2 over QUIC, and most port-443 inspection is scoped to TCP

    Security · August 24, 2026 · 1 publisher

  25. U.S. warning on Siemens S7 PLCs: AI-written scripts, borrowed scan data, read access first

    Security · August 24, 2026 · 1 publisher

  26. The Meta Sev 1 that argues approval is a snapshot, not a control

    Security · August 20, 2026 · 1 publisher

  27. Defender's own signed driver becomes the bypass: BTR.sys and the week's trusted-component defects

    Security · August 20, 2026 · 1 publisher

  28. A vCenter bug patched on July 29 is already a ransomware chain, not a ticket

    Security · August 17, 2026 · 1 publisher

  29. Pass-ta-key breaks Chrome's device trust, not WebAuthn: harden the endpoint, keep the rollout

    Build · August 16, 2026 · 1 publisher