Cybersecurity
- Revolut confirms customer data breach through fake government requests
- The Deathray: A simple way for an untrusted site to freeze a Mac
- We have a year to fix security everywhere
- I've factored the RSA keys of a Certificate Authority from the 90s
- It took a year to ship WebAssembly in Anubis
- Actively exploited sandbox RCE in all Chromium versions
- Hackers had a live feed of every ID verification company scanned for over a year
- VMs won't contain cyber-capable agents
- Omarchy development practices lead to predictable security issues
- C2PA Cameras Do Not Survive Contact with Reality
- Everything I own, owned
- Slovakia finds Russian backdoor in traffic speed cameras
- I spent $266 and four AI models to own my tablet. GLM-5.3 finished it in a day
- Malware infects Android-based automotive head unit firmware
- How to compromise your system with a job interview
- Malicious Rust crate Arrayref runs a build-time payload
- Pacing model development in an era of cyber-critical capabilities
- Quake Shareware, a CD-ROM just a little too full
- AI-Generated GitHub Copilot “Autofix” Allowed Compromise of Snowflake's Jira
- Going Dark, and the era of law enforcement hacking
- Spaghettifying DRAM
- Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
- Stealing Reasoning Traces from Proprietary LLM APIs
- Tl;dv: Over 180k meetings left wide open
- Timeline of the OpenAI accidental attack against Hugging Face
- Hardware backdoors in some x86 CPUs
- Water system controllers don't belong on the internet, says ex-NSA chief
- Responding to the next frontier of critical cyber capabilities
- Atlassian Rovo Exfiltrates Data, Bypassing Controls
- AI fuels more than half of cybercrime in Africa as scams surge – Interpol
- Web Security is Too Hard
- Online ad giant Adform was hacked, proving once again why ad blockers are needed
- Keyv and friends compromised in active Shai-Hulud supply chain attack
- SQLite Critical CVEs or LLM Slop?
- Show HN: ssh ssh.place
- Tailscale didn't stop the Hugging Face intrusion
- Arch Linux disables AUR package adoption
- Read this before you buy that TV streaming stick
- Document-borne AI worms can self-propagate through Copilot for Word
- Anatomy of a Frontier Lab Agent Intrusion: A Timeline of the July 2026 Incident
- Discovering Cryptographic Weaknesses with Claude
- DMARC has been public since 2012 but most company domains still don't enforce it
- About the security content of macOS Tahoe 26.6
- MAI-Cyber-1-Flash inside MDASH
- How to Block Some of the Bots
- My security camera shipped a GitHub admin token in its login page
- Tell HN: Namecheap gave my account to an unverified third party
- Hacker wipes Romania's land registry database
- I found a WordPress RCEs with GPT5.6 and $25
- The Three-Second Theft: Why AI Voice Fraud Outruns Every Defence
- I tricked Claude into leaking your deepest, darkest secrets
- TS-2026-009: Insecure argument handling in Tailscale SSH permitted root access
- Microsoft has released software updates to plug at least 570 security holes
- Dependabot version updates introduce default package cooldown
- Cursor 0day: When Full Disclosure Becomes the Only Protection Left
- Codex scraped the ICM website and discovered 2026 Fields Medal winner list
- Precursor
- Grok CLI uploaded the whole home directory to GCS
- Ghost Font: A font that humans can read but AI cannot
- TLS certificates for internal services done right
- Remote Attestation
- OpenBSD has a use-after-free allowing local privilege escalation to root
- Decoding the obfuscated bash script on a Uniqlo t-shirt
- GitLost: We Tricked GitHub's AI Agent into Leaking Private Repos
- Tenda firmware (multiple versions) contains hidden authentication backdoor
- NSA and IETF: Fairness
- Kernel anti-cheat is an overreach
- Web-based cryptography is always snake oil
- Leaking YouTube creators' private videos
- Potential session/cache leakage between workspace instances or consumer accounts
- Espionage Against the European Parliament
- Order a burned CD of your own public GitHub repo
- Since Linux 6.9, LUKS suspend stopped wiping disk-encryption keys from memory
- Claude Code is steganographically marking requests
- A way to exclude sensitive files issue still open for OpenAI Codex
- Anonymous GitHub account mass-dropping undisclosed 0-days
- We all depend on open source. We will defend it together
- What happened after 2k people tried to hack my AI assistant
- LastPass notifies users of yet another data breach
- OAuth for all
- Vulnerability reports are not special anymore
- Will It Mythos?
- Prompt Injection as Role Confusion
- NSA director: 'Mythos "broke into almost all of our classified systems in hours"
- Developers don't understand CORS (2019)
- Unauthorized alert sent to cell phones across Brazil
- Satellite reveals immense scale of GPS signal tampering
- Let's Encrypt had a higher error rate for 90 minutes today
- Zero-Touch OAuth for MCP
- I found 10k GitHub repositories distributing Trojan malware
- AMD silently removes memory encryption from consumer Ryzen CPUs
- Stop Using JWTs
- A backdoor in a LinkedIn job offer
- Curl will not accept vulnerability reports during July 2026
- Arch Linux Now Believes Malware Incident Under Control: More Than 1,500 Packages
- Twenty One Zero-Days in FFmpeg
- The Future of Email
- AUR packages compromised with Infostealer and Rootkit
- Malware developers added nuclear and biological weapons text to to their spyware
- The RCE that AMD wouldn't fix
- AI agent runs amok in Fedora and elsewhere
- A €0.01 bank transfer could compromise a banking AI agent
- Upcoming breaking changes for npm v12
- Microsoft's open source tools were hacked to steal passwords of AI developers
- 1k Data Breaches Later, the Disclosure Lag Is Worse
- Meta confirms 1000s of Instagram accounts were hacked by abusing its AI chatbot
- Cloudflare CEO is lying to you about the bot traffic jump
- Anthropic's open-source framework for AI-powered vulnerability discovery
- A Post-Quantum Future for Let's Encrypt
- Pwnd Blaster: Hacking your PC using your speaker without ever touching it
- Expanding Project Glasswing
- The newest Instagram “exploit” is the goofiest I've seen
- Malicious npm packages detected across Red Hat Cloud Services
- ChatGPT for Google Sheets exfiltrates workbooks
- Codex just found a "workaround" of not having sudo on my PC
- GitHub bans security researcher who posted zero-day Windows exploits
- Protestware for coding agents
- CVE-2026-28952: Apple macOS 26.5 Kernel Vuln found by Claude
- Scammers are abusing an internal Microsoft account to send spam links
- Project Glasswing: An Initial Update
- Trump Mobile exposed customers' personal data
- GitHub confirms breach of 3,800 repos via malicious VSCode extension
- GitHub is investigating unauthorized access to their internal repositories
- CISA Admin Leaked AWS GovCloud Keys on GitHub
- Mini Shai-Hulud Strikes Again: 314 npm Packages Compromised
- Project Glasswing: what Mythos showed us
- Linux security mailing list 'almost unmanageable'
- Security researcher says Microsoft built a Bitlocker backdoor, releases exploit
- Frontier AI has broken the open CTF format
- 'No way to prevent this,' says only package manager where this regularly happens
- SQL patterns I use to catch transaction fraud
- A 0-click exploit chain for the Pixel 10
- We are retiring our bug bounty program
- Ask HN: How to be SOC2 Type 2 compliant as a solo-entreprenuer?
- First public macOS kernel memory corruption exploit on Apple M5
- Microsoft BitLocker – YellowKey zero-day exploit
- SecurityBaseline.eu
- Twin brothers wipe 96 government databases minutes after being fired
- CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
- The Future of Obsidian Plugins
- Instructure pays ransom to Canvas hackers
- Postmortem: TanStack NPM supply-chain compromise
- Can someone please explain whether Cloudflare blackmailed Canonical?
- Google says criminal hackers used AI to find a major software flaw
- Gmail registration now requires scanning a QR code and sending a text message
- Mythos Finds a Curl Vulnerability
- Obsidian plugin was abused to deploy a remote access trojan
- Incident Report: CVE-2024-YIKES
- Debian must ship reproducible packages
- Local privilege escalation via execve()
- GrapheneOS fixes Android VPN leak Google refused to patch
- You gave me a u32. I gave you root. (io_uring ZCRX freelist LPE)
- AI is breaking two vulnerability cultures
- Maybe you shouldn't install new software for a bit
- Canvas online again as ShinyHunters threatens to leak schools’ data
- Dirty Frag: Universal Linux LPE
- Hardening Firefox with Claude Mythos Preview
- Google Cloud fraud defense, the next evolution of reCAPTCHA
- From Supabase to Clerk to Better Auth
- CVE-2026-31431: Copy Fail vs. rootless containers
- Microsoft Edge stores all passwords in memory in clear text, even when unused
- Securing a DoD contractor: Finding a multi-tenant authorization vulnerability
- Security through obscurity is not bad
- Credit cards are vulnerable to brute force kind attacks
- For Linux kernel vulnerabilities, there is no heads-up to distributions
- Shai-Hulud Themed Malware Found in the PyTorch Lightning AI Training Library
- Will you heed my warnings now?
- Copy Fail
- Bugs Rust won't catch
- AISLE Discovers 38 CVEs in OpenEMR Healthcare Software
- Three men are facing charges in Toronto SMS Blaster arrests
- The woes of sanitizing SVGs
- 4TB of voice samples just stolen from 40k AI contractors at Mercor
- GoDaddy gave a domain to a stranger without any documentation
- French government agency confirms breach as hacker offers to sell data
- Bitwarden CLI compromised in ongoing Checkmarx supply chain campaign
- The Vercel breach: OAuth attack exposes risk in platform environment variables
- A Roblox cheat and one AI tool brought down Vercel's platform
- Quantum Computers Are Not a Threat to 128-Bit Symmetric Keys
- Vercel April 2026 security incident
- "cat readme.txt" is not safe if you use iTerm2
- Show HN: PanicLock – Close your MacBook lid disable TouchID –> password unlock
- €54k spike in 13h from unrestricted Firebase browser key accessing Gemini APIs
- Codex Hacked a Samsung TV
- Open Source Isn't Dead
- Dependency cooldowns turn you into a free-rider
- Tell HN: Fiverr left customer files public and searchable
- Cybersecurity looks like proof of work now
- Someone bought 30 WordPress plugins and planted a backdoor in all of them
- This year’s insane timeline of hacks
- CPU-Z and HWMonitor compromised
- FBI used iPhone notification data to retrieve deleted Signal messages
- Open source security at Astral
- LittleSnitch for Linux
- Microsoft terminates VeraCrypt account, halting Windows updates
- Bitcoin and quantum computing
- Project Glasswing: Securing critical software for the AI era
- Cloudflare targets 2029 for full post-quantum security
- A cryptography engineer's perspective on quantum computing timelines
- My Google Workspace account suspension
- Claude Code Found a Linux Vulnerability Hidden for 23 Years
- OpenClaw privilege escalation vulnerability
- SSH certificates: the better SSH experience
- Post Mortem: axios NPM supply chain compromise
- Significant raise of reports
- Subscription bombing and how to mitigate it
- Quantum computing bombshells that are not April Fools
- Claude wrote a full FreeBSD remote kernel RCE with root shell
- Claude Code's source code has been leaked via a map file in their NPM registry
- Axios compromised on NPM – Malicious versions drop remote access trojan
- Vulnerability research is cooked
- Ghostmoon.app – A Swiss Army Knife for your macOS menu bar
- ChatGPT won't let you type until Cloudflare reads your React state
- Miasma: A tool to trap AI web scrapers in an endless poison pit
- Iran-linked hackers breach FBI director's personal email
- Telnyx package compromised on PyPI
- My minute-by-minute response to the LiteLLM malware attack
- Tell HN: Litellm 1.82.7 and 1.82.8 on PyPI are compromised
- The Resolv hack: How one compromised key printed $23M
- Cyber.mil serving file downloads using TLS certificate which expired 3 days ago
- Cyberattack on vehicle breathalyzer company leaves drivers stranded in the US
- Cloudflare flags archive.today as "C&C/Botnet"; no longer resolves via 1.1.1.2
- Ubuntu 26.04 Ends 46 Years of Silent sudo Passwords
- Delve – Fake Compliance as a Service
- North Korean's 100k fake IT workers net $500M a year for Kim
- CVE-2026-3888: Important Snap Flaw Enables Local Privilege Escalation to Root
- Microsoft's 'unhackable' Xbox One has been hacked by 'Bliss'
- Cert Authorities Check for DNSSEC from Today
- Glassworm is back: A new wave of invisible Unicode attacks hits repositories
- How kernel anti-cheats work
- Source code of Swedish e-government services has been leaked
- Iran-backed hackers claim wiper attack on medtech firm Stryker
- Whistleblower claims ex-DOGE member says he took Social Security data to new job
- How we hacked McKinsey's AI platform
- Hardening Firefox with Anthropic's Red Team
- A GitHub Issue Title Compromised 4k Developer Machines
- Wikipedia was in read-only mode following mass admin account compromise
- FBI couldn't get into WaPo reporter's iPhone because Lockdown Mode enabled
- Notepad++ hijacked by state-sponsored actors
- Poland's energy grid was targeted by never-before-seen wiper malware
- cURL removes bug bounties
- IPv6 is not insecure because it lacks a NAT
- The 'untouchable hacker god' behind Finland's biggest crime
- Tailscale state file encryption no longer enabled by default
- The PGP problem (2019)
- Rainbow Six Siege hacked as players get billions of credits and random bans
- Things I learnt about passkeys when building passkeybot
- I got hacked: My Hetzner server started mining Monero
- Hunting for North Korean Fiber Optic Cables
- SmartTube Compromised
- NSA and IETF, part 3: Dodging the issues at hand
- Disrupting the first reported AI-orchestrated cyber espionage campaign
- Switching from GPG to Age
- Open Source Implementation of Apple's Private Compute Cloud
- X.org Security Advisory: multiple security issues X.Org X server and Xwayland
- Leaker reveals which Pixels are vulnerable to Cellebrite phone hacking
- Unlocking free WiFi on British Airways
- Google flags Immich sites as dangerous
- Could the XZ backdoor been detected with better Git/Deb packaging practices?
- Don’t Look Up: Sensitive internal links in the clear on GEO satellites [pdf]
- DDoS Botnet Aisuru Blankets US ISPs in Record DDoS
- Cache of devices capable of crashing cell network is found in NYC
- Pnpm has a new setting to stave off supply chain attacks
- Oh no, not again a meditation on NPM supply chain attacks
- You too can run malware from NPM (I mean without consequences)
- Secure Boot, TPM and Anti-Cheat Engines
- Microsoft became incompetent in IT
- OpenAI's ChatGPT Agent casually clicks through "I am not a robot" verification
- I hacked my washing machine
- Fully homomorphic encryption and the dawn of a private internet
- Ukrainian hackers destroyed the IT infrastructure of Russian drone manufacturer
- Breaking Git with a carriage return and cloning RCE
- What a Hacker Stole from Me
- I made my VM think it has a CPU fan
- Game Hacking – Valve Anti-Cheat (VAC)
- Another Crack in the Chain of Trust: Uncovering (Yet Another) Secure Boot Bypass
- A proposal to restrict sites from accessing a users’ local network
- A thought on JavaScript "proof of work" anti-scraper systems
- Why I no longer have an old-school cert on my HTTPS site
- SMS 2FA is not just insecure, it's also hostile to mountain people
- The cryptography behind passkeys
- Starlink User Terminal Teardown
- Thieves took their iPhones. Apple won't give their digital lives back
- CVE program faces swift end after DHS fails to renew contract [updated]
- 4chan Sharty Hack And Janitor Email Leak
- AI cheats: Why you didn't notice your teammate was cheating
- Curl-impersonate: Special build of curl that can impersonate the major browsers
- Matrix.org Will Migrate to MAS
- We hacked Gemini's Python sandbox and leaked its source code (at least some)
- Ask HN: Is Washington Post correct in saying Signal is unsecure?
- CVE-2024-9956 – PassKey Account Takeover in All Mobile Browsers
- 2FA or Not 2FA
- Feds Link Cyberheist to 2022 LastPass Hacks
- How to gain code execution on hundreds of millions of people and popular apps
- All Kindles can now be jailbroken
- We got hit by an alarmingly well-prepared phish spammer
- New speculative attacks on Apple CPUs
- Bitwarden is turning 2FA on by default for new devices
- Almost one in 10 people use the same four-digit PIN
- Ask HN: Why buy domains and 301 redirect them to me?
- A phishing attack involving g.co, Google's URL shortener
- Mastercard DNS error went unnoticed for years
- Reverse engineering Call of Duty anti-cheat
- Bambu Lab - Setting the Record Straight About Our Security Update
- Reverse Engineering Bambu Connect
- Using your Apple device as an access card in unsupported systems
- Amazon's AI crawler is making my Git server unstable
- Investigating an “evil” RJ45 dongle
- Trusting clients is probably a security flaw
- Bypassing disk encryption on systems with automatic TPM2 unlock
- Six day and IP address certificate options in 2025
- Google’s OAuth login doesn’t protect against purchasing a failed startup domain
- DoubleClickjacking: A New type of web hacking technique
- Snyk security researcher deploys malicious NPM packages targeting cursor.com
- WorstFit: Unveiling Hidden Transformers in Windows ANSI
- Show HN: Tetris in a PDF
- Cracking a 512-bit DKIM key for less than $8 in the cloud
- A day in the life of a prolific voice phishing crew
- Magic/tragic email links: don't make them the only option
- Human study on AI spear phishing campaigns
- A story on home server security
- iTerm2 critical security release
- Tell HN: Impassable Cloudflare challenges are ruining my browsing experience
- The GPU, not the TPM, is the root of hardware DRM
- Why does storing 2FA codes in your password manager make sense?
- DOOM CAPTCHA
- U.S. Army Soldier Arrested in AT&T, Verizon Extortions
- More telcos confirm Salt Typhoon breaches as White House weighs in
- Dumping Memory to Bypass BitLocker on Windows 11
- Passkey technology is elegant, but it's most definitely not usable security
- Curl-Impersonate
- From Pegasus to Predator – The evolution of commercial spyware on iOS [video]
- Why it's hard to trust software, but you mostly have to anyway
- VW breach exposes location of 800k electric vehicles
- A Tour of WebAuthn
- Portspoof: Emulate a valid service on all 65535 TCP ports
- The Swedish cabin on the frontline of a possible hybrid war
- US could ban TP-Link routers over hacking fears: report
- How to lose a fortune with one bad click
- Microsoft Confirms Password Deletion for 1B Users
- Review of Mullvad VPN
- Dear OAuth Providers
- Tell HN: Need help, locked out of Google account with 10 years of personal data
- Phishers Love New TLDs Like .shop, .top and .xyz
- When was the famous "sudo warning" introduced? (2019)
- A Brazilian CA trusted only by Microsoft has issued a certificate for google.com
- Breaking the 4Chan CAPTCHA
- Malware can turn off webcam LED and record video, demonstrated on ThinkPad X230
- Emacs arbitrary code execution and how to avoid it
- Hacker in Snowflake extortions may be a U.S. soldier
- D-Link says it won't patch 60k older modems
- Let's Encrypt is 10 years old now
- Reverse Engineering iOS 18 Inactivity Reboot
- New Apple security feature reboots iPhones after 3 days, researchers confirm
- PyPI now supports digital attestations
- PRC Targeting of Commercial Telecommunications Infrastructure
- Bypassing regulatory locks, hacking AirPods and Faraday cages
- Backdoor attempt on Exolabs GitHub repo through an innocent looking PR
- YubiKey still selling old stock with vulnerable firmware
- OpenID Connect specifications published as ISO standards
- Hackers use ZIP file concatenation to evade detection
- Multiple new macOS sandbox escape vulnerabilities
- Cops suspect iOS 18 iPhones are communicating to force reboots
- All the data can be yours: reverse engineering APIs
- Hacking 700M Electronic Arts accounts
- Writing secure Go code
- Security flaws found in Nvidia GeForce GPUs
- Apex Legends is taking away its support for the Steam Deck and Linux
- RCE Vulnerability in QBittorrent
- Steam games will need to disclose kernel-level anti-cheat on store pages
- How to get the whole planet to send abuse complaints to your best friends
- New Windows driver signature bypass allows kernel rootkit installs
- Company named "><SCRIPT SRC=HTTPS://MJT.XSS.HT> LTD" forced to change it (2020)
- Ask HN: Website with 6^16 subpages and 80k+ daily bots
- Fearless SSH: Short-lived certificates bring Zero Trust to infrastructure
- ByteDance sacks intern for sabotaging AI project
- Microsoft said it lost weeks of security logs for its customers' cloud products
- Internet Archive breached again through stolen access tokens
- Code that helped end Apartheid
- Apple Passwords’ generated strong password format
- Just want simple TLS for your .internal network?
- Redbox left PII on decommissioned machines
- FIDO Alliance publishes new spec to let users move passkeys across providers
- SSL certificate lifetimes are going down. Dates proposed. 45 days by 2027
- ACF Plugin no longer available on WordPress.org
- The Copenhagen Book: general guideline on implementing auth in web applications
- End-to-End Encrypted Cloud Storage in the Wild: A Broken Ecosystem
- Mozilla fixes Firefox zero-day actively exploited in attacks
- Internet Archive: Security breach alert
- Two never-before-seen tools, from same group, infect air-gapped devices
- European govt air-gapped systems breached using custom malware
- Can you get root with only a cigarette lighter?
- ABC News hacks into popular robot vacuum, watches owner through camera
- Meta fined $102M for storing passwords in plain text
- Attacking UNIX Systems via CUPS
- Hacking Kia: Remotely controlling cars with just a license plate
- Eliminating Memory Safety Vulnerabilities at the Source
- NIST to forbid requirement of specific passwords character composition
- Hacker plants false memories in ChatGPT to steal user data in perpetuity
- What's inside the QR code menu at this cafe?
- CISA boss: Makers of insecure software are the real cyber villains
- Critical Exploit in MediaTek Wi-Fi Chipsets: Zero-Click Vulnerability
- Gaining access to anyones Arc browser without them even visiting a website
- GitHub notification emails used to send malware
- iOS 18 breaks IMAPS self-signed certs
- 0day Contest for End-of-Life Devices Announced
- Bricked iPhone 16 Can Be Restored Wirelessly Using Another iPhone
- Hezbollah pager explosions kill several people in Lebanon
- Bitcoin puzzle #66 was solved: 6.6 BTC (~$400k) withdrawn
- Void captures over a million Android TV boxes
- Zero-Click Calendar invite vulnerability chain in macOS
- GAZEploit: Remote keystroke inference attack by gaze estimation in VR/MR devices
- Vulnerabilities in the Feeld dating app
- We spent $20 to achieve RCE and accidentally became the admins of .mobi
- The "email is authentication" pattern
- Keyhole – Forge own Windows Store licenses
- The Insecurity of Debian
- EUCLEAK Side-Channel Attack on the YubiKey 5 Series
- Owners of 1-Time Passcode Theft Service Plead Guilty
- OAuth from First Principles
- Ask HN: How to store and share passwords in a company?
- Programming Zero Knowledge Proofs: From Zero to Hero
- I'm blocking connections from AWS to my on-prem services
- Bypassing airport security via SQL injection
- Are We Anti-Cheat Yet?
- UltimateAntiCheat
- Defenders think in lists, attackers think in graphs (2015)
- OpenSSH Backdoors
- Show HN: Ruroco – like port knocking, but better
- Claude's API now supports CORS requests, enabling client-side applications
- What is an SBAT and why does everyone suddenly care
- Data Exfiltration from Slack AI via indirect prompt injection
- The gigantic and unregulated power plants in the cloud
- FlightAware Leaks Customer Data (Name, Email Addresses and Passwords)
- Flaw has Microsoft Authenticator overwriting MFA accounts, locking users out
- Pixel smartphones delivered with secret but inactive remote maintenance
- Inside the "3 billion people" national public data breach
- Hackers may have leaked the Social Security Numbers of every American
- Introducing passkey support to Fastmail
- Hacking the largest airline and hotel rewards platform (2023)
- OpenSnitch is a GNU/Linux interactive application firewall
- Researchers discover potentially catastrophic exploit present in AMD chips
- USPS text scammers duped his wife, so he hacked their operation
- Launch HN: Stack Auth (YC S24) – An Open-Source Auth0/Clerk Alternative
- 70% of new NPM packages in last 6 months were spam
- Show HN: 1-FPS encrypted screen sharing for introverts
- Age is a simple, modern and secure file encryption tool, format, and Go library
- Make your electronics tamper-evident
- Techniques used by developers to bypass App Store review
- Threat actor abuses Cloudflare tunnels to deliver remote access trojans
- Coinbase awarded a $500k bug bounty
- Just disconnect the internet
- Why the CrowdStrike bug hit banks hard
- FakeTraveler: Fake where your phone is located (Mock location for Android)
- Our audit of Homebrew
- Swift Homomorphic Encryption
- Secure Boot is broken on 200 models from 5 big device makers
- EU parliament member hit by Israeli Candiru spyware
- Anyone can access deleted and private repository data on GitHub
- Phish-friendly domain registry ".top" put on notice
- Preliminary Post Incident Review
- Intent to end OCSP service
- The CrowdStrike Failure Was a Warning
- CrowdStrike's Falcon Sensor also linked to Linux kernel panics and crashes
- "Any sufficiently bad software update is indistinguishable from a cyberattack"
- Initial details about why CrowdStrike's CSAgent.sys crashed
- CrowdStrike broke Debian and Rocky Linux months ago
- Researcher finds flaw in a16z website that exposed some company data
- CrowdStrike fixes start at "reboot up to 15 times", gets more complex from there
- It's not just CrowdStrike – the cyber sector is vulnerable
- CrowdStrike Update: Windows Bluescreen and Boot Loops
- The golden age of scammers: AI-powered phishing
- Researchers: Weak Security Defaults Enabled Squarespace Domains Hijacks
- The six dumbest ideas in computer security (2005)
- Disney's Internal Slack Breached? NullBulge Leaks 1.1 TiB of Data
- CISA broke into a US federal agency, and no one noticed for a full 5 months
- AT&T says criminals stole phone records of 'nearly all' customers in data breach
- Second factor SMS: Worse than its reputation
- Reverse engineering Ticketmaster's rotating barcodes
- Zed Editor automatically downloads binaries and NPM packages without consent
- Modern-day spying: sometimes old technology is more secure
- Ente Auth: open-source Authy alternative for 2FA
- Twilio confirms data breach after hackers leak 33M Authy user phone numbers
- How random are TOTP codes?
- RegreSSHion: RCE in OpenSSH's server, on glibc-based Linux systems
- How to get root access to your Sleep Number bed
- Dev rejects CVE severity, makes his GitHub repo read-only
- Bytecode Breakdown: Unraveling Factorio's Lua Security Flaws
- Entrust Certificate Distrust
- ID verification service for TikTok, Uber, X exposed driver licenses
- South Korean telecom company attacks torrent users with malware
- Polyfill supply chain attack hits 100K+ sites
- More Memory Safety for Let's Encrypt: Deploying ntpd-rs
- Car dealerships revert to pens and paper after cyberattacks on software provider
- I found a 1-click exploit in South Korea's biggest mobile chat app
- Llama.ttf: A font which is also an LLM
- SSH as a Sudo Replacement
- I'm the hacker that brought down North Korea's Internet for over a week. AMA
- Cyber Scarecrow
- Sei pays out $2M bug bounty
- Backdoor in D-Link routers enables telnet access
- What You Get After Running an SSH Honeypot for 30 Days
- Microsoft Chose Profit over Security, Whistleblower Says
- British duo arrested for SMS phishing via homemade cell tower
- Apple unveils 'Passwords' manager app at WWDC 2024
- OpenSSH introduces options to penalize undesirable behavior
- TPM GPIO fail: How bad OEM firmware ruins Intel TPM security
- Things the guys who stole my phone have texted me to try to get me to unlock it
- Entropy, a CLI that scans files to find high entropy lines (might be secrets)
- Encryption at Rest: Whose Threat Model Is It Anyway?
- Hacking millions of modems and investigating who hacked my modem
- Hacker confirms access through infostealer infection [withdrawn]
- I connected Windows XP to the Internet; it was fine
- The Pumpkin Eclipse
- Ticketmaster breach affects more than half a billion users
- API Shouldn't Redirect HTTP to HTTPS
- Researchers cracked an 11-year-old password to a $3M crypto wallet
- Controlling the Taylor Swift Eras Tour wristbands with Flipper Zero
- The Internet Archive is under a DDoS attack
- Should I use JWTs for authentication tokens?
- Instead of “auth”, we should say “permissions” and “login”
- CVE-2024-4367 – Arbitrary JavaScript execution in PDF.js
- British engineering giant Arup revealed as $25M deepfake scam victim
- Cyber Security: A pre-war reality check
- Android's theft protection features
- Starting emails with "BEGIN PGP MESSAGE" will fool the filter
- One malicious car could trick smart traffic control systems in the US (2018)
- The most backdoor-looking bug I've ever seen (2021)
- Microsoft PlayReady – Complete Client Identity Compromise
- Hackers discover how to reprogram NES Tetris from within the game
- Attackers can decloak routing-based VPNs
- Social engineering takeovers of open source projects
- Show HN: I built a website to share files and messages without any server
- Microsoft ties executive pay to security after multiple failures and breaches
- You receive a call on your phone. The caller says they're from your bank
- Ask HN: How to handle user file uploads?
- Passkey Implementation: Misconceptions, pitfalls and unknown unknowns
- Apple users are being locked out of their Apple IDs with no explanation
- Passkeys: A shattered dream
- Visualizing malicious IP addresses
- Microsoft is a national security threat: ex-White House cyber policy director
- Glibc Buffer Overflow in Iconv
- Do not buy a Hisense TV (or at least keep them offline)
- Randar: A Minecraft exploit that uses LLL lattice reduction to crack server RNG
- T-Mobile employees across the country receive cash offers to illegally swap SIMs
- PuTTY vulnerability vuln-p521-bias
- My cat alerted me to a DDoS attack
- XZ backdoor story – Initial analysis
- Man creatively sneaks onto Delta flight, but gets caught
- Apple alerts users in 92 nations to mercenary spyware attacks
- Quantum Algorithms for Lattice Problems
- Why can't my mom email me?
- Twitter's pivot to x.com is a gift to phishers
- Microsoft employees exposed internal passwords in security lapse
- How I tripped over the Debian weak keys vulnerability
- Notepad++: Help us to take down the parasite website
- Rpgp: Pure Rust implementation of OpenPGP
- Command injection and backdoor account in D-Link NAS devices
- The xz sshd backdoor rabbithole goes quite a bit deeper
- The V8 Sandbox
- Kobold letters: HTML emails are a risk
- Reflections on Distrusting xz
- The xz attack shell script
- Timeline of the xz open source attack
- From xz to ibus: more questionable tarballs
- Bypassing Denuvo in Hogwarts Legacy
- Xzbot: Notes, honeypot, and exploit demo for the xz backdoor
- What we know about the xz Utils backdoor that almost infected the world
- Inside the failed attempt to backdoor SSH globally that got caught by chance
- XZ Backdoor: Times, damned times, and scams
- Xz: A microcosm of the interactions in open source projects
- Xz/liblzma: Bash-stage Obfuscation Explained
- XZ backdoor: "It's RCE, not auth bypass, and gated/unreplayable."
- Xz: Can you spot the single character that disabled Linux landlock?
- Debian on xz-utils: revert to version that does not contain changes by bad actor
- Someone has been attempting to DDoS us for weeks and we do nothing
- Backdoor in upstream xz/liblzma leading to SSH server compromise
- Doom Captcha (2021)
- What do you do if a hacker takes control of your ship? (2023)
- Recent 'MFA Bombing' Attacks Targeting Apple Users
- Flipping Pages: New Linux vulnerability in nf_tables and exploitation techniques
- ZenHammer: Rowhammer attacks on AMD Zen-based platforms
- Aegis v3.0 – a free, secure and open source 2FA app for Android
- TinySSH is a small SSH server using NaCl, TweetNaCl
- Post-quantum cryptography is too damn big
- New vuln in Apple M-series allowing secret keys extraction can't be patched
- Hackers found a way to open any of 3M hotel keycard locks
- What is a pig butchering scam? (2023)
- 900 Sites, 125M accounts, 1 Vulnerability
- Passkeys – Under the Hood
- Insult Passphrase Generator
- Scammed by the top result for 'Bitcoin wallet' in Apple App Store
- GrapheneOS finds Bluetooth memory corruption via ARM MTE
- Show HN: Timelock.dev – Send a secret into the future using timelock encryption
- Kernel Hardening: Protect Linux user accounts against brute force attacks
- You cannot simply publicly access private secure links, can you?
- Ex-Google engineer charged with stealing trade secrets
- Dear Linux Kernel CNA, what have you done?
- Detect when your installed Chrome extensions have changed owners
- Fonts are still a Helvetica of a Problem
- BlackCat ransomware group implodes after apparent payment by Change Healthcare
- Cracking Meta's Messenger Certificate Pinning on macOS
- Cloudflare Announces Firewall for AI
- US prescription market hamstrung for 9 days (so far) by ransomware attack
- I accidentally made my link shortener into a malware honeypot
- Over 100k Infected Repos Found on GitHub
- The /unblock API from Browserless: dodging bot detection as a service
- How to find the AWS account ID of any S3 bucket
- Amazon blocks long-running FireTV capability, Breaking apps with no warning
- A former Gizmodo writer changed name to 'Slackbot', stayed undetected for months
- Thanks FedEx, this is why we keep getting phished
- Auth0 OSS alternative Ory Kratos now with passwordless and SMS support
- Exodus Bitcoin Wallet: $490k swindle
- Endgame: A dashboard exploit for the original Xbox
- Wyze security incident update
- Apple Watch Ultra 2 Hacked
- How I got scammed out of $50k
- Just one bad packet can bring down a vulnerable DNS server thanks to DNSSEC
- End of Life for Twilio Authy Desktop App
- Wi-Fi jamming to knock out cameras suspected in nine Minnesota burglaries
- Keycloak SSO with Docker Compose and Nginx
- How I got scammed on Facebook Marketplace (2023)
- The three million toothbrush botnet story isn't true
- Three million malware-infected smart toothbrushes used in Swiss DDoS attacks
- Companies embracing SMS for account logins should be blamed for SIM-swap attacks
- Out-of-bounds read and write in the glibc's qsort()
- OnlyFake: A site where ‘neural networks’ churn out fake IDs
- Finance worker pays out $25M after video call call with deepfake CFO
- A brief history of the U.S. trying to add backdoors into encrypted data (2016)
- Google has another secret browser
- Thanksgiving 2023 security incident
- Macaroons Escalated Quickly
- Covid Test Data Breach: 1.3M Patient Records Exposed Online
- A mistakenly published password exposed Mercedes-Benz source code
- I looked through attacks in my access logs
- Try to make sudo less vulnerable to Rowhammer attacks
- I hacked a train toilet
- Gitlab password reset bug leaves more than 5.3K servers up for grabs
- Android now lets you transfer eSIMs between your phones
- Rook to XSS: How I hacked chess.com with a rookie exploit
- CVE-2023-40547 – avoid incorrectly trusting HTTP headers
- Out of bounds memory access in V8 in Google Chrome prior to 120.0.6099.224
- 23andMe is reportedly turning the blame back on its customers
- The NSA Furby Documents
- Data leak contains 26B records from numerous previous breaches
- Trello Allegedly Breached
- Forging signed commits on GitHub
- Password may not contain: select, insert, update, delete, drop
- Microsoft actions following attack by nation state actor Midnight Blizzard
- Winding down Google Sync and Less Secure Apps support
- Hacking into an insurance company by exploiting their premium calculator
- The Naz.API Credential Stuffing List
- Passwordless: a different kind of hell?
- When Random Isn't
- Ask HN: Does Cloudflare block HN comments if you have code blocks in a reply?
- A supply chain attack on PyTorch
- Statement regarding the ongoing Sourcehut outage
- Sourcehut and Codeberg are both currently experiencing a DDoS attack
- Engineer Used Water Pump to Get $1B Stuxnet Malware into Iranian Nuclear Plant
- Timeline to remove DSA support in OpenSSH
- Hackers can infect network-connected wrenches to install ransomware
- I pwned half of America's fast food chains simultaneously
- The curious case of the Raspberry Pi in the network closet (2019)
- The optimal amount of fraud is non-zero (2022)
- Facebook incorrectly reports personal blog to DigitalOcean for phishing
- WPA3 Enterprise 192-bit mode at home
- The Curious Case of MD5
- 23andMe tells victims it's their fault that their data was breached
- Bitwarden Heist – How to break into password vaults without using passwords
- AI generated security reports about curl
- Fail2ban Sucks (2020)
- Email addresses are not good 'permanent' identifiers for accounts
- Malware abuses Google OAuth endpoint to 'revive' cookies, hijack accounts
- No new iPhone? No secure iOS: Looking at an unfixed iOS vulnerability
- Operation Triangulation: What you get when attack iPhones of researchers
- High school student allegedly uses device to turn off nearby iPhones
- Non-interactive SSH password authentication
- GTA 5 source code leaks online
- Google OAuth is broken (sort of)
- iMessage Key Verification
- How to Escape a Container
- Comcast says hackers stole data of close to 36M Xfinity customers
- Unbricking my MacBook took an email to Tim Cook
- The British Library URL has been offline due to cyberattack for 10 days
- An Empirical Study and Evaluation of Modern CAPTCHAs
- MongoDB security notice
- What is the point of a public key fingerprint?
- Bluetooth keystroke-injection in Android, Linux, macOS and iOS
- Delta Dental says data breach exposed info of 7M people
- Security Issue: Cloud Site Manager presented me your consoles, not mine
- Ledger's NPM account has been hacked
- Trains were designed to break down after third-party repairs, hackers find
- Biscuit authorization
- Hardening cellular basebands in Android
- Cloud engineer gets 2 years for wiping ex-employer's code repos
- Stealthy Linux rootkit found in the wild after going undetected for 2 years
- OpenBSD – pinning all system calls
- OpenBao – FOSS Fork of HashiCorp Vault
- Verizon fell for fake "search warrant," gave victim's phone data to stalker
- A Schism in the OpenPGP World
- Linux being secure is a common misconception
- Can a Passenger Hack an Airplane?
- Making it clear when we're on a call with you to protect you from fraud
- Stop using JSON Web Tokens for user sessions
- Nothing's iMessage app was a security catastrophe, taken down in 24 hours
- After Boeing declines to pay up, ransomware group leaks 45 GB of data
- From email to phone number, a new OSINT approach (2019)
- Nothing Phone says it will hack into iMessage, bring blue bubbles to Android
- Reptar
- Energy Firms Hacked in Largest Coordinated Attack on Denmark's Infrastructure
- We've learned nothing from the SolarWinds hack
- Discouraging the use of web application firewalls
- Hacking Google Bard – From Prompt Injection to Data Exfiltration
- Reasons to Prefer Blake3 over Sha256
- Beg Bounties (2021)
- It's still easy for anyone to become you at Experian
- LockBit says it's leaked 50GB of stolen Boeing files after ransom fails to land