Cybersecurity News
Understand the Threats. Protect What Matters.
- This Coin-Sized Device Can Hack a Boeing 737by Andy Greenberg on August 12, 2026 at 12:00 pm
Security researchers found that in less than 60 seconds, they could open a hatch on a plane’s exterior, plug in a tiny device, and redirect the aircraft’s autopilot or sabotage its flight plan.
- CISA Unveils New Cybersecurity Resources for K-12 Schools and Districtsby CISA on August 12, 2026 at 12:00 pm
- ‘The Worst I’ve Ever Seen’: Cargo Thefts Have Turned Violent in Pursuit of AI Hardwareby Paresh Dave, Aarian Marshall on August 12, 2026 at 10:00 am
Experts allege that two recent incidents in California show the extreme lengths that criminal organizations are willing to go to to steal servers and other gear meant for data centers.
- Microsoft Plugs Nearly 400 Security Holesby BrianKrebs on August 11, 2026 at 9:28 pm
Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.
- A Zoom Screen-Sharing Bug Let Anyone Take Over Other Devices on a Callby Lily Hay Newman on August 11, 2026 at 12:37 pm
Researchers say it took fewer than 20 prompts for a public AI tool to find a flaw (now fixed) allowing anyone on a Zoom call to hijack another participants’ device.
The Hacker News Most trusted, widely-read independent cybersecurity news source for everyone; supported by hackers and IT professionals — Send TIPs to [email protected]
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoorby [email protected] (The Hacker News) on August 12, 2026 at 5:39 pm
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activity, per Check Point Research, is part of Operation Dream Job, a long-running cyber espionage and
- 737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have Oneby [email protected] (The Hacker News) on August 12, 2026 at 2:09 pm
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store developer accounts, racked up 75,486 installs. Of those identified, 274 have been found to impersonate 66
- OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoningby [email protected] (The Hacker News) on August 12, 2026 at 11:47 am
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers’ reasoning APIs, where a block created in one session could be replayed into another and, during testing,
- Enterprise Defenses Recovered at the Edge and Collapsed Insideby [email protected] (The Hacker News) on August 12, 2026 at 11:41 am
Enterprise defenses are tuned to catch the attacks that make noise. This year’s data shows attackers winning by making none. According to Picus Labs’ new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of 2026, defenses are having one of their strongest years yet. Average prevention effectiveness
- Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flawsby [email protected] (The Hacker News) on August 12, 2026 at 11:13 am
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below – CVE-2026-48362 (CVSS score: 10.0) – An operating system command injection vulnerability in ColdFusion that could









