Security stories
Security stories on Hacker News range from critical CVE disclosures and supply-chain attacks to privacy policy changes and encryption debates. Practitioners, researchers, and skeptics weigh in with technical depth that mainstream coverage often misses.
This page aggregates the security and privacy discussions worth reading — vulnerability write-ups, incident postmortems, and the community's reaction to new threats and defenses.
454 stories archived · Page 10 of 16
RSS feed for SecuritySecurity Vulnerability in Pioneer Rekordbox
alphatheta.com · 12 points · 18 comments
ChainDrop supply chain compromise: Anatomy of a self-propagating worm
microsoft.com · 5 points · 0 comments
Exploiting System Management Mode with a very long interrupt
github.com · 92 points · 80 comments
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
research.checkpoint.com · 15 points · 1 comments
Pioneer DJ Warns of Major Security Threat to Rekordbox and Every CDJ
5mag.net · 5 points · 0 comments
Did Apple Search engine bot enter the security LLM fuzzing gauntlet
3 points · 0 comments
The malignant rise of OnlyFans managers
theguardian.com · 20 points · 2 comments
Ransomware gangs skip the CEO, head straight for the 40-something IT manager
theregister.com · 52 points · 39 comments
Hims and Hers sent user health data to social media giants bombshell FTC lawsuit
nypost.com · 6 points · 2 comments
Computer maker Framework notifies 'all customers' of a data breach
techcrunch.com · 4 points · 0 comments
What it was like working on LLMs and security at Meta (2022-2026)
joshuasaxe181906.substack.com · 10 points · 0 comments
OpenAI Trained Models While They Were Coordinating Exploits via Message Boards
thezvi.substack.com · 25 points · 11 comments
OpenAI Trained Models for Months While Those Models Were Coordinating Exploits
thezvi.substack.com · 3 points · 0 comments
Water system controllers don't belong on the internet, says ex-NSA chief
theregister.com · 96 points · 169 comments
China's Kimi K3 AI model escapes isolated sandbox during security test
scmp.com · 7 points · 1 comments
OpenAI slows release of Astra model, citing cyber capabilities
axios.com · 5 points · 1 comments
AI agents fake identities, target real people in new security incident
cnn.com · 14 points · 5 comments
Meta's Ray-Bans are getting banned from UK pubs, and the EU is circling
thenextweb.com · 16 points · 9 comments
Restaurants and theatres ban Meta's smart glasses
theguardian.com · 7 points · 0 comments
Framework discloses data breach via Metabase 0-day
community.frame.work · 72 points · 60 comments
Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware
socket.dev · 59 points · 39 comments
How the U.S. Squandered Its Strategic Advantage
theatlantic.com · 5 points · 0 comments
New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes
bleepingcomputer.com · 11 points · 0 comments
0-day security update available for Metabase
metabase.com · 9 points · 1 comments
"not a single vulnerability was found by a US frontier model."
twitter.com · 7 points · 3 comments
Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86
github.com · 81 points · 14 comments
Restaurants, pubs and theatres ban Meta's 'spy glasses' over privacy fears
theguardian.com · 6 points · 6 comments
Servers can be backdoored by exploiting buggy motherboard controll
arstechnica.com · 24 points · 9 comments
London cops handed victim's new address and number to her stalker, watchdog says
theregister.com · 11 points · 1 comments
Iowa-led states ask OpenAI to keep their bots on a leash
iowaattorneygeneral.gov · 58 points · 121 comments