All topics

Security stories

Security stories on Hacker News range from critical CVE disclosures and supply-chain attacks to privacy policy changes and encryption debates. Practitioners, researchers, and skeptics weigh in with technical depth that mainstream coverage often misses.

This page aggregates the security and privacy discussions worth reading — vulnerability write-ups, incident postmortems, and the community's reaction to new threats and defenses.

454 stories archived · Page 10 of 16

RSS feed for Security

Security Vulnerability in Pioneer Rekordbox

alphatheta.com · 12 points · 18 comments

ChainDrop supply chain compromise: Anatomy of a self-propagating worm

microsoft.com · 5 points · 0 comments

Exploiting System Management Mode with a very long interrupt

github.com · 92 points · 80 comments

When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers

research.checkpoint.com · 15 points · 1 comments

Pioneer DJ Warns of Major Security Threat to Rekordbox and Every CDJ

5mag.net · 5 points · 0 comments

Did Apple Search engine bot enter the security LLM fuzzing gauntlet

3 points · 0 comments

The malignant rise of OnlyFans managers

theguardian.com · 20 points · 2 comments

Ransomware gangs skip the CEO, head straight for the 40-something IT manager

theregister.com · 52 points · 39 comments

Hims and Hers sent user health data to social media giants bombshell FTC lawsuit

nypost.com · 6 points · 2 comments

Computer maker Framework notifies 'all customers' of a data breach

techcrunch.com · 4 points · 0 comments

What it was like working on LLMs and security at Meta (2022-2026)

joshuasaxe181906.substack.com · 10 points · 0 comments

OpenAI Trained Models While They Were Coordinating Exploits via Message Boards

thezvi.substack.com · 25 points · 11 comments

OpenAI Trained Models for Months While Those Models Were Coordinating Exploits

thezvi.substack.com · 3 points · 0 comments

Water system controllers don't belong on the internet, says ex-NSA chief

theregister.com · 96 points · 169 comments

China's Kimi K3 AI model escapes isolated sandbox during security test

scmp.com · 7 points · 1 comments

OpenAI slows release of Astra model, citing cyber capabilities

axios.com · 5 points · 1 comments

AI agents fake identities, target real people in new security incident

cnn.com · 14 points · 5 comments

Meta's Ray-Bans are getting banned from UK pubs, and the EU is circling

thenextweb.com · 16 points · 9 comments

Restaurants and theatres ban Meta's smart glasses

theguardian.com · 7 points · 0 comments

Framework discloses data breach via Metabase 0-day

community.frame.work · 72 points · 60 comments

Mythos Attempted to Social Engineer Open Source Maintainer to Merge Malware

socket.dev · 59 points · 39 comments

How the U.S. Squandered Its Strategic Advantage

theatlantic.com · 5 points · 0 comments

New TONTOU CPU attack bypasses Spectre v2 fixes, leaks Linux password hashes

bleepingcomputer.com · 11 points · 0 comments

0-day security update available for Metabase

metabase.com · 9 points · 1 comments

"not a single vulnerability was found by a US frontier model."

twitter.com · 7 points · 3 comments

Zapscape (CVE-2026-64561): Guest-to-Host Escape in KVM/x86

github.com · 81 points · 14 comments

Restaurants, pubs and theatres ban Meta's 'spy glasses' over privacy fears

theguardian.com · 6 points · 6 comments

Servers can be backdoored by exploiting buggy motherboard controll

arstechnica.com · 24 points · 9 comments

London cops handed victim's new address and number to her stalker, watchdog says

theregister.com · 11 points · 1 comments

Iowa-led states ask OpenAI to keep their bots on a leash

iowaattorneygeneral.gov · 58 points · 121 comments