All topics

Security stories

Security stories on Hacker News range from critical CVE disclosures and supply-chain attacks to privacy policy changes and encryption debates. Practitioners, researchers, and skeptics weigh in with technical depth that mainstream coverage often misses.

This page aggregates the security and privacy discussions worth reading — vulnerability write-ups, incident postmortems, and the community's reaction to new threats and defenses.

454 stories archived · Page 6 of 16

RSS feed for Security

Brits would quite like their private messages to stay private

theregister.com · 196 points · 286 comments

Google Reduced Pixel 11's Security

twitter.com · 14 points · 2 comments

Anthropic Just Beat The Pentagon in Court

ibtimes.com · 17 points · 0 comments

Just the rumour of a bug is enough to find an exploit these days

anil.recoil.org · 209 points · 129 comments

CleanMySheet – Privacy-first CSV/Excel cleaner that runs in the browser

cleanmysheet.in · 4 points · 1 comments

Survey shows Americans have turned against license plate tracking cameras

washingtonpost.com · 13 points · 0 comments

You Can Now Carry a Teaching Mainframe in Your Bag – Planet Mainframe

planetmainframe.com · 3 points · 0 comments

Authorities arrest 2 alleged members of prolific hacking group TeamPCP

arstechnica.com · 8 points · 0 comments

Beating GPT5.5-xhigh for Coding agent security with SLMs and IRM

harden.run · 9 points · 5 comments

Sanitizing Kubernetes and Terraform Manifests Before Committing

capytoolkit.com · 3 points · 1 comments

Two alleged TeamPCP hackers arrested over global supply chain attacks

helpnetsecurity.com · 5 points · 1 comments

Feisty Duck's Cryptography and Security News Aggregator

feistyduck.com · 5 points · 1 comments

Two Alleged 'TeamPCP' Hackers Arrested in Australia

krebsonsecurity.com · 20 points · 2 comments

OpenAI saw warning signs weeks before Hugging Face breach

axios.com · 4 points · 1 comments

Railo – Deterministic security patch bot using AST and Z3 (no LLMs)

railo.dev · 4 points · 1 comments

Omarchy is full of security holes

blog.happyfellow.dev · 69 points · 445 comments

Hands-on Docker security labs, from CIS checks to AI context poisoning

github.com · 3 points · 0 comments

Darkbloom (AI inference on idle Macs) – security audit with PRs submitted

gist.github.com · 3 points · 0 comments

CVE-2026-18963 – Keycloak Reset-Credentials Bypass → Account Takeover

github.com · 6 points · 0 comments

When str.lower() is a security vulnerability in Python

sethmlarson.dev · 174 points · 75 comments

Dribbling the AI Watermark Directly In-Prompt

explore-exploit.com · 2 points · 0 comments

I built a cybersecurity challenge for university students

vitb-polimi-cyber-v4.vercel.app · 2 points · 0 comments

CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw

theregister.com · 8 points · 0 comments

Anthropic tells staff to work from home due to possible security team strike

businessinsider.com · 56 points · 131 comments

Local Privilege Escalation via the NetBird Client Daemon IPC

netbird.io · 3 points · 0 comments

OpenKAT: Monitoring Tool and Vulnerability Scanner

docs.openkat.nl · 7 points · 0 comments

Nine Indicted by Taiwan over Illegal Export of Nvidia B300 GPUs to China

tomshardware.com · 6 points · 0 comments

LLMs could control their host machines by exploiting inference engines

boydkane.com · 27 points · 108 comments

A Blackstone real estate company exposed SSN digits, DOBs, addresses and more

alexschapiro.com · 62 points · 56 comments

Tblue – 614 passive security scanners for any website, runs locally

github.com · 14 points · 4 comments