Security stories
Security stories on Hacker News range from critical CVE disclosures and supply-chain attacks to privacy policy changes and encryption debates. Practitioners, researchers, and skeptics weigh in with technical depth that mainstream coverage often misses.
This page aggregates the security and privacy discussions worth reading — vulnerability write-ups, incident postmortems, and the community's reaction to new threats and defenses.
454 stories archived · Page 9 of 16
RSS feed for SecurityPrivate security firms will soon be allowed to hack overseas cybercriminals
arstechnica.com · 5 points · 1 comments
Rsync 3.5.0: a huge number of security fixes
download.samba.org · 24 points · 1 comments
Terabytes of credentials leaked in supply-chain attack
arstechnica.com · 32 points · 1 comments
LoongLeak: A Vulnerability Affecting Chinese Loongson 3A5000 and 3A6000 CPUs
loongleakattack.com · 10 points · 0 comments
Flock updates privacy, accountability, security, and transparency safeguards
flocksafety.com · 28 points · 74 comments
FTC, States Act Against Hims and Hers for Deceptive Unlawful Privacy Practices
ftc.gov · 12 points · 2 comments
We eliminated 1,400 CVEs in NanoClaw's container images
echo.ai · 70 points · 47 comments
Orca – Instant cross-platform in-app purchase orchestration
5 points · 0 comments
White House taps security firms for offensive hack-back operations
bleepingcomputer.com · 23 points · 5 comments
Despite Updates, Flock's Creepy Cameras Remain Major Civil Liberties Threat
aclu.org · 11 points · 1 comments
Edge is dropping older extensions(Manifest V2), affecting popular privacy tools
malwarebytes.com · 26 points · 2 comments
Terabytes of credentials leaked in supply-chain attack
arstechnica.com · 7 points · 3 comments
Building Security Agents That Cannot Escape Their Trust Boundary
cynative.com · 8 points · 0 comments
U.S. and Ukrainian Forces Went Head-to-Head in an Exercise. Ukraine's Drones Won
wsj.com · 9 points · 2 comments
Signal adds new security feature to thwart man-in-the-middle attacks
bleepingcomputer.com · 7 points · 0 comments
Lazarus hackers exploited Windows zero-day to target defense firms
bleepingcomputer.com · 7 points · 0 comments
NIST RFI for modernizing the NVD in the wake of AI
federalregister.gov · 3 points · 0 comments
A BSON symbol namespace bypasses MongoDB's authorization check (CVE-2026-18690)
hellorecon.com · 9 points · 0 comments
Prompt Injection as Defense
arstechnica.com · 4 points · 0 comments
Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot
knownagents.com · 91 points · 228 comments
Cellebrite zero-day exploit used to target phone of Serbian student activist
securitylab.amnesty.org · 4 points · 0 comments
RoguePlanet Vulnerability Still Exploitable
github.com · 6 points · 0 comments
Chrome adopts what may be the best protection yet against account takeovers
arstechnica.com · 6 points · 11 comments
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
theregister.com · 5 points · 3 comments
Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees
bleepingcomputer.com · 37 points · 21 comments
Microsoft Plugs Nearly 400 Security Holes
krebsonsecurity.com · 19 points · 4 comments
Flatpak 1.19 Released with Nine Security Fixes
phoronix.com · 5 points · 0 comments
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
theregister.com · 20 points · 1 comments
Cyber vulnerability sweep picks up Royal Navy drones sending data to China
theregister.com · 7 points · 0 comments
Updated GPG Key for Signing Firefox and Thunderbird Releases
blog.mozilla.org · 56 points · 21 comments