All topics

Security stories

Security stories on Hacker News range from critical CVE disclosures and supply-chain attacks to privacy policy changes and encryption debates. Practitioners, researchers, and skeptics weigh in with technical depth that mainstream coverage often misses.

This page aggregates the security and privacy discussions worth reading — vulnerability write-ups, incident postmortems, and the community's reaction to new threats and defenses.

454 stories archived · Page 9 of 16

RSS feed for Security

Private security firms will soon be allowed to hack overseas cybercriminals

arstechnica.com · 5 points · 1 comments

Rsync 3.5.0: a huge number of security fixes

download.samba.org · 24 points · 1 comments

Terabytes of credentials leaked in supply-chain attack

arstechnica.com · 32 points · 1 comments

LoongLeak: A Vulnerability Affecting Chinese Loongson 3A5000 and 3A6000 CPUs

loongleakattack.com · 10 points · 0 comments

Flock updates privacy, accountability, security, and transparency safeguards

flocksafety.com · 28 points · 74 comments

FTC, States Act Against Hims and Hers for Deceptive Unlawful Privacy Practices

ftc.gov · 12 points · 2 comments

We eliminated 1,400 CVEs in NanoClaw's container images

echo.ai · 70 points · 47 comments

Orca – Instant cross-platform in-app purchase orchestration

5 points · 0 comments

White House taps security firms for offensive hack-back operations

bleepingcomputer.com · 23 points · 5 comments

Despite Updates, Flock's Creepy Cameras Remain Major Civil Liberties Threat

aclu.org · 11 points · 1 comments

Edge is dropping older extensions(Manifest V2), affecting popular privacy tools

malwarebytes.com · 26 points · 2 comments

Terabytes of credentials leaked in supply-chain attack

arstechnica.com · 7 points · 3 comments

Building Security Agents That Cannot Escape Their Trust Boundary

cynative.com · 8 points · 0 comments

U.S. and Ukrainian Forces Went Head-to-Head in an Exercise. Ukraine's Drones Won

wsj.com · 9 points · 2 comments

Signal adds new security feature to thwart man-in-the-middle attacks

bleepingcomputer.com · 7 points · 0 comments

Lazarus hackers exploited Windows zero-day to target defense firms

bleepingcomputer.com · 7 points · 0 comments

NIST RFI for modernizing the NVD in the wake of AI

federalregister.gov · 3 points · 0 comments

A BSON symbol namespace bypasses MongoDB's authorization check (CVE-2026-18690)

hellorecon.com · 9 points · 0 comments

Prompt Injection as Defense

arstechnica.com · 4 points · 0 comments

Someone is running mass vulnerability scans, spoofing AI bots like ClaudeBot

knownagents.com · 91 points · 228 comments

Cellebrite zero-day exploit used to target phone of Serbian student activist

securitylab.amnesty.org · 4 points · 0 comments

RoguePlanet Vulnerability Still Exploitable

github.com · 6 points · 0 comments

Chrome adopts what may be the best protection yet against account takeovers

arstechnica.com · 6 points · 11 comments

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

theregister.com · 5 points · 3 comments

Delta probes Wi-Fi deauth attack on flight carrying DEF CON attendees

bleepingcomputer.com · 37 points · 21 comments

Microsoft Plugs Nearly 400 Security Holes

krebsonsecurity.com · 19 points · 4 comments

Flatpak 1.19 Released with Nine Security Fixes

phoronix.com · 5 points · 0 comments

Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub

theregister.com · 20 points · 1 comments

Cyber vulnerability sweep picks up Royal Navy drones sending data to China

theregister.com · 7 points · 0 comments

Updated GPG Key for Signing Firefox and Thunderbird Releases

blog.mozilla.org · 56 points · 21 comments