Hacking News Breaking Cybersecurity. No Filter.

Hacking News

Breaking Cybersecurity. No Filter.

Latest Articles

Passwordless Was Supposed to Save Us. So Why Are We Still Typing 'Password123'?
Opinion

Passwordless Was Supposed to Save Us. So Why Are We Still Typing 'Password123'?

The security industry declared passwords dead years ago. FIDO2, WebAuthn, and passkeys were supposed to bury them for good. But walk into almost any American enterprise in 2024 and you'll find the same sticky notes on monitors, the same quarterly password resets, and the same help desk tickets about forgotten credentials. Here's why the post-password future is taking forever to arrive.

The Phishing Email That Knows Your Boss's Writing Style — AI Did That
Investigation

The Phishing Email That Knows Your Boss's Writing Style — AI Did That

Generative AI didn't just make phishing emails better-written — it made them personal, scalable, and nearly impossible to catch with traditional filters. Security researchers are documenting a new generation of AI-assisted social engineering attacks that can clone communication styles, adapt in real time, and defeat the defenses most organizations have spent years building. This is what that looks like from the inside.

Selling Holes in the Internet: The Shadowy Marketplace Where Zero-Days Go to the Highest Bidder
Investigation

Selling Holes in the Internet: The Shadowy Marketplace Where Zero-Days Go to the Highest Bidder

There's a thriving underground economy where a single undisclosed software flaw can fetch more than a luxury car — or a house. We dug into the murky world of zero-day trading to find out who's buying, who's selling, and what it means for every enterprise security team trying to keep the lights on.

Your Inbox Is Being Targeted by a Machine That Knows You Better Than Your Coworkers Do
Opinion

Your Inbox Is Being Targeted by a Machine That Knows You Better Than Your Coworkers Do

Generative AI didn't just make phishing emails better — it made them terrifyingly personal. The old tells are gone, and the attacks are scaling in ways that traditional email security simply wasn't built for. Here's what's actually happening out there, and what you can realistically do about it.

Poison in the Pipeline: How Compromised Open-Source Packages Are Quietly Owning Your Codebase
Investigation

Poison in the Pipeline: How Compromised Open-Source Packages Are Quietly Owning Your Codebase

Attackers have figured out that they don't need to break down your front door if they can slip something nasty into the lumber you're using to build it. Supply chain attacks targeting npm, PyPI, and other package ecosystems are skyrocketing — and most dev teams are flying blind.

The Master Key Problem: Password Managers Promise Safety — But What Happens When They Get Hacked?
Opinion

The Master Key Problem: Password Managers Promise Safety — But What Happens When They Get Hacked?

Password managers are supposed to be the gold standard of personal security hygiene. But a string of high-profile breaches has security professionals asking an uncomfortable question: is storing every credential you own in one place actually brilliant — or is it the biggest single point of failure you've ever created?

Your Code Is Leaking: The Silent API Key Crisis Hiding in Plain Sight on GitHub
Investigation

Your Code Is Leaking: The Silent API Key Crisis Hiding in Plain Sight on GitHub

Thousands of companies are unknowingly handing attackers the keys to their kingdom — and those keys are sitting right there in public GitHub repos. We dug into the scale of the problem, how automated scanners are exploiting it around the clock, and what your security team needs to do before someone else finds your secrets first.

Ransomware Went Corporate: Inside the Underground Franchise Model Bleeding US Businesses Dry
Opinion

Ransomware Went Corporate: Inside the Underground Franchise Model Bleeding US Businesses Dry

Ransomware isn't a hacker in a hoodie anymore — it's a full-blown criminal enterprise with affiliate programs, SLAs, and customer support portals. We break down how the Ransomware-as-a-Service economy became a $50 million juggernaut, why US companies keep getting hit hardest, and what the latest law enforcement crackdowns actually accomplish.