Hacker & Security News
banner
hacker.at.thenote.app
Hacker & Security News
@hacker.at.thenote.app
#hacker and #security news from Hacker News, LifeHacker, Security Boulevard and others.
Our other projects: #macos, #ios and #android apps for notes TheNote.app
Pinned
We launched a Public Feed on Bluesky with #Hacker and #Security #News from sources like Hacker News, LifeHacker, Security Boulevard and others your convenience 🚀 🤗
bsky.app/profile/hack...
AI Will Decide Every B2B Deal by 2030 (And That’s a Conservative Guess)

Artificial intelligence will decide which B2B brands are considered, compared, and shortlisted before a human conversation ever begins. The buying journey doesn’t start with a website visit or a demo request …
#hackernews #news
AI Will Decide Every B2B Deal by 2030 (And That’s a Conservative Guess)
Artificial intelligence will decide which B2B brands are considered, compared, and shortlisted before a human conversation ever begins. The buying journey doesn’t start with a website visit or a demo request anymore.
hackernoon.com
January 17, 2026 at 5:55 PM
German cops add Black Basta boss to EU most-wanted list

Ransomware kingpin who escaped Armenian custody is believed to be lying low back home
German cops have added Russian national Oleg Evgenievich Nefekov to their list of most-wanted criminals for his services to ransomware.…
#hackernews #news
German cops add Black Basta boss to EU most-wanted list
Ransomware kingpin who escaped Armenian custody is believed to be lying low back home German cops have added Russian national Oleg Evgenievich Nefekov to their list of most-wanted criminals for his services to ransomware.…
go.theregister.com
January 17, 2026 at 5:24 PM
Data breach at Canada’s Investment Watchdog Canadian Investment Regulatory Organization impacts 750,000 people

A data breach at Canada’s investment watchdog, Canadian Investment Regulatory Organization (CIRO), impacted about 750,000 people. The Canadian Investment Regulatory Orga…
#hackernews #news
Data breach at Canada’s Investment Watchdog Canadian Investment Regulatory Organization impacts 750,000 people
A data breach at Canada’s investment watchdog, Canadian Investment Regulatory Organization (CIRO), impacted about 750,000 people. The Canadian Investment Regulatory Organization (CIRO) is Canada’s national self-regulatory body overseeing investment dealers and marketplaces, protecting investors, enforcing compliance, and maintaining fair, efficient capital markets. CIRO announced that threat actors stole personal data of 750,000 people in an […]
securityaffairs.com
January 17, 2026 at 4:54 PM
Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393)

Cisco has finally shipped security updates for its Email Security Gateway and Secure Email and Web Manager devices, which fix CVE-2025-20393, a vulnerability in the devices’ AsyncOS that has been exp…
#hackernews #news
Cisco fixes AsyncOS vulnerability exploited in zero-day attacks (CVE-2025-20393)
Cisco has finally shipped security updates for its Email Security Gateway and Secure Email and Web Manager devices, which fix CVE-2025-20393, a vulnerability in the devices’ AsyncOS that has been exploited as a zero-day by suspected Chinese attackers since at least late November 2025. The company revealed the flaw’s existence and in-the-wild exploitation on December 17, 2025, and urged customers to check whether their appliances had been breached and to rebuild them in case of …
www.helpnetsecurity.com
January 17, 2026 at 4:24 PM
AI and the Corporate Capture of Knowledge

More than a decade after Aaron Swartz’s death, the United States is still living inside the contradiction that destroyed him.

Swartz believed that knowledge, especially publicly funded knowledge, should be freely accessible. Acting on th…
#hackernews #news
AI and the Corporate Capture of Knowledge
More than a decade after Aaron Swartz’s death, the United States is still living inside the contradiction that destroyed him. Swartz believed that knowledge, especially publicly funded knowledge, should be freely accessible. Acting on that, he downloaded thousands of academic articles from the JSTOR archive with the intention of making them publicly available. For this, the federal government charged him with a felony and threatened decades in prison. After two years of prosecutorial pressure, Swartz died by suicide on Jan. 11, 2013. The still-unresolved questions raised by his case have resurfaced in today’s debates over artificial intelligence, copyright and the ultimate control of knowledge...
www.schneier.com
January 17, 2026 at 3:53 PM
6 ways to stop cleaning up after AI - and keep your productivity gains

It's the ultimate AI paradox, but it doesn't have to be that way.
#hackernews #news
6 ways to stop cleaning up after AI - and keep your productivity gains
It's the ultimate AI paradox, but it doesn't have to be that way.
www.zdnet.com
January 17, 2026 at 3:33 PM
Why Traditional Firewalls Fail Against Today’s High-Volume DDoS Attacks

Traditional firewalls can’t stop modern DDoS attacks. Learn why high-volume, multi-layer attacks overwhelm perimeter defenses—and how to build real DDoS resilience.
#hackernews #news
Why Traditional Firewalls Fail Against Today’s High-Volume DDoS Attacks
Traditional firewalls can’t stop modern DDoS attacks. Learn why high-volume, multi-layer attacks overwhelm perimeter defenses—and how to build real DDoS resilience.
securityboulevard.com
January 17, 2026 at 3:12 PM
Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts

Cybersecurity researchers have discovered five new malicious Google Chrome web browser extensions that masquerade as human resources (HR) and enterprise resource planning (ERP) platforms like Wor…
#hackernews #news
Five Malicious Chrome Extensions Impersonate Workday and NetSuite to Hijack Accounts
Cybersecurity researchers have discovered five new malicious Google Chrome web browser extensions that masquerade as human resources (HR) and enterprise resource planning (ERP) platforms like Workday, NetSuite, and SuccessFactors to take control of victim accounts. "The extensions work in concert to steal authentication tokens, block incident response capabilities, and enable complete account
thehackernews.com
January 17, 2026 at 2:51 PM
AI Is Hard Work

"Opportunity is missed by most people because it is dressed in overalls and looks like work." — Thomas A. Edison
#hackernews #news
AI Is Hard Work
"Opportunity is missed by most people because it is dressed in overalls and looks like work." — Thomas A. Edison
securityboulevard.com
January 17, 2026 at 2:30 PM
From Quantum Resilience to Identity Fatigue: Three Trends Shaping Print Security in 2026

From quantum resilience to identity fatigue, print security is emerging as a critical risk in 2026. Learn the three trends forcing organizations to rethink printer and edge-device security.
#hackernews #news
From Quantum Resilience to Identity Fatigue: Three Trends Shaping Print Security in 2026
From quantum resilience to identity fatigue, print security is emerging as a critical risk in 2026. Learn the three trends forcing organizations to rethink printer and edge-device security.
securityboulevard.com
January 17, 2026 at 2:09 PM
Inside the Rise of the Always Watching, Always Learning Enterprise Defense System

Perimeter security is obsolete. Modern cyberresilience demands zero-trust, continuous verification, and intelligent automation that detects and contains threats before damage occurs.
#hackernews #news
Inside the Rise of the Always Watching, Always Learning Enterprise Defense System
Perimeter security is obsolete. Modern cyberresilience demands zero-trust, continuous verification, and intelligent automation that detects and contains threats before damage occurs.
securityboulevard.com
January 17, 2026 at 1:48 PM
GitLab Duo Agent Platform solves the AI paradox in software delivery

GitLab announced the GitLab Duo Agent Platform, delivering agentic AI that enables teams to orchestrate agents across the entire software lifecycle. AI tools have been improving developers’ ability to write code…
#hackernews #news
GitLab Duo Agent Platform solves the AI paradox in software delivery
GitLab announced the GitLab Duo Agent Platform, delivering agentic AI that enables teams to orchestrate agents across the entire software lifecycle. AI tools have been improving developers’ ability to write code, and in some cases, developers are reporting 10x productivity gains. Unfortunately, since only about 20% of a developer’s time is spent writing code, the associated improvement in total innovation velocity and delivery gained by AI is incremental. This is often described as the AI …
www.helpnetsecurity.com
January 17, 2026 at 1:27 PM
I let Anthropic's Claude Cowork loose on my files, and it was both brilliant and scary

Let's just say backups and restraint are nonnegotiable.
#anthropic #claude #hackernews
I let Anthropic's Claude Cowork loose on my files, and it was both brilliant and scary
Let's just say backups and restraint are nonnegotiable.
www.zdnet.com
January 17, 2026 at 1:07 PM
Building Resilient Financial Systems With Explainable AI and Microservices

AI-driven microservices often fail due to black-box decision-making. This IEEE award-winning research introduces a transparency-driven resilience framework using explainable AI to make automated actions in…
#hackernews #news
Building Resilient Financial Systems With Explainable AI and Microservices
AI-driven microservices often fail due to black-box decision-making. This IEEE award-winning research introduces a transparency-driven resilience framework using explainable AI to make automated actions interpretable and auditable. Tested on 38 services, it reduced MTTR by 42%, improved mitigation success by 35%, and accelerated incident triage—critical gains for regulated finance and insurance systems.
hackernoon.com
January 17, 2026 at 12:46 PM
RondoDox botnet linked to large-scale exploit of critical HPE OneView bug

Check Point observes 40K+ attack attempts in our hours, with government organizations under fire
A critical HPE OneView flaw is now being exploited at scale, with Check Point tying mass, automated attacks …
#hackernews #news
RondoDox botnet linked to large-scale exploit of critical HPE OneView bug
Check Point observes 40K+ attack attempts in our hours, with government organizations under fire A critical HPE OneView flaw is now being exploited at scale, with Check Point tying mass, automated attacks to the RondoDox botnet.…
go.theregister.com
January 17, 2026 at 12:25 PM
Google confirms Android 17 features that should make every fan excited - but I'd love to see these, too

Android 17, aka 'Cinnamon Bun,' is on the horizon, and there's already a lot of speculation about what it includes. Here's what I want with the next OS.
#hackernews #news
Google confirms Android 17 features that should make every fan excited - but I'd love to see these, too
Android 17, aka 'Cinnamon Bun,' is on the horizon, and there's already a lot of speculation about what it includes. Here's what I want with the next OS.
www.zdnet.com
January 17, 2026 at 12:04 PM
Microsoft: Windows 11 update causes Outlook freezes for POP users

Microsoft confirmed that the KB5074109 January Windows 11 security update causes the classic Outlook desktop client to freeze and hang for users with POP email accounts. [...]
#hackernews #microsoft #news
Microsoft: Windows 11 update causes Outlook freezes for POP users
Microsoft confirmed that the KB5074109 January Windows 11 security update causes the classic Outlook desktop client to freeze and hang for users with POP email accounts. [...]
www.bleepingcomputer.com
January 17, 2026 at 11:43 AM
These unassuming devices promised to lower my electricity bills - only this one was legit

If you spot one of these in a friend's or family member's power outlet, unplug it ASAP and use this instead.
#hackernews #news
These unassuming devices promised to lower my electricity bills - only this one was legit
If you spot one of these in a friend's or family member's power outlet, unplug it ASAP and use this instead.
www.zdnet.com
January 17, 2026 at 11:23 AM
Bankrupt scooter startup left one private key to rule them all

Owner reverse-engineered his ride, revealing authentication was never properly individualized
An Estonian e-scooter owner locked out of his own ride after the manufacturer went bust did what any determined engineer m…
#hackernews #news
Bankrupt scooter startup left one private key to rule them all
Owner reverse-engineered his ride, revealing authentication was never properly individualized An Estonian e-scooter owner locked out of his own ride after the manufacturer went bust did what any determined engineer might do. He reverse-engineered it, and claims he ended up discovering the master key that unlocks every scooter the company ever sold.…
go.theregister.com
January 17, 2026 at 11:02 AM
Operation Endgame: Dutch Police Arrest Alleged AVCheck Operator

Dutch police arrest the alleged AVCheck operator at Schiphol as part of Operation Endgame, a global effort targeting malware services and cybercrime.
#hackernews #news
Operation Endgame: Dutch Police Arrest Alleged AVCheck Operator
Dutch police arrest the alleged AVCheck operator at Schiphol as part of Operation Endgame, a global effort targeting malware services and cybercrime.
hackread.com
January 17, 2026 at 10:41 AM
Probably not the best security in the world: Carlsberg wristbands spill visitor pics

Researcher shows how anyone can access Copenhagen experience attendees' names, videos
Exclusive  The Carlsberg exhibition in Copenhagen offers a bunch of fun activities, like blending your own b…
#hackernews #news
Probably not the best security in the world: Carlsberg wristbands spill visitor pics
Researcher shows how anyone can access Copenhagen experience attendees' names, videos Exclusive  The Carlsberg exhibition in Copenhagen offers a bunch of fun activities, like blending your own beer, and the Danish brewer lets you relive those memories by making images available to download after the tour is over.…
go.theregister.com
January 17, 2026 at 10:20 AM
Your Digital Footprint Can Lead Right to Your Front Door

You lock your doors at night. You avoid sketchy phone calls. You’re careful about what you post on social media.
But what about the information about you that’s already out there—without your permission?
Your name. Home add…
#hackernews #news
Your Digital Footprint Can Lead Right to Your Front Door
You lock your doors at night. You avoid sketchy phone calls. You’re careful about what you post on social media. But what about the information about you that’s already out there—without your permission? Your name. Home address. Phone number. Past jobs. Family members. Old usernames. It’s all still online, and it’s a lot easier to find than you think. The hidden safety threat lurking online Most
thehackernews.com
January 17, 2026 at 9:59 AM
Hackers now exploiting critical Fortinet FortiSIEM flaw in attacks

Attackers are now exploiting a critical Fortinet FortiSIEM vulnerability with publicly available proof-of-concept exploit code. [...]
#hackernews #news
Hackers now exploiting critical Fortinet FortiSIEM flaw in attacks
Attackers are now exploiting a critical Fortinet FortiSIEM vulnerability with publicly available proof-of-concept exploit code. [...]
www.bleepingcomputer.com
January 17, 2026 at 9:39 AM
LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing

Security experts have disclosed details of a new campaign that has targeted U.S. government and policy entities using politically themed lures to deliver a backdoor known as LOTUSLITE.
The targe…
#hackernews #news
LOTUSLITE Backdoor Targets U.S. Policy Entities Using Venezuela-Themed Spear Phishing
Security experts have disclosed details of a new campaign that has targeted U.S. government and policy entities using politically themed lures to deliver a backdoor known as LOTUSLITE. The targeted malware campaign leverages decoys related to the recent geopolitical developments between the U.S. and Venezuela to distribute a ZIP archive ("US now deciding what's next for Venezuela.zip")
thehackernews.com
January 17, 2026 at 9:18 AM
China-linked APT UAT-9686 abused now patched maximum severity AsyncOS bug

Cisco fixed a maximum severity AsyncOS flaw in Secure Email products, previously exploited as a zero-day by China-linked APT group UAT-9686. Cisco fixed a critical AsyncOS flaw, tracked as CVE-2025-20393 (C…
#hackernews #news
China-linked APT UAT-9686 abused now patched maximum severity AsyncOS bug
Cisco fixed a maximum severity AsyncOS flaw in Secure Email products, previously exploited as a zero-day by China-linked APT group UAT-9686. Cisco fixed a critical AsyncOS flaw, tracked as CVE-2025-20393 (CVSS score of 10.0), affecting Secure Email Gateway and Email and Web Manager, previously exploited as a zero-day by China-linked APT group UAT-9686. Cisco detected attacks […]
securityaffairs.com
January 17, 2026 at 8:57 AM