#1 Trusted Cybersecurity News Platform
Followed by 5.20+ million
The Hacker News Logo
Subscribe – Get Latest News

Web Security | Breaking Cybersecurity News | The Hacker News

Category — Web Security
When AI Writes the Code, Who Owns the Security Decisions?

When AI Writes the Code, Who Owns the Security Decisions?

Oct 05, 2026
AI is changing software development by compressing work that once took days into hours. Code can be generated, tested, refactored, and documented faster, allowing development teams to deliver functionality at a pace that was previously difficult to achieve.  That acceleration creates an important challenge for security teams.  AI-powered software development can accelerate innovation, but it can also introduce hidden vulnerabilities when security implications are not clearly understood. Watch this webinar series on AI threat realities and proactive security readiness to gain firsthand knowledge of what makes this AI threat unique, coupled with remediation guidance for long-term resilience:  This series also explores how organizations can securely adopt and implement AI at business speed without losing control of cyber risk.  The risk is not simply that AI-generated code can contain vulnerabilities. Human-written code has always contained vulnerabilities....
The Login Worked. That Was the Attack.

The Login Worked. That Was the Attack.

Sept 21, 2026
Session theft has been productized. The control most organizations still treat as the finish line does not touch it. Somewhere in your environment this quarter, an employee is going to authenticate correctly. Right password, right second factor, right device, no failed attempts, no alert. And an attacker is going to be inside that account seconds later, holding a session your identity provider considers entirely legitimate. That is the documented operating model of at least two commercial phishing services running right now, one of them a $320-a-month kit called NovaCookies, and it is what happened to a set of customers at one of the most security-literate software companies in the industry within the last month. What makes these attacks uncomfortable is not just their sophistication, but also that they are cheap, rented, and specifically engineered to produce a sign-in event that looks ordinary. The $320 Phishing Kit Selling Session Theft as a Service Researchers at Island di...
Why Deepfake Legislation Won't Save the 2026 Elections

Why Deepfake Legislation Won't Save the 2026 Elections

Sept 21, 2026
As the 2026 election cycle hits full stride with midterms approaching, the threats that voters, campaigns, and candidates are coming face-to-face with have completely changed from even two years ago. In 2024, most synthetic media and generative AI attacks were still unpolished, easy to spot, and deployed in isolated experiments.  Fast forward to today, and AI tools have grown up fast. What used to be scrappy proof-of-concept attacks are now slick, automated operations running at scale. That shift changes everything about what election security actually means. It's no longer just about locking down voter rolls or hardening voting machines. The real fight has moved upstream, into the channels where public trust gets shaped in the first place. If you're a security leader, a campaign staffer, or someone running digital infrastructure, the old perimeter-defense playbook won't cut it anymore.  For campaign security teams, that means the job has expanded well beyond protec...
When Your Browser Becomes The Attacker: AI Browser Exploits

When Your Browser Becomes The Attacker: AI Browser Exploits

Feb 02, 2026
AI-powered browsers are changing how we use the web, but they're also creating some serious new security risks. Tools like Perplexity's Comet and Opera's Neon can summarize pages and automate tasks for you. The problem is that researchers have found these agentic copilots can be hijacked by malicious prompts hidden in ordinary webpages, essentially turning your browser against you. In August 2025, Brave's security team disclosed an indirect prompt injection against Perplexity's Comet using hidden instructions in a Reddit spoiler tag, leading Comet to extract an email address and a one-time passcode. No memory corruption, no code execution exploit. The browser simply followed instructions it couldn't distinguish from legitimate user intent. In this post, we'll look at how these attacks work, why they slip past traditional defenses, and what security teams can do to keep data safe from compromised AI agents. AI Browsers: Powerful, But a New Target AI-ena...
Cybersecurity Resources