#1 Trusted Cybersecurity News Platform
Followed by 5.20+ million
The Hacker News Logo
Subscribe – Get Latest News

hide | Breaking Cybersecurity News | The Hacker News

Category — hide
The Invisible Cybersecurity Challenge Transforming Advanced Power Grids: How Enterprise Asset Visibility Is Strengthening Critical Infrastructure Stability

The Invisible Cybersecurity Challenge Transforming Advanced Power Grids: How Enterprise Asset Visibility Is Strengthening Critical Infrastructure Stability

Sept 06, 2026
Why Cyber Asset Visibility Matters More Than Ever The California wildfire crisis reshaped the utility industry's approach to risk. Investigations into major wildfire events underscored the need for strong infrastructure, asset maintenance, operational oversight, vegetation management, and timely risk identification. Litigation and regulatory actions led utilities to invest billions in grid modernization, advanced monitoring, asset management, inspection technologies, and operational resilience. Suchismita Chatterjee, a cybersecurity product specialist who works on governance, risk, and compliance for a large U.S. electric utility, approached the problem from a different angle. "My work did not focus directly on wildfire prevention," she said. "It addressed an equally critical question." Working within the U.S. utility sector, Chatterjee has supported cybersecurity initiatives for North American Electric Reliability Corporation (NERC) regulated environmen...
April's $621 Million in DeFi Hacks Traced Mostly to Stolen Keys and Permissions

April's $621 Million in DeFi Hacks Traced Mostly to Stolen Keys and Permissions

Sept 03, 2026
April 2026 produced $621 million in decentralized finance hacks, the sector's worst month since March 2022, with 66% of the damage traced to compromised access controls rather than smart-contract flaws, according to Binance Research. The losses were not caused by code that failed. They were caused by permissions that ended up in the wrong hands. A Record Number of Incidents, and Almost None of the Damage Contracts have got harder to break, and that is the point. Years of audits and hardened engineering pushed the attack outward, onto the keys and credentials and the infrastructure a team logs into every morning. Most months bury that shift inside a single headline number. April did the opposite: its internal composition points the other way from its total. DL News counted 29 separate incidents across the month, the highest count it has recorded, and 24 of those came from ordinary code bugs. Those two dozen contract bugs produced about $42 million between them, which ...
The AI Agent in Your Stack Is a Privileged User. Most Small Companies Have No Way to Govern It

The AI Agent in Your Stack Is a Privileged User. Most Small Companies Have No Way to Govern It

Sept 01, 2026
Machine identities already outnumber human ones. For organizations without an identity function, the reachable control sits at the network layer. In access-control terms, an AI assistant that can read a customer database, move files between systems, or call an internal API is a user. It holds credentials, acts on resources, and if it is over-permissioned it becomes one more route into the network that nobody is watching. Small and midsize companies are wiring these agents into daily operations at speed. Very few have a way to decide what a given bot is allowed to touch. The scale is no longer arguable. Palo Alto Networks' 2026 Identity Security Landscape, drawn from a survey of more than 2,900 cybersecurity decision-makers, puts machine identities at 109 for every human. The same research found 96% of respondents reporting that human identities operate with access far beyond what their roles require. 109:1 machine identities to human identities, across 2,900+ organization...
Why Cloud Security Teams Need Risk Context, Not More Alerts

Why Cloud Security Teams Need Risk Context, Not More Alerts

Aug 26, 2026
Alerts in the context of cloud security can be useful, but they require the right procedures in place to effectively act on them. Cloud security posture management (CSPM) is becoming increasingly valuable as more businesses and organizations make use of services like SaaS and IaaS to power their routine operations. The problem is, as modern cloud environments become more complex, traditional alert-by-alert security management processes become less useful. While knowing what problems are out there is useful, without the right context, knowing which problems to prioritize is much harder. One potential solution is to seek out services that are adequately prepared for this issue, thus making the best CSPM vendor one that understands which weaknesses matter together. When Cloud Scale Makes Raw Data Less Useful Modern cloud environments are, in a word, expansive. As companies take on more data, such environments necessarily grow in response. These changes might take the form of infra...
Evaluating the Real Impact of an AI SOC Agent in 2026

Evaluating the Real Impact of an AI SOC Agent in 2026

Aug 17, 2026
An AI SOC agent promises faster triage, fewer missed alerts, and analysts freed from repetitive work. This guide examines what an AI SOC Agent actually delivers, the prerequisites for AI-driven SOC automation, how to test explainability, and the practical benchmarks security leaders should use before signing a contract. Why your SOC needs an AI SOC agent today Most security operations centers are not failing because they lack detection technology. They are failing because the volume of signals produced by that technology exceeds what a human team can review with any consistency. A mid-sized organization routinely generates tens of thousands of alerts per week across endpoint, identity, cloud, and network telemetry, and analyst attention is the scarcest resource in the building. The pressures forcing the conversation Alert volume outpacing headcount: Detection coverage keeps expanding while SOC staffing stays flat or shrinks. Attacker speed: Credential abuse and ransomw...
AI Agent Security Risks: What Enterprise Teams Need to Know 

AI Agent Security Risks: What Enterprise Teams Need to Know 

Jul 22, 2026
Enterprises are deploying AI agents faster than their identity security programs can keep pace with. Every agent that enters production carries inherited permissions, operates outside traditional IAM visibility, and makes consequential decisions without human sign-off at each step. What is agentic AI in identity security, who owns the risk it generates, and what controls actually work at scale: that's what this guide covers. Why AI Agent Risk Doesn't Behave Like Traditional Security Risk Most enterprise security models rest on a foundational assumption: a human initiates access, a policy evaluates that request, and a control either permits or denies it. AI agents break every link in that chain simultaneously. Understanding what agentic AI in identity security is requires moving beyond the surface-level observation that agents are "automated." Automation has existed in enterprise environments for decades. What makes agentic AI categorically different is autonom...
Cybersecurity Resources