Bento
HN Top
Top Hacker News stories for AI builders, hackers, and founders.
A sentimental tour of late 1990s and early 2000s hacking tools
Fragnesia Made Public as Latest Linux Local Privilege Escalation Vulnerability
Deterministic Fully-Static Whole-Binary Translation Without Heuristics
CERT is releasing six CVEs for serious security vulnerabilities in dnsmasq
Canada's Bill C-22 Is a Repackaged Version of Last Year's Surveillance Nightmare
Dead.letter (CVE-2026-45185) Humans vs. LLM for Unauthenticated RCE Race on Exim
Postmortem: TanStack npm supply-chain compromise
Can someone please explain whether Cloudflare blackmailed Canonical?
Mythos Finds a Curl Vulnerability
Obsidian plugin was abused to deploy a remote access trojan
Stop MitM on the first SSH connection, on any VPS or cloud provider
Incident Report: CVE-2024-YIKES
Hardware Attestation as Monopoly Enabler
Tracesofhumanity.org by Joanna Rutkowska
Scientists warn Atlantic current at risk of shutting down
FreeBSD – A Lesson in Poor Defaults
User just tricked Grok and Bankrbot to send tokens with Morse code
Local privilege escalation via execve()
"Dirty Frag" (CVE-2026-43284): The Second Linux Root Exploit in Eight Days
CPanel's Black Week: 3 New Vulnerabilities Patched After Attack on 44k Servers
GrapheneOS fixes Android VPN leak Google refused to patch
The React2Shell Story
Dirty Frag: Universal Linux LPE
Non-determinism is an issue with patching CVEs
Man Finds $1M Worth of Yu-Gi-Oh Cards in a Dumpster
AI is Breaking Two Vulnerability Cultures
Four stable kernels with partial fixes for Dirty Frag
Podman rootless containers and the Copy Fail exploit
Hackers breach JDownloader website to serve malware-laced downloads
US will start revoking passports for parents who owe child support
Hardening Firefox with Claude Mythos Preview
GNU IFUNC is the real culprit behind CVE-2024-3094
Rolling the Root Key
Canvas is down as ShinyHunters threatens to leak schools' data
Mozilla says 271 vulnerabilities found by Mythos and "almost no false positives"
Dirtyfrag: Universal Linux LPE
How Cloudflare responded to the "Copy Fail" Linux vulnerability
ADT says customer data stolen in cyber intrusion
David Sacks crashed and burned in the White House
Mythos is the best cybersecurity news in a decade
Google Cloud Fraud Defense, the next evolution of reCAPTCHA
From Supabase to Clerk to Better Auth
Five Banana Lessons
Clarification on the Notepad++ Trademark Issue
Quantum Key Distribution (QKD) and Quantum Cryptography (QC)
Biscuit
Gaps in national food production, worldwide
CVE-2026-31431: Copy Fail vs. rootless containers