Hacker Noon Cybersecurity.
HackerNoon – cybersecurity Hacking is not a crime! Or is it? Well, it depends on which hat you are wearing. Find all about Offense-Defense dilemmas, theories, and practicals here!
- IEC 60870-5-104 Security: A Packet-Level Analysisby RUGERO Tesla on August 26, 2026 at 2:37 am
I dissected IEC 60870-5-104 from the wire up, tested its APCI state machine, ASDU/control paths, and parser boundaries, then compared the cleartext attack surface against IEC 62351 TLS and authorization controls.Read All
- Why Print Jobs Shouldn’t Live Forever in Chat Appsby Abhinay Gokul Pulla on August 26, 2026 at 2:34 am
Print jobs should be temporary. Docshy replaces chat-based printing with an encrypted relay designed to delete files after the job is done.Read All
- Claude Opus 5 Code Quality: What Sonar’s Benchmark Revealsby Sonar on August 25, 2026 at 4:40 am
Claude Opus 5 hits an 88.6% coding pass rate, with lower bug and vulnerability density—but generates 2.3× more code than Opus 4.8.Read All
- When an Expired Domain Becomes a Security Problemby Marek "Netbe" Lampart on August 25, 2026 at 1:09 am
Expired domains aren’t just an SEO asset — they can become a cybersecurity risk. Old domains may still be referenced in documentation, DNS, email systems, APIs and external websites. If someone else registers the domain, that forgotten digital footprint can potentially be abused. Organizations should treat domain retirement as part of their security lifecycle and audit dependencies before allowing a domain to expire.Read All
- Claude Code Hooks: How to Stop AI Agents From Breaking Your Codeby Sonar on August 24, 2026 at 5:39 am
Learn how Claude Code hooks create deterministic guardrails that block dangerous commands and verify AI-generated code before problems ship.Read All
- Everything Protocol Solves DeFi by Deleting the Price Oracle, the Part Attackers Keep Breakingby Ishan Pandey on August 23, 2026 at 3:45 pm
Everything Protocol published a whitepaper on 20 August 2026 setting out a DeFi architecture in which a single reserve per token pair simultaneously prices swaps, backs loans and leveraged positions and supports resting limit orders. Liquidity earns swap fees while supporting the credit market, and eligible capital resting in limit orders can opt into lending and earn borrower interest until those orders execute. The design removes the external price oracle, deriving credit terms from an internal price band computed from the pool’s own trading state and time, fixed within a block and adjusted under predefined decay and clamp rules. The paper also sets out a solvency hierarchy in which user escrow sits outside the pricing reserve, filled-order proceeds rank senior, and eligible liquidation losses are written down against the junior liquidity provider tranche first.Read All
- Flowra Launches Open Orderflow Auction, Bringing Ethereum’s Block-Building Market to Solanaby Ishan Pandey on August 22, 2026 at 3:47 am
Flowra launched its Open Orderflow Auction on 21 August 2026, a block-building framework that lets registered searchers bid openly for Solana transaction inclusion instead of routing through closed orderflow channels. The Seoul-based company also introduced Programmable Block Policy, which lets validators define their own transaction inclusion rules at the block-building layer without changes to the Solana protocol, with sanctions and risk screening supplied through a collaboration with Honeypot. In early testing on a single validator, a Flowra-enabled setup raised compute units per block by 20.6%, moving that node from 84% to 101% of the network average, with 100% block production and 99.999% block engine uptime.Read All
- How CertiK Found Five Vulnerabilities in Besu and Got Them Fixed in a Fortnightby Ishan Pandey on August 21, 2026 at 3:06 pm
CertiK reported five resource exhaustion bugs to the Besu maintainers who shipped the fixes within a fortnight and then published severity ratings that disagreeRead All
- What Changes When You Put a Local AI Project Onlineby Kashif Nazir on August 21, 2026 at 5:55 am
Local AI prototypes inherit security, identity, storage and cost controls from the laptop running them. Moving the same code onto a public URL exposes those hidden dependencies: MCP authentication, OAuth registration, permission models, resilience, abuse controls and who pays for inference. Hosting the code is easy; replacing the platform your machine quietly provided is the real work.Read All
- IEC 104 Explained: Protocol Stack, Frames, and Securityby RUGERO Tesla on August 21, 2026 at 5:53 am
IEC 104 carries SCADA telemetry and control over TCP/2404. This primer breaks down its framing, I/S/U formats, ASDUs, security boundaries, and IEC 62351 extensions before going on-wire.Read All
- Bring Your Own Hook: a 5-line PostToolUse Template Calling Sonar Analyze Agenticby Sonar on August 21, 2026 at 5:28 am
Build a five-line Claude Code hook that runs SonarQube Vortex Agentic Analysis after every edit and feeds CI-grade findings back to Claude.Read All
- The Hidden Risk in Beneficial Ownership Registersby Nadav Gover on August 20, 2026 at 7:24 am
The breach of Liechtenstein beneficial ownership data reveals that structural risk extends beyond physical assets. When ownership data is centralized across institutions, single-point failures expose entire capital structures. Protecting cross-border assets requires applying Zero Trust principles to information architecture. Read All
- How an AutoGPT Email Block Became an SSRF Surfaceby Pavan Nallamothu on August 20, 2026 at 7:17 am
AutoGPT enforces strict SSRF protections on its HTTP layer. But the SendEmailBlock uses Python’s smtplib to open raw TCP sockets, bypassing the blocklist entirely. Pointing this block at internal SSH or Redis ports forces smtplib to throw an exception that leaks the service banner directly in the API response. Authenticated users can map the internal network and identify vulnerable services from a single text field. Fixed in backend 0.6.52 by extending IP validation to all outbound protocols. Read All
- Tokenomics of Quality: Switch Sonar List Issues to –Format Toon for Measured Token Savingsby Sonar on August 20, 2026 at 7:12 am
Learn how TOON can cut AI coding-agent token usage by roughly a third to a half versus JSON using one simple Sonar CLI flag.Read All
- How to Stop Context Rot in Coding Agentsby Samuel Oladipupo on August 20, 2026 at 7:01 am
Coding agents get worse as investigative debris fills their context. Learn how subagents keep Claude Code focused and effective for longer sessions.Read All
- Are Humans Superior to AI—or Becoming Subordinate?by Emir Mirzamuhamed on August 19, 2026 at 6:29 am
Are we ≤ AI or are we ≥ AI ?…Read All
- SecurityMetrics Wins Cybersecurity Audit Team of the Year from the Hacker Newsby PR SecurityMetrics on August 18, 2026 at 12:59 pm
SecurityMetrics’ Audit team has won the Cybersecurity Audit Team of the Year award from the Hacker News. This award highlights the Audit team’s expertise and commitment to streamlining the compliance process for their clients.Read All
- Businesses Always Have Messy Emails (Part 2)by Arthur on August 18, 2026 at 6:32 am
Cross-team collaboration introduces additional complexity, and the volume of information being shared grows rapidly. Managing access rights, protecting customer information, and preventing accidental data exposure become increasingly difficult.Read All
- OpenMatter Network to Take Verification Message to Belgrade Blockchain Week 2026by CyberNewswire on August 17, 2026 at 10:39 pm
Head of Operations and Partnerships Chris Biele to lead sessions on secure scientific collaboration, agentic AI and the need to move from trust to cryptographicRead All
- One OPC UA GetEndpoints Request Exposed Five Security Configurations – I Followed the Weakest Oneby RUGERO Tesla on August 17, 2026 at 10:07 pm
A single OPC UA `GetEndpoints` request exposed five security configurations, including a `SecurityPolicy#None` endpoint. Following that path led to an accepted anonymous session, recursive address-space traversal, and successful writes to five variables. The lab also tested the other security boundaries: invalid username credentials and an independently generated self-signed X.509 certificate were both rejected. The complete scripts, packet captures, screenshots, and research notes are available in the OPC UA research repository : https://github.com/404saint/industrial-protocol-labs/tree/main/opcua-research. Read All



