2026-09-22
[Bleeping Computer]
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users’ passwords during legitimate login attempts. […]
#security
2026-09-22
[Bleeping Computer]
Sweden’s data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. […]
#security #government #legal
2026-09-22
[Bleeping Computer]
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. […]
#security #government
2026-09-22
[Dark Reading]
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
#phishing #windows
2026-09-22
[The Record]
The investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release.
#cybercrime #government #news #news-briefs #privacy
2026-09-22
[Bleeping Computer]
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. […]
#security
2026-09-22
[CERT/CC]
Overview
Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash in the UEFI Authorized Signature Database (DB)…
2026-09-22
[Bleeping Computer]
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. […]
#security #artificial-intelligence
2026-09-22
[The Hacker News]
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.
On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixe…
#patch
2026-09-22
[The Hacker News]
Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.
The package, named “tw-pkgprobe-7731,” was…
#authentication
2026-09-22
[SecurityWeek]
The attackers used a compromised BigCommerce application key held by Ribon to access customer data.
The post BigCommerce Data Stolen via Ribon Apps Hack appeared first on SecurityWeek.
#data-breaches #supply-chain-security #bigcommerce #data-breach #ribon
2026-09-22
[Dark Reading]
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee’s computer through the TanStack npm supply chain attack.
#apt #supply-chain
2026-09-22
[Bleeping Computer]
Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. [….
#security
2026-09-22
[Dark Reading]
As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.
2026-09-22
[The Hacker News]
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”
The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the e…
#phishing #windows
2026-09-22
[The Hacker News]
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.
The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versio…
#vulnerability #authentication
2026-09-22
[Bleeping Computer]
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. […]
#security
2026-09-22
[The Record]
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.
#cybercrime #government #news
2026-09-22
[Malwarebytes Labs]
Tests found that some cheap smart glasses can be hijacked over Bluetooth, exposing their owners’ photos, videos, and personal data.
#bugs #news #privacy #security #smart-glasses
2026-09-22
[Microsoft Security]
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and oper…
#adversary-in-the-middle-aitm #phishing
2026-09-22
[Bleeping Computer]
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft’s Digital Crimes Unit (DCU). […]
#security
2026-09-22
[SecurityWeek]
The data security company received the new investment from Goldman Sachs Alternatives, extending its Series G funding round.
The post Cyera Raises $400 Million at $12+ Billion Valuation appeared first on SecurityWeek.
#cybersecurity-funding #data-protection #cyera #data-security #funding
2026-09-22
[Infosecurity Magazine]
WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets
#authentication
2026-09-22
[SecurityWeek]
Abdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse.
The post Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity appeared first on SecurityWeek.
#vulnerabilities #bigdiskbuster #chaotic-eclipse #controversy #featured
2026-09-22
[The Record]
Dave Chismon, the NCSC’s chief technology officer for architecture, said in a blog post that the imbalance in AI means cyberattacks would likely grow as automated defenses struggle to keep pace.
#cybercrime #news #technology
2026-09-22
[Infosecurity Magazine]
A new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressure
2026-09-22
[Bleeping Computer]
Tomorrow’s webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. […]
#security
2026-09-22
[Bleeping Computer]
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. […]
#security
2026-09-22
[The Hacker News]
Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has?
A person may try several ways to complete a task. A deterministic application fol…
2026-09-22
[The Hacker News]
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.
The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and aff…
#vulnerability
2026-09-22
[SecurityWeek]
Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets.
The post Only 13% of OT Network Segments Are Fully Isolated: Analysis appeared first on SecurityWeek.
#icsot #iot-security #network-security #forescout #iomt
2026-09-22
[CISA Alerts]
View CSAF
Summary
Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected pr…
#vulnerability #authentication
2026-09-22
[CISA Alerts]
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives.
The following versions …
#vulnerability
2026-09-22
[Infosecurity Magazine]
Forescout warns that incomplete network segmentation is widening the potential blast radius of attacks
2026-09-22
[Dark Reading]
Industrial companies are increasing cybersecurity investment as connected operations, AI adoption, and IT/OT convergence expand operational risk.
2026-09-22
[CISA Alerts]
View CSAF
Summary
Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system.
The following versions of lwIP (Lightweight IP) are affected:
API >=2.0.1|<=2.2.1 (CVE-2026-91018)
CVSS
Vendor
E…
#vulnerability
2026-09-22
[SecurityWeek]
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches.
The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek.
#vulnerabilities #exploited #switch #vulnerability #zyxel
2026-09-22
[The Hacker News]
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and docume…
2026-09-22
[The Hacker News]
A new flaw in the Linux kernel’s KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled.
The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the resea…
#vulnerability #linux
2026-09-22
[SecurityWeek]
Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method.
The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek.
#application-security #supply-chain-security #npm #supply-chain-attack
2026-09-22
[The Hacker News]
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa.
The flaw, CVE-2026-65660…
#vulnerability #rce #windows
2026-09-22
[Schneier on Security]
This is pretty amazing:
However, the most astonishing thing about this break is that the GPT6 Astra did it entirely on its own. Carter Leffer only directed GPT6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the …
#uncategorized #ai #cryptanalysis #enigma #history-of-cryptography
2026-09-22
[Infosecurity Magazine]
Akamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threats
2026-09-22
[SecurityWeek]
The bug lets attackers automatically install and preview themes and could lead to remote code execution.
The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek.
#vulnerabilities #click2shell #patch #vulnerability #wordpress
2026-09-22
[Bleeping Computer]
Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. […]
#security #microsoft
2026-09-22
[The Hacker News]
A malicious npm package named “indexed-btree” has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls.
“Indexed-btree is a malicious npm package mim…
#apt
2026-09-22
[Infosecurity Magazine]
Gartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detect
#phishing
2026-09-22
[Bleeping Computer]
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). […]
#security
2026-09-22
[SecurityWeek]
The US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign.
The post Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme appeared first on SecurityWeek.
#nation-state #fake-it-workers #fbi #featured #japan
2026-09-22
[The Hacker News]
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.
“SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.ex…
#phishing #apt
2026-09-22
[The Hacker News]
Malware already running on a Mac can quietly take over Meta’s Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21.
It works by changing a hidden setting so that when the user taps the micropho…
#malware
2026-09-22
[The Hacker News]
A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site’s server.
WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed “Comment2Shell,” on Sep…
#vulnerability #rce #xss
2026-09-22
[The Hacker News]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerability, tracked as CVE-2026-7273 (CVSS score: …
#vulnerability #patch
2026-09-22
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco ThousandEyes Virtual Appliance. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20350.
#vulnerability #rce #authentication #injection
2026-09-22
[SecurityWeek]
Trump has resisted calls to slow down AI development, saying that would help China catch up to U.S. companies.
The post US Proposes AI Incident Alert System in Talks With China, Bessent Says appeared first on SecurityWeek.
#artificial-intelligence
2026-09-21
[The Record]
Russia’s growing restrictions on mobile internet and cellular service are making it harder for people to receive warnings about incoming Ukrainian drone and missile attacks.
#government #news
2026-09-21
[Dark Reading]
Unbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.
2026-09-21
[Bleeping Computer]
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. […]
#security
2026-09-21
[Bleeping Computer]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. […]
#security #linux
2026-09-21
[Dark Reading]
ShinyHunters defaced Clop’s Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.
2026-09-21
[The Record]
Ireland’s Data Protection Commission will fine Google more than €403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020.
#news #news-briefs #privacy
2026-09-21
[Dark Reading]
Victims have been identified in Africa, including in Kenya and Uganda.
#malware
2026-09-21
[Bleeping Computer]
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed ‘Click2Shell’ that affects the platform’s Core component. […]
#security
2026-09-21
[Bleeping Computer]
Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. […]
#microsoft
2026-09-21
[The Hacker News]
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.
Microsoft’s own hardware-c…
#malware #windows #linux
2026-09-21
[SecurityWeek]
Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data.
The post Google Hit With $463 Million Fine for EU Location Data Rule Breach appeared first on SecurityWeek.
#privacy--compliance #fine #gdpr #google #privacy
2026-09-21
[The Hacker News]
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory.
The primary targets …
#apt #authentication
2026-09-21
[Malwarebytes Labs]
This week on the Lock and Code podcast, we speak with Emanuel Maiberg about Amazon’s effort to scan and destroy rare books for AI training.
#podcast #404-media #ai #ai-training #amazon
2026-09-21
[SecurityWeek]
The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.
The post Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer appeared first on SecurityWeek.
#malware--threats #edr-killer #infostealer #lastpass #malware
2026-09-21
[Bleeping Computer]
Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users’ location data. […]
#security #google #legal
2026-09-21
[Malwarebytes Labs]
More than 100 linked sites use a $249 toolkit to turn copied product names and unfamiliar AI brands into paid subscriptions.
#ai #scams #threat-intel
2026-09-21
[AWS Security]
Security teams investigating possible AI-related security events need guardrail intervention data alongside their existing security telemetry. When a guardrail identifies or blocks a prompt injection attempt or redacts sensitive data, that intervention carries additional investigative value comparab…
#advanced-300 #amazon-bedrock #amazon-bedrock-guardrails #security-identity--compliance #amazon-athena
2026-09-21
[Infosecurity Magazine]
The Irish DPC found that Google users were unaware that their location was being used to influence them with ads
#privacy
2026-09-21
[The Record]
Belgium’s national table tennis federation is investigating a cyberattack after a hacker claimed to have stolen data on tens of thousands of members.
#news #news-briefs #cybercrime
2026-09-21
[Dark Reading]
The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.
2026-09-21
[Bleeping Computer]
Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. […]
#microsoft
2026-09-21
[Infosecurity Magazine]
Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic
2026-09-21
[SecurityWeek]
Noopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be.
The post CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast appeared first on SecurityWeek.
#ciso-conversations #ciso-strategy #ciso
2026-09-21
[The Hacker News]
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.
The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost t…
#zero-day #rce
2026-09-21
[Malwarebytes Labs]
Gemini crossed the boundaries of a capture-the-flag test and accessed systems belonging to three real companies.
#ai #news #ai-models #alignment #gemini
2026-09-21
[The Hacker News]
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.
The backdoor “automatically harvests and exfiltrates business documents, watches the filesystem for new files in real t…
#malware
2026-09-21
[Bleeping Computer]
The FBI’s CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upc…
#security
2026-09-21
[The Record]
The university, commonly known as LMU Munich, said Saturday that an attacker accessed enrollment data stored on one of its IT systems.
#cybercrime #news
2026-09-21
[SecurityWeek]
The transaction is part of the $4.1 billion deal in which Accenture acquired a majority stake in Dragos in an OT cybersecurity push.
The post Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal appeared first on SecurityWeek.
#ma-tracker #accenture #acquisitions #dragos #ma
2026-09-21
[Infosecurity Magazine]
CloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenance
2026-09-21
[Bleeping Computer]
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. […]
#microsoft #security
2026-09-21
[The Record]
The agreement between LinkedIn, ProAPIs and joint business operator Netswift also requires the firms to stop selling and transferring the data, no longer access LinkedIn through fake accounts and delete the data that was scraped, according to a senior LinkedIn executive.
#news #news-briefs #privacy
2026-09-21
[Infosecurity Magazine]
ShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational data
#ransomware
2026-09-21
[The Record]
Google’s artificial intelligence model Gemini accessed computer systems belonging to three real companies without authorization during a cybersecurity test in May — the latest in a string of similar incidents.
#news #news-briefs #industry
2026-09-21
[SecurityWeek]
It’s unclear if the attacks are part of previous campaigns against Rust, but the techniques used by the attackers match those used by North Korea.
The post Rust Team Members and Popular Crate Owners Targeted via Video Calls appeared first on SecurityWeek.
#supply-chain-security #north-korea #rust #supply-chain-attack
2026-09-21
[Bleeping Computer]
Microsoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates. […]
#microsoft
2026-09-21
[SecurityWeek]
The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.
The post CrowdSec Confirms Source Code Stolen in Supply Chain Attack appeared first on SecurityWeek.
#data-breaches #supply-chain-security #crowdsec #data-breach #source-code
2026-09-21
[Malwarebytes Labs]
Hackers hacked the hackers as a feud between two cybercrime groups escalated, leaving ShinyHunters with the upper hand over rival Clop.
#news #clop #fight #shinyhunters
2026-09-21
[SecurityWeek]
The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said.
The post Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems appeared first on SecurityWeek.
#icsot #nation-state #cyberattack #ics #ot
2026-09-21
[Kaspersky Securelist]
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.
#active-directory #data-leaks #data-theft #detection-engineering #digital-forensics
2026-09-21
[Palo Alto Unit 42]
We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies.
The post From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies appeared first on Unit 42.
#cloud-cybersecurity-research #threat-research #aws #aws-cloudtrail #bedrock
2026-09-21
[SecurityWeek]
Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory.
The post Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities appeared first on SecurityWeek.
#vulnerabilities #cisa-kev #exploited #linux #linux-kernel
2026-09-21
[Infosecurity Magazine]
A breach at image-sharing service Gyazo on September 11 affected over 23 million customers
2026-09-21
[ESET WeLiveSecurity]
As AI opens new paths to company data while making familiar attacks faster and cheaper, SMBs need protection designed around the time and expertise available to operate it
#business-security
2026-09-21
[Infosecurity Magazine]
Following a major data breach, Revolut customers are being sent convincing phishing messages
#phishing #data-breach
2026-09-21
[The Hacker News]
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.
“ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zo…
#malware #apt
2026-09-21
[SecurityWeek]
Google is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies.
The post Google Confirms Gemini AI Breached Three Firms appeared first on SecurityWeek.
#artificial-intelligence #ai #featured #gemini #google
2026-09-21
[Google Project Zero]
This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804, that I and 14 others reported. This issue is an incomplete fix for CVE-2026-50343, a bug dubbed “Dark Elevator” by Calif. The root cause of the bug was a dangling COM object reg…
#vulnerability #windows
2026-09-21
[The Hacker News]
The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based “much smaller organization” in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks.
Cybersecuri…
#malware #apt
2026-09-21
[Elastic Security Labs]
Cloud threat emulation is more than detonation. A plan-first methodology for cloud detection engineering: scope, victim model, telemetry, coverage, cleanup. Learn how to properly leverage AI to automate your emulations.
#detection-engineering
2026-09-20
[The Record]
Claims by officials of cyberattacks against election infrastructure could not be independently verified. Russian officials provided little technical evidence about the attacks or who it claimed who was behind them.
#government #cybercrime #news
2026-09-20
[Bleeping Computer]
An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts. […]
#security
2026-09-20
[Bleeping Computer]
Researchers escaped OpenAI’s Codex sandbox two ways, one running commands on a developer’s machine from its most locked-down mode. OpenAI has patched both. […]
#security
2026-09-19
[SecurityWeek]
The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA.
The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.
#cybersecurity-funding #funding #tigerbyte-cyber
2026-09-19
[Bleeping Computer]
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation’s data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. […]
#security
2026-09-19
[The Hacker News]
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon’s annual Data Breach Investigations Report. This article explains what identity visibility …
#data-breach #authentication
2026-09-19
[Bleeping Computer]
AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her “Talking Tilly” video call service face-scans every caller for an 18+ age check, senses callers’ moods during calls, and shuts down permanently on September 27. We tried it and read the fine p…
#security
2026-09-19
[The Hacker News]
Three researchers at the security firm Hacktron used Anthropic’s Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.
The chain began with a bug in the software that runs OpenAI’s public help forum …
2026-09-19
[The Hacker News]
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.
The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring s…
#vulnerability #rce #patch
2026-09-19
[The Hacker News]
Google’s Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal.
The incidents occurred in May 2026 as part of a test run conducted …
2026-09-19
[The Hacker News]
An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.
The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on T…
#supply-chain
2026-09-19
[The Hacker News]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
The vulnerabilities are listed below -
CVE-2025-39682 (CVSS score: 9.8) …
#vulnerability #linux
2026-09-18
[Dark Reading]
The new program expands Vectra AI’s partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.
2026-09-18
[Dark Reading]
The authentication bypass flaw CVE-2026-76460 impacts Cisco’s Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
#zero-day #vulnerability #authentication
2026-09-18
[Dark Reading]
A new survey of senior AI execs shows that while organizations are rapidly deploying AI and autonomous systems, their process and controls are not keeping pace.
2026-09-18
[Dark Reading]
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.
#authentication
2026-09-18
[The Hacker News]
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine.
Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the explo…
#vulnerability #linux
2026-09-18
[SentinelOne Labs]
North Korean operators built a foothold on a DevOps engineer’s Mac in a campaign whose job interview lures deliver malware via Terraform lock files.
#dprk #macos
2026-09-18
[The Hacker News]
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.
The security firm pwn.ai, whose …
#vulnerability #patch
2026-09-18
[Bleeping Computer]
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. […]
#security
2026-09-18
[Malwarebytes Labs]
RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.
#mobile #news #accessibility #adb #rathat
2026-09-18
[The Hacker News]
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.
The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tool…
#malware
2026-09-18
[Bleeping Computer]
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. […]
#security
2026-09-18
[The Record]
A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.
#government #cybercrime #news
2026-09-18
[SecurityWeek]
Noteworthy stories that might have slipped under the radar: Mandiant’s 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited.
The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek…
#artificial-intelligence #cybercrime #vulnerabilities #in-other-news
2026-09-18
[Malwarebytes Labs]
An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.
#ai #news #ai-model #break-free
2026-09-18
[Bleeping Computer]
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and re…
#security
2026-09-18
[Bleeping Computer]
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company’s security requirements. […]
#security #microsoft
2026-09-18
[Infosecurity Magazine]
Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks
#ransomware
2026-09-18
[The Record]
Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.
#cybercrime #news #news-briefs
2026-09-18
[Bleeping Computer]
Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resou…
#security
2026-09-18
[The Hacker News]
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.
The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.
“Missing authentication for critical function i…
#vulnerability #patch #cloud #authentication #windows
2026-09-18
[SecurityWeek]
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.
The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek.
#artificial-intelligence #ai #chatgpt #openai #source-code
2026-09-18
[Bleeping Computer]
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. […]
#security
2026-09-18
[CISA Alerts]
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2025-39964 Linux Kernel Race Condition Vulnerability
CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability
These types of vulnerabilities are a frequen…
#vulnerability #linux
2026-09-18
[SecurityWeek]
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.
The post 23 Million User Records Compromised in Gyazo Data Breach appeared first on SecurityWeek.
#data-breaches #data-breach #gyazo #images
2026-09-18
[Schneier on Security]
Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.
In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification te…
#uncategorized #ai #captchas #games
2026-09-18
[The Hacker News]
In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation page…
2026-09-18
[The Hacker News]
A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.
The firm said Anthropic has pat…
2026-09-18
[SecurityWeek]
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.
#artificial-intelligence #cloud-security #vulnerabilities #ai #azure
2026-09-18
[The Hacker News]
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.
The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democ…
#malware
2026-09-18
[SecurityWeek]
Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world.
The post NightmareStresser DDoS Service Disrupted in International Operation appeared first on SecurityWeek.
#cybercrime #tracking--law-enforcement #cybercrime #ddos #disrupted
2026-09-18
[Palo Alto Unit 42]
Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents.
The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.
#cloud-cybersecurity-research #threat-research #agentcore-runtime #agentic-ai #cloud
2026-09-18
[Infosecurity Magazine]
The US cybersecurity agency is moving to a new vulnerability coordination platform called VINCE-NT
#vulnerability
2026-09-18
[SecurityWeek]
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.
#malware--threats #supply-chain-security #brevo #clickfix #featured
2026-09-18
[The Hacker News]
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.
“The developer likely wrote the malware using a large language model (LLM), an assessment made with high confid…
#malware #apt
2026-09-18
[ESET WeLiveSecurity]
Whether you’re a victim, the parent of a victim, or just concerned, here’s what you can do about fake nude images
#privacy
2026-09-18
[SecurityWeek]
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.
The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek.
#vulnerabilities #exploited #orkes #vulnerability
2026-09-18
[Infosecurity Magazine]
Black Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in incidents in H1 2026
#ransomware
2026-09-18
[Malwarebytes Labs]
Parcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.
#scams #threat-intel
2026-09-18
[SecurityWeek]
The company will use the funding to accelerate platform development and expand its presence in key enterprise markets.
The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek.
#cybersecurity-funding #data-protection #data-protection #data-security #funding
2026-09-18
[SecurityWeek]
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.
The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.
#endpoint-security #vulnerabilities #check-point #kaspersky #patch
2026-09-18
[Dark Reading]
AI-driven cyberattacks used to be exotic. Soon, it’ll be odd if threat actors aren’t using agents to do all of their bidding.
#apt
2026-09-18
[The Hacker News]
Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices.
“Distributed primarily via targeted smishing (SMS/text phi…
#malware #apt
2026-09-18
[Zero Day Initiative]
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.
#vulnerability #authentication
2026-09-18
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20211.
#vulnerability #rce #authentication
2026-09-18
[The Record]
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies.
#cybercrime #news
2026-09-18
[CrowdStrike]
#securing-ai
2026-09-18
[Elastic Security Labs]
We linked one Elastic Security project to 100 others and ran the full prebuilt detection catalog from the origin, with all the ingest landing in the linked projects. It held up, and where it deliberately does not reach is the interesting part.
#soc #security-operations #threat-hunting
2026-09-17
[Qualys Threat Research]
AI-driven threats are outpacing traditional audits. Discover how continuous monitoring, automated evidence collection, and risk-based remediation help security teams close compliance gaps and maintain audit readiness as environments change daily.
#product-and-tech #compliance
2026-09-17
[Palo Alto Unit 42]
Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths.
The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42.
#inside-the-modern-soc #insights #ai #attack-surface #unit-42-incident-response-report
2026-09-17
[Bleeping Computer]
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. […]
#security #artificial-intelligence #mobile
2026-09-17
[Dark Reading]
The move is consistent with the agency’s advice on the need for organizations to prioritize the vulnerabilities that actually matter.
#vulnerability
2026-09-17
[AWS Security]
European organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can now run generative AI workloads on open weight models on Amazon Bedrock in the AWS European Sovereign Cloud. We’re excited to announ…
#amazon-bedrock #artificial-intelligence #europe #generative-ai #security-identity--compliance
2026-09-17
[The Record]
The proposal, known as the EU KIDS Act, would block social media platforms from offering accounts to children younger than 13 and establish a bloc-wide minimum age of 15 for account creation.
#government #leadership #news
2026-09-17
[Dark Reading]
Amid the US and China’s fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
#malware #apt
2026-09-17
[Qualys Threat Research]
Executive Summary Vulnerability exploitation now happens at a speed that manual, ticket-based remediation can’t match. Qualys’s Enterprise TruRisk Management Platform closes that gap with autonomous remediation: exposures are prioritized by threat, business, and environmental context, then validated…
#product-and-tech #qualys-insights #agent-val #autonomous-remediation #enterprise-trurisk-platform
2026-09-17
[Bleeping Computer]
OpenAI has presented new examples of what they call “AI model misalignment” from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. […]
#security #artificial-intelligence
2026-09-17
[Malwarebytes Labs]
Two reports reveal how Flock’s license plate camera network tracks people’s movements while oversight continues to lag.
#news #privacy #encrypted #flock #surveillance
2026-09-17
[The Hacker News]
A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network.
The Security Management Server is the system that controls firewall policy and administrator access. Check Point has…
#vulnerability #authentication #network
2026-09-17
[The Hacker News]
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.
This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying …
#patch
2026-09-17
[Bleeping Computer]
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. […]
#security
2026-09-17
[SecurityWeek]
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.
The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first on SecurityWeek.
#icsot #nation-state #coast-guard #cyberattack #fbi
2026-09-17
[Microsoft Security]
AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take action and stay ahead of cyberthreats.
The post From guidance to action: Security fundamentals that materially reduce risk appeared first on Microsof…
2026-09-17
[The Record]
Alleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.”
#news #news-briefs #nation-state #malware
2026-09-17
[CrowdStrike]
#threat-hunting--intel
2026-09-17
[Microsoft Security]
The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve.
The post Improving email security outcomes with real-world Microsoft Defender insights appeared first on…
#windows
2026-09-17
[SecurityWeek]
OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior.
The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek.
#artificial-intelligence #ai #openai #rogue-ai
2026-09-17
[The Hacker News]
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15.
The escape runs with the rights of the host account that runs the …
2026-09-17
[CERT/CC]
Overview
Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacker to escalate privil…
#vulnerability #injection
2026-09-17
[Infosecurity Magazine]
ESET said FamousSparrow has replaced SparrowDoor with SparroWocky
#malware
2026-09-17
[Check Point Research]
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions: models now act as …
#check-point-research-publications
2026-09-17
[SecurityWeek]
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.
The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.
#government #vulnerabilities #cisa #risk-management #vulnerability
2026-09-17
[Malwarebytes Labs]
Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.
#scams #threat-intel #account #revolut #scam
2026-09-17
[Bleeping Computer]
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. […]
#security
2026-09-17
[Infosecurity Magazine]
CISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networks
2026-09-17
[SecurityWeek]
Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.
The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.
#data-breaches #data-breach #data-leak #featured #revolut
2026-09-17
[The Record]
An anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament.
#news #cybercrime
2026-09-17
[The Record]
Congressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contributions to high-profile missions against Iran and Venezuela.
#government #leadership #news #people
2026-09-17
[Bleeping Computer]
Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. […]
#microsoft
2026-09-17
[Kaspersky Securelist]
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as “The Odyssey,” and uses the Solana blockchain to hide its C2 infrastructure.
#great-research #malware-descriptions #blockchain #malware-descriptions #malware-technologies
2026-09-17
[Infosecurity Magazine]
Researchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilities
#malware
2026-09-17
[SecurityWeek]
The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure.
The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek.
#compliance #cybersecurity-funding #risk-management #compliance #funding
2026-09-17
[SecurityWeek]
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.
The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek.
#vulnerabilities #bind #dns #patch #vulnerability
2026-09-17
[The Hacker News]
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound …
#rce #network
2026-09-17
[SecurityWeek]
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns.
The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.
#icsot #ransomware #ot
2026-09-17
[The Record]
An Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media personas and media outlets, researchers found.
#news #government #influence-operations
2026-09-17
[Infosecurity Magazine]
New government figures reveal a 20% annual increase in certifications
2026-09-17
[CISA Alerts]
View CSAF
Summary
Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to appl…
#vulnerability
2026-09-17
[CISA Alerts]
View CSAF
Summary
Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, de…
#vulnerability
2026-09-17
[CISA Alerts]
View CSAF
Summary
Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a de…
#vulnerability
2026-09-17
[CISA Alerts]
View CSAF
Summary
Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems …
#vulnerability
2026-09-17
[CISA Alerts]
View CSAF
Summary
ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow…
#vulnerability #linux
2026-09-17
[The Hacker News]
A new CVE drops. Your scanner finds it. The severity score looks ugly.
But that still does not answer the question that matters: Can it actually be exploited in your environment?
Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still…
#vulnerability
2026-09-17
[Bleeping Computer]
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world’s longest-running distributed denial-of-service (DDoS) platforms. […]
#security
2026-09-17
[Malwarebytes Labs]
The largest known celebrity deepfake seizure has taken 12 websites offline, disrupting access to videos depicting some 1,200 people.
#ai #privacy
2026-09-17
[Infosecurity Magazine]
Cisco urged ISE customers to apply a software update, as well as check for signs of exploitation
#vulnerability
2026-09-17
[Schneier on Security]
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian.
There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to spread lies. The Wh…
#uncategorized #ai #democracy #llm
2026-09-17
[The Hacker News]
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one …
#vulnerability #patch
2026-09-17
[Malwarebytes Labs]
A large phishing campaign is using fake T-Mobile rewards points and looming expiry dates to pressure recipients into clicking malicious links.
#scams #threat-intel #reward-points #t-mobile
2026-09-17
[Bleeping Computer]
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. […]
#security #government
2026-09-17
[ESET WeLiveSecurity]
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
#eset-research
2026-09-17
[Infosecurity Magazine]
Spanish data protection agency AEPD reveals the country’s first AI-powered data breach
#data-breach
2026-09-17
[Bleeping Computer]
Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. […]
#microsoft
2026-09-17
[SecurityWeek]
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.
The post CISA Releases Guidance on Deploying Cyber Decoys appeared first on SecurityWeek.
#government #cisa #decoys #guidance
2026-09-17
[SecurityWeek]
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks.
The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.
#artificial-intelligence #ai #ai-training #irregular #rogue-ai
2026-09-17
[Bleeping Computer]
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. […]
#security
2026-09-17
[SecurityWeek]
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests.
The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.
#vulnerabilities #cisco #cisco-ise #exploited #featured
2026-09-17
[Bleeping Computer]
Anthropic is testing a new personal finance feature called “Claude Money” that will allow you to connect your bank accounts directly to Claude and “understand your money.” […]
#artificial-intelligence #technology
2026-09-16
[Graham Cluley]
Researchers wanted to test if LG’s smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can’t be legally bound to a contract you agr…
#ai #android #malware #podcast #privacy
2026-09-16
[Dark Reading]
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
2026-09-16
[AWS Security]
The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AWS partition (aws-eus…
#advanced-300 #security-identity--compliance #technical-how-to #europe #security-blog
2026-09-16
[The Record]
“It’s really complicated, and I wouldn’t want to do something in a lame duck session to do it quickly and not get it right,” said House Energy and Commerce Chairman Brett Guthrie about the FRONTIER Act.
#technology #government #news
2026-09-16
[Bleeping Computer]
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. […]
#microsoft
2026-09-16
[Bleeping Computer]
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. […]
#security
2026-09-16
[The Record]
U.S. personnel boarded an oil tanker in the Gulf of Mexico to “ensure integrity of the vessel’s operational and information technology systems," after an apparent cyberattack, the U.S. Coast Guard said.
#government #industry #news
2026-09-16
[The Record]
The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped to properly investiga…
#cybercrime #government #news
2026-09-16
[Krebs on Security]
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides…
#a-little-sunshine #neer-do-well-news #andtop-company #atlas-data-privacy #bitseller-expert-limited
2026-09-16
[Dark Reading]
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.
2026-09-16
[Bleeping Computer]
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). […]
#security #artificial-intelligence
2026-09-16
[CERT/CC]
Overview
A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply …
#vulnerability
2026-09-16
[Dark Reading]
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
2026-09-16
[SecurityWeek]
Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks.
The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.
#artificial-intelligence #data-breaches #ai #data-breach #featured
2026-09-16
[The Hacker News]
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.
The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote at…
#vulnerability
2026-09-16
[The Record]
A website used around the world for reporting meteors faces weeks of downtime as the organization moves away from systems that were hacked recently.
#news #news-briefs #cybercrime
2026-09-16
[The Hacker News]
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky.
The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to …
#ransomware #malware #apt
2026-09-16
[CERT/CC]
Overview
A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories. This vulnerability…
#vulnerability
2026-09-16
[CrowdStrike]
#data-security
2026-09-16
[Infosecurity Magazine]
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
#vulnerability
2026-09-16
[The Hacker News]
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension.
Once the extension was ins…
#windows
2026-09-16
[SecurityWeek]
Join SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces.
The post Virtual Event Today: Attack Surface Management Summit appeared first on SecurityWeek.
#application-security #attack-surface-management
2026-09-16
[The Record]
Three Ukrainians are set to stand trial for allegedly stealing access to more than 610,000 Roblox accounts and selling them to buyers in Russia, authorities said.
#news #cybercrime #malware
2026-09-16
[SecurityWeek]
Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children.
The post EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media appeared first on SecurityWeek.
#artificial-intelligence #government #ai #eu #featured
2026-09-16
[Bleeping Computer]
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. […]
#security
2026-09-16
[Infosecurity Magazine]
CISA and NIST issued final guidance to help protect cloud identity tokens and assertions
2026-09-16
[The Record]
Washington, D.C.’s police department has used information from Flock cameras for misconduct investigations, prompting a formal complaint from its officers’ union.
#news #government #privacy
2026-09-16
[SecurityWeek]
The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions.
The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared first on SecurityWeek.
#artificial-intelligence #cybersecurity-funding #ai #aiuc #funding
2026-09-16
[The Hacker News]
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories.
Before the repository spread, the assistant recommended software that the attacker had poisoned, and the rec…
2026-09-16
[The Hacker News]
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week.
The attack needs code already running on the machine as a normal user, so it does not work over the network. JFrog says the fix is …
2026-09-16
[The Record]
Delivering her annual State of the Union address in Strasbourg, Ursula von der Leyen said threats were “mounting on our soil,” pointing to recent incidents in Denmark, Lithuania and Poland and an attempted drone attack in Leipzig.
#government #cybercrime #leadership #news
2026-09-16
[SecurityWeek]
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15.
The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek.
#mobile--wireless #vulnerabilities #android #exploited #pixel
2026-09-16
[The Record]
Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.
#news #news-briefs #cybercrime #government
2026-09-16
[Bleeping Computer]
Microsoft says it’s still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. […]
#microsoft
2026-09-16
[Bleeping Computer]
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. […]
#security
2026-09-16
[SecurityWeek]
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.
The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek.
#malware--threats #chosen-brick #espionage #government #iran
2026-09-16
[CISA Alerts]
CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and li…
#authentication
2026-09-16
[The Hacker News]
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity.
From there, a single c…
#malware #phishing #apt #authentication
2026-09-16
[SecurityWeek]
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities.
The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek.
#vulnerabilities #calendar #plugin-vulnerability #vulnerability #wordpress
2026-09-16
[Schneier on Security]
New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.
#uncategorized #captchas #scams
2026-09-16
[The Hacker News]
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild.
The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw.
“In Cellular Modem, there is a possible permission bypass due to a logic erro…
#vulnerability #patch
2026-09-16
[The Hacker News]
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelera…
#vulnerability #authentication
2026-09-16
[Bleeping Computer]
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). […]
#security
2026-09-16
[SecurityWeek]
The company will use the new capital to expand its vulnerability operations platform and support international growth.
The post Hackuity Raises $19 Million for AI-Powered Vulnerability Management appeared first on SecurityWeek.
#cybersecurity-funding #funding
2026-09-16
[Infosecurity Magazine]
Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000
2026-09-16
[SecurityWeek]
In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information.
The post 280,000 Impacted by Premier Medical Group Data Breach appeared first on SecurityWeek.
#data-breaches #data-breach #healthcare #premier-medical-group
2026-09-16
[Malwarebytes Labs]
Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.
#bugs #mobile #news #cve-2026-58704 #modem
2026-09-16
[SecurityWeek]
Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox.
The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek.
#vulnerabilities #chrome #firefox #patch #vulnerability
2026-09-16
[SentinelOne Labs]
Two Hugging Face accounts reveal that OpenAI’s agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.
2026-09-16
[Kaspersky Securelist]
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
#kerberos #dcsync #nighteagle #traffic-tunneling #ghostcontainer
2026-09-16
[Palo Alto Unit 42]
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats.
The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.
#general #insights #malware #macos #malware
2026-09-16
[Infosecurity Magazine]
OPSWAT researchers find two zero-days in TP-Link cameras
#zero-day
2026-09-16
[Bleeping Computer]
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. […]
#microsoft
2026-09-16
[Infosecurity Magazine]
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
2026-09-16
[ESET WeLiveSecurity]
As AI adoption expands the attack surface and adds to the security workload, businesses need automation backed by experts
#business-security
2026-09-16
[Malwarebytes Labs]
A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.
#scams #threat-intel
2026-09-16
[SecurityWeek]
The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data.
The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability appeared first on SecurityWeek.
#vulnerabilities #exploited #vulnerability #wso2
2026-09-16
[Infosecurity Magazine]
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
2026-09-16
[CrowdStrike]
#threat-hunting--intel
2026-09-16
[Bleeping Computer]
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. […]
#security #google
2026-09-16
[The Hacker News]
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.
“This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote …
#malware #vulnerability #apt
2026-09-16
[The Hacker News]
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr.
The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeove…
#vulnerability
2026-09-16
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs ar…
#vulnerability #rce
2026-09-16
[Zero Day Initiative]
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-92210.
#vulnerability #authentication
2026-09-16
[Zero Day Initiative]
This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs…
#vulnerability #authentication
2026-09-16
[Zero Day Initiative]
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3.
#zero-day #vulnerability #windows
2026-09-16
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of MindsDB. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92207.
#zero-day #vulnerability #rce #authentication #injection
2026-09-16
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must load a malicious agent configuration from the repository. The ZDI has assigned a CVSS rating of 8.8. The…
#zero-day #vulnerability #rce
2026-09-16
[CrowdStrike]
#endpoint-security--xdr
2026-09-16
[CrowdStrike]
#agentic-soc
2026-09-15
[AWS Security]
AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes. STS now reports session tok…
#advanced-300 #aws-security-token-service #security-identity--compliance #technical-how-to #aws-sts
2026-09-15
[Bleeping Computer]
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. […]
#security
2026-09-15
[Tenable Research]
Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates.Key TakeawaysThe September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates104 issues (15.5% of all patches) were assig…
#patch
2026-09-15
[Bleeping Computer]
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. […]
#security
2026-09-15
[SecurityWeek]
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers.
The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.
#artificial-intelligence #ai #microsoft
2026-09-15
[Dark Reading]
You can’t make an omelet without breaking a few eggs, and you can’t patch nearly 1,000 CVEs without a few glitches.
#patch #windows
2026-09-15
[The Record]
Oslo-based Telenor potentially enabled crimes against humanity and violated sanctions in its dealings with the military regime that took over Myanmar in 2021, Norwegian authorities said.
#nation-state #news
2026-09-15
[SecurityWeek]
Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today.
The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek.
#ciso-strategy #risk-management #controls
2026-09-15
[Dark Reading]
The ‘Breaking’ News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI
At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, …
2026-09-15
[AWS Security]
Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geographies, ensuring authentication is always available becomes a core architectural r…
#advanced-300 #amazon-cognito #security-identity--compliance #technical-how-to #security-blog
2026-09-15
[The Hacker News]
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN.
Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersona…
#malware #apt #authentication #privacy
2026-09-15
[Qualys Threat Research]
Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signali…
#product-and-tech #mttr #patch-management #qualys-patch-reliability-score
2026-09-15
[Dark Reading]
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.
#malware #windows
2026-09-15
[Bleeping Computer]
CenterPoint Energy disclosed a breach compromising some customers’ personal information after an attacker leaked data allegedly stolen from the utility company. […]
#security
2026-09-15
[The Hacker News]
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and activists around the world.
The malware is controlled via the Telegram messaging app and can cop…
#malware #windows
2026-09-15
[The Record]
According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.”
#cybercrime #government #news #nation-state
2026-09-15
[SecurityWeek]
AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage.
The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek.
#vulnerabilities #linux #sandbox #vulnerabilities
2026-09-15
[AWS Security]
The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s faster to get things working, and the plan is always to tighten permissions later. B…
#aws-identity-and-access-management-iam #best-practices #expert-400 #security-identity--compliance #technical-how-to
2026-09-15
[SecurityWeek]
The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion.
The post Exein Secures $270M at $1.7B Valuation for Physical AI Security appeared first on SecurityWeek.
#cybersecurity-funding #iot-security #ai #exein #funding
2026-09-15
[Malwarebytes Labs]
ChatGPT contractors are reviewing real users’ conversations. Here’s how to stop AI companies using your chats for model training.
#ai #how-to #news #anthropic #human-review
2026-09-15
[Infosecurity Magazine]
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations
#authentication
2026-09-15
[The Record]
Ihor Klymenko, who has experience in law enforcement and as interior minister, will run Ukraine’s National Cybersecurity Coordination Center.
#nation-state #news #government #people #leadership
2026-09-15
[Bleeping Computer]
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. […]
#security
2026-09-15
[Qualys Threat Research]
Executive Summary Remediation deadlines slip for reasons outside your control: a patch does not exist yet, a patch is delayed, or a remediation attempt fails. The outcome is the same either way: the host stays unpatched and stays on the network. TruRisk Eliminate closes that window by isolating the …
#product-and-tech #isolation #patchless-patching #remediation-intelligence #trurisk-eliminate
2026-09-15
[Bleeping Computer]
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. […]
#security
2026-09-15
[Infosecurity Magazine]
Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours
#ransomware
2026-09-15
[The Record]
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.
#industry #cybercrime #news #news-briefs
2026-09-15
[Bleeping Computer]
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attacke…
#security
2026-09-15
[Infosecurity Magazine]
Alleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claims
2026-09-15
[SecurityWeek]
The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools.
The post Thai Broadband Provider Hacked via Fortinet Vulnerability appeared first on SecurityWeek.
#malware--threats #3bb #exploited #fortinet #thailand
2026-09-15
[Tenable Research]
Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Key takeawaysThe Australian Signals Directorate (ASD) is movin…
2026-09-15
[Cloudflare Security]
Cloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountable designation establish a shared model with Apple, Google, and Microsoft.
#ai #ai-bots #bot-management #network-services #product-news
2026-09-15
[Cloudflare Security]
You can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents get only the access they need to debug, deploy, or monitor safely.
#developers #identity #product-news #security #workers
2026-09-15
[Infosecurity Magazine]
IANS finds AI is dominating net-new budgets even as overall funding for the function is flat
2026-09-15
[The Record]
China’s spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.
#china #cybercrime #government #industry #leadership
2026-09-15
[SecurityWeek]
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity.
The post OpenAI Investigates Report Linking AI Agents to RubyGems Attack appeared first on SecurityWeek.
#artificial-intelligence #ai #openai #rubygems
2026-09-15
[The Record]
Manhattan District Attorney Alvin Bragg held a press conference on Monday touting the takedown of the sites, which hosted AI-generated videos of more than 1,200 people. The sites allowed users to use the faces and bodies of real people to create illegal pornography.
#cybercrime #government #news #news-briefs
2026-09-15
[CISA Alerts]
Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptographic mechanisms that support modern authentication and author…
#authentication
2026-09-15
[CISA Alerts]
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem.
The following versions of mySCADA myPRO Manager are affected:
mySCADA myPRO Manager <=2.1 (CVE-2026-73…
#vulnerability
2026-09-15
[CISA Alerts]
View CSAF
Summary
Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point.
The following versions of Digital Watchdog …
#vulnerability #privacy
2026-09-15
[The Hacker News]
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access.
In one instance highlighted by …
#vulnerability #rce
2026-09-15
[Malwarebytes Labs]
Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.
#news #clickfix #hbo-max #pasteswitch #reddit
2026-09-15
[SecurityWeek]
Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.
The post 240,000 Hit by Data Breach at Japan’s Digital Agency appeared first on SecurityWeek.
#data-breaches #data-breach #government #japan #vpn
2026-09-15
[The Hacker News]
Introduction
Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continu…
#phishing
2026-09-15
[The Hacker News]
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data.
The first is an automated effort aimed at internet-exposed Vite development servers that’s designed to steal cloud credentials, configurations from Amazon Web Servi…
#vulnerability #authentication
2026-09-15
[SecurityWeek]
The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks.
The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases appeared first on SecurityWeek.
#vulnerabilities #apple #featured #ios #ios-27
2026-09-15
[Schneier on Security]
This essay was written with Cindy Cohn, and originally appeared in Lawfare.
One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as …
#uncategorized #privacy #surveillance
2026-09-15
[Schneier on Security]
Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.
#uncategorized #history-of-computing #history-of-cryptography #ibm #intelligence
2026-09-15
[Bleeping Computer]
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. […]
#security
2026-09-15
[Malwarebytes Labs]
A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.
#ai #family-and-parenting #privacy
2026-09-15
[Graham Cluley]
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison.
That should be plenty of time for him to rue the day he agreed to increase his monthly income by helping a SIM swap gang in their attempt to steal …
#guest-blog #law--order #att #mobile #sim-swap
2026-09-15
[SecurityWeek]
The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability.
The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints appeared first on SecurityWeek.
#artificial-intelligence #ai #code-of-conduct #microsoft
2026-09-15
[Malwarebytes Labs]
Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.
#scams #threat-intel
2026-09-15
[Infosecurity Magazine]
Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday
#patch #windows
2026-09-15
[The Hacker News]
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14.
On such servers, many customers’ sites run on a single machine, and an attacker with one of those h…
#vulnerability
2026-09-15
[The Hacker News]
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild.
The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insuffi…
#vulnerability
2026-09-15
[The Hacker News]
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.
Volexity, which is tracking the threat cluster under the moniker UTA0560, said th…
#zero-day #malware #phishing #vulnerability #apt
2026-09-15
[SecurityWeek]
An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges.
The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek.
#email-security #vulnerabilities #cisco #exploited #featured
2026-09-14
[Dark Reading]
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.
#malware #vulnerability
2026-09-14
[Bleeping Computer]
Japan’s Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. […]
#security #government
2026-09-14
[Dark Reading]
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
#vulnerability #supply-chain
2026-09-14
[Bleeping Computer]
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. […]
#security #software
2026-09-14
[The Record]
Prosecutors unsealed a 2021 indictment accusing the five men of conducting lucrative romance scams that stole thousands of dollars from more than 100 people.
#cybercrime #news #news-briefs
2026-09-14
[Schneier on Security]
This is a current list of where and when I am scheduled to speak:
I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM ET.
I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk i…
#uncategorized #schneier-news
2026-09-14
[Bleeping Computer]
Hackers compromised HBO Max’s official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. […]
#security
2026-09-14
[The Hacker News]
An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said.
The company uncovered the intrusion by examining a ser…
#malware #authentication
2026-09-14
[The Hacker News]
A flaw in Telegram Desktop let a bot’s message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12.
In Telegram, the message looked ordinary, with a link button, and the script ran only when someone open…
#patch
2026-09-14
[AWS Security]
Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive. This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance for organizations tha…
#announcements #foundational-100 #security-identity--compliance #pci-dss #security-blog
2026-09-14
[The Hacker News]
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the processor keeps reading old encrypted data as if it were current.
The attack requires an attacker who al…
2026-09-14
[The Hacker News]
A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign.
“Red Heron scanned 1,386 Gitea instances across seven countries and maintai…
#vulnerability #apt #rce
2026-09-14
[Dark Reading]
Dario Amodei says it’s time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?
2026-09-14
[Bleeping Computer]
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. […]
#security
2026-09-14
[The Record]
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.
#news #cybercrime #nation-state
2026-09-14
[Schneier on Security]
Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this:
We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodi…
#uncategorized #ai #reports #weapons
2026-09-14
[The Record]
The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices.
#cybercrime #government #news #news-briefs
2026-09-14
[The Hacker News]
WordPress has announced it’s launching an automated security review for every release of a plugin before it’s distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved.
“New plugins are reviewed before they enter the di…
2026-09-14
[Rapid7 Blog]
The managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detection and moved to a world with a convergence of exposure management and response to deliver measurable, outcome-based defenses of a larger, AI-…
#managed-detection-and-response-mdr
2026-09-14
[The Hacker News]
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination.
The rest of the week is more familiar: old bugs still working, fresh exploit chains, …
#vulnerability
2026-09-14
[SecurityWeek]
China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI.
The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on SecurityWeek.
#artificial-intelligence #ai #anthropic #china
2026-09-14
[Malwarebytes Labs]
Google says its new opaque redirects tackle evolving abuse, but they also prevent users from checking a result’s destination by hovering over it.
#news #google #gotourl #serp
2026-09-14
[Infosecurity Magazine]
A human attacker exploited a Marimo RCE and reached an SSH bastion in eight seconds
#vulnerability #rce
2026-09-14
[Bleeping Computer]
Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control. […]
#security
2026-09-14
[SecurityWeek]
Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims.
The post New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate appeared first on SecurityWeek.
#artificial-intelligence #ai #risk
2026-09-14
[SecurityWeek]
As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity.
The post The Race to Control AI and Protect What Makes Us Human appeared first on SecurityWeek.
#artificial-intelligence #icsot #ai #featured #humanity
2026-09-14
[Infosecurity Magazine]
MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military
2026-09-14
[Check Point Research]
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data includ…
#global-cyber-attack-reports
2026-09-14
[Bleeping Computer]
Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. […]
#security
2026-09-14
[The Record]
British fintech Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.
#news #cybercrime #privacy
2026-09-14
[The Hacker News]
There’s a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action.
…
#vulnerability
2026-09-14
[SecurityWeek]
The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.
The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek.
#nation-state #vulnerabilities #china #china-apt #exploit
2026-09-14
[Infosecurity Magazine]
An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data
#data-breach
2026-09-14
[Malwarebytes Labs]
The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.
#data-breaches #news #government-request #ids #revolut
2026-09-14
[Schneier on Security]
Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record:
Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold.
It was only two months ago that Micro…
#uncategorized #ai #microsoft #patching #vulnerabilities
2026-09-14
[SecurityWeek]
Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm.
The post CISOs Race to Control AI Agents Without Destroying Their Value appeared first on SecurityWeek.
#artificial-intelligence #ciso-strategy #ai #ciso
2026-09-14
[Rapid7 Blog]
OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to Git…
#emergent-threat-response #emerging-threats
2026-09-14
[Palo Alto Unit 42]
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.
The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.
#cloud-cybersecurity-research #threat-research #aws-cloudtrail #cloud-detection #devops
2026-09-14
[SecurityWeek]
Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.
The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek.
#data-breaches #account-takeover #canada #data-breach #telecom
2026-09-14
[Bleeping Computer]
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. […]
#microsoft
2026-09-14
[SecurityWeek]
The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator.
The post Three JFrog Artifactory Flaws Exploited for Backdoor Deployment appeared first on SecurityWeek.
#vulnerabilities #backdoor #exploited #jfrog-artifactory #vulnerability
2026-09-14
[Infosecurity Magazine]
Researchers confirm that OpenAI agents uploaded hundreds of malicious packages to RubyGems
2026-09-14
[Bleeping Computer]
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. […]
#security
2026-09-14
[SecurityWeek]
The flaw allows attackers to send files and execute them without authorization through an active remote session.
The post ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks appeared first on SecurityWeek.
#vulnerabilities #exploited #featured #patch #screenconnect
2026-09-14
[Bleeping Computer]
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. […]
#microsoft
2026-09-14
[The Hacker News]
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.
The extension, named “Twitch Enhanced Viewer | JeetBot,” lists HISHIMIRO/jeetbot.cc as its developer and has the following iden…
2026-09-14
[Bleeping Computer]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. […]
#security
2026-09-14
[Malwarebytes Labs]
A list of topics we covered in the week of September 7 to September 13 of 2026
#news #bluemoon #grindr #lg-tvs
2026-09-14
[Zero Day Initiative]
This vulnerability allows physically present attackers to escalate privileges on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2025-22050.
#vulnerability #authentication #linux
2026-09-14
[Zero Day Initiative]
This vulnerability allows local attackers to disclose sensitive information on affected installations of Linux Kernel. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 6.7. The…
#vulnerability #linux
2026-09-14
[Elastic Security Labs]
Elastic Security Labs tracked this malicious browser extension across seven campaigns and 15 months, through Brazilian bank lures and the Ethereum smart contracts that hold its C2 configuration.
#malware-analysis #threat-intelligence
2026-09-13
[The Record]
The largest electronic spy agency in the world is reorganizing. And fast.
#government #news
2026-09-13
[Bleeping Computer]
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. […]
#security
2026-09-13
[SecurityWeek]
Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet.
The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared first on SecurityWeek.
#artificial-intelligence #ai #anthropic #featured #openai
2026-09-13
[The Hacker News]
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.
The first campaign, per the tech giant, involved sending ove…
#phishing #apt #windows
2026-09-12
[The Hacker News]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.
Details of the vul…
#vulnerability #network
2026-09-12
[SecurityWeek]
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments.
The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.
#vulnerabilities #bluemoon #chrome #exploit-kit #exploited
2026-09-12
[The Hacker News]
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from dev…
2026-09-12
[The Hacker News]
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.
On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Men…
#supply-chain #rce
2026-09-12
[SecurityWeek]
Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket.
The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek.
#artificial-intelligence #ai #anthropic #featured
2026-09-11
[Schneier on Security]
Smells awful:
But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association.
Ogg said anyone familiar wi…
#uncategorized #squid #video
2026-09-11
[Bleeping Computer]
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. […]
#security #artificial-intelligence
2026-09-11
[CERT/CC]
Overview
An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture (CUDA) extension. Successful exploitation can lead to an immediate denial of service or application instability. This vulnerabil…
#vulnerability #patch #ddos #linux
2026-09-11
[The Record]
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer’s personal device.
#news #news-briefs #privacy #cybercrime
2026-09-11
[Dark Reading]
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
#apt
2026-09-11
[Bleeping Computer]
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. […]
#security
2026-09-11
[Dark Reading]
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.
2026-09-11
[The Record]
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.
#cybercrime #news #news-briefs #industry
2026-09-11
[Dark Reading]
The Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities.
#zero-day #vulnerability
2026-09-11
[Dark Reading]
Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.
2026-09-11
[SecurityWeek]
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks.
The post Phishing Research Challenges Conventional Security Awareness Testing appeared first on SecurityWeek.
#phishing #awareness-training #phishing
2026-09-11
[Dark Reading]
Adversaries can manipulate AI defensive reasoning to silently compromise target networks.
2026-09-11
[The Hacker News]
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.
The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits AP…
#vulnerability #patch
2026-09-11
[Bleeping Computer]
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. […]
#security
2026-09-11
[The Hacker News]
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax.
Knowledge distillation by itself is a legitimate training method. It refers to a …
2026-09-11
[SecurityWeek]
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.
The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.
#vulnerabilities #exploited #gitlab #vulnerability
2026-09-11
[Dark Reading]
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.
2026-09-11
[Malwarebytes Labs]
A breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.
#news #scams
2026-09-11
[The Hacker News]
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026.
The threat actors, which the artificial intelligence (AI) company has branded Generative…
#vulnerability #apt #privacy
2026-09-11
[SecurityWeek]
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.
The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review ap…
#cybercrime #in-other-news
2026-09-11
[The Hacker News]
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.
The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands…
#malware #apt
2026-09-11
[Bleeping Computer]
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. […
#security
2026-09-11
[Rapid7 Blog]
This One Goes to Sixteen!Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watcher…
#metasploit-weekly-wrapup #metasploit
2026-09-11
[Rapid7 Blog]
IntroductionThe surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various sma…
#threat-intel
2026-09-11
[Infosecurity Magazine]
KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails
#phishing #windows
2026-09-11
[SecurityWeek]
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.
The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.
#data-breaches #email-security #phishing #brevo #cryptocurrency
2026-09-11
[The Record]
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.
#news #cybercrime
2026-09-11
[The Record]
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.
#news #news-briefs #cybercrime #malware
2026-09-11
[The Hacker News]
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise.
A critical vulnerability may look alarming on a scanner report, but if it…
#vulnerability
2026-09-11
[Bleeping Computer]
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. […]
#security
2026-09-11
[SecurityWeek]
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.
The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek.
#vulnerabilities #check-point #vpn #vulnerability
2026-09-11
[Schneier on Security]
In August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago.
Great fun.
#uncategorized #history-of-security #video
2026-09-11
[SecurityWeek]
Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars.
The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek.
#data-protection #ma-tracker #acquisition #bonfy #data-security
2026-09-11
[SecurityWeek]
A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.
The post Surfshark Systems Targeted by Hackers appeared first on SecurityWeek.
#data-breaches #data-breach #surfshark #vpn
2026-09-11
[Infosecurity Magazine]
A new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before doing so
#windows
2026-09-11
[SecurityWeek]
Anthropic reveals how criminal groups are increasingly targeting AI vendors’ own infrastructure, including to steal a pre-release Claude model.
The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek.
#artificial-intelligence #nation-state #ai #anthropic #claude
2026-09-11
[The Hacker News]
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report.
Wiz saw the attacks between August 15 and September 8. JFrog had fixe…
#malware #cloud
2026-09-11
[The Hacker News]
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims’ computers, security company Gen Digital said in research published Thursday.
The attack started with a crafted link and …
#malware #vulnerability #windows
2026-09-11
[Bleeping Computer]
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. […]
#security
2026-09-11
[The Hacker News]
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.
The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.1…
#vulnerability #patch
2026-09-11
[Dark Reading]
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
#malware #vulnerability
2026-09-11
[Elastic Security Labs]
Seven of the thirteen Linux privilege escalation CVEs we tracked in 2026 turned out to be the same copy-on-write bug pointed at different kernel interfaces. We ran the public proof-of-concept for eleven exploits and two misconfigurations, and noted which rules fired.
#detection-engineering
2026-09-10
[Bleeping Computer]
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. […]
#security #mobile
2026-09-10
[The Record]
As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what’s happening to their customers.
#government #cybercrime #news
2026-09-10
[Dark Reading]
Threat actors are leveraging Microsoft’s Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
#vulnerability #apt #windows
2026-09-10
[Bleeping Computer]
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. […]
#microsoft
2026-09-10
[SecurityWeek]
Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board.
The post Mandiant Founder Kevin Mandia Joins Amazon Board appeared first on SecurityWeek.
#management--strategy #amazon
2026-09-10
[Bleeping Computer]
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. […]
#security #software
2026-09-10
[Bleeping Computer]
Microsoft Excel users report that this week’s KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. […]
#microsoft
2026-09-10
[The Record]
Ronzelle Green, most recently a senior official at the National Geospatial-Intelligence Agency, will be U.S. Cyber Command’s chief AI officer.
#people #leadership #news #government
2026-09-10
[The Hacker News]
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”
An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful…
#phishing
2026-09-10
[CERT/CC]
Overview
An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physical disk. When Secure Boot is disabled, this can be leveraged to execute arbitrary UEFI-level c…
#vulnerability #linux
2026-09-10
[Microsoft Security]
Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud.
The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security B…
#social-engineering
2026-09-10
[SecurityWeek]
Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.
The post Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 appeared first on SecurityWeek.
#fundingma #ma-tracker #acquisitions #ma
2026-09-10
[Microsoft Security]
See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain.
The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.
#adversary-in-the-middle-aitm #credential-theft #social-engineering
2026-09-10
[Bleeping Computer]
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. […]
#security #artificial-intelligence #education
2026-09-10
[Bleeping Computer]
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. […]
#security
2026-09-10
[Dark Reading]
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
#zero-day #vulnerability #windows
2026-09-10
[SecurityWeek]
Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns.
The post Anthropic Researcher Resigns With Warning About the Dangers of AI Development appeared first on SecurityWeek.
#artificial-intelligence #ai #anthropic
2026-09-10
[Check Point Research]
Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all pre…
#check-point-research-publications
2026-09-10
[SecurityWeek]
Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox.
The post Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster appeared first on SecurityWeek.
#hacker-conversations #hacker
2026-09-10
[Bleeping Computer]
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. […]
#security
2026-09-10
[Bleeping Computer]
Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. […]
#security
2026-09-10
[Infosecurity Magazine]
CISA has updated its insider threat guide with new advice on remote work, AI and risk detection
2026-09-10
[SecurityWeek]
Deceptive apps in Early Access are being used by dishonest developers for their own benefit.
The post Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews appeared first on SecurityWeek.
#fraud--identity-theft #mobile--wireless #android
2026-09-10
[Graham Cluley]
Here’s a tip for any budding cybercriminals out there.
If you’re going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don’t broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub.
Read more in my artic…
#guest-blog #law--order #phishing #cryptocurrency #phishing
2026-09-10
[The Record]
Wildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to track and withdraw their earnings.
#cybercrime #news #technology
2026-09-10
[SecurityWeek]
Join the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT operations accelerate.
The post Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation appeared first on SecurityWeek.
#artificial-intelligence #endpoint-security #vulnerabilities #endpoint #webinar
2026-09-10
[Tenable Research]
Learn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environmentKey takeawaysAI models can quickly understand data, but not your business. While modern AI models are great at reasonin…
2026-09-10
[Infosecurity Magazine]
MantaxOtax Android malware combines ransomware with extensive spyware capabilities
#ransomware #malware
2026-09-10
[Cloudflare Security]
1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale.
#1111 #cryptography #dns #dnssec #post-quantum
2026-09-10
[The Record]
The individual has not yet been avowed — the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged — as routine security considerations are still being worked through.
#government #cybercrime #leadership #news
2026-09-10
[Malwarebytes Labs]
AI researchers are warning that the technology could kill us all within the next decade, although they say the risk from current models is low.
#ai #news
2026-09-10
[CISA Alerts]
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition.
The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected:
Evolution iQ‑Series term…
#vulnerability #ddos
2026-09-10
[CISA Alerts]
View CSAF
Summary
Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition.
The foll…
#vulnerability #ddos
2026-09-10
[CISA Alerts]
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition.
The following versions of NextGen Healthcare Mirth Connect are affected:
Mirth Connect <=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578)
…
#vulnerability #ddos
2026-09-10
[CISA Alerts]
View CSAF
Summary
Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session.
The following versions of AVEVA Pipeline Integrity Monitor are affected:
AVEVA Pipeline Integrity Monitor <=2025_SP1_P1…
#vulnerability
2026-09-10
[SecurityWeek]
Anthropic is most concerned about Claude Mythos 5’s reckless behavior after recent incidents in which real systems were hacked.
The post Widened Scan Turns Up Fourth Rogue Claude Cyber Incident appeared first on SecurityWeek.
#artificial-intelligence #ai #anthropic #claude
2026-09-10
[The Hacker News]
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only “under specific conditions” that it has not described.
One flaw affects Check Poin…
#vulnerability #rce #patch #network
2026-09-10
[The Hacker News]
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances.
According to independent reports from Blackpoint Cyber and GreyNoi…
#vulnerability
2026-09-10
[The Hacker News]
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9.
A work profile is a separate space that Android typically reserves for employer…
#malware
2026-09-10
[Bleeping Computer]
Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. […]
#microsoft
2026-09-10
[Malwarebytes Labs]
Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.
#bugs #news
2026-09-10
[Schneier on Security]
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.
What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour …
#uncategorized #ai #exploits #open-source
2026-09-10
[The Hacker News]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.
…
#vulnerability #patch
2026-09-10
[SecurityWeek]
Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.
The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek.
#vulnerabilities #cisco #exploited #firewall #fmc
2026-09-10
[Palo Alto Unit 42]
Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities.
The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.
#malware #threat-research #api #cryptographic #json
2026-09-10
[Malwarebytes Labs]
Scammers are filing fraudulent copyright complaints to suspend Instagram accounts, then demanding payment to withdraw them.
#scams
2026-09-10
[Bleeping Computer]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. […]
#security
2026-09-10
[ESET WeLiveSecurity]
LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor
#business-security
2026-09-10
[Qualys Threat Research]
Key Takeaways Identity Security Posture Management (ISPM) is the continuous risk and posture layer of the identity stack not a replacement for Identity and Access Management (IAM), Privileged Access Management (PAM), Identity Governance and Administration (IGA), or Identity-as-a-Service (IDaaS), but…
#product-and-tech #etm-identity #iam #idaas #identity-security
2026-09-10
[Infosecurity Magazine]
Anthropic has found a fourth case of its model accessing third-party systems without authorization
2026-09-10
[Bleeping Computer]
Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. […]
#microsoft
2026-09-10
[Infosecurity Magazine]
The US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi Guarantee
2026-09-10
[The Hacker News]
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup guide.
LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That k…
2026-09-10
[The Hacker News]
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents.
The AI company said the incident da…
2026-09-10
[Dark Reading]
Starting Friday, businesses operating in the EU will have just 24 hours to notify the government any time they discover serious product security incidents.
2026-09-10
[Bleeping Computer]
Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. […]
#security
2026-09-10
[SecurityWeek]
The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.
The post Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks appeared first on SecurityWeek.
#malware--threats #vulnerabilities #exploited #featured #fortigate
2026-09-10
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Photoshop. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The follow…
#vulnerability #rce
2026-09-09
[Graham Cluley]
When a chap called Matt noticed his Bluetooth headphones wouldn’t switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one …
#data-loss #malware #podcast #privacy #ransomware
2026-09-09
[Bleeping Computer]
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. […]
#security
2026-09-09
[Bleeping Computer]
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. […]
#security #healthcare
2026-09-09
[Microsoft Security]
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms.
The post Threat matrix: Mapping threats across cloud web applications appeared first on…
#windows
2026-09-09
[The Record]
CISA’s cybersecurity, infrastructure security and emergency communications divisions are among the priorities as the agency fills vacancies created at the beginning of the Trump administration, acting director Nick Andersen says.
#news-briefs #news #government #technology
2026-09-09
[Dark Reading]
An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.
#vulnerability
2026-09-09
[AWS Security]
Security teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response, and code review. The promise is speed, but a security tool that moves fast and raises too many false alarms doesn’t save time. Engineers spend ti…
#advanced-300 #artificial-intelligence #generative-ai #security-identity--compliance #thought-leadership
2026-09-09
[The Hacker News]
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Cente…
2026-09-09
[Microsoft Security]
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance.
T…
#social-engineering
2026-09-09
[SecurityWeek]
The company will increase its US market presence and will expand its engineering and go-to-market teams.
The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek.
#compliance #cybersecurity-funding #risk-management #ai #funding
2026-09-09
[The Record]
Veradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the company added.
#cybercrime #news #privacy
2026-09-09
[SecurityWeek]
Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG.
The post AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns appeared first on SecurityWeek.
#artificial-intelligence #nation-state #ai #google #gtig
2026-09-09
[Bleeping Computer]
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. […]
#security #artificial-intelligence
2026-09-09
[The Hacker News]
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.
The first in-the-wild use of BlueMoon has been attributed to the China-aligned …
#vulnerability #windows
2026-09-09
[SecurityWeek]
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.
The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek.
#mobile--wireless #vulnerabilities #android #vulnerability
2026-09-09
[The Record]
A Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers.
#china #nation-state #malware #news
2026-09-09
[SecurityWeek]
Major chipmakers announced patches for vulnerabilities recently discovered in their products.
The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek.
#vulnerabilities #amd #arm #nvidia #patch-tuesady
2026-09-09
[Schneier on Security]
A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.
#uncategorized #cars #dark-web #data-breaches #databases
2026-09-09
[The Record]
The first public cybersecurity strategy issued by the FBI “directs our teams, our field offices, our global presence” to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett Leatherman says.
#government #cybercrime #nation-state #news
2026-09-09
[Bleeping Computer]
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients’ personal data. […]
#security #healthcare
2026-09-09
[Rapid7 Blog]
If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating po…
#vulnerability-management
2026-09-09
[Malwarebytes Labs]
DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.
#news #scams #doppelcart #fake-webshops
2026-09-09
[Qualys Threat Research]
The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. Claude Mythos Preview identified thousands of previously unknown flaws across every major operating system and browser, including a 27-year-old denial-of-service condition …
#qualys-insights #frontier-ai #frontier-ai-intrusion #hugging-face
2026-09-09
[Infosecurity Magazine]
The hacking tool, built using a combination of AI models, is effective against Android and iOS devices
2026-09-09
[Dark Reading]
“Workflow identity hijacking” can bypass standard security controls and hijack an organization’s data by sending a basic request through an unauthenticated entry point.
2026-09-09
[SecurityWeek]
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic.
The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.
#network-security #vulnerabilities #fortinet
2026-09-09
[Infosecurity Magazine]
Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud
#malware
2026-09-09
[The Hacker News]
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create “stolen keys” that grant illicit access to tools from model providers like Google, Anthropic, and others.
Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide r…
#malware #authentication
2026-09-09
[Bleeping Computer]
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account rec…
#security
2026-09-09
[Infosecurity Magazine]
ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency
2026-09-09
[Infosecurity Magazine]
SpyCloud claims non-human identities are the most likely route into the enterprise
2026-09-09
[Tenable Research]
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the Cyber…
2026-09-09
[SecurityWeek]
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.
The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.
#artificial-intelligence #ai #china #featured
2026-09-09
[The Record]
Ukraine’s prosecutor general, Ruslan Kravchenko, resigned this week over allegations that officials in his office took bribes to shield scam call centers from law enforcement.
#news #government #cybercrime
2026-09-09
[SecurityWeek]
Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data.
The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek.
#artificial-intelligence #ai #facebook #meta #muse
2026-09-09
[The Hacker News]
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed?
For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enoug…
#vulnerability
2026-09-09
[The Hacker News]
A flaw in DeepSeek Harness, DeepSeek’s open-source tool for running AI coding agents on a developer’s machine, let a sandboxed agent turn off its own sandbox with a single command.
The tool runs an agent’s commands inside an operating-system sandbox, so that an agent working on untrusted files cann…
2026-09-09
[Schneier on Security]
Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes.
This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.
#uncategorized #ai #cryptography #history-of-cryptography #mathematics
2026-09-09
[SecurityWeek]
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.
The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek.
#icsot #vulnerabilities #aveva #ics #patches
2026-09-09
[The Hacker News]
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet.
Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own comp…
2026-09-09
[SecurityWeek]
Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.
The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek.
#network-security #vulnerabilities #ivanti #vulnerabilities
2026-09-09
[Bleeping Computer]
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. […]
#security
2026-09-09
[Malwarebytes Labs]
Microsoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.
#bugs #news #cve-2026-81963 #cve-2026-85880 #patch-tuesday
2026-09-09
[Palo Alto Unit 42]
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks.
The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.
#malware #threat-research #arktunnel #c2 #cl-cri-1171
2026-09-09
[SecurityWeek]
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here’s a proposal to make that the default.
The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek.
#application-security #identity--access #api #credentials
2026-09-09
[SecurityWeek]
Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block.
The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek.
#phishing #featured #phishing
2026-09-09
[SecurityWeek]
The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible.
The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek.
#vulnerabilities #chrome
2026-09-09
[The Hacker News]
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting “systematic extraction” of proprietary functionalities and capabilities of American frontier models through distillation attacks.
The activity has been described as occurring a…
2026-09-09
[The Hacker News]
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.
The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome’s J…
#zero-day #vulnerability #patch
2026-09-09
[ESET WeLiveSecurity]
AI scams are now hyper-realistic. But there’s one simple way to see through them.
#digital-security
2026-09-09
[Bleeping Computer]
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. […]
#security
2026-09-09
[Graham Cluley]
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business.
Read more in my article on the Fortra blog.
#guest-blog #malware #ransomware #ransomware
2026-09-09
[Malwarebytes Labs]
Australia is proposing a law that gives people a choice over what fills their feeds. It may not be long before other countries demand the same.
#news
2026-09-09
[The Hacker News]
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user.
cPanel published the ad…
#patch
2026-09-09
[The Hacker News]
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7.
When Apache loads any of the three appliances’ own PHP scripts, the malware adds the web shell to the copy hel…
#malware
2026-09-09
[Bleeping Computer]
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldCrash” right after Microsoft rolled out its September 2026 Patch Tuesday security updates. […]
#security #microsoft
2026-09-09
[Bleeping Computer]
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. […]
#security #google
2026-09-09
[CrowdStrike]
#exposure-management
2026-09-09
[Zero Day Initiative]
This vulnerability allows local attackers to escalate privileges on affected installations of VMware Workstation. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. Th…
#vulnerability
2026-09-09
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Progress Software Kemp LoadMaster. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-8037.
#vulnerability #rce #authentication
2026-09-09
[Zero Day Initiative]
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Fortinet FortiSandbox. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-84387.
#vulnerability #rce #authentication #injection
2026-09-09
[Zero Day Initiative]
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Backblaze Personal Computer Backup. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigne…
#vulnerability #ddos
2026-09-09
[The Hacker News]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.
T…
#vulnerability #rce
2026-09-09
[Bleeping Computer]
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. […]
#microsoft #software
2026-09-08
[Krebs on Security]
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many o…
#latest-warnings #security-tools #time-to-patch #cve-2026-69730 #cve-2026-69829
2026-09-08
[Google Project Zero]
Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: Confirming bug candidates that have been discovered manually or through static analysis. Regression tests: A…
#injection
2026-09-01
[Krebs on Security]
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning i…
#a-little-sunshine #data-breaches #the-coming-storm #web-fraud-20 #cybera
2026-08-25
[PortSwigger Research]
I was on my laptop, as I often am when there’s rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with “a-zA-Z”, but what about after that? I t
2026-08-13
[SentinelOne Labs]
OpenAI, Anthropic and Meta disclosed agents reaching external systems. The tools didn’t matter, and that changes the playbook for investigating intrusions.
#frontier-ai #llm
2026-08-06
[PortSwigger Research]
Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It’s quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
2026-08-05
[PortSwigger Research]
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
#xss #injection
2026-05-13
[Google Project Zero]
We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible to go from a zero-click context to root on Android in just two exploits. The Dolby 0-click vulnerability existed across all of Android, until it was patched in January 2026. While we had an exploit chain …
#vulnerability #patch
2026-04-23
[Google Security Blog]
Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the secur…
#injection
2026-04-10
[Google Security Blog]
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team
Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with m…
#android #android-security #pixel
2026-04-09
[Google Security Blog]
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team
Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upco…
#authentication #windows
2025-05-07
[NCSC UK]
An NCSC assessment highlighting the impacts on cyber threat from AI developments between now and 2027.
2025-01-28
[NCSC UK]
Research from the NCSC designed to eradicate vulnerability classes and make the top-level mitigations easier to implement.
#vulnerability
2024-01-18
[Assetnote]
#vulnerability #rce #authentication
2023-10-23
[Assetnote]
#vulnerability
2023-10-03
[Assetnote]
#vulnerability #rce