Cybersecurity research, threat intelligence & CVE tracking

> Security Feed

Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Sweden’s data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. […]

#security #government #legal

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. […]

#security #government

Microsoft Disrupts EvilTokens Device Code Phishing Service

Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.

#phishing #windows

VU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypass

Overview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash in the UEFI Authorized Signature Database (DB)…

New ClosedQuorum Windows malware uses AI for attack decisions

A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. […]

#security #artificial-intelligence

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.

On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixe…

#patch

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.

The package, named “tw-pkgprobe-7731,” was…

#authentication

BigCommerce Data Stolen via Ribon Apps Hack

The attackers used a compromised BigCommerce application key held by Ribon to access customer data. The post BigCommerce Data Stolen via Ribon Apps Hack appeared first on SecurityWeek.

#data-breaches #supply-chain-security #bigcommerce #data-breach #ribon

Reducing shadow IT visibility gaps with Wazuh

Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. [….

#security

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.

The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versio…

#vulnerability #authentication

Some cheap smart glasses are a security disaster

Tests found that some cheap smart glasses can be hijacked over Bluetooth, exposing their owners’ photos, videos, and personal data.

#bugs #news #privacy #security #smart-glasses

Unmasking EvilTokens: Getting to the root of device code phishing

EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and oper…

#adversary-in-the-middle-aitm #phishing

Cyera Raises $400 Million at $12+ Billion Valuation

The data security company received the new investment from Goldman Sachs Alternatives, extending its Series G funding round. The post Cyera Raises $400 Million at $12+ Billion Valuation appeared first on SecurityWeek.

#cybersecurity-funding #data-protection #cyera #data-security #funding

Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity

Abdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse.  The post Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity appeared first on SecurityWeek.

#vulnerabilities #bigdiskbuster #chaotic-eclipse #controversy #featured

Webinar tomorrow: Inside real-world Google Workspace breaches

Tomorrow’s webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. […]

#security

D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. […]

#security

AI Agents Are Rewriting the Rules of Lateral Movement

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has?

A person may try several ways to complete a task. A deterministic application fol…

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.

The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and aff…

#vulnerability

Only 13% of OT Network Segments Are Fully Isolated: Analysis

Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets. The post Only 13% of OT Network Segments Are Fully Isolated: Analysis appeared first on SecurityWeek.

#icsot #iot-security #network-security #forescout #iomt

Siemens Industrial Edge Management

View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verification. Siemens has released new versions for the affected pr…

#vulnerability #authentication

OpenPLC Runtime v3

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller and the physical processes it drives. The following versions …

#vulnerability

lwIP (Lightweight IP)

View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (Lightweight IP) are affected:

API >=2.0.1|<=2.2.1 (CVE-2026-91018)

CVSS Vendor E…

#vulnerability

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches. The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek.

#vulnerabilities #exploited #switch #vulnerability #zyxel

DORA Year Two: Can Your SOC Actually See the Attack?

When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and docume…

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

A new flaw in the Linux kernel’s KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled.

The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the resea…

#vulnerability #linux

Malicious B-tree NPM Package Accumulates Millions of Downloads

Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method. The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek.

#application-security #supply-chain-security #npm #supply-chain-attack

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa.

The flaw, CVE-2026-65660…

#vulnerability #rce #windows

GPT-6 Astra Breaks an Old Enigma Message

This is pretty amazing: However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the …

#uncategorized #ai #cryptanalysis #enigma #history-of-cryptography

WordPress Patches ‘Click2Shell’ Vulnerability

The bug lets attackers automatically install and preview themes and could lead to remote code execution. The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek.

#vulnerabilities #click2shell #patch #vulnerability #wordpress

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

A malicious npm package named “indexed-btree” has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls.

“Indexed-btree is a malicious npm package mim…

#apt

Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme

The US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign. The post Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme appeared first on SecurityWeek.

#nation-state #fake-it-workers #fbi #featured #japan

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.

“SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.ex…

#phishing #apt

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Malware already running on a Mac can quietly take over Meta’s Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21.

It works by changing a hidden setting so that when the user taps the micropho…

#malware

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site’s server.

WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed “Comment2Shell,” on Sep…

#vulnerability #rce #xss

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability, tracked as CVE-2026-7273 (CVSS score: …

#vulnerability #patch

US Proposes AI Incident Alert System in Talks With China, Bessent Says

Trump has resisted calls to slow down AI development, saying that would help China catch up to U.S. companies. The post US Proposes AI Incident Alert System in Talks With China, Bessent Says appeared first on SecurityWeek.

#artificial-intelligence

BigCommerce alerts merchants of data breach linked to Ribon apps

Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. […]

#security

WordPress Click2Shell flaw lets hackers execute PHP on the server

Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed ‘Click2Shell’ that affects the platform’s Core component. […]

#security

Google Hit With $463 Million Fine for EU Location Data Rule Breach

Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data. The post Google Hit With $463 Million Fine for EU Location Data Rule Breach appeared first on SecurityWeek.

#privacy--compliance #fine #gdpr #google #privacy

Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto

The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory.

The primary targets …

#apt #authentication

Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware. The post Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer appeared first on SecurityWeek.

#malware--threats #edr-killer #infostealer #lastpass #malware

Transforming Bedrock Guardrails events into OCSF with CloudWatch

Security teams investigating possible AI-related security events need guardrail intervention data alongside their existing security telemetry. When a guardrail identifies or blocks a prompt injection attempt or redacts sensitive data, that intervention carries additional investigative value comparab…

#advanced-300 #amazon-bedrock #amazon-bedrock-guardrails #security-identity--compliance #amazon-athena

CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast

Noopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be. The post CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast appeared first on SecurityWeek.

#ciso-conversations #ciso-strategy #ciso

TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data

Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.

The backdoor “automatically harvests and exfiltrates business documents, watches the filesystem for new files in real t…

#malware

FBI's CJIS v6.1: What Security Teams Need to Know.

The FBI’s CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upc…

#security

Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal

The transaction is part of the $4.1 billion deal in which Accenture acquired a majority stake in Dragos in an OT cybersecurity push. The post Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal appeared first on SecurityWeek.

#ma-tracker #accenture #acquisitions #dragos #ma

Microsoft reminds admins to migrate Entra ID users to passkeys

Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. […]

#microsoft #security

LinkedIn wins court order blocking mass scraping of user data

The agreement between LinkedIn, ProAPIs and joint business operator Netswift also requires the firms to stop selling and transferring the data, no longer access LinkedIn through fake accounts and delete the data that was scraped, according to a senior LinkedIn executive.

#news #news-briefs #privacy

Google says Gemini breached three companies during security test

Google’s artificial intelligence model Gemini accessed computer systems belonging to three real companies without authorization during a cybersecurity test in May — the latest in a string of similar incidents.

#news #news-briefs #industry

Rust Team Members and Popular Crate Owners Targeted via Video Calls

It’s unclear if the attacks are part of previous campaigns against Rust, but the techniques used by the attackers match those used by North Korea. The post Rust Team Members and Popular Crate Owners Targeted via Video Calls appeared first on SecurityWeek.

#supply-chain-security #north-korea #rust #supply-chain-attack

CrowdSec Confirms Source Code Stolen in Supply Chain Attack

The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack. The post CrowdSec Confirms Source Code Stolen in Supply Chain Attack appeared first on SecurityWeek.

#data-breaches #supply-chain-security #crowdsec #data-breach #source-code

Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems

The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said.  The post Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems appeared first on SecurityWeek.

#icsot #nation-state #cyberattack #ics #ot

Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO

Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.

#active-directory #data-leaks #data-theft #detection-engineering #digital-forensics

From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies

We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies appeared first on Unit 42.

#cloud-cybersecurity-research #threat-research #aws #aws-cloudtrail #bedrock

Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities

Attackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory. The post Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities appeared first on SecurityWeek.

#vulnerabilities #cisa-kev #exploited #linux #linux-kernel

ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.

“ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zo…

#malware #apt

Google Confirms Gemini AI Breached Three Firms

Google is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies. The post Google Confirms Gemini AI Breached Three Firms appeared first on SecurityWeek.

#artificial-intelligence #ai #featured #gemini #google

Windows Exploitation Techniques: Dangling COM Object Registrations

This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804, that I and 14 others reported. This issue is an incomplete fix for CVE-2026-50343, a bug dubbed “Dark Elevator” by Calif. The root cause of the bug was a dangling COM object reg…

#vulnerability #windows

Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors

The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based “much smaller organization” in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks.

Cybersecuri…

#malware #apt

Cloud Threat Emulation on Autopilot: Context is Everything

Cloud threat emulation is more than detonation. A plan-first methodology for cloud detection engineering: scope, victim model, telemetry, coverage, cleanup. Learn how to properly leverage AI to automate your emulations.

#detection-engineering

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the ‘indexed-btree’ package shows how threat actors bypass supply chain defenses by hiding malicious code in a package’s normal runtime behavior rather than in installation scripts. […]

#security

TigerByte Cyber Emerges From Stealth With $3 Million in Funding

The company has secured over $7 million in contracts with US government agencies, including the US Space Force, the US Navy, and DARPA. The post TigerByte Cyber Emerges From Stealth With $3 Million in Funding appeared first on SecurityWeek.

#cybersecurity-funding #funding #tigerbyte-cyber

Identity Visibility in 2026: The Foundation of Identity Security

Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon’s annual Data Breach Investigations Report. This article explains what identity visibility …

#data-breach #authentication

Calling viral AI actress Tilly Norwood? Agree to a face scan first

AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her “Talking Tilly” video call service face-scans every caller for an 18+ age check, senses callers’ moods during calls, and shuts down permanently on September 27. We tried it and read the fine p…

#security

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic’s Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.

The chain began with a bug in the software that runs OpenAI’s public help forum …

SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.

The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring s…

#vulnerability #rce #patch

Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

Google’s Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal.

The incidents occurred in May 2026 as part of a test run conducted …

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18.

The French security company had kept his GitHub access open. CrowdSec says his laptop was compromised in May’s supply chain attack on T…

#supply-chain

CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerabilities are listed below -

CVE-2025-39682 (CVSS score: 9.8) …

#vulnerability #linux

MFA Won't Save You From OAuth Consent Abuse

MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.

#authentication

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine.

Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the explo…

#vulnerability #linux

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.

The security firm pwn.ai, whose …

#vulnerability #patch

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.

The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tool…

#malware

Nations take action on North Korean IT workers after UN report

A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.

#government #cybercrime #news

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

Noteworthy stories that might have slipped under the radar: Mandiant’s 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek…

#artificial-intelligence #cybercrime #vulnerabilities #in-other-news

Secure enterprise sharing with access reviews for Microsoft 365

Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and re…

#security

Webinar: Which Google Workspace security controls actually matter?

Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resou…

#security

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.

The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.

“Missing authentication for critical function i…

#vulnerability #patch #cloud #authentication #windows

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.  The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek.

#artificial-intelligence #ai #chatgpt #openai #source-code

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.

CVE-2025-39964 Linux Kernel Race Condition Vulnerability CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability

These types of vulnerabilities are a frequen…

#vulnerability #linux

23 Million User Records Compromised in Gyazo Data Breach

Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach  appeared first on SecurityWeek.

#data-breaches #data-breach #gyazo #images

Are AIs Still Struggling with CAPTCHAs?

Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification te…

#uncategorized #ai #captchas #games

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

In July 2025, someone registered a domain that used to belong to a content delivery network.  The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation page…

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.

#artificial-intelligence #cloud-security #vulnerabilities #ai #azure

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.

The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democ…

#malware

NightmareStresser DDoS Service Disrupted in International Operation

Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world. The post NightmareStresser DDoS Service Disrupted in International Operation appeared first on SecurityWeek.

#cybercrime #tracking--law-enforcement #cybercrime #ddos #disrupted

A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity

Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.

#cloud-cybersecurity-research #threat-research #agentcore-runtime #agentic-ai #cloud

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.

#malware--threats #supply-chain-security #brevo #clickfix #featured

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.

“The developer likely wrote the malware using a large language model (LLM), an assessment made with high confid…

#malware #apt

Critical Orkes Conductor Vulnerability Exploited in Attacks

CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek.

#vulnerabilities #exploited #orkes #vulnerability

MIND Secures $72 Million for AI-Powered DLP

The company will use the funding to accelerate platform development and expand its presence in key enterprise markets. The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek.

#cybersecurity-funding #data-protection #data-protection #data-security #funding

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.

#endpoint-security #vulnerabilities #check-point #kaspersky #patch

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices.

“Distributed primarily via targeted smishing (SMS/text phi…

#malware #apt

Inside the Modern SOC: Defending the Cross-Environment Pivot

Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42.

#inside-the-modern-soc #insights #ai #attack-surface #unit-42-incident-response-report

New RatHat Android malware uses AI to automate device control

A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. […]

#security #artificial-intelligence #mobile

Run open weight models on Amazon Bedrock in AWS European Sovereign Cloud

European organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can now run generative AI workloads on open weight models on Amazon Bedrock in the AWS European Sovereign Cloud. We’re excited to announ…

#amazon-bedrock #artificial-intelligence #europe #generative-ai #security-identity--compliance

The Autonomous Engine Behind Remediation, and What Finally Makes It Safe

Executive Summary Vulnerability exploitation now happens at a speed that manual, ticket-based remediation can’t match. Qualys’s Enterprise TruRisk Management Platform closes that gap with autonomous remediation: exposures are prioritized by threat, business, and environmental context, then validated…

#product-and-tech #qualys-insights #agent-val #autonomous-remediation #enterprise-trurisk-platform

OpenAI details more cases of AI agents taking unauthorized actions

OpenAI has presented new examples of what they call “AI model misalignment” from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. […]

#security #artificial-intelligence

Flock cameras are tracking people as well as cars

Two reports reveal how Flock’s license plate camera network tracks people’s movements while oversight continues to lag.

#news #privacy #encrypted #flock #surveillance

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network.

The Security Management Server is the system that controls firewall policy and administrator access. Check Point has…

#vulnerability #authentication #network

Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran. The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first on SecurityWeek.

#icsot #nation-state #coast-guard #cyberattack #fbi

From guidance to action: Security fundamentals that materially reduce risk

AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take action and stay ahead of cyberthreats. The post From guidance to action: Security fundamentals that materially reduce risk  appeared first on Microsof…

Improving email security outcomes with real-world Microsoft Defender insights

The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve. The post Improving email security outcomes with real-world Microsoft Defender insights appeared first on…

#windows

OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior. The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek.

#artificial-intelligence #ai #openai #rogue-ai

VU#280377: Dokploy is vulnerable to OS command injection

Overview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacker to escalate privil…

#vulnerability #injection

AI Threat Landscape Digest: July–August 2026

The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions: models now act as …

#check-point-research-publications

CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.

#government #vulnerabilities #cisa #risk-management #vulnerability

Revolut phishing texts appear days after data breach

Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.

#scams #threat-intel #account #revolut #scam

What Recent AI-Powered Attacks Mean for Your Identity Security

AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. […]

#security

Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.

#data-breaches #data-breach #data-leak #featured #revolut

Congress eyes new support for Cyber Command after recent suicide deaths

Congressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contributions to high-profile missions against Iran and Venezuela.

#government #leadership #news #people

Comp AI Raises $34 Million for AI-Native Compliance and Security

The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek.

#compliance #cybersecurity-funding #risk-management #compliance #funding

ISC Patches 14 Vulnerabilities in BIND 9 Security Update

Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek.

#vulnerabilities #bind #dns #patch #vulnerability

Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.

An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.

Unbound …

#rce #network

Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows

Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.

#icsot #ransomware #ot

Schneider Electric PowerChute Serial Shutdown

View CSAF Summary Schneider Electric is aware of vulnerabilities in its PowerChute Serial Shutdown product. The PowerChute Serial Shutdown product is a UPS management software enabling graceful system shutdown and energy management capabilities for desktops, servers and workstations. Failure to appl…

#vulnerability

Mitsubishi Electric GX Works3 and Motion Control Settings

View CSAF Summary Successful exploitation of this vulnerability could allow a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modify part of the executable module in memory, and thereby allows the attacker to view, tamper with, de…

#vulnerability

Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A)

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker with access to the same network segment to tamper with communication data in the affected product by sending specially crafted packets under specific timing conditions. This could allow the attacker to cause a de…

#vulnerability

Hitachi Energy FACTS Control Platform (FCP)

View CSAF Summary Hitachi Energy is aware of vulnerabilities that affect the FACTS Control systems with GWS component listed in this document. An attacker exploiting these vulnerabilities can cause impact on confidentiality, integrity and availability of the product. Following FACTS Control systems …

#vulnerability

ABB Ability Edgenius

View CSAF Summary ABB is aware of public reports of a vulnerability CVE‑2026‑31431 (Copy Fail) in the product versions listed as affected in the advisory. An update is available that resolves a publicly reported vulnerability. CVE‑2026‑31431 (Copy Fail) is a Linux kernel vulnerability that may allow…

#vulnerability #linux

Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

A new CVE drops. Your scanner finds it. The severity score looks ugly.

But that still does not answer the question that matters: Can it actually be exploited in your environment?

Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still…

#vulnerability

US takes down NightmareStresser DDoS-for-hire platform

The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world’s longest-running distributed denial-of-service (DDoS) platforms. […]

#security

How Candidates Could Use AI for Good

This essay was written with Nathan E. Sanders, and originally appeared in The Guardian. There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to spread lies. The Wh…

#uncategorized #ai #democracy #llm

CISO's Expert Guide to Agentic Pentesting for Websites

Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one …

#vulnerability #patch

T-Mobile rewards points expiry texts are a phishing scam

A large phishing campaign is using fake T-Mobile rewards points and looming expiry dates to pressure recipients into clicking malicious links.

#scams #threat-intel #reward-points #t-mobile

Microsoft shares workaround for Windows domain login issues

Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. […]

#microsoft

CISA Releases Guidance on Deploying Cyber Decoys

Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Guidance on Deploying Cyber Decoys appeared first on SecurityWeek.

#government #cisa #decoys #guidance

AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals

New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.

#artificial-intelligence #ai #ai-training #irregular #rogue-ai

Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day

Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.

#vulnerabilities #cisco #cisco-ise #exploited #featured

Smashing Security podcast #485: These researchers got drunk to hack an LG TV

Researchers wanted to test if LG’s smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can’t be legally bound to a contract you agr…

#ai #android #malware #podcast #privacy

Architecting a secure landing zone in the AWS European Sovereign Cloud

The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AWS partition (aws-eus…

#advanced-300 #security-identity--compliance #technical-how-to #europe #security-blog

Windows 11 KB5124008 update breaks domain trust for some users

Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. […]

#microsoft

House passes bill to equip local law enforcement with scam-fighting tools

The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped to properly investiga…

#cybercrime #government #news

Data Broker Radaris Loses Domains in Privacy Fight

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides…

#a-little-sunshine #neer-do-well-news #andtop-company #atlas-data-privacy #bitseller-expert-limited

Fighting Your Dragons Through Tough Tech Times

Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.

VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control

Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels flavor does not apply …

#vulnerability

First Agentic AI Data Breach Reported to Spanish Regulator

Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.

#artificial-intelligence #data-breaches #ai #data-breach #featured

Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.

The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote at…

#vulnerability

Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky.

The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to …

#ransomware #malware #apt

Virtual Event Today: Attack Surface Management Summit

Join SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces. The post Virtual Event Today: Attack Surface Management Summit appeared first on SecurityWeek.

#application-security #attack-surface-management

EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media

Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children. The post EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media appeared first on SecurityWeek.

#artificial-intelligence #government #ai #eu #featured

The true cost of a ransomware attack, with and without BCDR

The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. […]

#security

AIUC Raises $40 Million to Certify Enterprise AI Agents

The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared first on SecurityWeek.

#artificial-intelligence #cybersecurity-funding #ai #aiuc #funding

EU chief wants joint response to cyberattacks, sabotage

Delivering her annual State of the Union address in Strasbourg, Ursula von der Leyen said threats were “mounting on our soil,” pointing to recent incidents in Denmark, Lithuania and Poland and an attempted drone attack in Leipzig.

#government #cybercrime #leadership #news

Pixel Modem Zero-Day Exploited in Targeted Attacks

Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek.

#mobile--wireless #vulnerabilities #android #exploited #pixel

Ukraine moves to crack down on scam call centers after corruption scandal

Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.

#news #news-briefs #cybercrime #government

Webinar: What happens in the first hours of a Google Workspace breach

The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. […]

#security

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek.

#malware--threats #chosen-brick #espionage #government #iran

Using Cyber Decoys to Strengthen Detection and Response

CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and li…

#authentication

N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security

N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity.

From there, a single c…

#malware #phishing #apt #authentication

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek.

#vulnerabilities #calendar #plugin-vulnerability #vulnerability #wordpress

Fake CAPTCHA Scams

New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.

#uncategorized #captchas #scams

Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild.

The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw.

“In Cellular Modem, there is a possible permission bypass due to a logic erro…

#vulnerability #patch

Threat Intelligence Alone Won't Close the Exploitation Gap

A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelera…

#vulnerability #authentication

Hackuity Raises $19 Million for AI-Powered Vulnerability Management

The company will use the new capital to expand its vulnerability operations platform and support international growth. The post Hackuity Raises $19 Million for AI-Powered Vulnerability Management appeared first on SecurityWeek.

#cybersecurity-funding #funding

280,000 Impacted by Premier Medical Group Data Breach

In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information. The post 280,000 Impacted by Premier Medical Group Data Breach appeared first on SecurityWeek.

#data-breaches #data-breach #healthcare #premier-medical-group

Chrome, Firefox Updates Patch 115 Vulnerabilities

Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox. The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek.

#vulnerabilities #chrome #firefox #patch #vulnerability

NightEagle targets Russian companies

Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.

#kerberos #dcsync #nighteagle #traffic-tunneling #ghostcontainer

Atomic macOS (AMOS) Stealer Activity

Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.

#general #insights #malware #macos #malware

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability appeared first on SecurityWeek.

#vulnerabilities #exploited #vulnerability #wso2

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.

“This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote …

#malware #vulnerability #apt

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr.

The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeove…

#vulnerability

ZDI-26-711: NoMachine Redis Improper Authentication Local Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of NoMachine. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs…

#vulnerability #authentication

ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability

This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.3.

#zero-day #vulnerability #windows

ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability

This vulnerability allows remote attackers to execute arbitrary code on affected installations of MindsDB. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92207.

#zero-day #vulnerability #rce #authentication #injection

AWS STS simplifies session token size limits and adds session token size monitoring

AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes. STS now reports session tok…

#advanced-300 #aws-security-token-service #security-identity--compliance #technical-how-to #aws-sts

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates.Key TakeawaysThe September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates104 issues (15.5% of all patches) were assig…

#patch

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer’s website and pushed updates that created a hidden user account. […]

#security

“We Think the Security Control Is Working” Is No Longer Good Enough

Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek.

#ciso-strategy #risk-management #controls

Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident

The ‘Breaking’ News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, …

Architecting resilient authentication with Amazon Cognito multi-Region replication

Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geographies, ensuring authentication is always available becomes a core architectural r…

#advanced-300 #amazon-cognito #security-identity--compliance #technical-how-to #security-blog

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN.

Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersona…

#malware #apt #authentication #privacy

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signali…

#product-and-tech #mttr #patch-management #qualys-patch-reliability-score

VectraRAT Can Hack Windows Enterprises for $250 per Month

The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.

#malware #windows

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and activists around the world.

The malware is controlled via the Telegram messaging app and can cop…

#malware #windows

Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’

According to the United Kingdom’s National Cyber Security Centre (NCSC), Iran has used this and similar cyber activity to “support the repression of individuals who are seen as a threat to the regime, such as dissidents, activists and journalists.”

#cybercrime #government #news #nation-state

$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage. The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek.

#vulnerabilities #linux #sandbox #vulnerabilities

Operationalizing least privilege: Automate IAM remediation through your CI/CD pipeline

The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s faster to get things working, and the plan is always to tighten permissions later. B…

#aws-identity-and-access-management-iam #best-practices #expert-400 #security-identity--compliance #technical-how-to

Exein Secures $270M at $1.7B Valuation for Physical AI Security

The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion. The post Exein Secures $270M at $1.7B Valuation for Physical AI Security appeared first on SecurityWeek.

#cybersecurity-funding #iot-security #ai #exein #funding

How to opt out of AI chatbot training

ChatGPT contractors are reviewing real users’ conversations. Here’s how to stop AI companies using your chats for model training.

#ai #how-to #news #anthropic #human-review

BambooToken malware controls Windows and Linux systems via MQTT

A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. […]

#security

Automate Asset Isolation: Your Last Resort to Meet Remediation Deadlines

Executive Summary Remediation deadlines slip for reasons outside your control: a patch does not exist yet, a patch is delayed, or a remediation attempt fails. The outcome is the same either way: the host stays unpatched and stays on the network. TruRisk Eliminate closes that window by isolating the …

#product-and-tech #isolation #patchless-patching #remediation-intelligence #trurisk-eliminate

What Zero-Day Response Should Be in the Post-Mythos Era

AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attacke…

#security

Thai Broadband Provider Hacked via Fortinet Vulnerability

The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked via Fortinet Vulnerability appeared first on SecurityWeek.

#malware--threats #3bb #exploited #fortinet #thailand

Give every teammate and agent the right level of access to your Workers

You can now scope access to individual Workers and assign narrower Developer Platform roles, so teammates, CI tokens, and agents get only the access they need to debug, deploy, or monitor safely.

#developers #identity #product-news #security #workers

China spy chief points at US AI models in cyber threat warning

China’s spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.

#china #cybercrime #government #industry #leadership

OpenAI Investigates Report Linking AI Agents to RubyGems Attack

The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity. The post OpenAI Investigates Report Linking AI Agents to RubyGems Attack appeared first on SecurityWeek.

#artificial-intelligence #ai #openai #rubygems

Manhattan DA takes down 12 AI deepfake porn sites

Manhattan District Attorney Alvin Bragg held a press conference on Monday touting the takedown of the sites, which hosted AI-generated videos of more than 1,200 people. The sites allowed users to use the faces and bodies of real people to create illegal pornography.

#cybercrime #government #news #news-briefs

mySCADA myPRO Manager

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem. The following versions of mySCADA myPRO Manager are affected:

mySCADA myPRO Manager <=2.1 (CVE-2026-73…

#vulnerability

Digital Watchdog VMAX DVR and NVR Product Lineups

View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a network pivot point. The following versions of Digital Watchdog …

#vulnerability #privacy

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access.

In one instance highlighted by …

#vulnerability #rce

240,000 Hit by Data Breach at Japan’s Digital Agency

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people. The post 240,000 Hit by Data Breach at Japan’s Digital Agency appeared first on SecurityWeek.

#data-breaches #data-breach #government #japan #vpn

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases

The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks. The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  appeared first on SecurityWeek.

#vulnerabilities #apple #featured #ios #ios-27

25 Years of Mass Surveillance Is Enough

This essay was written with Cindy Cohn, and originally appeared in Lawfare. One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as …

#uncategorized #privacy #surveillance

On the NSA’s Supercomputer from the 1960s

Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.

#uncategorized #history-of-computing #history-of-cryptography #ibm #intelligence

Suspected Black Axe gang leaders face cybercrime charges in the US

Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. […]

#security

Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man

44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison.

That should be plenty of time for him to rue the day he agreed to increase his monthly income by helping a SIM swap gang in their attempt to steal …

#guest-blog #law--order #att #mobile #sim-swap

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-76461, carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insuffi…

#vulnerability

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE.

Volexity, which is tracking the threat cluster under the moniker UTA0560, said th…

#zero-day #malware #phishing #vulnerability #apt

Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation

An unauthenticated attacker can exploit CVE-2026-76461 to execute arbitrary commands on the underlying OS with root privileges. The post Root RCE Zero-Day in Cisco Secure Email Gateway Under Active Exploitation appeared first on SecurityWeek.

#email-security #vulnerabilities #cisco #exploited #featured

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

#vulnerability #supply-chain

Homebrew 7.0.0 gets built-in GUI, better security controls

Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. […]

#security #software

Upcoming Speaking Engagements

This is a current list of where and when I am scheduled to speak:

I’m speaking online (via Zoom) at a League of Women Voters event on Tuesday, September 22, 2026 at 5 PM ET. I’m speaking at CanSecWest 2026 in Vancouver, Canada. The conference runs September 30–October 1, 2026; the time of my talk i…

#uncategorized #schneier-news

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said.

The company uncovered the intrusion by examining a ser…

#malware #authentication

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

A flaw in Telegram Desktop let a bot’s message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12.

In Telegram, the message looked ordinary, with a link button, and the script ran only when someone open…

#patch

AWS Security Reference Architecture: A deep dive into PCI DSS compliance

Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive. This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance for organizations tha…

#announcements #foundational-100 #security-identity--compliance #pci-dss #security-blog

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the processor keeps reading old encrypted data as if it were current.

The attack requires an attacker who al…

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign.

“Red Heron scanned 1,386 Gitea instances across seven countries and maintai…

#vulnerability #apt #rce

Using AI for Weapons Development

Last week, Anthropic released a long and detailed document describing current misuses of their Claude models. I’m still reading it, but I wanted to flag this: We identified a cell of threat actors based in northern Yemen running three weapons development programs: a guided rocket that used a commodi…

#uncategorized #ai #reports #weapons

Hundreds of fake government websites target users in Central Asia

The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices.

#cybercrime #government #news #news-briefs

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

WordPress has announced it’s launching an automated security review for every release of a plugin before it’s distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved.

“New plugins are reviewed before they enter the di…

Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development

China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI. The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on SecurityWeek.

#artificial-intelligence #ai #anthropic #china

Why Patch Automation Needs Brakes, Not Just an Accelerator

Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control. […]

#security

New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate

Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims. The post New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate appeared first on SecurityWeek.

#artificial-intelligence #ai #risk

The Race to Control AI and Protect What Makes Us Human

As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity. The post The Race to Control AI and Protect What Makes Us Human appeared first on SecurityWeek.

#artificial-intelligence #icsot #ai #featured #humanity

14th September – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data includ…

#global-cyber-attack-reports

Webinar: How malicious OAuth apps can lead to Google Workspace breaches

Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. […]

#security

AI Changed the Exposure Problem. Validation Needs to Change With It.

There’s a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action.

#vulnerability

Microsoft’s Patching

Once a month, Microsoft pushes a security update to all Windows users. Tomorrow’s is a new record: Microsoft’s patch for September is a doozy, with a record number of roughly 972 vulnerabilities fixed and 112 of them meeting the high critical-severity threshold. It was only two months ago that Micro…

#uncategorized #ai #microsoft #patching #vulnerabilities

CISOs Race to Control AI Agents Without Destroying Their Value

Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. The post CISOs Race to Control AI Agents Without Destroying Their Value appeared first on SecurityWeek.

#artificial-intelligence #ciso-strategy #ai #ciso

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to Git…

#emergent-threat-response #emerging-threats

Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection

We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.

#cloud-cybersecurity-research #threat-research #aws-cloudtrail #cloud-detection #devops

Telus Warns Customers of Account Breaches

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records. The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek.

#data-breaches #account-takeover #canada #data-breach #telecom

Three JFrog Artifactory Flaws Exploited for Backdoor Deployment

The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator. The post Three JFrog Artifactory Flaws Exploited for Backdoor Deployment appeared first on SecurityWeek.

#vulnerabilities #backdoor #exploited #jfrog-artifactory #vulnerability

ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks

The flaw allows attackers to send files and execute them without authorization through an active remote session. The post ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks appeared first on SecurityWeek.

#vulnerabilities #exploited #featured #patch #screenconnect

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service.

The extension, named “Twitch Enhanced Viewer | JeetBot,” lists HISHIMIRO/jeetbot.cc as its developer and has the following iden…

ZDI-26-702: Linux Kernel usbnet Driver Race Condition Privilege Escalation Vulnerability

This vulnerability allows physically present attackers to escalate privileges on affected installations of Linux Kernel. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.1. The following CVEs are assigned: CVE-2025-22050.

#vulnerability #authentication #linux

Hackers exploit Tencent app flaw to deploy GrayRabbit malware

Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. […]

#security

Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up

Dario Amodei warned that within six to 12 months AI could be capable of leading a swarm of agents that could take over the entire internet. The post Anthropic CEO Dario Amodei Says AI Industry Needs to Give Safety Measures Time to Catch Up appeared first on SecurityWeek.

#artificial-intelligence #ai #anthropic #featured #openai

Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments.

The first campaign, per the tech giant, involved sending ove…

#phishing #apt #windows

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

Details of the vul…

#vulnerability #network

BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.

#vulnerabilities #bluemoon #chrome #exploit-kit #exploited

When the Whole Company Adopts AI: What It Does to Your SOC

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from dev…

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.

On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Men…

#supply-chain #rce

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket. The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek.

#artificial-intelligence #ai #anthropic #featured

Friday Squid Blogging: Rotting Squid on a Beached California Boat

Smells awful: But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association. Ogg said anyone familiar wi…

#uncategorized #squid #video

Hackers abused Claude to extract secrets from 1.8M Android apps

Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. […]

#security #artificial-intelligence

Florida confirms DMV database breached via stolen police account

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. […]

#security

Microsoft sees some new wrinkles in invoice-scam emails

Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.

#cybercrime #news #news-briefs #industry

SpiderSilk Hunts External Threats With AI-Based Scanner

The Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities.

#zero-day #vulnerability

Why AI Is So Good at Scamming Humans

Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.

Phishing Research Challenges Conventional Security Awareness Testing

Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness Testing appeared first on SecurityWeek.

#phishing #awareness-training #phishing

AI Governance Can't Wait

Adversaries can manipulate AI defensive reasoning to silently compromise target networks.

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.

The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits AP…

#vulnerability #patch

Artifactory flaws chained in attacks deploying backdoor malware

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. […]

#security

GitLab Vulnerability Exploited One Day After Disclosure

The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.

#vulnerabilities #exploited #gitlab #vulnerability

Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026.

The threat actors, which the artificial intelligence (AI) company has branded Generative…

#vulnerability #apt #privacy

In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY. The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review ap…

#cybercrime #in-other-news

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.

The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands…

#malware #apt

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. […

#security

Metasploit Wrap Up: This One Goes to Sixteen!

This One Goes to Sixteen!Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watcher…

#metasploit-weekly-wrapup #metasploit

The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

IntroductionThe surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various sma…

#threat-intel

Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.

#data-breaches #email-security #phishing #brevo #cryptocurrency

Your Critical Vulnerabilities Might Not Be Your Biggest Risk

Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise.

A critical vulnerability may look alarming on a scanner report, but if it…

#vulnerability

Check Point Patches Critical VPN Vulnerabilities

Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek.

#vulnerabilities #check-point #vpn #vulnerability

Cliff Stoll’s DEF CON Talk

In August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago. Great fun.

#uncategorized #history-of-security #video

Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance

Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars. The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek.

#data-protection #ma-tracker #acquisition #bonfy #data-security

Surfshark Systems Targeted by Hackers

A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors. The post Surfshark Systems Targeted by Hackers appeared first on SecurityWeek.

#data-breaches #data-breach #surfshark #vpn

Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

Anthropic reveals how criminal groups are increasingly targeting AI vendors’ own infrastructure, including to steal a pre-release Claude model. The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek.

#artificial-intelligence #nation-state #ai #anthropic #claude

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report.

Wiz saw the attacks between August 15 and September 8. JFrog had fixe…

#malware #cloud

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims’ computers, security company Gen Digital said in research published Thursday.

The attack started with a crafted link and …

#malware #vulnerability #windows

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.

The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.1…

#vulnerability #patch

Linux Detection Engineering - Local Privilege Escalation

Seven of the thirteen Linux privilege escalation CVEs we tracked in 2026 turned out to be the same copy-on-write bug pointed at different kernel interfaces. We ran the public proof-of-concept for eleven exploits and two misconfigurations, and noted which rules fired.

#detection-engineering

September Windows Server updates break Remote Desktop Services

Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. […]

#microsoft

Mandiant Founder Kevin Mandia Joins Amazon Board

Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board. The post Mandiant Founder Kevin Mandia Joins Amazon Board appeared first on SecurityWeek.

#management--strategy #amazon

Microsoft Excel KB5002914 update breaks copy and paste for some users

Microsoft Excel users report that this week’s KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. […]

#microsoft

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”

An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful…

#phishing

Protecting organizations from AI-assisted executive impersonation and invoice fraud

Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security B…

#social-engineering

Cybersecurity M&A Roundup: 33 Deals Announced in August 2026

Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa. The post Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 appeared first on SecurityWeek.

#fundingma #ma-tracker #acquisitions #ma

Detect and disrupt AI-themed attacks with Microsoft Defender

See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.

#adversary-in-the-middle-aitm #credential-theft #social-engineering

Anthropic Researcher Resigns With Warning About the Dangers of AI Development

Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns. The post Anthropic Researcher Resigns With Warning About the Dangers of AI Development appeared first on SecurityWeek.

#artificial-intelligence #ai #anthropic

PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector

Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all pre…

#check-point-research-publications

Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster

Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox. The post Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster appeared first on SecurityWeek.

#hacker-conversations #hacker

The Top 4 Threats We Found by Investigating Every Alert for a Quarter

Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. […]

#security

Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews

Deceptive apps in Early Access are being used by dishonest developers for their own benefit. The post Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews appeared first on SecurityWeek.

#fraud--identity-theft #mobile--wireless #android

‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars

Here’s a tip for any budding cybercriminals out there.

If you’re going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don’t broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub.

Read more in my artic…

#guest-blog #law--order #phishing #cryptocurrency #phishing

Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation

Join the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT operations accelerate. The post Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation appeared first on SecurityWeek.

#artificial-intelligence #endpoint-security #vulnerabilities #endpoint #webinar

1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it

1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale.

#1111 #cryptography #dns #dnssec #post-quantum

UK appoints new commander of National Cyber Force

The individual has not yet been avowed — the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged — as routine security considerations are still being worked through.

#government #cybercrime #leadership #news

Will AI kill us all within the next decade?

AI researchers are warning that the technology could kill us all within the next decade, although they say the risk from current models is low.

#ai #news

ST Engineering iDirect iQ-Series Terminals (Update A)

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST Engineering iDirect iQ-Series Terminals (Update A) are affected:

Evolution iQ‑Series term…

#vulnerability #ddos

Orthanc DICOM Server

View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image, resulting in a crash of the Orthanc process and a denial-of-service condition. The foll…

#vulnerability #ddos

NextGen Healthcare Mirth Connect

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are affected:

Mirth Connect <=v4.7.1 (CVE-2026-82583, CVE-2026-78224, CVE-2026-82578)

#vulnerability #ddos

AVEVA Pipeline Integrity Monitor

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA Pipeline Integrity Monitor are affected:

AVEVA Pipeline Integrity Monitor <=2025_SP1_P1…

#vulnerability

Widened Scan Turns Up Fourth Rogue Claude Cyber Incident

Anthropic is most concerned about Claude Mythos 5’s reckless behavior after recent incidents in which real systems were hacked. The post Widened Scan Turns Up Fourth Rogue Claude Cyber Incident appeared first on SecurityWeek.

#artificial-intelligence #ai #anthropic #claude

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only “under specific conditions” that it has not described.

One flaw affects Check Poin…

#vulnerability #rce #patch #network

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances.

According to independent reports from Blackpoint Cyber and GreyNoi…

#vulnerability

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9.

A work profile is a separate space that Android typically reserves for employer…

#malware

AIs Compress Exploit Timeline

Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour …

#uncategorized #ai #exploits #open-source

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.

#vulnerability #patch

Organizations Warned of Cisco Secure FMC Exploitation

Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek.

#vulnerabilities #cisco #exploited #firewall #fmc

The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42.

#malware #threat-research #api #cryptographic #json

CISA: WatchGuard RCE flaw now exploited in ransomware attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. […]

#security

What Is ISPM? How It Differs from IAM, PAM, IGA, and IDaaS

Key Takeaways Identity Security Posture Management (ISPM) is the continuous risk and posture layer of the identity stack not a replacement for Identity and Access Management (IAM), Privileged Access Management (PAM), Identity Governance and Administration (IGA), or Identity-as-a-Service (IDaaS), but…

#product-and-tech #etm-identity #iam #idaas #identity-security

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example 'sk-1234' Admin Key

Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup guide.

LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That k…

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents.

The AI company said the incident da…

Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026. The post Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks appeared first on SecurityWeek.

#malware--threats #vulnerabilities #exploited #featured #fortigate

Smashing Security podcast #484: How websites are tracking you with silence

When a chap called Matt noticed his Bluetooth headphones wouldn’t switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one …

#data-loss #malware #podcast #privacy #ransomware

Threat matrix: Mapping threats across cloud web applications

Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. The post Threat matrix: Mapping threats across cloud web applications appeared first on…

#windows

The state of AI for security: Measuring what matters most for building trust

Security teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response, and code review. The promise is speed, but a security tool that moves fast and raises too many false alarms doesn’t save time. Engineers spend ti…

#advanced-300 #artificial-intelligence #generative-ai #security-identity--compliance #thought-leadership

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Cente…

Passkey-themed social engineering leads to identity and cloud compromise

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. T…

#social-engineering

HelmGuard Raises $7.3 Million for Agentic GRC and Security

The company will increase its US market presence and will expand its engineering and go-to-market teams. The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek.

#compliance #cybersecurity-funding #risk-management #ai #funding

Electronic health record company says customer data stolen in breach

Veradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the company added.

#cybercrime #news #privacy

AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG. The post AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns appeared first on SecurityWeek.

#artificial-intelligence #nation-state #ai #google #gtig

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.

The first in-the-wild use of BlueMoon has been attributed to the China-aligned …

#vulnerability #windows

Android’s September 2026 Updates Patch 180 Vulnerabilities

The security updates resolve critical flaws across Android’s Framework, System, and Kernel components. The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek.

#mobile--wireless #vulnerabilities #android #vulnerability

Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories

Major chipmakers announced patches for vulnerabilities recently discovered in their products. The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek.

#vulnerabilities #amd #arm #nvidia #patch-tuesady

Driver’s License Data for Sale

A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.

#uncategorized #cars #dark-web #data-breaches #databases

FBI puts its cyber strategy on paper

The first public cybersecurity strategy issued by the FBI “directs our teams, our field offices, our global presence” to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett Leatherman says.

#government #cybercrime #nation-state #news

Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it

If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating po…

#vulnerability-management

The Models That Found 10,000 Zero-Days Broke Into Three Companies Using Weak Passwords

The question of whether a Frontier AI model could find vulnerabilities that no human researcher had found was settled in April. Claude Mythos Preview identified thousands of previously unknown flaws across every major operating system and browser, including a 27-year-old denial-of-service condition …

#qualys-insights #frontier-ai #frontier-ai-intrusion #hugging-face

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create “stolen keys” that grant illicit access to tools from model providers like Google, Anthropic, and others. 

Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide r…

#malware #authentication

MFA's Weakest Link: Account Recovery Is the New Attack Path

MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account rec…

#security

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.

#artificial-intelligence #ai #china #featured

Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy

Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek.

#artificial-intelligence #ai #facebook #meta #muse

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed?

For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enoug…

#vulnerability

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

A flaw in DeepSeek Harness, DeepSeek’s open-source tool for running AI coding agents on a developer’s machine, let a sandboxed agent turn off its own sandbox with a single command.

The tool runs an agent’s commands inside an operating-system sandbox, so that an agent working on untrusted files cann…

Claude Fable Solves a Historical Cipher

Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.

#uncategorized #ai #cryptography #history-of-cryptography #mathematics

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek.

#icsot #vulnerabilities #aveva #ics #patches

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet.

Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own comp…

Ivanti Patches Critical Flaws Across Enterprise Security Products

Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek.

#network-security #vulnerabilities #ivanti #vulnerabilities

Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.

#malware #threat-research #arktunnel #c2 #cl-cri-1171

This Key Will Self-Destruct: An Open Standard for Revocable API Keys

Every leaked credential should be dead, or dying, within sixty seconds of being found. Here’s a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek.

#application-security #identity--access #api #credentials

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek.

#phishing #featured #phishing

Chrome 153 Patches Seventh Zero-Day of 2026

The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek.

#vulnerabilities #chrome

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting “systematic extraction” of proprietary functionalities and capabilities of American frontier models through distillation attacks.

The activity has been described as occurring a…

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.

The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome’s J…

#zero-day #vulnerability #patch

CRPx0 ransomware: what you need to know

CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business.

Read more in my article on the Fortra blog.

#guest-blog #malware #ransomware #ransomware

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user.

cPanel published the ad…

#patch

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7.

When Apache loads any of the three appliances’ own PHP scripts, the malware adds the web shell to the copy hel…

#malware

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldCrash” right after Microsoft rolled out its September 2026 Patch Tuesday security updates. […]

#security #microsoft

Google warns of new Chrome zero-day bug exploited in attacks

Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. […]

#security #google

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026.

T…

#vulnerability #rce

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many o…

#latest-warnings #security-tools #time-to-patch #cve-2026-69730 #cve-2026-69829

Testing race conditions with memory access tracing and stack-based delay injection

Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: Confirming bug candidates that have been discovered manually or through static analysis. Regression tests: A…

#injection

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning i…

#a-little-sunshine #data-breaches #the-coming-storm #web-fraud-20 #cybera

What's in a tag name? JavaScript, apparently

I was on my laptop, as I often am when there’s rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with “a-zA-Z”, but what about after that? I t

CRLF-Powered Desync Attacks: Beheading HTTP Streams

Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power

#xss #injection

A 0-click exploit chain for the Pixel 10: When a Door Closes, a Window Opens

We recently published an exploit chain for the Google Pixel 9 that demonstrated it was possible to go from a zero-click context to root on Android in just two exploits. The Dolby 0-click vulnerability existed across all of Android, until it was patched in January 2026. While we had an exploit chain …

#vulnerability #patch

AI threats in the wild: The current state of prompt injections on the web

Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now, Indirect Prompt Injection (IPI) is a top priority for the secur…

#injection

Bringing Rust to the Pixel Baseband

Posted by Jiacheng Lu, Software Engineer, Google Pixel Team

Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks associated within the complex modem firmware, Pixel 9 shipped with m…

#android #android-security #pixel

Protecting Cookies with Device Bound Session Credentials

Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team

Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for Windows users on Chrome 146, and expanding to macOS in an upco…

#authentication #windows

> Vulnerability Research

Working on a claude Skill

Hey guys! I’m working on a claude skill that automates recon,endpoint discovery,tech fingerprinting, vulnerability/cve research and organizes the results for manual pentesting. What would you add to a…

I need Help!!

Guys, I am doing my thesis work and deadline is in 15 days. I don’t have much time left to collect survey responses. could you please help me by participating in the survey? I need 100 responses atlea…

What's in a tag name? JavaScript, apparently

I was on my laptop, as I often am when there’s rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with “a-zA-Z”, but what about after that? I t

CRLF-Powered Desync Attacks: Beheading HTTP Streams

Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power

On the Effectiveness of Mutational Grammar Fuzzing

Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar that describes the structure of the samples. When a sample gets mutated, the mutations happen in such a …

A Deep Dive into the GetProcessHandleFromHwnd API

In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application….

Top 10 web hacking techniques of 2025

Welcome to the Top 10 Web Hacking Techniques of 2025, the 19th edition of our annual community-powered effort to identify the most innovative must-read web security research published in the last year

Leaking File Contents with a Blind File Oracle in Flarum

Introduction

Flarum is a free, open source PHP-based forum software used for everything from gaming hobbyist sites to cryptocurrency discussion. A quick survey on Shodan suggests there are over 1200 …

Advisory: Flarum LFI - CVE-2023-40033

Summary

An attacker with a basic user forum account can specify a malicious avatar URL that discloses the contents of arbitrary local files on the file system.

Impact

An attacker can read the conte…

> This Month's Exploited CVEs

CVE-2026-75650 Critical CVSS: 10.0

EPSS: 2.1% probability of exploitation in the next 30 days.

Adobe Commerce is affected by an Improper Neutralization of Special Elements Used in a Template Engine vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue does not require user interaction. Scope is changed.

Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.

2026-09-07 Affected: adobe commerce
#actively-exploited #critical #rce
CVE-2026-83548 Critical CVSS: 10.0

EPSS: 0.7% probability of exploitation in the next 30 days.

A Pre-authentication SSRF vulnerability exists in the SMA1000 Appliance Work Place interface due to an unintended alternate access path. A remote unauthenticated attacker could potentially exploit this vulnerability to gain unauthorized access to sensitive functionality and perform unauthorized operations.

SonicWall SMA1000 Appliances contains a server-side request forgery vulnerability that could allow a remote unauthenticated attacker to gain unauthorized access to sensitive functionality and perform unauthorized operations.

2026-09-01 Affected: sonicwall sma8200v
#actively-exploited #critical #auth-bypass #ssrf
CVE-2026-86218 Critical CVSS: 9.8

EPSS: 0.7% probability of exploitation in the next 30 days.

N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.

N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.

References

2026-09-06 Affected: See references
#actively-exploited #critical #rce
CVE-2026-81578 Critical CVSS: 9.8

EPSS: 1.6% probability of exploitation in the next 30 days.

An improper access control vulnerability exists in the web management interface of PaperCut MF and PaperCut NG. Under specific conditions, unauthenticated remote requests targeting administrative functions can trigger backend actions prior to the completion of access validation checks. This allows an unauthenticated remote attacker to modify certain system configurations.

PaperCut NG/MF contains a missing authentication for critical function vulnerability which allows an unauthenticated remote attacker to modify certain system configurations. This vulnerability can be chained with CVE-2026-82078.

2026-08-28 Affected: papercut papercut_mf
#actively-exploited #critical
CVE-2026-82329 Critical CVSS: 9.8

EPSS: 7.7% probability of exploitation in the next 30 days.

JFrog Artifactory contains an authentication weakness that, under default configuration, may allow an unauthenticated attacker with network access to obtain administrative privileges.

JFrog Artifactory contains an improper authentication vulnerability that under default configuration can allow an unauthenticated attacker with network access to obtain administrative privileges.

References

2026-08-28 Affected: jfrog artifactory
#actively-exploited #critical #privilege-escalation #auth-bypass
CVE-2026-60004 Critical CVSS: 9.8

EPSS: 86.8% probability of exploitation in the next 30 days.

Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.

Gitea contains a code injection vulnerability that allows an attacker with repository write access to send a malicious patch to the diffpatch API endpoint to plant an executable Git hook and run shell commands as the Gitea service account.

References

2026-08-26 Affected: gitea gitea
#actively-exploited #critical #rce
CVE-2026-72529 Critical CVSS: 9.8

EPSS: 1.6% probability of exploitation in the next 30 days.

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could execute an arbitrary script by calling an undocumented function.

TrueConf Server contains a missing authentication for critical function vulnerability which could allow a remote unauthorized attacker with network access via port 4307/TCP to execute an arbitrary script.

2026-08-19 Affected: trueconf trueconf_server
#actively-exploited #critical #auth-bypass
CVE-2026-64849 Critical CVSS: 9.3

EPSS: 16.4% probability of exploitation in the next 30 days.

MLflow is an open source AI engineering platform for agents, large language models, and machine learning models. Prior to 3.15.0, the unauthenticated POST /api/2.0/mlflow/webhooks/{id}/test endpoint calls _validate_webhook_url() in mlflow/utils/validation.py only for the original URL while mlflow/webhooks/delivery.py follows redirects and re-resolves the hostname without pinning the validated address, allowing attackers to reach internal or cloud metadata services and receive response_status and response_body. This issue is fixed in version 3.15.0.

2026-08-17 Affected: lfprojects mlflow
#actively-exploited #critical #rce
CVE-2026-82078 Critical CVSS: 9.1

EPSS: 1.7% probability of exploitation in the next 30 days.

An unsafe dynamic class loading vulnerability exists in the database connection utilities of PaperCut MF and PaperCut NG. The application instantiates database driver classes based on configurable driver names without validating against an allowlist of approved drivers. If an attacker can manipulate system configuration parameters, this enables the execution of arbitrary Java bytecode residing on the application classpath under the security context of the PaperCut server process.

2026-08-28 Affected: papercut papercut_mf
#actively-exploited #critical
CVE-2026-72530 Critical CVSS: 9.0

EPSS: 1.8% probability of exploitation in the next 30 days.

A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

TrueConf Server contains a code injection vulnerability that could allow an unauthorized remote attacker with network access via port 4307/TCP to use a specially crafted script to break out of the isolated environment and execute arbitrary code on the host system.

2026-08-19 Affected: trueconf trueconf_server
#actively-exploited #critical #auth-bypass
CVE-2026-73570 High CVSS: 8.9

EPSS: 32.4% probability of exploitation in the next 30 days.

A remote code execution vulnerability exists in Zimbra Collaboration (ZCS) before 10.1.20 when the optional zimbra-snmp package is installed and SNMP notifications are enabled. Due to improper sanitization of untrusted input during SNMP notification processing, an unauthenticated attacker can send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

Zimbra Collaboration Suite (ZCS) contains an OS command injection vulnerability which could allow an unauthenticated attacker to send specially crafted SMTP requests that may result in execution of arbitrary operating system commands as the Zimbra user.

2026-08-13 Affected: synacor zimbra_collaboration_suite
#actively-exploited #high #rce
CVE-2026-87491 High CVSS: 8.8

EPSS: 0.3% probability of exploitation in the next 30 days.

Out of bounds write in V8 in Google Chrome prior to 153.0.8010.36 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: Medium)

Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

2026-09-09 Affected: google chrome
#actively-exploited #high
CVE-2026-85046 High CVSS: 8.8

EPSS: 1.2% probability of exploitation in the next 30 days.

Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. (Chromium security severity: High)

Google Chromium V8 contains a type confusion vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utilize Chromium, including, but not limited to, Google Chrome, Microsoft Edge, and Opera.

2026-09-03 Affected: google chrome
#actively-exploited #high
CVE-2026-20349 High CVSS: 8.6

EPSS: 2.2% probability of exploitation in the next 30 days.

A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. 

This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remote Access SSL VPN service on an affected device. A successful exploit could allow the attacke

2026-08-11 Affected: cisco adaptive_security_appliance_software
#actively-exploited #high #dos
CVE-2026-81963 High CVSS: 7.8

EPSS: 0.6% probability of exploitation in the next 30 days.

Improper link resolution before file access (’link following’) in Windows Update Stack allows an authorized attacker to elevate privileges locally.

Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.

References

2026-09-08 Affected: microsoft windows_11_23h2
#actively-exploited #high #privilege-escalation
CVE-2026-85880 High CVSS: 7.8

EPSS: 0.6% probability of exploitation in the next 30 days.

Heap-based buffer overflow in Windows ALPC allows an authorized attacker to elevate privileges locally.

Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.

References

2026-09-08 Affected: See references
#actively-exploited #high #overflow #privilege-escalation
CVE-2026-83549 High CVSS: 7.8

EPSS: 1.6% probability of exploitation in the next 30 days.

Post-authentication Improper Neutralization of Special Elements used in an OS Command (‘OS Command Injection’) vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

SonicWall SMA1000 Appliances contains an OS command injection vulnerability that could enable a remote authenticated attacker as administrator to execute arbitrary OS commands, resulting in remote code execution.

2026-09-01 Affected: sonicwall sma8200v
#actively-exploited #high #rce #injection #auth-bypass
CVE-2026-68820 High CVSS: 7.0

EPSS: 6.2% probability of exploitation in the next 30 days.

Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.

Microsoft Windows Ancillary Function Driver for WinSock contains a use-after-free vulnerability that allows an authorized attacker to elevate privileges locally.

References

2026-08-11 Affected: microsoft windows_10_1607
#actively-exploited #high #privilege-escalation #memory-corruption
CVE-2026-66384 Medium CVSS: 5.3

EPSS: 0.6% probability of exploitation in the next 30 days.

An authenticated user may write data outside the intended Docker cache path under specific remote-repository conditions.

JFrog Artifactory contains an improper limitation of a pathname to a restricted directory vulnerability. This can allow an authenticated user to write data outside the intended Docker cache path under specific remote-repository conditions.

References

2026-08-12 Affected: jfrog artifactory
#actively-exploited
CVE-2026-19490 Low CVSS: 0.0

EPSS: 3.4% probability of exploitation in the next 30 days.

Vulnerability in NetScaler ADC and NetScaler Gateway.

This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.

Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Proxy, CVPN, or RDP Proxy), an unauthenticated remote threat actor may be able to bypass authentication.

2026-08-19 Affected: See references
#actively-exploited

> whoami

root@s3c.zip:~# cat /etc/hacker.conf
[identity]
name      = Andrii Lyho
role      = Penetration Testing Lead
location  = Warsaw, PL
motto     = Hacking for Fun and Profit
 
[focus]
areas     = AppSec, Cloud Security, Offensive Research
tools     = Burp Suite, AWS, Kubernetes, Python
 
[certs]
offensive = OSCP, OSWE
cloud     = ARTE
web       = BSCP
root@s3c.zip:~# ls -la ./links
-r--r-----  LinkedIn