← Home

Global Cyber Intelligence

Worldwide Cyber Security News

Curated cyber security intelligence from national cyber agencies, independent researchers, and leading industry media across North America, Europe, the United Kingdom, and the Asia-Pacific region. Updated every thirty minutes.

14authoritative sources
11live right now
245stories indexed

Showing 120 of 245 matching stories

Last refreshed 14:22 UTC

  • Threat IntelligenceInformationalGlobalIndustry Media

    [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI

    Dark Reading · Just now
  • Threat IntelligenceInformationalGlobalIndustry Media

    [Virtual Event] Building a Secure AI Strategy for the Enterprise

    Dark Reading · Just now
  • Policy & RegulationInformationalNorth AmericaIndustry Media

    FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching

    The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy. The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop .

    CyberScoop · 1h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

    Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek .

    SecurityWeek · 1h agoRead at source →
  • Threat IntelligenceCriticalGlobalVendor-Neutral Intelligence

    Ukraine prosecutor general steps down amid scam call center bribery probe

    Ukraine’s prosecutor general, Ruslan Kravchenko, resigned this week over allegations that officials in his office took bribes to shield scam call centers from law enforcement.

    The Record by Recorded Future · 2h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy

    Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek .

    SecurityWeek · 2h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

    A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more

    The Hacker News · 2h agoRead at source →
  • Threat IntelligenceCriticalGlobalIndustry Media

    DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

    A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web

    The Hacker News · 3h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndependent Research

    Claude Fable Solves a Historical Cipher

    Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.

    Schneier on Security · 3h agoRead at source →
  • Critical InfrastructureCriticalGlobalIndustry Media

    ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

    AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek .

    SecurityWeek · 3h agoRead at source →
  • Threat IntelligenceCriticalGlobalIndustry Media

    Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

    Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through

    The Hacker News · 3h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Ivanti Patches Critical Flaws Across Enterprise Security Products

    Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek .

    SecurityWeek · 3h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    This Key Will Self-Destruct: An Open Standard for Revocable API Keys

    Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek .

    SecurityWeek · 4h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

    Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek .

    SecurityWeek · 4h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Chrome 153 Patches Seventh Zero-Day of 2026

    The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek .

    SecurityWeek · 4h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

    U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to

    The Hacker News · 4h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

    Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to

    The Hacker News · 5h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

    cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

    The Hacker News · 6h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

    Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are

    The Hacker News · 6h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

    The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

    The Hacker News · 7h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

    SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP

    The Hacker News · 7h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

    Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.

    The Hacker News · 9h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

    The Hacker News · 9h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndependent Research

    ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)

    SANS Internet Storm Center · 12h agoRead at source →
  • Vulnerability & ExploitInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Google Chrome (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Google indique que la vulnérabilité CVE-2026-87491 est activement exploitée.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Vulnérabilité dans Microsoft Edge (09 septembre 2026)

    Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Xen (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Xen. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et un contournement de la politique de sécurité.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Citrix Workspace app (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Citrix Workspace app. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans les produits Adobe (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Adobe. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Vulnérabilité dans les produits Cisco (09 septembre 2026)

    Une vulnérabilité a été découverte dans les produits Cisco. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Microsoft Office (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Microsoft Office. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Vulnerability & ExploitInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Microsoft Windows (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Microsoft indique que les vulnérabilités CVE-2026-81963...

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Vulnérabilité dans les produits ESET (09 septembre 2026)

    Une vulnérabilité a été découverte dans les produits ESET. Elle permet à un attaquant de provoquer une élévation de privilèges.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Postfix (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Cloud SecurityInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Microsoft Azure (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans les produits Microsoft (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Microsoft .Net (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Vulnérabilité dans Mozilla Firefox (09 septembre 2026)

    Une vulnérabilité a été découverte dans Mozilla Firefox. Elle permet à un attaquant de provoquer un déni de service à distance.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans les produits Ivanti (09 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Ivanti. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un contournement de la politique de sécurité.

    CERT-FR — French National Cyber Security Agency · 14h agoRead at source →
  • Vulnerability & ExploitCriticalNorth AmericaIndustry Media

    Microsoft discloses two actively exploited zero-days among 974 vulnerabilities

    While the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk and exposure. The post Microsoft discloses two actively exploited zero-days among 974 vulnerabilities appeared first on CyberScoop .

    CyberScoop · 15h agoRead at source →
  • Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence

    Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited

    The new record total for Patch Tuesday is 973 vulnerabilities.

    The Record by Recorded Future · 15h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndependent Research

    Microsoft Plugs Nearly 1,000 Security Holes

    Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.

    Krebs on Security · 16h agoRead at source →
  • Threat IntelligenceCriticalGlobalIndustry Media

    Patch Tuesday Sets Another Record With 974 CVEs

    Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.

    Dark Reading · 16h ago
  • Threat IntelligenceInformationalGlobalIndustry Media

    Attackers Use Multi-Hop Google Redirects for Phishing Campaign

    Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.

    Dark Reading · 17h ago
  • Threat IntelligenceCriticalGlobalVendor-Neutral Intelligence

    Scammer behind $245 million crypto heist pleads guilty to RICO charges

    Malone Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets.

    The Record by Recorded Future · 17h agoRead at source →
  • Threat IntelligenceInformationalNorth AmericaIndustry Media

    Feds accuse China of ‘systematic’ distillation of U.S. AI models

    A joint advisory alleges Chinese companies are using sophisticated systems to route millions of data requests to US AI models across different accounts and platforms. The post Feds accuse China of ‘systematic’ distillation of U.S. AI models appeared first on CyberScoop .

    CyberScoop · 17h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    OpenAI Agents Took Over Wiki Site Before Hugging Face Attack

    Researchers and OpenAI disagree on whether the earlier incident involving DseWiki, which the company did not disclose, was a “hack."

    Dark Reading · 17h ago
  • Threat IntelligenceInformationalNorth AmericaIndustry Media

    Russian national extradited to US for alleged involvement in bank-account takeover scheme

    Authorities accuse the 36-year-old and co-conspirators of collecting more than 5,000 victim login credentials to various banks. The post Russian national extradited to US for alleged involvement in bank-account takeover scheme appeared first on CyberScoop .

    CyberScoop · 17h agoRead at source →
  • Threat IntelligenceInformationalNorth AmericaIndustry Media

    CIA’s Michael Ellis says cyber intelligence is changing how the agency operates

    The deputy director cited Operation Absolute Resolve as evidence that cyber teams have become central to CIA missions. The post CIA’s Michael Ellis says cyber intelligence is changing how the agency operates appeared first on CyberScoop .

    CyberScoop · 18h agoRead at source →
  • Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence

    CIA official touts agency’s Cyber Mission Center in capture of Venezuela’s Maduro

    A "flawless" performance by the CIA's Cyber Mission Center contributed to the capture of Venezuelan President Nicolás Maduro in January, agency Deputy Director Michael Ellis says.

    The Record by Recorded Future · 18h agoRead at source →
  • Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence

    Russian suspect in bank account takeovers is extradited to US

    A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment.

    The Record by Recorded Future · 18h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndependent Research

    September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

    This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while none were publicly disclosed before Patch Tuesday. Notable fixes include Windows privilege escalation and critical RCEs in Skype for Business, MSMQ and RRAS.

    SANS Internet Storm Center · 19h agoRead at source →
  • Threat IntelligenceCriticalGlobalIndustry Media

    Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

    The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities. The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek .

    SecurityWeek · 19h agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

    Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek .

    SecurityWeek · 19h agoRead at source →
  • Threat IntelligenceInformationalNorth AmericaIndustry Media

    Why federal cyber defense demands an offense-driven mindset

    Static checklists and annual penetration tests leave agencies with dangerous blind spots. True resilience requires moving from reactive attestation to continuous, automated validation. The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberScoop .

    CyberScoop · 19h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    ClickFix Campaigns Abuse Legitimate Services for Persistent Access

    Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.

    Dark Reading · 20h ago
  • Threat IntelligenceInformationalGlobalIndependent Research

    AIs as Modern Genies

    This essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by ...

    Schneier on Security · 21h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    The Hidden Instructions That Can Hijack AI Agents

    Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions. The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek .

    SecurityWeek · 21h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

    A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment

    The Hacker News · 22h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

    Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&

    The Hacker News · 23h agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

    Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel

    The Hacker News · 1d agoRead at source →
  • Identity & AccessInformationalGlobalIndustry Media

    Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

    Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI

    The Hacker News · 1d agoRead at source →
  • Critical InfrastructureCriticalNorth AmericaGovernment CERT

    CareCam Pro IP Cameras

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083) CVSS Vendor Equipment Vulnerabilities v3 6.8 CareCam CareCam Pro IP Cameras Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-85083 The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain privileged bootloader access, allowing unauthorized modification of firmware and system configuration and potentially resulting in complete device compromise. View CVE Details Affected Products CareCam Pro IP Cameras Vendor: CareCam Product Version: CareCam ANJIA AJL33PC0801 Firmware: linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 Product Status: known_affected Remediations Mitigation CareCam has not responded to CISA's attempts for coordination. Users are encouraged to reach out to CareCam. Relevant CWE: CWE-798 Use of Hard-coded Credentials Metrics CVSS Version Base Score Base Severity Vector String 3.1 6.8 MEDIUM CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H 4.0 7 HIGH CVSS:4.0/AV:P/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Acknowledgments Omkar Mali reported this vulnerability to CISA Legal Notice and Terms of Use This product is provided subject to this Notification (https://www.cisa.gov/notification) and this Privacy & Use policy (https://www.cisa.gov/privacy-policy). Recommended Practices CISA recommends users take defensive measures to minimize the risk of exploitation of this vulnerability. Minimize network exposure for all control system devices and

    CISA — Cybersecurity and Infrastructure Security Agency · 1d agoRead at source →
  • Data BreachCriticalNorth AmericaGovernment CERT

    China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

    Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authoring agencies) are releasing this joint Cybersecurity Advisory to alert organizations about these malicious activities and techniques and recommend mitigations to reduce their potential impact.  Likely with Chinese government awareness, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI extracted billions of tokens across millions of exchanges/requests from U.S. frontier AI models, including variants of Claude, GPT, Gemini, and Grok, since at least late 2024. DeepSeek has conducted organized campaigns since at least 2024 targeting reasoning capabilities, specialized optimizations, and domain-specific functions to train its R1 and V3 models. Alibaba leveraged industrial-scale distillation to improve the company’s Qwen family of AI models. Moonshot AI, MiniMax, Stepfun, and Z.AI also engaged in malicious knowledge distillation of U.S. AI companies’ models.  China-based AI companies route distillation requests through multiple pathways to gain unauthorized access, consequently violating U.S. AI companies’ terms of use. These pathways include native application programming interfaces (APIs), remote cloud providers, and third-party aggregators that automatically obfuscate

    CISA — Cybersecurity and Infrastructure Security Agency · 1d agoRead at source →
  • Vulnerability & ExploitCriticalNorth AmericaGovernment CERT

    CISA Adds Four Known Exploited Vulnerabilities to Catalog

    CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability   CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability  CVE-2026-86218 N-able N-central Static Code Injection Vulnerability  These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities . CISA will continue to add vulnerabilities to the catalog that meet the specified criteria . Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form . Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. 

    CISA — Cybersecurity and Infrastructure Security Agency · 1d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

    A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.

    Dark Reading · 1d ago
  • Threat IntelligenceInformationalGlobalIndustry Media

    WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

    Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

    The Hacker News · 1d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    What It Took to Reach 1 Billion Build Manifests

    In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally

    The Hacker News · 1d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

    A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The

    The Hacker News · 1d agoRead at source →
  • Threat IntelligenceCriticalGlobalIndependent Research

    Stealing AI Reasoning Traces

    Interesting research: “ Stealing Reasoning Traces from Proprietary LLM APIs “: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. Building on prior research, we identify an architectural vulnerability: these encrypted blocks are fully compatible and interchangeable across different sessions, users, and models within a provider’s ecosystem. We exploit this compatibility to develop a scalable decryption jailbreak. By injecting an encrypted reasoning trace from a given model into a weaker, and less safeguarded model from the same provider, we force it to decode and output the trace verbatim in plaintext, without ever jailbreaking the more capable model directly. This vulnerability enables four distinct attack vectors. First, it circumvents anti-distillation mechanisms, allowing adversaries to extract a proprietary model’s reasoning, as we demonstrate across Anthropic, OpenAI, and Google. Second, it allows for large-scale private data extraction. Developers frequently share session logs publicly, unaware of contents of the encrypted blocks. By decoding 315,320 reasoning blocks scraped from public repositories, we recovered 367 Personally Identifiable Information (PII) artifacts and 182 credentials. Third, it inadvertently reveals hazardous information hidden within the reasoning process, even in cases where the model’s final, visible output safely rejects a malicious request. Fourth, attackers can leverage this flaw to execute invisible prompt injections, embedding malicious payloads entirely within encrypted blocks to poison public agentic rollouts. Following responsible disclosure, we propose concrete cryptographic and system-level mit

    Schneier on Security · 1d agoRead at source →
  • Threat IntelligenceInformationalNorth AmericaIndustry Media

    In most cities, nobody owns the whole network

    July’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions a utility can make this fiscal year, out of money it already applies for. The post In most cities, nobody owns the whole network appeared first on CyberScoop .

    CyberScoop · 1d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

    Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

    The Hacker News · 1d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

    Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect

    The Hacker News · 1d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

    Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.

    The Hacker News · 1d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndependent Research

    ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)

    SANS Internet Storm Center · 1d agoRead at source →
  • Vulnerability & ExploitInformationalEuropeGovernment CERT

    Vulnérabilité dans les produits Adobe (08 septembre 2026)

    Une vulnérabilité a été découverte dans les produits Adobe. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Adobe indique que la vulnérabilité CVE-2026-75650 est activement exploitée.

    CERT-FR — French National Cyber Security Agency · 1d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans les produits Siemens (08 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Siemens. Elles permettent à un attaquant de provoquer une exécution de code arbitraire et une élévation de privilèges.

    CERT-FR — French National Cyber Security Agency · 1d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans strongSwan (08 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans strongSwan. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.

    CERT-FR — French National Cyber Security Agency · 1d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Schneider Electric EcoStruxure (08 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Schneider Electric EcoStruxure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une falsification de requêtes côté serveur (SSRF).

    CERT-FR — French National Cyber Security Agency · 1d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans les produits SAP (08 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.

    CERT-FR — French National Cyber Security Agency · 1d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Mattermost Server (08 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Mattermost Server. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

    CERT-FR — French National Cyber Security Agency · 1d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Typo3 (08 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Typo3. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

    CERT-FR — French National Cyber Security Agency · 1d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

    Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

    The Hacker News · 1d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

    Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff

    The Hacker News · 1d agoRead at source →
  • Supply ChainCriticalGlobalIndustry Media

    ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

    Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management

    The Hacker News · 1d agoRead at source →
  • Cloud SecurityInformationalGlobalIndustry Media

    Your Cloud Security Checklist Doesn't Work the Way You Think It Does

    If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers

    The Hacker News · 2d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

    Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake

    The Hacker News · 2d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

    The Hacker News · 2d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndependent Research

    Automobile Camouflage to Hide from Flock Cameras

    Not sure it’s practical, but it’s certainly striking .

    Schneier on Security · 2d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a

    The Hacker News · 2d agoRead at source →
  • Identity & AccessCriticalGlobalIndustry Media

    JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

    The Hacker News · 2d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Bulletin d'actualité CERTFR-2026-ACT-038 (07 septembre 2026)

    Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...

    CERT-FR — French National Cyber Security Agency · 2d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans les produits VMware (07 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.

    CERT-FR — French National Cyber Security Agency · 2d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Roundcube Webmail (07 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Roundcube Webmail. Certaines d'entre elles permettent à un attaquant de provoquer une falsification de requêtes côté serveur (SSRF), une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.

    CERT-FR — French National Cyber Security Agency · 2d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans les produits Juniper Networks (07 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.

    CERT-FR — French National Cyber Security Agency · 2d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans MongoDB (07 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et une injection de requêtes illégitimes par rebond (CSRF).

    CERT-FR — French National Cyber Security Agency · 2d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Multiples vulnérabilités dans Traefik (07 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.

    CERT-FR — French National Cyber Security Agency · 2d agoRead at source →
  • Threat IntelligenceInformationalEuropeGovernment CERT

    Vulnérabilité dans Belden HiOS Switch Platform (07 septembre 2026)

    Une vulnérabilité a été découverte dans Belden HiOS Switch Platform. Elle permet à un attaquant de provoquer un déni de service à distance.

    CERT-FR — French National Cyber Security Agency · 2d agoRead at source →
  • Threat IntelligenceCriticalGlobalIndependent Research

    Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

    Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access after a patch is installed.

    SANS Internet Storm Center · 2d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

    Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or

    The Hacker News · 3d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

    Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

    The Hacker News · 3d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

    Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

    The Hacker News · 3d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

    JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

    The Hacker News · 3d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

    Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

    The Hacker News · 3d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

    Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

    The Hacker News · 4d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

    A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

    The Hacker News · 4d agoRead at source →
  • Vulnerability & ExploitCriticalGlobalIndustry Media

    Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

    Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

    The Hacker News · 4d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndependent Research

    numbat - AI agent observability, (Fri, Sep 4th)

    SANS Internet Storm Center · 4d agoRead at source →
  • Threat IntelligenceInformationalNorth AmericaIndustry Media

    European parliament members call for slowdown of Serbia’s EU entry over spyware use

    The letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop .

    CyberScoop · 4d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndependent Research

    Friday Squid Blogging: Squid on a Stick at the New York State Fair

    Looks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

    Schneier on Security · 4d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndependent Research

    Using a VM to Contain an AI Agent

    It won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.

    Schneier on Security · 4d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    Companies Have 6 Months to Prepare for Automated Attacks

    Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.

    Dark Reading · 4d ago
  • Threat IntelligenceInformationalGlobalIndustry Media

    Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

    Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The

    The Hacker News · 4d agoRead at source →
  • Vulnerability & ExploitInformationalGlobalIndustry Media

    PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

    PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are

    The Hacker News · 4d agoRead at source →
  • Threat IntelligenceCriticalGlobalIndustry Media

    New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

    A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

    The Hacker News · 4d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndustry Media

    AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?

    A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.

    Dark Reading · 5d ago
  • Threat IntelligenceInformationalGlobalIndustry Media

    Insurers Search for Answers to Rein in Rogue AI

    As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.

    Dark Reading · 5d ago
  • Vulnerability & ExploitCriticalNorth AmericaGovernment CERT

    CISA Adds One Known Exploited Vulnerability to Catalog

    CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation.   CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities . CISA will continue to add vulnerabilities to the catalog that meet the specified criteria . Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form . Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. 

    CISA — Cybersecurity and Infrastructure Security Agency · 5d agoRead at source →
  • Threat IntelligenceCriticalGlobalIndependent Research

    Security Vulnerability in a Voting System

    It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses affected scanners) in the recent May 2026 primary. Notably, I never touched a voting machine, exploited a network, examined source code, or accessed anything non-public. After pointing a coding agent to the original vulnerability paper, I supplied it with two data sources highlighted in the paper: the early-voting list for each county, and the “CVR” (cast-vote record) file, containing every ballot and its selections (but not the voters’ names or other identifying information). The CVR file is available upon request, precisely because a public, ballot-level record is what makes election results independently verifiable...

    Schneier on Security · 5d agoRead at source →
  • Threat IntelligenceInformationalGlobalIndependent Research

    AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

    We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication...

    Schneier on Security · 5d agoRead at source →

Indexed sources

Every item displayed here links back to the original publication. CyberZonic does not host or re-publish full article text.