114Articles
9Categories
2026-09-01Date
🚨 CISA KEV 2[−]
1 Sep KEVPaperCut Exploitation Escalates to Active IntrusionsCISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek .SECURITYWEEK.COM
1 Sep KEVU.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulner…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 8[−]
1 SepAttackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 ActivityThreat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability …THEHACKERNEWS.COM
1 Sep KEVCritical JFrog Artifactory Vulnerability Reportedly Exploited in the WildExploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure. The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepHackers Start Exploiting Critical Langflow VulnerabilityTracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepCritical Langflow flaw exploited to steal OpenAI and AWS keysThreat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]BLEEPINGCOMPUTER.COM
1 SepAttackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After DisclosureThreat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to admin…THEHACKERNEWS.COM
1 SepCritical Langflow Flaw Exploited as Attacks on AI Platform RiseThe attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.DARKREADING.COM
1 SepAttackers Pounce on Critical Artifactory Flaw Following DisclosureCVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.DARKREADING.COM
1 SepWhat happens when AI models take aim at ICS exploitsLLMs have shown great improvement in vulnerability research and exploit development capabilities over the past six months. But it’s one thing to find vulnerabilities in well documented open-source projects and an entirely different skillset to decrypt file systems and reverse-eng…CSOONLINE.COM
⚠️ VULNERABILITY DISCLOSURE 37[−]
1 SepBot detection arrives in CrowdSec 1.8.0, along with two DoS fixesFailed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which addresses are misbehaving, and hands the block to a separate remediation component sitting in front of the servic…HELPNETSECURITY.COM
1 SepNIS2 compliance: Fixing IAM and access control before the 2026 auditThe NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member states move from transposition into enforcement. …HELPNETSECURITY.COM
1 Sep179: The Courthouse - RevisitedIn this episode we follow up with Gabby and Justin from Episode 59 - two seasoned penetration testers who tell us a story about the time when they tried to break into a courthouse but it went all wrong, and what happened in the aftermath. Sponsors This show is brought to you by D…DARKNETDIARIES.COM
1 SepRecently patched PaperCut zero-days used in data theft attacksTwo security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]BLEEPINGCOMPUTER.COM
1 SepRussia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI AnalysisCybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in …THEHACKERNEWS.COM
1 SepChina-linked hackers turn Cisco routers into covert attack infrastructureA China-linked cyber espionage group has expanded beyond VMware environments to target network and authentication infrastructure that enterprises rely on to manage access and administer critical systems, according to new findings from incident response firm Sygnia . The threat ac…CSOONLINE.COM
1 SepFixing Software Weaknesses Rather Than Just Finding More Flaws - ASW #398AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and …YOUTUBE.COM
1 SepChaotic Eclipse Releases Kaspersky Zero-Day HardBreacherChaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day…SECURITYAFFAIRS.COM
1 SepAttackers Steal METR API Key and Consume AI Credits Worth About $600,000METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" …THEHACKERNEWS.COM
1 SepAesto healthcare data breach impacts 9.5 million peopleHealthcare data migration and archiving provider Aesto has disclosed to the US Department of Health and Human Services (HHS) that a data breach announced earlier this year affected 9,540,683 individuals. The incident involved unauthorized access to part of Aesto’s Amazon Web Serv…CYBERINSIDER.COM
1 SepIntroducing Continuous Vulnerability Assessment: Real-Time Defense for the AI Threat EraDetect exposure to new vulnerabilities the moment they are published with Wiz CVAWIZ.IO
1 SepFake Cloudflare CAPTCHA tricks victims into opening a tunnel for attackersAttackers are using fake CAPTCHA prompts to trick victims into running malicious PowerShell commands as part of a multi-stage intrusion campaign that can establish persistence, conduct network reconnaissance and potentially give operators a path to deeper access within an organiz…CSOONLINE.COM
1 SepFive Venezuelans Plead Guilty in US Court to ATM JackpottingThe defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash. The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepOpenClaw rolls out system-wide overhaul, updates security controls across agent platformOpenClaw has released what it describes as the largest update in its history, introducing a system-wide overhaul spanning runtime behavior, plugins, and security controls, as enterprises increasingly evaluate how such agent-based systems operate across connected environments. “Th…CSOONLINE.COM
1 SepWhite House Launches Pilot Program in Texas to Protect Water InfrastructureProject Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid rising nation-state threatsINFOSECURITY-MAGAZINE.COM
1 SepNearly 22,000 Microsoft Exchange servers vulnerable to hijack attacksNearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]BLEEPINGCOMPUTER.COM
1 SepExperiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of DollarsForescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepFake Claude Opus 5 app delivers malware and wipes its own tracksA malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, according to Morphisec. Repository R…HELPNETSECURITY.COM
1 SepIE: HSE fined €645,000 over data breach affecting Westmeath hospitalAdrian Cusack reports: The Data Protection Commission has fined the HSE [Health, Safety, and Environment] more than €600,000 over the mismanagement of historical records held at St Loman’s hospital, Mullingar, and St Conal’s Hospital, Letterkenny. The fine was issued …DATABREACHES.NET
1 SepSanta Fe Schools Move Forward With New Cybersecurity PolicyAndré Salkin reports: The Santa Fe school board approved a new cybersecurity policy this week but delayed a vote on a separate policy governing student data privacy, with most board members calling it too broad and too important to rush through. The delayed measure, Draft Policy …DATABREACHES.NET
1 SepWhat AI Researchers See Beyond AIAI models can identify vulnerabilities and sometimes conclude that there is nothing further to exploit. Researchers with deep domain expertise can challenge that conclusion. Knowing the specifics of an asset, environment, and deployment can allow researchers to take an AI-generat…YOUTUBE.COM
1 SepVU#456290: Hugging Face Transformers library writes remote code to disk prior to consent checkOverview A vulnerability in the Hugging Face Transformers library (versions 4.49.0 through 5.8.1) allows remote, attacker‑controlled Python files to be written to the local disk without user authorization. The library performs a remote module fetch and local cache write before ev…KB.CERT.ORG
1 Sep13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet SeedsCybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS d…THEHACKERNEWS.COM
1 SepNovocure data breach affects more than 1,400 cancer patientsHealthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]BLEEPINGCOMPUTER.COM
1 SepWhy Even the Best Edge Security Still Misses High-Risk SessionsAttackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronge…BLEEPINGCOMPUTER.COM
1 SepChaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPragueChaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting …SECURITYAFFAIRS.COM
1 SepNightmare Eclipse releases PoC exploit for Kaspersky Endpoint Security.Healthcare companies disclose breaches. Attackers exploit recently patched JFrog Artifactory flaw.THECYBERWIRE.COM
1 SepCISA review makes the case for eliminating vulnerability classesFor years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of weaknesses at the s…HELPNETSECURITY.COM
1 SepAttackers Access Aesto Health AWS Infrastructure, Exposing 9.5 Million RecordsAesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to …SECURITYAFFAIRS.COM
1 SepLeaked Russian Cyber-Operations Training MaterialsThis is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. […] …SCHNEIER.COM
1 SepFrontier AI used to help exploit flaws in tests using key industrial devicesA report showed that Claude could help hackers develop attack strategies targeting PLCs used by water utilities and other industries.CYBERSECURITYDIVE.COM
1 SepBreeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment SystemsBrazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializ…THEHACKERNEWS.COM
1 SepMalicious website themes infect outdated iPhones with spywareMalicious website themes infect unpatched iPhones with spyware when users visit a compromised site, allowing attackers to steal messages, photos, passwords, location data, and cryptocurrency wallet recovery phrases. Socket’s Threat Research Team uncovered the packages on Packagis…CYBERINSIDER.COM
1 SepAesto Health says data breach affects over 9.5 million patientsAesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]BLEEPINGCOMPUTER.COM
1 SepNightmare on Windows 11.Nightmare Eclipse drops a Kaspersky zero-day. The Financial Stability Board warns frontier AI could threaten the global financial system. Anthropic says it has tightened security. CISA adopts a risk-based approach to patching. A new Windows infostealer hides in fake AI models. A …THECYBERWIRE.COM
1 SepFBI Probes Service Selling 153M+ Drivers LicensesA new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appea…KREBSONSECURITY.COM
1 SepThe CAPTCHA Is Actually the Attack“Click-fix” attacks use social engineering to convince victims to execute malicious commands themselves. One technique disguises the instructions behind a fake Cloudflare CAPTCHA and tells the user to open PowerShell or Terminal and paste a command. The attacker doesn't necessari…YOUTUBE.COM
📢 SECURITY ADVISORIES 10[−]
1 SepMicrosoft nudges enterprise security closer to its passwordless future. But ‘123456’ will survive.Today marks the beginning of the end of an era for enterprise Microsoft authentication. As of Sept. 1, passkeys are now the default authentication method for Entra ID , Microsoft’s cloud-based identity and access management (IAM) service. By Feb. 1, 2027, Microsoft-provided SMS a…CSOONLINE.COM
1 SepBerlin refuses to be blackmailed after network breachBerlin’s state government has confirmed an extortion attempt following a data theft from its administrative network in August. Governing Mayor Kai Wegner and Interior Senator Iris Spranger addressed the extortion attempt on Friday, following an emergency Senate session at t…HELPNETSECURITY.COM
1 SepIranian cyber spies target aviation, fintech developers with new malwareIn a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.THERECORD.MEDIA
1 SepHackers abuse Faronics Deploy admin tool to install ScreenConnectPhishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]BLEEPINGCOMPUTER.COM
🔥 INCIDENT REPORTING 9[−]
1 SepQuestel - 1,226,209 breached accountsIn August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published an extensive corpus of data they alleged was obtained from the company, largely comprising c…HAVEIBEENPWNED.COM
1 SepHealthcare Giant McKesson Investigates Data Breach IncidentShinyHunters claims to have stolen 284 million records from McKessonINFOSECURITY-MAGAZINE.COM
1 Sep9.5 Million Impacted by Aesto Health Data BreachHackers stole personal and health information from the healthcare technology company’s AWS infrastructure. The post 9.5 Million Impacted by Aesto Health Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepRansomware Gang Claims Nutex Health Data BreachThe company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information. The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepHealthcare facilities operator Nutex says patient, employee data stolen in August incidentCybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.THERECORD.MEDIA
1 SepCrowdStrike launches cyber frontier AI models, agentic security systemCrowdStrike today announced SafeMind, a cybersecurity-specific AI model-harness system that CEO George Kurtz described as the “first complete agentic system for cybersecurity” at the company’s Fal.Con conference in Las Vegas. At the heart of SafeMind are two purpose-built cyberse…CSOONLINE.COM
1 SepChina's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacksA hacking operation dubbed Fire Ant "didn’t just compromise systems," according to researchers. "It compromised the trust layer those systems depend on."THERECORD.MEDIA
1 SepStronger Security Drives Ransomware Groups to Recruit From WithinSome security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.DARKREADING.COM
1 SepWeekly Update 519: Breaches & Data IntegrityPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite It does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the &q…TROYHUNT.COM
🕵️ THREAT INTELLIGENCE 27[−]
1 SepISC Stormcast For Tuesday, September 1st, 2026 https://isc.sans.edu/podcastdetail/10076, (Tue, Sep 1st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
1 SepCybersecurity jobs available right now: September 1, 2026Security Engineer, PSO Google | USA | On-site – View job details As a Security Engineer, you will provide technical guidance to customers adopting Google Cloud Platform, helping them navigate their cloud journey with the Professional Services team. The role includ…HELPNETSECURITY.COM
1 SepWhat your vendor says about PQC tells you if they are readyIn this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, including subscriber identity mappings, billing records a…HELPNETSECURITY.COM
1 SepLastPass enhancements improve visibility, governance, and controlLastPass announced a series of strategic product innovations, customer experience enhancements, and industry milestones. These advancements reflect the company’s continued focus on providing practical tools to protect access and identity in an increasingly AI-driven threat landsc…HELPNETSECURITY.COM
1 SepAskeal, the AI cybersecurity assistant that gives verifiable, expert-backed answersAskeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to help users conduct manual investigations. The sta…HELPNETSECURITY.COM
1 SepWatchGuard Patches Critical VulnerabilitiesThree critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely. The post WatchGuard Patches Critical Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepRewiring Democracy Series on The RenovatorNathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator . I haven’t been posting the full text on the blog because they’re a bit long, but here are links. Part 1 is about the Japanese digital democracy…SCHNEIER.COM
1 SepThe Collective Cyber Defense letter wrote your next vendor questionnaireMore than 200 companies have now signed to an August 27 letter about improving cyber defenses in the age of AI. Buried in it are three metrics every one of them endorse under its own logo: coverage, containment speed, and whether fixes work. The post The Collective Cyber Defense …CYBERSCOOP.COM
1 SepThreat Actors Don’t Want Better Attacks. They Want Repeatable OnesThe most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is…THEHACKERNEWS.COM
1 SepNorth Korea-linked IT Workers Are Getting Hired Inside Western CompaniesHuntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The…SECURITYAFFAIRS.COM
1 SepTerminalFix looks like ClickFix, but delivers a very different payloadThe familiar ClickFix fake CAPTCHA trick has been adapted to deliver a payload that can give attackers access to the victim’s wider network.MALWAREBYTES.COM
1 SepIranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding TestsThe Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote acces…THEHACKERNEWS.COM
1 SepWhistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballotsThe Federal Ballot Mail Portal is described by a federal official as one of several IT systems that will be used to potentially deny thousands of mail-in ballots or more to states. The post Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots app…CYBERSCOOP.COM
1 SepFirefox 155 speeds up web connections with Happy Eyeballs v3 and QUIC v2Mozilla has released Firefox 155, introducing networking changes designed to reduce connection delays, alongside new privacy indicators and Smart Window improvements. The new release adds Happy Eyeballs v3 and QUIC v2 support for HTTP/3, both aimed at helping Firefox establish fa…CYBERINSIDER.COM
1 SepVishing campaign abuses Microsoft Teams to give attackers a foothold in company networksA coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ threat intelligence team. …HELPNETSECURITY.COM
1 SepSecurity policies fail to keep up with a hybrid cloud worldRoughly two-thirds of companies have suffered a business-critical app outage due to misconfigured security policies, a Cloud Security Alliance report found.CYBERSECURITYDIVE.COM
1 SepGoogle removes uBlock Origin from Chrome Web Store in final Manifest V2 purgeGoogle has removed uBlock Origin from the Chrome Web Store as it completes the final stage of its years-long phase-out of Manifest V2 extensions. The removal also affects every other remaining extension still using the older framework. The change took effect on August 31, 2026, i…CYBERINSIDER.COM
1 SepSevii Targets AI-Speed Attacks With Preemptive Autonomous DefenseSevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes. The post Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepCoast Guard Establishes Office of Maritime Cybersecurity PolicyThe new office will serve as the central authority for cybersecurity policy covering US ports, vessels, and maritime facilities. The post Coast Guard Establishes Office of Maritime Cybersecurity Policy appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepAI Didn’t Kill Bug BountiesThe rise of AI models has sparked predictions that bug bounty programs could become obsolete. But the data discussed here points in the opposite direction. Security researchers are finding more sophisticated and impactful vulnerabilities with increasingly powerful tooling. The re…YOUTUBE.COM
1 SepCybersecurity IR Workshop: The workshop you shouldn’t missCyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog .MICROSOFT.COM
1 SepTina Peters, through attorney, backs off formal role in Shasta County electionsPeters still left the door open to working with Shasta County on elections and doubled down on her statements that electronic voting machines should be discontinued. The post Tina Peters, through attorney, backs off formal role in Shasta County elections appeared first on CyberSc…CYBERSCOOP.COM
1 SepPalo Alto Networks Acquires AI Agent Platform ConsoleThe cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR. The post Palo Alto Networks Acquires AI Agent Platform Console appeared first on SecurityWeek .SECURITYWEEK.COM
1 SepAI Model Evaluator METR Hit by Credential Theft, ProbingIn one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.DARKREADING.COM
1 SepVictorians, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Aaran Leyland - SWN #612Victorian Bug Bounties, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Nimbus Manticore, Isambard Kingdom Brunel, Rote Tod, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://…YOUTUBE.COM
1 SepFBI raises alarm over deceptive phishing campaign targeting prominent peopleThe ongoing social engineering threat, which dates back to late 2025, tricks victims into granting threat actors long-term access to their accounts. The post FBI raises alarm over deceptive phishing campaign targeting prominent people appeared first on CyberScoop .CYBERSCOOP.COM
1 SepCounterfeit installers to system compromise: Tracking a deceptive software download campaignAn active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical …MICROSOFT.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
1 SepMirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware setKaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.SECURELIST.COM
1 SepFive Venezuelans plead guilty to ATM jackpotting attacks in USFive Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]BLEEPINGCOMPUTER.COM
1 SepInfostealers are hijacking Claude accounts at users’ expenseAnthropic has warned that infostealers are stealing Claude session cookies to access users’ accounts and consume usage at their expense.MALWAREBYTES.COM
1 Sep65% of Enterprises Have Seen AI Agents Act Out of ScopeEMA survey finds 65% of enterprises have seen AI agents act beyond intended scopeINFOSECURITY-MAGAZINE.COM
🎙️ PODCASTS 1[−]
1 SepBetween Two Nerds: The perfect hackerIn this edition of Between Two Nerds Tom Uren and The Grugq talk about how AI is the perfect hacker, but what makes it perfect for states is the opposite of what makes it perfect for criminals. This episode is also available on YouTube.RISKY.BIZ
📡 INFOSEC NEWS 15[−]
1 SepFinancial Stability Board Sounds the Alarm Over Frontier AI RisksThe Financial Stability Board has warned G20 banking leaders about the cyber risks of frontier AIINFOSECURITY-MAGAZINE.COM
1 SepJapanese Surveillance, Enslavement, and Experimentation in Wartime ChinaThe Asia-Pacific theater saw its own scenes of brutality during World War II. But many of us don't know about them. Jenny Chan co-founded Pacific Atrocities Education to raise awareness of these lesser-known horrors. This conversation focuses on the Imperial Japanese Army, which …THECYBERWIRE.COM
1 SepUsing High-Energy Laser, US Shoots Down Drones Near Mexico BorderThe US Army’s laser system is part of a new generation of directed-energy weapons capable of detecting, tracking, and destroying drones with a concentrated beam of light.WIRED.COM
1 SepCyber risk from frontier AI poses ‘most immediate concern’ to global financial system, watchdog warnsAndrew Bailey, chair of the Financial Stability Board, called on financial institutions and technology providers to “prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies.”THERECORD.MEDIA
1 SepFive Venezuelan Nationals Plead Guilty in Kansas ATM Jackpotting AttemptFive Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty after trying to steal cash from ATMs in Kansas using the popular ATM jackpotting te…SECURITYAFFAIRS.COM
1 SepFlorida and Texas move to block Flock cameras over privacy concernsFlock's searchable network of 130,000 license plate cameras around the U.S. have sparked bipartisan privacy and civil liberties concerns.TECHCRUNCH.COM
1 SepAttackers Steal METR API Key and Burn $600,000 in AI CreditsAttackers used a stolen METR API key for three weeks, consuming model credits worth $600,000INFOSECURITY-MAGAZINE.COM
1 SepHackers push malicious Virtualizor update in BGP hijacking attackHackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]BLEEPINGCOMPUTER.COM
1 SepClickFix Campaign Compromises 31 Orgs, Abuses Polygon BlockchainThe campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.DARKREADING.COM
1 SepAIR raises $50M to help companies vet the skills and add-ons AI agents useAIR's platform can discover agents running at a company, continuously vets any skills and add-ons they use, and blocks any unwanted behaviour.TECHCRUNCH.COM
1 SepDual-RMM Phishing and PowerShell RAT Campaign Hits SLTTsAn active phishing campaign is targeting U.S. SLTTs with a custom PowerShell WebSocket RAT and dual RMM tools. Read the CIS CTI team's analysis.CISECURITY.ORG
1 SepFake GTA 6 leaked copy drains your crypto walletA fake GTA 6 leak is using wallet-draining code to steal cryptocurrency, tokens, and NFTs from eager fans.MALWAREBYTES.COM
1 SepWhat’s the Scam?To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Starting last weekend, I have been receiving …SCHNEIER.COM
1 SepOpenAI Is About to Release Its First AI Model With ‘Critical’ Cyber AbilitiesThe company will give select partners early access to its Astra AI model—so they have time to shore up their defenses.WIRED.COM
1 SepX says attackers are targeting user accounts after the launch of X MoneyX is investigating a wave of unsolicited password reset emails that it believes may be tied to the rollout of its new payments service.TECHCRUNCH.COM