131Articles
9Categories
2026-09-02Date
🐛 COMMON VULNERABILITIES AND EXPOSURES 17[−]
2 Sep22,000 Exchange servers open to hijack, 700 rogue AI agents swarmed Hugging Face, AI threatens global finance22,000 Exchange Servers Exposed, 700 AI Agents Swarm Hugging Face, and FSB Warns Frontier AI Is Top Financial Risk Cybersecurity Today with host David Shipley reports nearly 21,899 Microsoft Exchange servers still exposed and unpatched for high-severity auth-bypass CVE-2026-62911…CYBERSECURITYTODAY.LIBSYN.COM
2 SepSonicWall Warns of Two SMA1000 Zero-Days Exploited in AttacksThe vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepResearchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to AnotherForescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets&…THEHACKERNEWS.COM
2 SepAttackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without CredentialsThreat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulne…THEHACKERNEWS.COM
2 SepHackers Target Langflow in CVE-2026-0768 AttacksHackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems. Hackers have started exploiting a critical vulnerability, tracked as CVE-2026-0768 (CVSS score of 9.8), in the AI-focused low-code platform Lang…SECURITYAFFAIRS.COM
2 SepAttackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack ChainSonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by SonicWall's William Perry and Adam Babis, are list…THEHACKERNEWS.COM
2 SepSonicWall SMA 1000 appliances under attack via zero-day flawsAttackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA 1000 series is a line of secure remote ac…HELPNETSECURITY.COM
2 Sep KEVExploited JFrog Artifactory bug puts software supply chain on alertA critical authentication bypass in JFrog Artifactory is now being exploited in the wild, with attackers observed generating administrator tokens and probing the software supply-chain platform’s sensitive data. The flaw, tracked as CVE-2026-82329 , was disclosed by JFrog on Augus…CSOONLINE.COM
2 SepExploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How CVE-2026-9586 works Switchvox is a VoIP-based unifi…HELPNETSECURITY.COM
2 SepNearly 22,000 Microsoft Exchange servers remain exposed to critical security flaw (CVE-2026-62911)Nearly 22,000 Microsoft Exchange servers remain unpatched against CVE-2026-62911, a critical authentication bypass vulnerability, according to daily scans from the Shadowserver Foundation. The United States and Germany top the list with 6,200 and 5,100 unpatched servers. CVE-2026…HELPNETSECURITY.COM
2 SepHackers exploit critical JFrog Artifactory flaw to forge admin tokensA critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]BLEEPINGCOMPUTER.COM
2 SepCVE-2026-47285 Visual Studio Code Information Disclosure VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
2 SepCVE-2026-58650 Visual Studio Code Security Feature Bypass VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
2 SepCVE-2026-59113 Visual Studio Code Remote Code Execution VulnerabilityAffected software updated with new package information.MSRC.MICROSOFT.COM
2 Sep KEVCritical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the WildOverview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote c…RAPID7.COM
2 SepHackers exploit Sangoma Switchvox flaw to deploy reverse shellsAttackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]BLEEPINGCOMPUTER.COM
2 Sep KEVSonicWall reports two major security holes under active exploitSonicWall on Monday reported two major security holes in its Secure Mobile Access 1000 series appliances, both of which it said are being actively exploited, and published patches for each. Consultants called the holes, one of which permits remote attacks that bypass authenticati…CSOONLINE.COM
⚠️ VULNERABILITY DISCLOSURE 38[−]
2 SepOld, Unpatched Flaws Give Attackers Access to Philippines Nuclear AgencyThreat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.DARKREADING.COM
2 SepAnthropic makes changes to stop AI agents running amok againLearning from the OpenAI-Hugging Face fiasco, as well as from recent revelations about its own model, Anthropic is revamping its security and alignment practices. The company has established controls that flag when a model attempts to break out of a sandbox or successfully access…CSOONLINE.COM
2 SepOpen-source secrets scanning tool Sift hunts credentials in Microsoft 365, Slack, and JiraSift is a free, open-source command line tool that searches for passwords, API keys, and other sensitive data across the places a company keeps its work: local disks, Windows file shares, an entire Active Directory domain, SharePoint, OneDrive, Teams channel files, Slack messages…HELPNETSECURITY.COM
2 Sep KEVSonicWall warns of actively exploited SMA1000 zero-day flawsSonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]BLEEPINGCOMPUTER.COM
2 SepDuckDB stays open source while the team behind it goes to work for AmazonHannes Mühleisen and Mark Raasveldt started as AWS employees. The two built DuckDB, an analytical database that runs inside your process instead of on a server somebody has to administer. If you ship anything on top of DuckDB, your license does not change. Amazon did not buy the …HELPNETSECURITY.COM
2 SepAuthorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware PayloadsThe U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, a…THEHACKERNEWS.COM
2 SepSality botnet infrastructure dismantled in joint global takedownInternational law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]BLEEPINGCOMPUTER.COM
2 SepHow China industrialized the infrastructure behind state hackingLast week, the US Justice Department and FBI announced court-authorized seizures of domains hard-coded into two complementary hacking platforms known as “QScan” and “QTRouter,” used by Chinese state-sponsored hackers to target US critical infrastructure and other sensitive networ…CSOONLINE.COM
2 Sep KEVHackers Chain Two New SonicWall Zero-Day VulnerabilitiesSonicWall has urged customers to patch two new zero-day vulnerabilities being exploited in the wildINFOSECURITY-MAGAZINE.COM
2 SepGlobal sinkhole operation ends Sality botnet’s 23-year runSality, a peer-to-peer (P2P) botnet that had been running for 23 years and infecting more than 15,000 machines worldwide, has been taken down in a joint operation by international law enforcement agencies, working with CrowdStrike and the Shadowserver Foundation. The operation cu…HELPNETSECURITY.COM
2 SepKeepnet launches free SMS/Call Reporter for iOSKeepnet, an Extended Human Risk Management (xHRM) and Secure Behavior Management platform, today launched the Keepnet SMS/Call Reporter. It is a free app that turns a suspicious SMS or phone call into a one-tap report. Anyone can download it for personal protection. Organizations…HELPNETSECURITY.COM
2 SepGeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal BackendsTwo vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026…THEHACKERNEWS.COM
2 SepManchester Airports Group - 8,728,451 breached accountsIn August 2026, Manchester Airports Group (MAG) disclosed a data breach impacting their services . The incident was later claimed by the FulcrumSec hacking group , who subsequently published email addresses and phone numbers relating to 8.7M customers of Manchester, Stansted and …HAVEIBEENPWNED.COM
2 Sep KEVWhen the patch tsunami meets the maintenance windowIn April 2026, the balance between finding software flaws and fixing them broke. Frontier AI models released by Anthropic and OpenAI can now autonomously identify exploitable vulnerabilities in production software — work that used to take experienced human researchers roughly six…CSOONLINE.COM
2 SepChrome and Firefox Updates Patch Dozens of VulnerabilitiesThe browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs. The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepUS and European authorities disrupt Sality botnet after 23 yearsUS and European law enforcement agencies have disrupted the long-running Sality malware operation, cutting its operators off from more than 15,000 infected computers worldwide. The coordinated action, carried out on August 31, involved the US Department of Justice, FBI, Defense C…CYBERINSIDER.COM
2 SepOpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity ThresholdThe designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems. The post OpenAI’s Astra Becomes First Model to Cross Critical Cybersecurity Threshold appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepAnthropic introduces zero-retention AI safety monitoring for enterprisesAnthropic is introducing a new framework aimed at helping enterprises monitor AI misuse without ceding control over sensitive data, as organizations struggle to balance security visibility with strict compliance requirements. The company announced a new solution called Enterprise…CSOONLINE.COM
2 SepDropbox accounts breached through Lenovo email verification flawDropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [...]BLEEPINGCOMPUTER.COM
2 SepExploit Published for Fresh Cleo Harmony VulnerabilityThe security defect allows remote attackers to bypass authentication through argument bearer manipulation. The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
2 Sep$536 and 8 Hours: AI Learns to Attack a Different PLCExperts got Claude to port a PLC exploit, but it cost $536 and 8 hours, and a later AI-generated payload accidentally destroyed the hardware. Forescout researchers just answered a question that’s been hanging over industrial security for a while: can AI actually port a work…SECURITYAFFAIRS.COM
2 SepMeta Ads Push StreamRat Android Trojan That Can Gain Near-Complete Device ControlCybersecurity researchers have disclosed details of a new Android banking trojan called StreamRat that was promoted to Spanish-speaking users through a fake television-streaming campaign on Meta and can give operators near-complete control of infected devices. ThreatFabric said t…THEHACKERNEWS.COM
2 SepMalicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker CodeManifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at publication. The command executes as the u…THEHACKERNEWS.COM
2 Sep KEVSonicWall Patches Two New Actively Exploited Zero-Days in SMA 1000 VPNsSonicWall patched two zero-days in SMA 1000 VPNs, including a CVSS 10 pre-auth SSRF flaw, after confirming active exploitation. SonicWall has released security updates for two vulnerabilities in its SMA 1000 VPN appliances that are actively exploited in attacks in the wild. Sonic…SECURITYAFFAIRS.COM
2 SepNew darknet marketplace peddles millions of driver's licenses.Law enforcement and industry partners shutter the Sality botnet. Business news: Socure raises $156 million and acquires Fravity.THECYBERWIRE.COM
2 SepAI Security Findings Aren’t ProofAI can generate remarkably polished security findings, complete with severity ratings, CWE classifications, explanations, and proposed patches. But a convincing output is not proof that a vulnerability exists—or that a proposed fix actually resolves it. AI can still be valuable w…YOUTUBE.COM
2 SepWordPress backup plugin flaw exposes millions of sites to takeover attacksAn SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]BLEEPINGCOMPUTER.COM
2 SepOpenLeash Adds a Human Check to Risky AI Agent ActionsThe security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain. The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepManaging identity source transition for AWS IAM Identity CenterSeptember 2, 2026: This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center manages user access to Amazon Web Services (AWS) resources, including both AWS accounts and applications. You can use IAM Iden…AWS.AMAZON.COM
2 SepDrive-by data theft.Nexus sells driver’s license scans on the dark web. OpenAI says its models have reached a “Critical” capability threshold. International law enforcement disrupts a decades-old botnet. AI hallucinations fuel “slop squatting.” Plus, urgent patches for Cleo Harmony and Virtualizor, …THECYBERWIRE.COM
2 SepSonicWall SMA 1000 Zero-Days Enable Unauthenticated RCEThe exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.DARKREADING.COM
2 SepDoD confirms ‘refrigeration disruption’ at military commissariesDysruptionHub raised the suspicion flag yesterday, but couldn’t get a straight answer from DOD as to whether refrigeration outages at 14 commissaries represented a cyberattack. The Military Times fared no better: With more than a half-dozen commissaries on military bases in…DATABREACHES.NET
2 SepHackers expose donor data from Russian fundraisers for Ukrainians, political prisonersDaryna Antoniuk reports: Hackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information. The unknown threat actor targeted Davayte, wh…DATABREACHES.NET
2 SepLuminis Health facilities dealing with a cyberattackBridget Byrne reports: Luminis Health is experiencing a cybersecurity incident affecting certain systems across its organization, according to a Facebook post Tuesday. “Our priority remains providing safe, high-quality care to our patients,” the health system said in the post tha…DATABREACHES.NET
2 SepJail time for Maine child in 764 marks turning point in federal law enforcementResearcher tracking 764 said the first-of-its-kind case has a wider impact that will cause ripples across the landscape of violent extremist crime. The post Jail time for Maine child in 764 marks turning point in federal law enforcement appeared first on CyberScoop .CYBERSCOOP.COM
2 SepAI’s Vulnerability Surge May Be More Manageable Than First FearedNew research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.DARKREADING.COM
2 SepOpenAI Astra Brings Autonomous Zero-Day Exploitation to AIOpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now officially OpenAI’s highest-risk cybersecurity model. In August, OpenAI said it “couldn’t rule out” that its upcoming model had rea…SECURITYAFFAIRS.COM
2 SepSmashing Security podcast #483: This AI helps thieves steal your iPhoneYou've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And …GRAHAMCLULEY.COM
📋 SECURITY BULLETINS 1[−]
2 SepMalicious Virtualizor Update Served via BGP HijackingUsing a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. The post Malicious Virtualizor Update Served via BGP Hijacking appeared first on SecurityWeek .SECURITYWEEK.COM
📢 SECURITY ADVISORIES 8[−]
2 SepRisky Business #851 -- Agents are just ones and zeros, and tigers are just atomsOn this week’s show Patrick Gray and James Wilson are joined by guest co-host The Grugq to talk through the week’s news, including: Two alleged TeamPCP hackers got arrested in Australia The White House has a plan to boost security for water facilities, but we can’t see it working…RISKY.BIZ
2 SepLenovo ID flaw let attackers access Dropbox accounts without passwordsDropbox users are reporting unauthorized account access caused by a flaw in Lenovo’s email verification process that allowed attackers to create Lenovo IDs using victims’ email addresses and use them to sign in to associated Dropbox accounts. The number of affected users remains …CYBERINSIDER.COM
2 SepUK Moves to Block High-Risk Tech Suppliers From Critical InfrastructureLate amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify. The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek .SECURITYWEEK.COM
🔥 INCIDENT REPORTING 16[−]
2 SepVali Cyber ZeroLock 5 brings MFA to the hypervisor command lineVali Cyber released ZeroLock 5, a major release focused on closing the two most dangerous gaps in hypervisor security: insider threats and stolen credentials on ESX and Linux hosts. The hypervisor is now the target Over the past two years, ransomware operators and nation-state ac…HELPNETSECURITY.COM
2 SepFulcrumSec Claims Responsibility for Manchester Airport Group BreachThreat group FulcrumSec claims MAG breach and leaks 550GB of data onlineINFOSECURITY-MAGAZINE.COM
2 SepA battery storage cyberattack would look exactly like a badly tuned controllerBatteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should not have the command, would look the same on a control room screen right …HELPNETSECURITY.COM
2 SepDark web site puts 153 million driver’s licenses and millions more IDs up for saleThe FBI is investigating a possible breach of idscan.net linked to 153 million driver’s license scans for sale online.MALWAREBYTES.COM
2 SepNutex Health Says Patient Data Stolen, Hackers Threaten LeakThe US healthcare provider confirmed that sensitive patient and employee data, alongside financial and business information, were exfiltrated by a third partyINFOSECURITY-MAGAZINE.COM
2 SepAn AI-Assisted Cyber Attack: Inside a Unit 42 InvestigationUsing autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
2 SepAnthropic Details Response to Security Incidents, Unveils Enterprise SafeguardsAnthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse. The post Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepHow to Secure Enterprise AI: From Adoption to Incident ReadinessThe debate about whether AI delivers business value is over. The challenge now is implementing it at scale and securely across every function while meeting board-level pressure to move fast. Organizations must focus on adopting AI at business speed without losing control of cyber…THEHACKERNEWS.COM
2 SepBGP Hijack Delivers Malicious Virtualizor Update That Establishes Persistent Root AccessVirtualizor said hackers used a Border Gateway Protocol (BGP) hijack to divert Softaculous traffic. The hackers then used the diverted update traffic to deliver a malicious Virtualizor package to some installations. A hosting-provider account separately said 5 of its 34 checked V…THEHACKERNEWS.COM
2 SepGambling Goblin Turns Brazilian Government Sites Into SEO WeaponsGambling Goblin compromised Brazilian government sites to drive gambling traffic through SEO fraudINFOSECURITY-MAGAZINE.COM
2 Sep153 million driver’s licenses exposed in suspected IDScan breachThe FBI is investigating an apparent breach involving identity verification provider IDScan after a dark web service began selling access to more than 153 million US and Canadian driver’s license scans, according to an exclusive KrebsOnSecurity report. The marketplace, called Nex…CYBERINSIDER.COM
2 SepMalicious Apache Modules Hijack Brazilian Government Site Traffic to Push Betting PagesA Chinese-speaking cybercrime cluster known as Gambling Goblin has been observed installing malicious Apache modules on compromised web servers run by Brazilian government and educational institutions, and using them to divert visitors to attacker-controlled pages promoting onlin…THEHACKERNEWS.COM
2 SepRansomware protection for MSPs: A 6-point checklist for faster recoveryRansomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. [...]BLEEPINGCOMPUTER.COM
2 SepNew pro-Ukraine hacker group targets Russian companies with custom ransomwareThe group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.THERECORD.MEDIA
2 SepHealth data of more than 9.5 million people leaked from Aesto record systemThe healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.THERECORD.MEDIA
2 SepIt sure looks like hackers breached a major ID card verification serviceAn identity theft search site claimed to have more than 150 million driver's license photos stolen from an ID verification service. The crime site has now shut down.TECHCRUNCH.COM
🕵️ THREAT INTELLIGENCE 28[−]
2 SepISC Stormcast For Wednesday, September 2nd, 2026 https://isc.sans.edu/podcastdetail/10078, (Wed, Sep 2nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
2 SepAnthropic’s Enterprise Frontier Safeguards lets your Claude logs stay in your cloudEight members of the Analysis and Resilience Center for Systemic Risk, a group whose roster includes the CISOs of Goldman Sachs, Morgan Stanley, Citi, Bank of America, and Wells Fargo, spent months working with Anthropic on a question their examiners care about more than benchmar…HELPNETSECURITY.COM
2 SepAn AI CAPTCHA solver talked itself out of the right answerYou have probably spent a few seconds of your life turning a picture until it lines up. Some sites, instead of asking you to tick a box, show you a circular chunk of a photo that has been spun around, and you drag it until the inside matches the ring around it. Simple enough. Ann…HELPNETSECURITY.COM
2 SepScareware ads keep running on Google’s transparency tool, even after they’re reportedA team of NYU and Radboud University researchers spent a year building a tool to find deceptive software ads inside Google’s public ad archive. It works. It also exposed something more uncomfortable: reporting a bad ad to Google doesn’t mean the ad, or the domain behi…HELPNETSECURITY.COM
2 SepVisa enhances A2A Protect to stop fraud before money leaves the accountVisa announced an enhanced version of A2A Protect, delivering real-time risk insights that help banks stop account-to-account fraud before money leaves customer accounts. The expanded solution introduces a new unified fraud score—Visa’s integration of Featurespace technology—givi…HELPNETSECURITY.COM
2 SepEdge Case launches Guardian, an AI platform for tracking risk across autonomous systemsEdge Case launched Guardian, an AI-driven platform that connects safety analysis, engineering data, and operational signals to give teams a continuous understanding of how system risk evolves. At launch, Guardian will support some of the world’s most advanced autonomous pla…HELPNETSECURITY.COM
2 SepF5 speeds up virtual patching to counter AI-driven threatsF5 announced innovations to block frontier AI-driven threats in the data path and enable faster virtual patching, giving security leaders time to make intelligent risk-based decisions rather than reactive operational compromises. With new features such as anomaly detection and ag…HELPNETSECURITY.COM
2 SepNational Life Group CISO expects more vulnerabilities in six months than in thirty yearsIn this Help Net Security interview, Becky Palmer is VP and CISO at National Life Group, answers five questions about defending against AI-driven attacks. The discussion covers why patch cycles built for human speed cannot keep up, and which compensating controls buy time when an…HELPNETSECURITY.COM
2 Sep23-Year-Old Sality P2P Botnet DisruptedThe shutdown operation involved peer list manipulation and Sality payload URL takedown. The post 23-Year-Old Sality P2P Botnet Disrupted appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepExtradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected ThousandsThe U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017. Searzhudin Tamirlanovich A…THEHACKERNEWS.COM
2 SepPreventing Wire Fraud and 2 Interviews From BH USA 2026 From Optiv Security and Kai - ... - BSW #463Wire fraud, identity spoofing, and PII exposure now top the list of operational risks for private capital. In a world of ongoing fraud risk, fiduciary responsibility doesn’t end with sound investment decisions — it must extend to operational best practices that protect every capi…YOUTUBE.COM
2 SepWireless Routers as Motion DetectorsComcast has added motion detection as a feature to its wireless routers: The feature sends push notifications to users when motion is detected near a connected device, such as a TV or printer. It has different settings for when people are home, asleep, or away. The Xfinity app al…SCHNEIER.COM
2 SepGaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weaponResearch by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented …RESEARCH.CHECKPOINT.COM
2 SepAttackers are going after prominent individuals through OAuth phishing, FBI warnsAttackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI has warned. The FBI’s Internet Crime Complaint Center (IC3) says the activity, which uses a technique call…HELPNETSECURITY.COM
2 SepIran-linked APT Mirage Kitten Uses Fake Job Tests to Spread MalwareMirage Kitten used fake LinkedIn coding tests to spread NodeRabbit and PollCat, even banning AI tools that could have spotted the malware. Iran-linked Mirage Kitten hackers just found a genuinely clever way to make their own malware harder to detect: telling job candidates not to…SECURITYAFFAIRS.COM
2 SepRockwell Automation Patches Over a Dozen Vulnerabilities Across ProductsThe industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products. The post Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products appeared first on SecurityWeek .SECURITYWEEK.COM
2 SepDownload: The Agentic Software Development GuideAI makes it easy to ship more code. It does not make that code easier to trust. Most teams don’t fail because their developers can’t use AI. They fail because the dev’s job changed and nobody redefined it. Under AI, cracks appear: Reviews weaken while output multiplies Code looks…HELPNETSECURITY.COM
2 SepWhat If Every Wire Recipient Was Verified?Sending a wire often means entering and relying on account information for another person or entity. The sender is ultimately responsible for making sure the information is correct. That creates a fundamental trust problem. What if the person, entity, and bank account were verifi…YOUTUBE.COM
2 SepU.K. Supreme Court Opens Door for Spyware Victims to Sue Foreign StatesLast month, the Supreme Court of the United Kingdom issued a highly anticipated decision in The Kingdom of Bahrain v. Shehabi and another (Shehabi). The claimants, two Bahraini dissidents living in the U.K., allegedly suffered psychological harm after Bahrain used FinSpy spyware …CITIZENLAB.CA
2 SepPegasus, NoviSpy variant spyware found on devices of Serbian activistsIt’s the first Pegasus infection of 2026 that Citizen Lab is forensically confirming, and the SHARE Foundation said it’s the biggest wave of spyware surveillance in Serbia yet. The post Pegasus, NoviSpy variant spyware found on devices of Serbian activists appeared first on Cyber…CYBERSCOOP.COM
2 SepWyden seeks upgraded NSA security guidance on commercial VPN useit’s the latest in a sequence of letters to feds from Sen. Ron Wyden, D-Ore., on commercial VPNs. The post Wyden seeks upgraded NSA security guidance on commercial VPN use appeared first on CyberScoop .CYBERSCOOP.COM
2 SepCybersecurity Insiders: AI Infrastructure’s Firmware Problem Is Bigger Than Any Single VendorThe rapid construction of AI infrastructure is creating new security challenges across the hardware and software stack, from inference servers and telemetry tools to network adapters, management controllers and trusted platform modules. The post Cybersecurity Insiders: AI Infrast…ECLYPSIUM.COM
2 SepThe FCC wants consumers to rate their telecom’s anti-robocall protectionsThe FCC wants consumers to rate their telecom’s anti-robocall protections. The post The FCC wants consumers to rate their telecom’s anti-robocall protections appeared first on CyberScoop .CYBERSCOOP.COM
2 SepDogged Russia-based botnet dismantled after 23-year runSality’s peer-to-peer infrastructure allowed it to evade system-wide disruption efforts for an exceptionally long period. Authorities and cybersecurity experts finally brought it down. The post Dogged Russia-based botnet dismantled after 23-year run appeared first on CyberScoop .CYBERSCOOP.COM
2 SepMalicious “privacy browser” hijacks PCs with mouse and keyboard injectionSecurity researchers at Intezer have uncovered a deceptive browser application that can remotely inject keyboard and mouse commands into Windows systems. The campaign was discovered after an employee mistyped a single character while following setup instructions for a newly purch…CYBERINSIDER.COM
2 SepAI Gives Cybercriminals a Dangerous Time AdvantageFormer cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.DARKREADING.COM
2 SepAI Is Fighting AI-Powered Identity FraudIdentity verification is becoming a data-intensive process. At SixLock, the system can pull roughly 130 data points from different databases and compare them against information associated with a person and their identity documents. The goal is to determine whether all those sign…YOUTUBE.COM
2 SepImpersonating IT support: how threat actors turn a remote session into enterprise-wide accessMicrosoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement us…MICROSOFT.COM
🌐 CYBER THREAT LANDSCAPE 7[−]
2 SepUS charges Russian for infecting 80,000 freelancers with malwareA California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]BLEEPINGCOMPUTER.COM
2 SepScammers are getting smarter about where they target youNew Malwarebytes research reveals how different scams are tailored to different platforms.MALWAREBYTES.COM
2 SepSality, one of the longest-running botnets, finally gets disruptedU.S. and European authorities disrupted the long-running botnet Sality, turning the malware’s peer-to-peer architecture against itself to cut thousands of infected computers off from operators.THERECORD.MEDIA
2 SepRussian Man Extradited Over Malware Campaign Targeting FreelancersRussian man extradited to US over malware campaign that targeted 80,000 freelance usersINFOSECURITY-MAGAZINE.COM
2 SepThreat Gang 'Springs' Vishing Attacks on Microsoft Teams UsersThe "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.DARKREADING.COM
2 SepFake Software Installers Disable Windows Update and Weaken Microsoft DefenderAn active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industr…THEHACKERNEWS.COM
2 SepRussian national facing 20 years for malware campaign that infected 80,000 freelancersSearzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week.THERECORD.MEDIA
🎙️ PODCASTS 1[−]
2 SepHow to Build a Marketing Strategy AI Cannot Commoditize with Brian Reed of CorshaBrian Reed has been a CMO six times. He's also watched AI flatten marketing for the past two years and has said so out loud, including in a manifesto he published called AI is Flattening Marketing: Cue the Return of Mad Men. On this CyberCMO Confidential episode, Brian, Gianna, a…THECYBERWIRE.COM
📡 INFOSEC NEWS 15[−]
2 SepWeekly Threat Bulletin – September 2nd, 2026These are the top threats you should know about this week.F5.COM
2 SepRisky Bulletin: BGP hijack delivers malicious Virtualizor updatesA BGP hijack delivered malicious Virtualizor updates, the White House launches Project Watershed 250, Indian authorities take down a Telegram doxing bot, and Composer packages deliver iOS badness.RISKY.BIZ
2 SepYour AI chats could be used in courtWhat you tell an AI chatbot could come back to haunt you in court. The Washington Post found chat histories already used in 12 legal cases.MALWAREBYTES.COM
2 SepMicrosoft Defender flags legitimate Google search links as maliciousMicrosoft is investigating an issue causing the Defender for Office 365 security software to mistakenly block access to legitimate Google search links. [...]BLEEPINGCOMPUTER.COM
2 SepTwo critical Chrome flaws put users at risk on malicious websitesUpdate Chrome now: Two critical vulnerabilities could allow a malicious website to run code on your device.MALWAREBYTES.COM
2 SepNorway considers ban on camera-enabled wearable ‘pervert glasses’The Nordic country says wearable camera headsets need to be regulated given their privacy risks.TECHCRUNCH.COM
2 SepHackers expose donor data from Russian fundraisers for Ukrainians, political prisonersHackers reportedly gained access to payment accounts used by two Russian fundraising projects supporting Ukrainians and political prisoners, exposing donor email addresses and limited payment card information.THERECORD.MEDIA
2 SepJoint guidance on best practices for service providers when communicating under pressureThis joint guidance explains why effective communications during outages is critical to minimize operational impacts, maintain credibility and situational awareness, and support response efforts.CYBER.GC.CA
2 SepHiddenLayer nabs $100M as enterprises rush to secure their AI deploymentsHiddenLayer has raised a $100M Series B from Delta-v Capital, Ten Eleven Ventures, Morgan Stanley, Microsoft's M12, Booz Allen Hamilton, and others.TECHCRUNCH.COM
2 SepRevolut scam wave steals £180,000 from Jersey residents in just four weeksIf you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls. Because local police on the largest of the Channel Islands have warned that over a single four-week period, an astonishing 75% of all scam crime reports they have received have invo…BITDEFENDER.COM
2 SepTech support scams look different now. Here’s what to watch forTech support scams have evolved beyond fake virus warnings. Here’s how scammers reach their targets now, and how to stay safe.MALWAREBYTES.COM
2 SepAI Agents Are Now Emailing Me with Their Security ConcernsI received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After …SCHNEIER.COM
2 SepAgentic security: Detection and response at machine speedAfter talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud. Organizations across every industry are adopting AI agents that authenticate …AWS.AMAZON.COM
2 SepGoogle, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access ProgramsGoogle on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like go…THEHACKERNEWS.COM
2 SepSocure raises $156 million and acquires agentic AI platform Fravity.Palo Alto Networks has acquired San Francisco-based agentic workflow platform Console.THECYBERWIRE.COM