🚨 CISA KEV 1[−]
3 Sep KEVCISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto MinersThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A ser…THEHACKERNEWS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 7[−]
3 SepOver 3 Million WordPress Sites Affected by Migration Plugin VulnerabilityThe high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution. The post Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepDecade-old PostgreSQL flaw turns backup account into a backdoorA critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise. The issue, dubbed PostGREShell by Cyera Research, exists in the database’s replication functionality…CSOONLINE.COM
3 SepCritical Elementor Pro flaw exploited to take over WordPress sitesA recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]BLEEPINGCOMPUTER.COM
3 SepCVE-2026-58641 .NET Elevation of Privilege VulnerabilityAdded SkiaSharp 4.151.2 to the affected software table.MSRC.MICROSOFT.COM
3 SepCritical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as RootCisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8…THEHACKERNEWS.COM
3 SepVU#889462: Casdoor authentication server is vulnerable to authorization bypassOverview Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions 3.115.0 and earlier. The vulnerability allows a non-global organization administrator to perform unauthorized admini…KB.CERT.ORG
3 SepCisco Fixed Critical RCE in Nexus 9000 Series SwitchesCisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulner…SECURITYAFFAIRS.COM
⚠️ VULNERABILITY DISCLOSURE 28[−]
3 SepFlipping AI’s kill switch.This week, Dave and Ben look at two major AI stories. The first involves Anthropic winning one of its legal challenges regarding the Pentagon designating the company as a supply chain risk. The second story looks at a recent law introduced in Congress that seeks to give CISA the …THECYBERWIRE.COM
3 SepI just want to give you $25 million!This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittner…THECYBERWIRE.COM
3 SepSrsly Risky Biz: China's botnets are worth disruptingTom Uren and James Wilson talk about China’s long-term shift to getting private companies to build botnets for cyberespionage. A disruption effort from the US this week is good news, but China has been using these networks for a surprisingly long time and will rebuild. They also …RISKY.BIZ
3 SepResearcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike FalconThe security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day privilege escalation that abuses the offic…THEHACKERNEWS.COM
3 SepSeemplicity Response Options accelerates vulnerability mitigationSeemplicity announced Response Options for vulnerability management and exposure management workflows. This new capability gives security teams multiple, actionable paths to closing a vulnerability finding based on context. The problem Response Options addresses is straightforwar…HELPNETSECURITY.COM
3 SepZero trust has a big AI agent problem aheadDespite singing the praises of zero trust for many years, many CISOs have struggled to implement the framework in full . And now comes what could be the final nail: agentic AI. Can zero trust coexist with autonomous agents in typical enterprise environments? Technically, yes. In …CSOONLINE.COM
3 SepPegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhoneThe iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to …THEHACKERNEWS.COM
3 SepAI agents help compress ransomware intrusion to under 10 hours, raising stakes for CISOsA ransomware attacker used AI agents to move through an enterprise network in less than 10 hours, according to Palo Alto Networks researchers, who estimated that similar work could have taken human operators about two weeks. The incident involved more than 50 techniques mapped to…CSOONLINE.COM
3 SepStop playing with the CISO role. Fix cybersecurity leadershipWe have spent years telling chief information security officers (CISOs) that they need to become better aligned with the business. They need to understand strategy. They need to speak the language of the board. They need to build relationships with business leaders. They need to …CSOONLINE.COM
3 SepYour phone or computer may soon ask how old you areCalifornia and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt.MALWAREBYTES.COM
3 SepChaotic Eclipse Releases Crowdstrike Falcon ZeroDay FalconFlankChaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Crowdstri…SECURITYAFFAIRS.COM
3 SepCisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch VulnerabilitiesPublicly disclosed S/MIME flaws could expose encrypted email content, while critical IOS XR and Nexus bugs could enable remote code execution and authentication bypass. The post Cisco Warns of Unpatched Secure Email Flaws, Patches Critical Switch Vulnerabilities appeared first on…SECURITYWEEK.COM
3 SepCounterfeit installers turn routine software downloads into enterprise breachesMicrosoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access. “Once executed, the malicious installers deploy malwar…CSOONLINE.COM
3 SepUS and Canadian Court Records Breached Following Thomson Reuters IncidentThomson Reuters has disclosed a cyber incident affecting its C-Track court management software, potentially exposing court records in Canada and the USINFOSECURITY-MAGAZINE.COM
3 SepPegasus zero-click attack infects Serbian activist’s iPhoneA member of Serbia’s pro-democracy student movement was infected with NSO Group’s Pegasus spyware through a zero-click iMessage exploit. The case is part of a broader surveillance wave that has targeted at least 14 students, activists and opposition politicians since the beginnin…CYBERINSIDER.COM
3 SepWhatsApp rolls out emergency fix for locked Android photo access bugWhatsApp announced it has begun rolling out a fix for an Android privacy issue that could allow someone with physical access to a locked phone to view the owner’s photos after initiating a WhatsApp video call. Security researcher Jose Rodriguez publicly disclosed the behavior on …CYBERINSIDER.COM
3 Sep'Breeze Comet' Tears Into Brazilian & Global Financial SystemsBrazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.DARKREADING.COM
3 SepRussian National Indicted For Exploiting Online Platform Used For Freelance Employment And Distributing Malware To Thousands Of VictimsSAN FRANCISCO – A federal grand jury has indicted Searzhudin Tamirlanovich Aktulaev on charges of Conspiracy, Transmission of a Program, Information, Code, and Command to Cause Damage to a Protected Computer, and Aggravated Identity Theft, among other offenses. Defendant was arre…DATABREACHES.NET
3 SepNorth Dakota Supreme Court impacted by third-party data breach that has affected dozens of statesJoe Kurzewski reports: A criminal investigation is underway after data associated with the North Dakota Supreme Court was affected by a breach of a third-party vendor used by the court. According to a news release, the North Dakota Court System was informed in late July that C-Tr…DATABREACHES.NET
3 SepThomson Reuters reveals breach that exposed U.S. and Canadian court recordsThomson Reuters has disclosed a data breach affecting C-Track, a court case management platform operated by its subsidiaries, exposing court records and sensitive personal information across courts in at least 12 US states, the US Virgin Islands, and Canada. The company published…HELPNETSECURITY.COM
3 SepMap Your AWS Network FirstA strong AWS audit starts with understanding the environment. Mapping network routes and security groups shows which systems are able—or supposed—to communicate. IAM roles then show what those systems are authorized to do. These two views reveal different parts of the attack surf…YOUTUBE.COM
3 SepSonicWall urges immediate patching of chained vulnerabilitiesJust weeks after a wave of ransomware attacks, new flaws in SMA1000 series appliances are being exploited.CYBERSECURITYDIVE.COM
3 SepPegasus Zero-Click Exploit Infects Serbian Student Activist's iPhonePegasus infected a Serbian student activist's iPhone through an iMessage zero-click exploitINFOSECURITY-MAGAZINE.COM
3 SepBraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace InventoryCybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master…THEHACKERNEWS.COM
3 SepThomson Reuters Court Software Breach May Have Exposed SSNs and Sealed DataThomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Pu…THEHACKERNEWS.COM
3 SepBTS #81 - Infratrust Pulse, AI's Role in SecurityIn this episode of Below the Surface, host Paul Asadoorian is joined by Eclypsium’s Vlad Babkin for a wide-ranging discussion on the latest infrastructure security risks, beginning with the August InfraTrust Pulse and expanding into management plane exploitation, BMC persistence,…ECLYPSIUM.COM
3 SepAgentic Ransomware Took Down Enterprise in Ten Hours: AI Left 80-Page AuditRoger Satterfield reports: An attacker handed an unknown corporate victim a comprehensive, 80-page security audit on Wednesday — not as a service, but as a postscript to the ransomware attack that had just consumed the victim’s enterprise. According to Palo Alto Networks…DATABREACHES.NET
3 SepHPE patches critical ArubaOS-CX remote code execution flawHewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]BLEEPINGCOMPUTER.COM
📋 SECURITY BULLETINS 1[−]
3 SepMicrosoft Teams, Outlook fail to launch on ARM-based Windows PCsMicrosoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 7[−]
🔥 INCIDENT REPORTING 7[−]
3 SepFBI Probes Possible Breach of 153 Million Driver’s LicensesThe FBI is investigating how scans of over 153 million driver’s licenses are being sold on the dark webINFOSECURITY-MAGAZINE.COM
3 SepAttackers Expose Ongoing AI Tool Use Targeting Organizations in Latin AmericaExplore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
3 SepAttackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted AttacksThreat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government…THEHACKERNEWS.COM
3 SepUS and Canadian court data exposed in Thomson Reuters breachSealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada.THERECORD.MEDIA
3 SepYour Employee’s Password Appeared in an Infostealer Log. Now What?Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeove…BLEEPINGCOMPUTER.COM
3 SepAI 'Machine Speed' Cuts 2-Week Attack Down to 10 HoursThe incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.DARKREADING.COM
3 SepFishbrain data breach exposes user details and password hashesFishing app Fishbrain is notifying users of a data breach after an unauthorized person accessed an environment containing user data, exposing personal information and account credentials. The company says some compromised password hashes may be vulnerable to cracking and has rese…CYBERINSIDER.COM
🕵️ THREAT INTELLIGENCE 20[−]
3 SepISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
3 SepWindows memory integrity switches on automatically for eligible devices in October 2026Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those same updates enable VBS too. Memory integrit…HELPNETSECURITY.COM
3 SepYour threat feed is someone else’s database: What ingesting malware intel at scale takesThe advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was never the hard part. A threat feed is someone…HELPNETSECURITY.COM
3 SepWhen AI quietly breaks things, who pays?David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a merger, how governance disclosures …HELPNETSECURITY.COM
3 SepYour AI agent’s system prompt is not a security controlAn AI agent told in its system prompt to show a user only what that user is cleared to see will hand over more the moment someone talks it into doing so. Gee Rittenhouse, who oversees Security Hub, GuardDuty, and Inspector at AWS, and Eric Johnson, a fellow at the SANS Institute,…HELPNETSECURITY.COM
3 Sep2,000 Leaked Documents Reveal How Russia Turns Engineering Students Into GRU Cyber Operators2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Devel…SECURITYAFFAIRS.COM
3 SepResearchers built a $7 gadget for anyone paranoid about hidden cameras in hotel roomsMost of us, staying in a hotel room or a vacation rental, have wondered at least once whether we’re safe there, whether someone might be watching or recording us without our knowledge. The thought alone leaves a bitter taste in the mouth. A team from the Korea Advanced Inst…HELPNETSECURITY.COM
3 Sep153 Million Driver License Images Offered on Dark WebCybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net. The post 153 Million Driver License Images Offered on Dark Web appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepRussian man indicted for spreading malware to 80,000 freelancersA Russian national accused of using fake accounts on a freelance employment platform to spread malware to approximately 80,000 users has been indicted by a federal grand jury in California. Searzhudin Tamirlanovich Aktulaev, 40, faces charges of conspiracy, transmission of malici…HELPNETSECURITY.COM
3 SepResearching Employment ScamsResearchers built a fake company to study fake employee scams .SCHNEIER.COM
3 SepAI Agent Firewall Startup AIR Security Emerges From Stealth With $50 MillionThe startup’s firewall evaluates AI skills, plugins and MCP servers for malicious instructions, excessive permissions and software supply chain risks. The post AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepHiddenLayer Raises $100 Million for AI Runtime SecurityThe Austin-based company will invest in agentic runtime security capabilities to secure AI coding agents. The post HiddenLayer Raises $100 Million for AI Runtime Security appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepWhy your data is safer than you think on public Wi-FiTL;DR The coffee shop hacker Public Wi-Fi has acquired a slightly theatrical reputation. Join the network in a coffee shop, we are told, and a hacker in the corner can immediately steal your passwords and empty your bank account. It makes for good VPN ad…PENTESTPARTNERS.COM
3 SepGoogle’s Gemini 3.8 Flash takes on bigger AI models at a lower costGoogle has introduced Gemini 3.8 Flash, available to developers today, and a gated sibling, Gemini 3.8 Flash Cyber, reserved for vetted security teams. “Our 3rd Flash release in just 6 wks,” Google CEO Sundar Pichai said on X, adding that it makes sizable gains over 3…HELPNETSECURITY.COM
3 SepManchester Airports Group Data on 8.8 Million People Leaked After Ransom RefusalHacker group published roughly 550GB of data after MAG reportedly refused to pay a ransom demand; the group says it gained access via exposed admin keys. The post Manchester Airports Group Data on 8.8 Million People Leaked After Ransom Refusal appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepCapsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue AgentsNew models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review. The post Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents appeared first on SecurityWeek .SECURITYWEEK.COM
3 SepASCII smuggling crosses over from AI prompt injection to phishing evasionInvisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog .MICROSOFT.COM
3 SepBrave tests show lower CPU and memory usage than Chrome, Edge, and FirefoxBrave says its desktop browser used less CPU, memory, energy, and network bandwidth than Chrome, Edge, and Firefox in a new round of macOS testing, attributing much of the difference to its built-in ad and tracker blocking. The benchmarks were conducted by Brave itself, and the b…CYBERINSIDER.COM
3 SepThe story behind the intelligenceFrom engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.TALOSINTELLIGENCE.COM
3 SepThe G7 tells industry to hurry up and prep for post-quantum encryptionThe nations warn that governments and industry can no longer treat quantum codebreaking as a distant or theoretical possibility. The post The G7 tells industry to hurry up and prep for post-quantum encryption appeared first on CyberScoop .CYBERSCOOP.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
3 SepInternational Operation Disrupts Sality P2P BotnetUS-led action sinkholes machines caught up in Sality botnetINFOSECURITY-MAGAZINE.COM
3 SepShai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That MeansIn early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI…THEHACKERNEWS.COM
3 SepNonprofit sues Trump admin for details on AI safety reviews.Rogue ScreenConnect installations spread malware with worm-like behavior. Maine teenager jailed for participation in the 764 extremist network.THECYBERWIRE.COM
3 SepStreamRat Android malware spreads through Meta and TikTok adsSocial media ads for a free streaming service exposed roughly 570,000 people to StreamRat, a banking Trojan that can take control of infected phones.MALWAREBYTES.COM
3 SepLarge group of Serbian opposition, activist figures targeted with spywareAt least 14 Serbians have been targeted with advanced spyware since December, with victims including a member of Parliament, a local opposition politician and student protesters, according to digital forensic researchers.THERECORD.MEDIA
📡 INFOSEC NEWS 15[−]
3 SepHoneypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
3 SepThis Is Flock’s AI Search Tool for CopsWIRED rebuilt Flock’s latest search tool from code the company sends to a police officer’s browser. Its AI can keep watch across multiple cameras for anyone fitting a written description.WIRED.COM
3 SepPlex warns users to patch security vulnerabilities immediatelyPlex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]BLEEPINGCOMPUTER.COM
3 SepUS Becomes Top Target in RMM Phishing Campaign Spanning 46 CountriesAn RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, mak…THEHACKERNEWS.COM
3 SepCREST Onboards First Cohort for AI-Enabled Pentesting AccreditationCREST’s new AI-enabled penetration testing accreditation welcomes its first 10 providersINFOSECURITY-MAGAZINE.COM
3 SepMicrosoft says KB5120998 Windows update resets desktop settingsMicrosoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]BLEEPINGCOMPUTER.COM
3 SepOutsider Phishing Kit Survives Takedown With 700 New PagesOutsider phishing kit generated 700 new pages after a Google-led disruptionINFOSECURITY-MAGAZINE.COM
3 Sep412,000 The Town 2025 Ticket Buyers’ Data Hits the Dark Web412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, clai…SECURITYAFFAIRS.COM
3 SepAnthropic confirms Claude is down, multiple models affectedClaude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]BLEEPINGCOMPUTER.COM
3 SepMicrosoft: KB5120998 mouse reset bug affects only non-English PCsMicrosoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]BLEEPINGCOMPUTER.COM
3 SepOpenAI confirms ChatGPT is down ahead of 'Astra' model launchChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]BLEEPINGCOMPUTER.COM
3 SepAbliteration.ai is making a business out of removing AI guardrailsAbliteration.AI is making powerful AI models without guardrails easier to access, arguing that giving defenders the same tools as bad actors could ultimately improve cybersecurity.TECHCRUNCH.COM
3 SepThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More StoriesThe worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and…THEHACKERNEWS.COM
3 SepMeta agrees to pay $18 billion to settle US lawsuits over social media addiction.Review finds that more OpenAI agents went rogue.THECYBERWIRE.COM