88Articles
9Categories
2026-09-04Date
🚨 CISA KEV 1[−]
4 Sep KEVU.S. CISA adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Google Chromium V8 flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Google Chromium V8 flaw, tracked as CVE-2026-85046 (CVSS score of 8,8…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 12[−]
4 SepOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE FlawsThreat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms …THEHACKERNEWS.COM
4 Sep KEVGoogle Releases Chrome Update to Patch Actively Exploited V8 Zero-DayGoogle on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's Ja…THEHACKERNEWS.COM
4 Sep KEVGoogle fixes actively exploited Chrome V8 zero-day vulnerabilityGoogle has released a Chrome security update addressing 12 vulnerabilities, including a high-severity V8 flaw that is being actively exploited in attacks. The fixes are included in Chrome 152.0.7977.82/.83 for Windows and macOS and version 152.0.7977.82 for Linux, with deployment…CYBERINSIDER.COM
4 Sep KEVSangoma Switchvox Vulnerabilities Exploited in the WildTracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek .SECURITYWEEK.COM
4 Sep12-Year-Old PostgreSQL Vulnerability Enables Database, Server TakeoverDubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover appeared first on SecurityWeek .SECURITYWEEK.COM
4 Sep KEVGoogle patches actively exploited Chrome zero-day (CVE-2026-85046)Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a Thursday security advisory. The …HELPNETSECURITY.COM
4 SepPostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server TakeoverPostGREShell (CVE-2026-6471) is a 12-year-old PostgreSQL flaw that lets low-privileged attackers execute code and take over servers. Cyera researchers found a severe PostgreSQL vulnerability, dubbed PostGREShell and tracked as CVE-2026-6471 (CVSS score of 7.2). Present in release…SECURITYAFFAIRS.COM
4 Sep KEVGoogle fixes the sixth actively exploited Chrome zero-day of 2026Google patched 12 Chrome flaws, including an actively exploited V8 zero-day that could enable remote code execution through a crafted webpage. Google released a Chrome security update fixing 12 vulnerabilities, including CVE-2026-85046 (CVSS score of 8.8), an actively exploited V…SECURITYAFFAIRS.COM
4 SepCritical Citrix NetScaler auth bypass now leveraged in attacksAttackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]BLEEPINGCOMPUTER.COM
4 SepPostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code ExecutionPostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical de…THEHACKERNEWS.COM
4 SepHPE Patches Critical RCE Vulnerabilities in AOS-CXNearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek .SECURITYWEEK.COM
⚠️ VULNERABILITY DISCLOSURE 33[−]
4 SepSecurity Vulnerability in a Voting SystemIt’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses af…SCHNEIER.COM
4 SepFBI probes 153 million driver's licence leak, Health data breach hits 9.5 million, Cyberattack closes Slovenian casinos153M Driver's Licenses for Sale, 9.5M-Patient Breach, and CISA Drops Key Security Assessments The episode reports the FBI investigating Nexus, a dark web service selling scans of over 153 million U.S. and Canadian driver's licenses and other identity documents, with evidence sugg…CYBERSECURITYTODAY.LIBSYN.COM
4 SepPlex Urges Immediate Updates After Patching Multiple Undisclosed Security FlawsPlex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those …THEHACKERNEWS.COM
4 SepGPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit RequestsOpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under…THEHACKERNEWS.COM
4 SepFBI investigates breach of 153 million driving license records at IDscan.netDrivers in North America received a nasty shock this week when it was revealed that digital scans of 153 million drivers’ licenses were for sale on the dark web. Among the victims were US Defense Secretary Pete Hegseth – and investigative reporter Brian Krebs, who has dug deep in…CSOONLINE.COM
4 SepOpenAI launches GPT-6 Astra, its first model to cross a critical cybersecurity thresholdOpenAI launched GPT-6 Astra on Thursday, disclosing that the new flagship model has crossed the “Critical” threshold for cybersecurity risk under its Preparedness Framework, a classification the company said triggers additional deployment restrictions. “GPT‑6 Astra is rolling out…CSOONLINE.COM
4 SepThe democratization of cyber warfare — and what it means for CISOsFor most of modern history, sophisticated and costly warfare had a high barrier to entry. In order to maintain a significant tactical advantage, you needed money, infrastructure and highly trained human resources. In the physical realm, you needed trained and capable warfighters …CSOONLINE.COM
4 SepRecorded Future Announces Automated Signature Creation, Accelerating Vulnerability PrioritizationRecorded Future's Automated Signature Creation turns new vulnerabilities into detection signatures in under an hour, matching the pace of AI-driven exploits.RECORDEDFUTURE.COM
4 SepTrezor says data of another 67,000 US customers exposed in breachTrezor says a recent breach at logistics provider ShipMonk exposed the personal and shipping information of another approximately 67,000 customers, dramatically expanding the scope of an incident first disclosed in August. The newly identified records belong to US customers who o…CYBERINSIDER.COM
4 SepNew CrowdStrike 'FalconFlank' zero-day grants SYSTEM privilegesAn anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]BLEEPINGCOMPUTER.COM
4 Sep KEVGoogle warns of new Chrome zero-day flaw exploited in attacksGoogle has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...]BLEEPINGCOMPUTER.COM
4 SepVMware Workstation and Fusion Updates Patch Critical VulnerabilityThe flaws could allow attackers with administrative access to a virtual machine to execute code on the host system. The post VMware Workstation and Fusion Updates Patch Critical Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
4 SepGoogle Patches 6th Chrome Zero-Day of 2026Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
4 SepNvidia Is Buying AI Platform Hugging Face for $13 BillionThe deal highlights Nvidia’s push to champion increasingly popular open-source AI models. The post Nvidia Is Buying AI Platform Hugging Face for $13 Billion appeared first on SecurityWeek .SECURITYWEEK.COM
4 Sep KEVSeptember 2026 Patch Tuesday forecast: All we need is more timeThe Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was the second biggest in history with 398 resolved CVEs: 42 rated Critical, 355 rated Important, and 1 rated …HELPNETSECURITY.COM
4 SepScammers have figured out the best time to text youThe suspicious calls, texts, and DMs you got recently aren’t a coincidence, according to Malwarebytes. Scammers have worked out which platform gets them the best results for each type of con, and they stick to that formula. (Source: Malwarebytes) The company looked at its o…HELPNETSECURITY.COM
4 SepOpenAI is putting $1 billion behind Daybreak for defenders working without enterprise budgetsOpenAI committed $1 billion to subsidize access to its Daybreak cyber models, along with training and technical support, for organizations defending water and wastewater systems, the electric grid, state and local government, community and regional banks, nonprofits, and open-sou…HELPNETSECURITY.COM
4 SepMost of the bugs Claude Mythos found have never been checked by a humanAnthropic pointed Claude Mythos Preview at 281 open-source projects and collected 23,019 candidate vulnerabilities. External security firms reviewed 1,900 of them. Maintainers received 1,596 reports and acknowledged 1,451; 97 fixes landed upstream, and 88 findings became publishe…HELPNETSECURITY.COM
4 SepDPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectorsOverview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty,…RAPID7.COM
4 SepHoneywell Aerospace Inc. Agrees to Pay Over $2M to Settle False Claims Act Allegations of Failing to Comply with Cybersecurity Requirements in a U.S. Department of Defense ContractA DOJ press release on September 1: The Justice Department announced today that Honeywell Aerospace Inc. has agreed to pay $2,042,518 to resolve allegations that it is liable under the False Claims Act for failing to comply with cybersecurity requirements in a contract with the U…DATABREACHES.NET
4 SepDaVita settles ransomware attack lawsuit for $15MChad Van Alstin reports an update on a ransomware attack previously reported on DataBreaches.net: Nationwide kidney dialysis chain DaVita has agreed to pay $15 million to settle a class action lawsuit stemming from a 2025 ransomware attack that exposed sensitive patient data to h…DATABREACHES.NET
4 SepLedger faces $500 million class action over data breachesPavlo Kot reports: ​Hardware crypto wallet maker Ledger is facing a class action seeking at least $500 million over a series of customer data breaches. The plaintiff claims the company failed to adequately protect customers’ personal information and did not take sufficient …DATABREACHES.NET
4 SepFBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scansPierluigi Paganini reports: A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada. The FBI’s New Orleans field office opened a…DATABREACHES.NET
4 SepTR: Fine for famous kebab chain that allowed theft of 500 thousand customers’ dataThe Turkish Data Protection Authority (KVKK) investigation into the data breach at the famous restaurant chain Baydöner, where the full names, phone numbers, emails, and city information of 505,337 customers were compromised, has been completed. The investigation found that there…DATABREACHES.NET
4 SepNew Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web TrafficA previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug stri…THEHACKERNEWS.COM
4 SepNightmare Eclipse drops a CrowdStrike zero-day.Extortion group leaks alleged Manchester Airports Group data. France's CNIL fines hospital over 2025 data breach.THECYBERWIRE.COM
4 SepNvidia’s $12.9B Hugging Face deal could benefit enterprisesThe chipmaker’s acquisition could eventually bring additional security resources and model evaluation tools to the platform, according to experts.CYBERSECURITYDIVE.COM
4 SepOpenAI pledges $1 billion to provide resources, training for frontline cyber defendersAmid heightened scrutiny, the company will use frontier AI to help water, power and local government providers fight malicious actors.CYBERSECURITYDIVE.COM
4 SepUsing a VM to Contain an AI AgentIt won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is…SCHNEIER.COM
4 SepOpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure DefendersThe Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility. The post OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders appeared fir…SECURITYWEEK.COM
4 SepOSPAR 2026 report now available with 167 services in scopeWe’re pleased to confirm the successful completion of our annual Amazon Web Services (AWS) Outsourced Service Provider’s Audit Report (OSPAR) assessment on July 29, 2026, in line with the OSPAR version 2.0 framework. The Association of Banks in Singapore (ABS) established the Gui…AWS.AMAZON.COM
4 Sep KEVWhat the Flock?The G7 and CISA prepare for the quantum threat. Nightmare Eclipse drops a CrowdStrike zero-day. The White House’s offensive hacking plan raises legal questions. CISA offers a playbook for communicating through cyber incidents. OpenAI puts a billion dollars behind AI-powered defen…THECYBERWIRE.COM
4 SepLegitimate RMM Tools Became the TrapA phishing campaign operating across 46 countries used familiar lures such as tax documents, invoices, Social Security notices, VAT notices, and shipping communications. Victims were directed toward legitimate remote management and monitoring software, including ScreenConnect, Co…YOUTUBE.COM
📋 SECURITY BULLETINS 1[−]
4 SepSynology ActiveProtect Manager 2.0 improves AI-driven securitySynology launched ActiveProtect Manager 2.0 (APM 2.0), the latest software update for its ActiveProtect data protection appliances. This release introduces expanded platform coverage, cross-platform recovery, and enhanced security, with future updates bringing AI-driven threat mi…HELPNETSECURITY.COM
📢 SECURITY ADVISORIES 4[−]
4 SepG7 urges organizations to prepare for quantum cyber threatsIn a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now.THERECORD.MEDIA
4 SepRisky Bulletin: Russia tells data centers to deploy drone defensesRussia tells data centers to deploy drone defenses, Dropbox discloses a security breach, a new spyware wave hits Serbia, and CISA scraps six free cybersecurity assessment programs.RISKY.BIZ
4 SepChinese Hackers Use AI Agents in Multi-Country Cyber CampaignHunt.io uncovered a Chinese-speaking campaign using AI agents to automate cyberattacks against Asian government, education and industrial targets. Threat intelligence firm Hunt.io just documented a second, separate China-linked campaign wiring commercial AI models directly into l…SECURITYAFFAIRS.COM
🔥 INCIDENT REPORTING 5[−]
4 SepYour Linux System Can Lie To YouOn a compromised Linux or Unix system, an attacker may manipulate the tools and mechanisms investigators rely on. A command such as ps could potentially return altered information through modified binaries, hooked system calls, libraries, or kernel-level tampering. If the utiliti…YOUTUBE.COM
4 SepDark Web Service Nexus Sells 153M+ Driver’s LicensesFBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans. A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver̵…SECURITYAFFAIRS.COM
4 SepIDScan sued over alleged data breach affecting 153 million driversMultiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]BLEEPINGCOMPUTER.COM
4 SepIn Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B ValuationNoteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’…SECURITYWEEK.COM
4 SepCrooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million PeopleManchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information…SECURITYAFFAIRS.COM
🕵️ THREAT INTELLIGENCE 13[−]
4 SepAI Coding Agents Are Installing Unknown/Untrusted Code on Corporate NetworksWe cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hoste…SCHNEIER.COM
4 SepISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
4 SepBidding war for defunct Spirit Airlines’ employee data will not dieThe destiny of Spirit Airline’s data is still undecided, months after the company sought bankruptcy protection. AI data company Micro1 has now offered $12.5 million to acquire a trove of the company’s emails, Teams chats, operations and employee productivity data, according to a …CSOONLINE.COM
4 SepWhy judgment is emerging as cybersecurity’s defining skillAI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their …CYBERSCOOP.COM
4 SepMullvad to shut down public encrypted DNS servers, back Quad9 insteadMullvad has announced that it will shut down its public encrypted DNS-over-HTTPS (DoH) servers on November 2, 2026, and will instead financially support privacy-focused DNS provider Quad9. Users who manually configured Mullvad’s public DNS service will need to migrate befor…CYBERINSIDER.COM
4 SepCatch Raises $5 Million for AI Executive Assistant With GuardrailsCatch promises the capabilities of a trusted executive assistant, with built-in controls governing what data and systems it can access. The post Catch Raises $5 Million for AI Executive Assistant With Guardrails appeared first on SecurityWeek .SECURITYWEEK.COM
4 SepMicrosoft Teams is about to make QR code phishing much harderMicrosoft is preparing a new feature for Teams users that will help them stay safe from QR code phishing. Teams will automatically hide QR codes sent by people outside the organization. Users will need to reveal the image first before they can view or scan it. It’s currentl…HELPNETSECURITY.COM
4 SepA five-part inventory for your AI agent credentialsIn this Help Net Security video, Roy Katmor, co-founder and CEO of Orchid, explains why AI agents hold credentials that nobody reviews. Organizations build agents in AI studios, connect them to enterprise tools, and give them accounts to do useful work. The agent is approved, the…HELPNETSECURITY.COM
4 SepNew infosec products of the week: September 4, 2026Here’s a look at the most interesting products from the past week, featuring releases from BugBase, F5 Networks, Ping Identity, and Superna. F5 speeds up virtual patching to counter AI-driven threats With new features such as anomaly detection and agentic threat intelligence, F5’…HELPNETSECURITY.COM
4 SepHow to secure edge AI in customer-owned environmentsAs AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments appeared first on Microsoft …MICROSOFT.COM
4 SepFriday Squid Blogging: Squid on a Stick at the New York State FairLooks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
4 SepWireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, and Josh Marpet - SWN #613Wireguard, Chrome, RMMS, Sonicwall, Microsoft, Sumerian VPNS, Harvard, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-613YOUTUBE.COM
4 SepEuropean parliament members call for slowdown of Serbia’s EU entry over spyware useThe letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop .CYBERSCOOP.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
4 SepAngry Birds: Toy Ghouls’ new toysKaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.SECURELIST.COM
4 SepThe hidden work of modernizing MalwarebytesWhy disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.MALWAREBYTES.COM
📡 INFOSEC NEWS 17[−]
4 SepUS military disabled ad tracking on troops’ devices following reports of targeted attacksA senator's letter confirms the U.S. military moved to prevent the tracking after foreign adversaries used location data to target troops.TECHCRUNCH.COM
4 SepData access: the hidden cost of security vendor lock-inGetting data into a security platform is always easy; getting it back out is where vendors add cost, extra tooling, and latency, and it is the part of the evaluation most teams overlook.ELASTIC.CO
4 SepX Money rollout linked to password-reset attacksAs X expands into payments, users are receiving password-reset emails they didn’t request. Here’s what may be happening and how to stay safe.MALWAREBYTES.COM
4 SepFree streaming boxes may be routing criminal traffic through your homeResearchers found that apps available on SuperBox devices could add your household connection to a residential proxy network.MALWAREBYTES.COM
4 SepRussian data centers face new security requirements amid Ukraine's drone threatsRussia's data centers are concentrated in areas increasingly exposed to Ukrainian drone attacks. The Kremlin wants them to stiffen their physical defenses.THERECORD.MEDIA
4 SepICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 YearsHomeland Security Investigations agents hit the outdoor retailer with a controversial subpoena as part of a dragnet search for the identities of protesters who entered a Minnesota church in March.WIRED.COM
4 SepOpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential ServicesOpenAI has committed to subsidizing access to Daybreak, helping defenders deploy its AI models in its existing cybersecurity infrastructureINFOSECURITY-MAGAZINE.COM
4 SepG7 Urges Fast-Track on Quantum-Safe Cybersecurity RulesThe G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transitionINFOSECURITY-MAGAZINE.COM
4 Sep39 New Methods That Compromise Passkey AuthenticationPasskeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries withou…BLEEPINGCOMPUTER.COM
4 SepExchange Online outage causes email delays, 'Server busy' errorsMicrosoft is working to resolve an ongoing Exchange Online outage that is delaying email sent to and received from external domains. [...]BLEEPINGCOMPUTER.COM
4 SepAI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.DARKREADING.COM
4 SepUK account-hack losses surge as new reporting system exposes hidden casesIn its first annual assessment, published Friday, the City of London Police said victims reported losing £6.3 million ($8.5 million) to account hacks in the year ending March 31, up from £1.2 million ($1.6 million) a year earlier.THERECORD.MEDIA
4 SepMicrosoft says some users can’t open the Teams desktop clientMicrosoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]BLEEPINGCOMPUTER.COM
4 SepUS, Britain to coordinate on scam center takedownsThe U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations.THERECORD.MEDIA
4 SepPhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade FiltersMicrosoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure w…THEHACKERNEWS.COM
4 SepCompanies Have Six Months to Prepare for Automated AttacksFrontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.DARKREADING.COM