70Articles
8Categories
2026-09-07Date
🐛 COMMON VULNERABILITIES AND EXPOSURES 3[−]
7 Sep KEVBack-to-back N-able bugs send admins on a patching spreeA max-severity zero-day bug could be affecting cybersecurity firm N-able’s N-central remote monitoring and management platform, the company said, even as administrators were applying a hotfix for two vulnerabilities disclosed just a day earlier. The latest flaw, tracked as CVE-20…CSOONLINE.COM
7 Sep KEVN-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “cri…HELPNETSECURITY.COM
7 SepN-able Releases Hotfix for Critical Remote Code Execution VulnerabilityThe vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itselfINFOSECURITY-MAGAZINE.COM
⚠️ VULNERABILITY DISCLOSURE 35[−]
7 SepIDScan sued over 153 million licence breach, FalconFlank zero-day hijacks CrowdStrike, Magento stores backdoored with no patchIdentity verification firm IDScan faces multiple lawsuits and investigations after hackers allegedly breached it. The criminals offered over 153 million U.S. and Canadian driver's license scans for sale. Nightmare Eclipse releases FalconFlank, a zero-day privilege escalation that…CYBERSECURITYTODAY.LIBSYN.COM
7 SepToolHive: The open-source way to run any MCP server securelyToolHive is an open-source platform that runs Model Context Protocol servers inside containers. An MCP server is the connector that lets an AI client like Cursor or Claude Code reach an outside tool, and Stacklok ships ToolHive under Apache 2.0, so the runtime, the Kubernetes ope…HELPNETSECURITY.COM
7 SepN-able patches max severity N-central flaw amid ongoing attacksN-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. [...]BLEEPINGCOMPUTER.COM
7 SepJSCeal Malware Can Bypass Google Authentication Using Stolen Session CookiesCybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-pr…THEHACKERNEWS.COM
7 SepWhat do CISOs need to rest easy about future AI risks?Security leaders’ confidence in their ability to navigate the security risks AI will pose over the next two years rests on several clear factors, according to IANS analysis of its AI Security Survey, fielded earlier this year. Of the 113 CISOs IANS surveyed in April and May, 41% …CSOONLINE.COM
7 SepResearcher Publishes CrowdStrike Privilege Escalation Zero DayA security researcher has posted a zero-day exploit in CrowdStrike which could allow hackers to escalate privilegesINFOSECURITY-MAGAZINE.COM
7 Sep KEVMikroTik RouterOS bugs actively exploited in device takeover attacksCERT Polska is warning MikroTik customers to urgently update RouterOS after confirming that attackers are exploiting two critical SSH vulnerabilities to gain full administrative access to internet-exposed devices. The Polish national cybersecurity team disclosed six RouterOS vuln…CYBERINSIDER.COM
7 Sep KEVN-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE FlawEvery on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix…THEHACKERNEWS.COM
7 SepShadow AI Epidemic: Uncovering Agents on the Endpoint, British Library Breach, & News ... - ESW #475Interview - Amit Assaraf As employees rapidly adopt local AI models, autonomous agents, and browser extensions to boost productivity, enterprise endpoints are quietly accumulating unchecked security risks. This episode explores how traditional EDR solutions miss non-binary softwa…YOUTUBE.COM
7 SepOpenAI just hit a milestone on the road to self-improving AIOpenAI has announced that it has reached a goal set last fall of having an automated research intern by September 2026. The milestone means a system can carry out well-defined research tasks under human direction, including work that would take a skilled researcher several days. …HELPNETSECURITY.COM
7 SepHackers exploit new MikroTik RouterOS flaws to hijack routersHackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. [...]BLEEPINGCOMPUTER.COM
7 SepConnectWise warns of new ScreenConnect flaw without patchConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. [...]BLEEPINGCOMPUTER.COM
7 SepBimbo Bakeries confirms data stolen in Oracle EBS zero-day attackBimbo Bakeries USA has disclosed a data breach caused by the exploitation of an Oracle E-Business Suite (EBS) zero-day that allowed attackers to steal files containing names and Social Security numbers. The company says it determined on December 6, 2025, that unauthorized parties…CYBERINSIDER.COM
7 SepAdobe Commerce Zero-Day Exploited to Backdoor Online StoresThe StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek .SECURITYWEEK.COM
7 SepRogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected HostsCybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use divers…THEHACKERNEWS.COM
7 SepTelerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit ReleasedA TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports …THEHACKERNEWS.COM
7 SepSam Altman calls GPT-6 Astra rollout ‘messy’ as enterprise users wait for accessOpenAI’s rollout of its GPT-6 Astra model ran into early access issues after paying ChatGPT users were unable to use the system shortly after launch, prompting CEO Sam Altman to apologize and say the release had been “messy.” “First, sorry for the messy rollout,” OpenAI CEO Sam A…CSOONLINE.COM
7 SepNightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day ExploitsThe proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek .SECURITYWEEK.COM
7 SepJapan’s Health Ministry to Strengthen Cybersecurity Measures at HospitalsThe Yomiuri Shimbun reports: The Health, Labor and Welfare Ministry is set to strengthen cybersecurity measures at hospitals to counter a surging number of cyberattacks on medical institutions. The ministry has included ¥13.7 billion in its budget request for fiscal 2027 to imple…DATABREACHES.NET
7 SepPersonal Data of Approximately 220,000 Domestic and International Gangnam Unni Users LeakedLee Seunghyeong reports: Personal information of approximately 220,000 domestic and international users has been leaked from Gangnam Unni, a beauty medical platform operated by Healing Paper. On September 7, Healing Paper announced through a public notice that on September 4, the…DATABREACHES.NET
7 SepWeverse Data Leak Affects More Than 422,000 K-Pop Fan Accountskbizoom reports: Weverse, the fan platform operated by HYBE-affiliated Weverse Company, has confirmed a security incident that affected 422,584 user accounts. The company said the exposed information consisted mainly of internal identifiers that cannot be used outside the platfor…DATABREACHES.NET
7 SepMathspace Breach Impacts More Than 1 Million Users in Australia, NZAshish Khaitan reports: The Mathspace data breach has affected 1,079,819 people in Australia and New Zealand after unauthorized parties accessed an internal reporting system and downloaded user information. Mathspace confirmed the security incident on September 3, 2026, and said …DATABREACHES.NET
7 SepMathspace discloses data breach affecting over 1 million peopleOnline maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. [...]BLEEPINGCOMPUTER.COM
7 SepHackers exploit RouterOS flaws to hijack MikroTik devices without authenticationAttackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska, Poland’s national CSIRT team, have discovered six vulnerabilities in RouterOS and coordinated their disclosure with MikroTi…HELPNETSECURITY.COM
7 SepChaotic Eclipse Released A PoC For NVIDIA GreenSection Memory Corruption Zero-DayChaotic Eclipse released GreenSection, a PoC exploit for an Nvidia GreenSection Memory Corruption Zero-Day Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Nvidia. The researcher na…SECURITYAFFAIRS.COM
7 SepFake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion AttacksThreat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and res…THEHACKERNEWS.COM
7 Sep⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and MoreTurning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a tr…THEHACKERNEWS.COM
7 Sep7th September – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platfor…RESEARCH.CHECKPOINT.COM
7 SepMagento StyleSmuggler zero-day exploited to deploy Linux backdoorA zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]BLEEPINGCOMPUTER.COM
7 SepHackers drain $320M in Bitcoin from Liquid Network, claim they’re the good guysCarly Page reports: Hackers have drained roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network, while claiming to be the good guys. Liquid, a Bitcoin sidechain developed by Blockstream and used by exchanges and other financial institutions, said in…DATABREACHES.NET
7 SepBigBear Microsoft 365 phishing service bypassed MFA at 258 organizationsBill Toulas reports: A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. Researchers at cybersecurity company CloudSEK gained administrator access to the…DATABREACHES.NET
7 SepPEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command ExecutionCybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly…THEHACKERNEWS.COM
7 SepStyleSmuggler: The Magento Zero-Day Behind New Store AttacksStyleSmuggler Magento zero-day is under active attack, letting unauthenticated attackers execute code and install backdoors on stores that may already be patched. A new zero-day flaw, dubbed StyleSmuggler, in Magento and Adobe Commerce is under active attack, giving unauthenticat…SECURITYAFFAIRS.COM
7 SepAI Found Vulnerabilities Just By AskingAn AI assistant was casually asked whether it could find vulnerabilities in devices connected to a computer. The result was reportedly significant vulnerabilities across consumer and prosumer products, although the findings were described as largely local and not necessarily rele…YOUTUBE.COM
7 SepMA: Springfield Public Schools will be closed Tuesday after a cyber incidentCarolyn Rodriguez reports: Springfield Public Schools will be closed Tuesday after a cyber incident disrupted systems necessary for essential school operations, Superintendent Dr. Sonia Dinnall announced Monday. According to the district, the closure will help the district contin…DATABREACHES.NET
📢 SECURITY ADVISORIES 3[−]
7 SepBerlin Ransomware Leak Exposes State SecretsBerlin refused a 30 Bitcoin ransom, leading hackers to leak 6TB of sensitive state administration and national defense data on the dark web. When a ransomware gang dumps nearly six terabytes of state administration files onto the dark web, ignoring them does not make the problem …SECURITYAFFAIRS.COM
7 SepAttackers spread malware through ScreenConnect file transfersA file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. “A CVE identifier and an official fix will be issued within the week,” the company wrote in its September 3 advisory. …HELPNETSECURITY.COM
7 SepNCSC Warns Shadow AI Creates New Security RisksNCSC warns unapproved AI tools can expose corporate data and create new security risksINFOSECURITY-MAGAZINE.COM
🔥 INCIDENT REPORTING 5[−]
7 SepRisky Bulletin: BEC campaign steals €35 million from French notariesHackers steal €35 million euros from French notaries, OpenAI agents hacked a German wiki, a new bill will allow the Pentagon to use cyber contractors, and the Five Eyes members tell hacked companies to drop PR spin.RISKY.BIZ
7 SepMultiple Class Action Lawsuits Filed Against IDScanSeveral victims of a recent breach of driver’s license information have sued the company they believe responsibleINFOSECURITY-MAGAZINE.COM
7 SepRhysida Publishes Berlin Government Data After €2m Extortion Demand RefusedThe ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plansINFOSECURITY-MAGAZINE.COM
7 SepOpenAI Agents Hijack Another Victim WebsiteOpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach. The post OpenAI Agents Hijack Another Victim Website appeared first on SecurityWeek .SECURITYWEEK.COM
7 SepTrezor data breach impact now reaches 81,000 customersCryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 12[−]
7 SepSponsored: Authentik is rethinking PAM for AI agentsIn this Risky Business sponsored interview, James Wilson chats with Authentik Security CEO Fletcher Heisler about how AI is driving a need for privileged access management to adapt. Fletcher explains Authentik’s approach: each agent has its own identity, begins with no permission…RISKY.BIZ
7 SepZero trust AI agents demand a different kind of securityIn this interview, Chris Webber, VP, Product Marketing at Teleport, explains why zero trust principles need to change for AI agents. He covers how agents act fast, unpredictably, and continuously, and why old ideas like least privilege and point-in-time verification fall short. W…HELPNETSECURITY.COM
7 Sep18 ways to check whether data can be trusted for AIETSI has published TR 104 180, a technical report that defines 18 metrics for measuring data quality, giving companies a way to check whether their data is good enough for AI before they use it. The report defines each metric and includes the formulas needed to calculate it. The …HELPNETSECURITY.COM
7 SepHow a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accountsIf you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed. Read more in my article on the Hot for Security blog.BITDEFENDER.COM
7 SepNorth Korea’s Lazarus Operates Through Six Distinct Cyber ClustersSekoia and Kudelski Security have observed that North Korea's Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasionINFOSECURITY-MAGAZINE.COM
7 SepAutomobile Camouflage to Hide from Flock CamerasNot sure it’s practical, but it’s certainly striking .SCHNEIER.COM
7 SepSurfshark announces acquisition of data-removal service OpterySurfshark has acquired US-based data-removal service Optery, expanding a privacy portfolio that already includes Incogni and Ironwall. Optery will continue operating independently, with its own team, product, and technology. Surfshark Group announced the acquisition today, withou…CYBERINSIDER.COM
7 SepModified ScreenConnect Clients Used in Worm-Like CampaignThe attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. The post Modified ScreenConnect Clients Used in Worm-Like Campaign appeared first on SecurityWeek .SECURITYWEEK.COM
7 SepNew attack eavesdrops on headphone audio from 30 meters awaySecurity researchers have demonstrated a new electromagnetic attack that can recover audio playing through ordinary wired and wireless headphones, with intelligible speech captured from as far as 30 meters away. The technique, called InjectEave, can also operate through walls and…CYBERINSIDER.COM
7 SepNorth Korean Hackers Deploy New Linux Espionage ToolkitThe stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek .SECURITYWEEK.COM
7 SepBlock Agents or Make Them AskAI agent policies can do more than simply allow or block an action. They can require the agent to ask the user for explicit approval before proceeding. That creates a human decision point inside the agent’s workflow. The agent can identify what it wants to do, but the action does…YOUTUBE.COM
7 SepLG Smart TVs found scanning home networks for nearby devicesResearchers investigating LG smart TVs found that the devices repeatedly scan local networks for nearby hardware, identifying phones, computers, smartwatches, printers, network equipment, thermostats, and other connected devices. The Gamers Nexus investigation also found extensiv…CYBERINSIDER.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
7 SepA week in security (August 31 – September 6)Last week on Malwarebytes Labs: Stay safe!MALWAREBYTES.COM
7 SepJSCeal Hides Crypto Malware in V8 BytecodeJSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. Unlike most malware, it hides its code in a for…SECURITYAFFAIRS.COM
🎙️ PODCASTS 2[−]
7 SepThis call may be monitored.In this Special Episode, ⁠Maria Varmazis⁠ and ⁠Dave Bittner⁠ are joined by friend of the show, ⁠Brandon Karpf⁠, to unpack a new bipartisan congressional investigation into the lingering presence of Chinese state-owned telecommunications companies inside U.S. internet infrastructu…THECYBERWIRE.COM
7 SepLoyalty points fraud is funding hacker holidays (Lock and Code S07E18)This week on the Lock and Code podcast, we speak with Kim Sutherland about loyalty points fraud and how everyday people can stay safe.MALWAREBYTES.COM
📡 INFOSEC NEWS 8[−]
7 SepWhy AI Agent Sandboxes Are Failing Security TestsAutonomous AI agents escaped a sandbox and accessed Hugging Face via reward hacking, exposing serious architectural control and isolation flaws. The recent case involving OpenAI test agents and Hugging Face should concern security teams, but not for the reason implied by headline…SECURITYAFFAIRS.COM
7 SepChatGPT can now connect to your personal apps to mimic writing styleOpenAI appears to be testing a new "Writing Style" feature for ChatGPT that can learn how you write by looking at examples from your connected apps. [...]BLEEPINGCOMPUTER.COM
7 SepFlirty OnlyFans promoters on X may be using AI to appear humanPersonalized replies and voice notes make it increasingly difficult to tell whether you’re talking to a human, chatbot, or AI agent.MALWAREBYTES.COM
7 SepBerlin investigates new data leak after hackers publish stolen login credentialsAnother trove of data from Berlin's government has appeared online, authorities said. Germany's information security agency separately warned about the Rhysida cybercrime group.THERECORD.MEDIA
7 SepYour Cloud Security Checklist Doesn't Work the Way You Think It DoesIf managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across …THEHACKERNEWS.COM
7 SepLG TV flaws could let attackers listen in, even in standby modeTesting found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.MALWAREBYTES.COM
7 SepBigBear Microsoft 365 phishing service bypassed MFA at 258 organizationsA phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]BLEEPINGCOMPUTER.COM
7 SepCondé Nast Data of 32.8 Million Users Offered for Sale After WIRED LeakCondé Nast user data from 32.8 million accounts is reportedly for sale, raising risks of targeted phishing, fraud and scams. A database said to contain 32.8 million Condé Nast user records is being offered for $15,000 on a Russian-language cybercrime forum. Ransomnews reviewed a …SECURITYAFFAIRS.COM