🚨 CISA KEV 1[−]
10 Sep KEVU.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 7[−]
10 SepFortinet Code Execution Flaw Exploited in PivotC2 RAT AttacksThe high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026. The post Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepOrganizations Warned of Cisco Secure FMC ExploitationCisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026. The post Organizations Warned of Cisco Secure FMC Exploitation appeared first on SecurityWeek .SECURITYWEEK.COM
10 Sep KEVCISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch DeadlineThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by S…THEHACKERNEWS.COM
10 SepStealth rootkit targeting F5 BIG-IP could expose enterprise identity gatewaysA newly analyzed Linux rootkit is believed to have given attackers a way to hide shells inside recently compromised F5 BIG-IP Access Policy Management (APM) environments, without leaving the malicious PHP code on disk. Sophos said the malware, found in compromised BIG-IP APM envi…CSOONLINE.COM
10 SepCisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a networ…HELPNETSECURITY.COM
10 Sep KEVCritical NetScaler Vulnerability Exploited in AttacksTracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3. The post Critical NetScaler Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepVU#687587: AOMEI Backupper amwrtdrv.sys local privilege escalation vulnerability allows arbitrary writes to physical disksOverview An incorrect permissions assignment vulnerability in the amwrtdrv.sys kernel driver, included with AOMEI Backupper 8.4.0, allows an unprivileged local user to perform arbitrary writes to the physical disk. When Secure Boot is disabled, this can be leveraged to execute ar…KB.CERT.ORG
⚠️ VULNERABILITY DISCLOSURE 35[−]
10 SepLove, lies, and a fake 49er.This week, hosts of N2K CyberWire Maria Varmazis and Dave Bittn…THECYBERWIRE.COM
10 SepAI adoption brings new security headaches for already stretched CISOsCISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the CISO report. The Al mandate expands faster than res…HELPNETSECURITY.COM
10 SepEU Cyber Resilience Act to Enforce New Reporting RequirementsStarting Friday, businesses operating in the EU will have just 24 hours to notify the government any time they discover serious product security incidents.DARKREADING.COM
10 SepFour Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 DaysFour espionage groups used the BlueMoon Chrome+Windows exploit kit within 12 days. Researchers suspect AI development. Proofpoint published a detailed analysis of a Chrome-and-Windows exploit kit it tracks as BlueMoon that four nation-state actors adopted within roughly two weeks…SECURITYAFFAIRS.COM
10 SepMcKesson - 6,404,340 breached accountsIn August 2026, healthcare and pharmaceutical company McKesson was targeted in a ShinyHunters "pay or leak" extortion campaign . The group subsequently published a substantial corpus of data they alleged was sourced from the company, which included 6.4M unique email addresses amo…HAVEIBEENPWNED.COM
10 SepNew ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft DefenderThe exploit provides full System privileges on Windows machines running the September 2026 patches. The post New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepNearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin KeyNearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the m…THEHACKERNEWS.COM
10 SepAnthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company s…THEHACKERNEWS.COM
10 SepGetting ahead of ‘harvest-now-decrypt-later’: Post-quantum cryptography planningI’ve sat in enough boardroom conversations about quantum computing to notice a pattern. Someone raises it, someone else says “that’s ten years out,” and the topic gets tabled until next year’s budget cycle. The clock that matters isn’t the one measuring when a quantum computer ar…CSOONLINE.COM
10 Sep KEVCISA: WatchGuard RCE flaw now exploited in ransomware attacksThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. [...]BLEEPINGCOMPUTER.COM
10 SepApple is building photo verification for the people who need it mostApple has introduced Apple Reference Image, an opt-in feature designed to verify the authenticity of photos taken with iPhone 18 Pro models. Apple Reference Image provides users with an unalterable reference photo, visually confirming what the sensor saw at the moment of capture.…HELPNETSECURITY.COM
10 SepAIs Compress Exploit TimelineGive an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was availa…SCHNEIER.COM
10 SepThe Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRELearn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities. The post The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
10 SepSurfshark says hackers accessed internal engineering serverSurfshark has disclosed a security incident in which an improperly configured internal test server was exposed to the internet and accessed by an unauthorized third party. The VPN provider says the breach did not affect customer data, VPN traffic, production systems, apps, or bro…CYBERINSIDER.COM
10 SepScytale expands vendor risk management with AI-powered TPRM toolsScytale has announced the launch of their latest AI-powered third-party risk management (TPRM) capabilities within its Vendors module. The release further extends vendor risk management from a periodic review exercise into a continuously updated vendor risk intelligence engine, g…HELPNETSECURITY.COM
10 SepWordPress adds automated security checks to block risky plugin releasesWordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be secure today and introduce a vulnerability, or ma…HELPNETSECURITY.COM
10 Sep KEVUpdate Chrome now to protect against an actively exploited vulnerabilityChrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.MALWAREBYTES.COM
10 SepBlueMoon exploit kit lets hackers compromise fully updated Chrome usersMultiple state-aligned hacking groups have adopted a new exploit kit that can compromise Google Chrome users even when they run the latest stable browser version available at the time of the attack. The campaign, independently documented by Proofpoint and Volexity, uses a shared …CYBERINSIDER.COM
10 SepAI workflows may be creating a dangerous new authorization blind spotA newly identified AI attack technique can let unauthenticated users trigger privileged workflows and access enterprise systems, highlighting a gap in how identity and access controls apply to AI agents, according to research from Noma Labs. The report , authored by Noma Labs lea…CSOONLINE.COM
10 Sep KEVThe agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the railsLearn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environment Key takeaways AI models can quickly understand data, but not your business. While modern AI models…TENABLE.COM
10 SepUK appoints new commander of National Cyber ForceThe individual has not yet been avowed — the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged — as routine security considerations are still being worked through.THERECORD.MEDIA
10 SepCheck Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCECheck Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described. One flaw…THEHACKERNEWS.COM
10 SepPaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ InstancesA suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoin…THEHACKERNEWS.COM
10 SepRussian e-commerce giant Wildberries says DDoS attack delayed payments to sellersWildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to track and withdraw their earnings.THERECORD.MEDIA
10 SepDeceptive Android Apps Exploit Google Play Early Access to Evade ReviewsDeceptive apps in Early Access are being used by dishonest developers for their own benefit. The post Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepAttackers call employees’ personal phones to break into Microsoft 365 accountsAttackers are calling or texting employees on their personal phones, posing as internal IT staff, in a social engineering campaign that tricks them into handing over access to corporate cloud accounts. Once inside, they pull files and email from Microsoft 365 apps, SharePoint, On…HELPNETSECURITY.COM
10 SepFTC Withdraws Obsolete Policy StatementFrom the Federal Trade Commission: The Federal Trade Commission rescinded the 2021 Policy Statement on Breaches by Health Apps and Other Connected Devices. This controversial policy statement purported to apply the FTC’s Health Breach Notification Rule to health apps and connecte…DATABREACHES.NET
10 SepKorea raises data breach fines to 10% of revenueKorea JoongAng Daily reports: Korea’s privacy regulator is sharply raising the cost of data breaches, aiming to push companies to treat data protection as a preventive investment rather than a routine cost of doing business. Starting Friday, companies found to have leaked t…DATABREACHES.NET
10 SepShinyHunters expose 6.4M in attack on medical supplier McKessonConnor Jones reports: McKesson’s cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the scale of the attack for the first t…DATABREACHES.NET
10 SepNew 'BlueMoon' kit exploited Windows and Chrome zero-day flawsMultiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]BLEEPINGCOMPUTER.COM
10 SepBlueMoon exploit kit turns Chrome and Windows flaws into attacksFour different espionage groups used the same exploit kit to target recently fixed flaws, showing why “patch later” is a dangerous gamble.MALWAREBYTES.COM
10 SepFBI releases its first public cyber strategy.Anthropic discloses another instance of unauthorized AI access. Chinese espionage actors deploy new exploit kit.THECYBERWIRE.COM
10 SepCisco FMC flaws exploited by ransomware gang, state-sponsored hackersCisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]BLEEPINGCOMPUTER.COM
10 SepNightmare-Eclipse Strikes Again with 'ShieldCrash' Windows ExploitThe disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.DARKREADING.COM
10 SepAI-powered attack exploited PaperCut flaws to hack 395 organizationsA threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]BLEEPINGCOMPUTER.COM
📋 SECURITY BULLETINS 1[−]
10 SepMicrosoft fixes bug that wiped Windows desktop settingsMicrosoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 9[−]
10 SepFake GTA 6 download delivers malware-packed bundle to impatient gamersGrand Theft Auto VI (GTA 6) is still three months from release, but cybercriminals are not waiting for the launch date. Security firm Huntress found malware disguised as a leaked copy of the game, aimed at fans hoping to get their hands on it early. The sample Huntress pulled apa…HELPNETSECURITY.COM
10 Sep1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale.CLOUDFLARE.COM
10 SepCISA Updates Insider Threat Guide With New Mitigation AdviceCISA has updated its insider threat guide with new advice on remote work, AI and risk detectionINFOSECURITY-MAGAZINE.COM
10 SepCISA is on the verge of filling hundreds of critical vacanciesMeanwhile, the agency is finalizing an incident-reporting regulation and setting up a new industry coordination structure.CYBERSECURITYDIVE.COM
🔥 INCIDENT REPORTING 14[−]
10 SepSrsly Risky Biz: America's drivers licence breach is a national security disasterTom Uren and James Wilson talk about how Chinese intelligence services will take advantage of a massive breach of 150 million American drivers licences. They also discuss the steps the US military is taking to counter adtech device tracking. It’s too slow and not enough. Finally,…RISKY.BIZ
10 SepTrezor warns users of email provider breach, phishing attacksTrezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. [...]BLEEPINGCOMPUTER.COM
10 SepAnthropic Reveals Yet Another Cybersecurity IncidentAnthropic has found a fourth case of its model accessing third-party systems without authorizationINFOSECURITY-MAGAZINE.COM
10 SepThe longitude problem: In the AI era, detection is won on facts, not guessesFor most of the age of sail, a captain could find his latitude in minutes and could not find his longitude at all. Latitude you could read off the sun. Longitude, your position east to west, offered no such trick. Three weeks into the Atlantic, a navigator knew how far north he w…CSOONLINE.COM
10 SepSporting goods chain Hibbett discloses employee data breachHibbett Retail, Inc. is notifying employees that an unknown third party gained unauthorized access to its systems and may have acquired files containing personnel records during an April 2026 security incident. The company said in a breach notification dated September 8, 2026, th…CYBERINSIDER.COM
10 SepA New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World HarmClaude models compromised real systems during misconfigured security tests, exposing a worrying mix of flawed reasoning, harmful actions and weak safeguards. Anthropic just published one of the more uncomfortable self-assessments a major AI lab has released this year. The company…SECURITYAFFAIRS.COM
10 SepWidened Scan Turns Up Fourth Rogue Claude Cyber IncidentAnthropic is most concerned about Claude Mythos 5’s reckless behavior after recent incidents in which real systems were hacked. The post Widened Scan Turns Up Fourth Rogue Claude Cyber Incident appeared first on SecurityWeek .SECURITYWEEK.COM
10 Sep4.1 Million Impacted by AdaptHealth Data BreachIn June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems. The post 4.1 Million Impacted by AdaptHealth Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepMantaxOtax Android Malware Combines Ransomware With SpywareMantaxOtax Android malware combines ransomware with extensive spyware capabilitiesINFOSECURITY-MAGAZINE.COM
10 SepID verification giant IDScan confirms data breach with more than 150 million driver’s licenses stolenThe ID checking company said the data breach included people's full names and driver's licenses and other government-issued identity documents.TECHCRUNCH.COM
10 SepIDScan confirms breach tied to 153 million stolen driver’s licensesIdentity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. [...]BLEEPINGCOMPUTER.COM
10 SepFollow the Money: The Financial Sector's Threat Landscape in 2026The financial sector moves trillions of dollars a day, making it one of the most heavily targeted industries in the world. Intel 471's latest report breaks down the threat landscape facing financial institutions, from ransomware and extortion groups to initial access brokers, nat…INTEL471.COM
10 SepThreat groups enhance cyberattack capabilities with AIA report shows state-linked and criminal hackers are incorporating automation and agentic technology to find new victims and bypass traditional defenses.CYBERSECURITYDIVE.COM
10 SepIDScan confirms breach after hackers offer 153 million driver’s license scans for saleA notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected.THERECORD.MEDIA
🕵️ THREAT INTELLIGENCE 19[−]
10 SepIs a closed or an open AI model more trustworthy?There's no silver bullet when it comes to AI security strategy, and treating one model, tool, or vendor as the answer can limit an organization’s ability to adapt. Morgan Adamski, who leads PwC’s Cyber, Data & Technology Risk practice, joins us to tackle two pressing questions: H…THECYBERWIRE.COM
10 SepA new open standard locks AI weights to approved hardwareOPAQUE, a confidential computing company that runs AI workloads inside hardware-isolated environments so operators cannot inspect them, released an open standard that lets AI model builders decide when and where their weights can be decrypted once those weights leave the builder&…HELPNETSECURITY.COM
10 Sep KEVKevin Mandia joins the Amazon board with 30-plus years in cybersecurityAmazon elected Kevin Mandia to its Board of Directors on September 8. Mandia founded Mandiant and served as its CEO before Google acquired the firm in September 2022, and he has worked against cyber threats in the public and private sectors for more than 30 years. Amazon called c…HELPNETSECURITY.COM
10 SepProduct showcase: GitGuardian Honeytoken catches credential theft as it happensCredential harvesting on developer machines has widened. Earlier infostealers worked from a short list of known targets, mostly browser stores and a few cloud credential paths. The families active now cast a much wider net. Shai-Hulud, for instance, ran a secret scanner across th…HELPNETSECURITY.COM
10 SepCybercriminals are building phishing pages that exist only inside victims’ browsersA phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. “Instead of delivering a phishing page from a web server, the maliciou…HELPNETSECURITY.COM
10 SepISC Stormcast For Thursday, September 10th, 2026 https://isc.sans.edu/podcastdetail/10088, (Thu, Sep 10th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
10 SepTor VPN Beta brings isolated app-by-app Tor routing to AndroidThe Tor Project has expanded the availability of Tor VPN Beta for Android, a new privacy tool that routes traffic from mobile applications through the Tor network rather than limiting Tor protection to web browsing. The project says early testing has shown particularly strong dem…CYBERINSIDER.COM
10 SepRedtail Payload Analysis [Guest Diary], (Wed, Sep 9th)[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
ISC.SANS.EDU
10 SepFBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat ActorsThe new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actorsINFOSECURITY-MAGAZINE.COM
10 SepGovernments ‘buying time’ in race between innovation, security, national cyber director saysSean Cairncross also said AI has shown long-standing issues in cyber rather than creating new ones. The post Governments ‘buying time’ in race between innovation, security, national cyber director says appeared first on CyberScoop .CYBERSCOOP.COM
10 SepWebinar Today: Keep Pace With AI – A New Operating Model for Endpoint RemediationJoin the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT operations accelerate. The post Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation appeared …SECURITYWEEK.COM
10 SepPuzzleMask: Abusing Plain Prose as a Covert AI Attack VectorExecutive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard…RESEARCH.CHECKPOINT.COM
10 SepAnthropic Researcher Resigns With Warning About the Dangers of AI DevelopmentBoth Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns. The post Anthropic Researcher Resigns With Warning About the Dangers of AI Development appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepHacker Conversations: Vinnie Liu, Performer Turned RingmasterVinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox. The post Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepWhite House sees water cybersecurity partnership in Texas as national blueprintA top cybersecurity official said the government was taking a new approach to protecting critical infrastructure.CYBERSECURITYDIVE.COM
10 SepCybersecurity M&A Roundup: 33 Deals Announced in August 2026Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa. The post Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 appeared first on SecurityWeek .SECURITYWEEK.COM
10 SepYour passkeys can now move between password managers on AndroidGoogle turned on a transfer feature in Android that moves passwords and passkeys straight from one password manager to another, with no file to download along the way. You start it from inside the app you are switching to, and Google says the data moves between the apps in a few …HELPNETSECURITY.COM
10 SepDetect and disrupt AI-themed attacks with Microsoft DefenderSee how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog .MICROSOFT.COM
10 SepGroup of Bipartisan Lawmakers Ask US Government to Ban Several Hack-for-Hire FirmsU.S. lawmakers call for sanctions on hack-for-hire companies, citing Citizen Lab report. The post Group of Bipartisan Lawmakers Ask US Government to Ban Several Hack-for-Hire Firms appeared first on The Citizen Lab .CITIZENLAB.CA
🌐 CYBER THREAT LANDSCAPE 2[−]
10 SepWiz achieves GovRAMP High AuthorizationDelivering unified cloud security and accelerating secure modernization to protect citizen data and critical infrastructure.WIZ.IO
10 SepGigabud Creates Android Work Profiles to Hide From Banking App Malware ChecksThe Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typical…THEHACKERNEWS.COM
📡 INFOSEC NEWS 14[−]
10 SepAddressing the social media algorithms.This week, Dave and Ben look at how AI and social media are coming under greater regulatory scrutiny. For AI, conversations people are having with their chatbots are beginning to find their way into court cases while Australia looks to continue its crackdown on how social media p…THECYBERWIRE.COM
10 SepOFAC Sanctions Chinese Scam Platform Xinbi GuaranteeThe US Treasury has placed sanctions on notorious Chinese cybercrime marketplace Xinbi GuaranteeINFOSECURITY-MAGAZINE.COM
10 SepProofpoint Expands AI-Powered Investigations to Microsoft 365 and Deepens Insider Risk Visibility into AI ActivityPROOFPOINT.COM
10 SepCopyright scammers get Instagram accounts suspended and demand paymentScammers are filing fraudulent copyright complaints to suspend Instagram accounts, then demanding payment to withdraw them.MALWAREBYTES.COM
10 SepClearview AI Is Testing an AI Tool That Would Let Cops Unearth Your Life OnlineInquiryIQ, a previously unreported prototype, tested a model from xAI, maker of Grok, to surface associates, social accounts, and other information about people identified through Clearview.WIRED.COM
10 SepMicrosoft says September updates fix mouse settings reset issuesMicrosoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. [...]BLEEPINGCOMPUTER.COM
10 SepWill AI kill us all within the next decade?AI researchers are warning that the technology could kill us all within the next decade, although they say the risk from current models is low.MALWAREBYTES.COM
10 Sep‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury carsHere's a tip for any budding cybercriminals out there. If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub. Rea…BITDEFENDER.COM
10 SepGoogle Play Early Access Abused to Push Thousands of Deceptive Android AppsBad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the prog…THEHACKERNEWS.COM
10 SepThe Top 4 Threats We Found by Investigating Every Alert for a QuarterIdentity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. [...]BLEEPINGCOMPUTER.COM
10 SepMore Capable AI, Not Enough GuardrailsAI agents are gaining real-world access faster than safeguards can mature, making permissions, isolation and oversight critical to prevent harmful actions. Jacob Coxon, a researcher who spent three years working on model training at OpenAI and later Anthropic, left Anthropic this…SECURITYAFFAIRS.COM
10 SepThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More StoriesA lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A p…THEHACKERNEWS.COM
10 SepCyber Command turns to veteran of intelligence agencies for top AI roleRonzelle Green, most recently a senior official at the National Geospatial-Intelligence Agency, will be U.S. Cyber Command's chief AI officer.THERECORD.MEDIA