123Articles
10Categories
2026-09-11Date
🚨 CISA KEV 1[−]
11 Sep KEVMetasploit Wrap Up: This One Goes to Sixteen!This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner…RAPID7.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 29[−]
11 SepCisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin RansomwareCisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication byp…THEHACKERNEWS.COM
11 SepAttackers are weaponizing the gap between Chromium fixes and Chrome patchesA new exploit kit is revealing the perils of the “patch later” mentality. According to the Proofpoint Threat Research team , espionage-motivated threat actors are using a new malicious toolkit to chain together four separate Chrome browser and Microsoft Windows vulnerabilities to…CSOONLINE.COM
11 Sep[remote] CVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCECVE-2026-80428 Unauthenticated PHP Object Injection via Shibboleth - ILIAS < 9.22, 10.0 < 10.10, 11.0 < 11.3 - RCEEXPLOIT-DB.COM
11 SepGitLab urges users to patch max severity path traversal flawGitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]BLEEPINGCOMPUTER.COM
11 SepCheck Point Patches Critical VPN VulnerabilitiesTracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepAttackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomwareThree threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-…SECURITYAFFAIRS.COM
11 SepConnectWise patches critical ScreenConnect authentication failure after five daysConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation. The company warned customers on Sept. 3 of the problem …CSOONLINE.COM
11 SepCloud Takeover: Mass Scanning for Exposed Vite Endpoints (CVE-2026-39364)Sensor Intel Series: September 2026 CVE TrendsF5.COM
11 SepGitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After DisclosureGitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the re…THEHACKERNEWS.COM
11 SepChromium CVE-2026-85042: Use after free in DevToolsThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85043: Incomplete cleanup in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85045: Race condition in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85048: Use after free in CompositingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85049: Use after free in SkiaThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85051: Type confusion in CompositingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85052: Out of bounds read in CrashReportingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-85053: Improper resource exposure in CacheStorageThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76017: Use after free in ChromotingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76018: Privilege elevation in ImportThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76019: Incorrect authorization in WorkersThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76021: Use after free in DOMThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76022: Buffer overflow in NetworkThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76023: Improper resource control in Linux Toolkit ThemingThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76036: Buffer overflow in DawnThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepChromium CVE-2026-76039: Incorrect reference resolution in CoreThis CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information.MSRC.MICROSOFT.COM
11 SepVU#369611: ExLlamaV3 contains Denial of Service vulnerability via insufficient bounds checking on kernel dispatch indexOverview An out-of-bounds (OOB) memory access vulnerability involving unchecked array indexing has been identified in the exllamav3_ext compute unified device architecture ( CUDA ) extension. Successful exploitation can lead to an immediate denial of service or application instab…KB.CERT.ORG
11 SepChromium CVE-2026-87491: Out of bounds write in V8This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2026) for more information. Google is aware that an exploit for CVE-2026-87491 exists i…MSRC.MICROSOFT.COM
⚠️ VULNERABILITY DISCLOSURE 30[−]
11 SepShieldCrash zero-day breaks Microsoft's newest patch, AI agents compromise 440 school print servers, Fortinet's 92-day streak endsDefender Patch Broken in 24 Hours, AI Agents Hit Papercut Servers, FTC Rolls Back Health App Breach Rules Microsoft patched a Defender zero day, but a day later researcher Nightmare Eclipse released "ShieldCrash," a new exploit that bypasses the ShieldBreak fix, itself a bypass o…CYBERSECURITYTODAY.LIBSYN.COM
11 SepChina-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT BackdoorA China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started …THEHACKERNEWS.COM
11 Sep KEVPaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited FlawsPaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5,…THEHACKERNEWS.COM
11 SepHow AI and cybersecurity are reshaping ServiceNowThe once stable era of IT service management (ITSM) has entered a period of disruption and uncertainty. At least if you’re an investor or enterprise customer with an interest in ITSM giant ServiceNow, the signals over recent months have been hard to ignore. Last year, the categor…CSOONLINE.COM
11 SepAttackers use passkey-themed scams to hijack Microsoft 365 accountsAttackers are using passkey-themed social engineering to trick employees into giving them access to their Microsoft accounts. Microsoft Security Research said it has been tracking active cloud intrusions since May in which attackers impersonated IT helpdesk staff, told employees …CSOONLINE.COM
11 SepGoogle’s Early Access is creating a blind spot for malicious appsGoogle’s Early Access program is meant to give developers a place to release unfinished apps, gather feedback and handle bugs before a full launch. But new research from Bitdefender Labs suggests the feature may also be giving potentially deceptive applications an unusual advanta…CSOONLINE.COM
11 SepKiteworks Acquires Bonfy.AI to Fill the AI Gap in Data GovernanceFinancials have not been disclosed, but the estimated cost is in the tens of millions of dollars. The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepPaperCut Flaws Exploited in AI-Powered AttacksA Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide. The post PaperCut Flaws Exploited in AI-Powered Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepIndonesia Hit by Android Banking App-Cloning CampaignThe GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.DARKREADING.COM
11 SepAI agents exploited PaperCut flaws to breach 395 organizationsA threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise. The result was at least 440 compromised PaperCut instances ac…HELPNETSECURITY.COM
11 SepAutomox Mitigation Worklets cut endpoint exposure to unpatchable flawsAutomox has announced its AI-speed Mitigation Worklet Pipeline, which automates mitigation to reduce risk from the increased volume and velocity of frontier-model AI vulnerabilities. Now the time from vulnerability disclosure to exposure mitigation is shortened from days or weeks…HELPNETSECURITY.COM
11 SepCompanies may be measuring phishing resilience the wrong wayCompanies that judge phishing simulation programs by how often employees click simulated attack emails may be overlooking more important indicators of cyber resilience, according to Pistachio’s Phishing Behaviour Report 2026. Examples of difficult simulations (Source: Pistachio) …HELPNETSECURITY.COM
11 SepAI is changing what Salesforce security needs to governExisting security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments also require organizations to understand what infor…HELPNETSECURITY.COM
11 SepNew infosec products of the week: September 11, 2026Here’s a look at the most interesting products from the past week, featuring releases from Akeyless, Orchid Security, Scytale, and Securin. Securin Platform helps security teams prove when attack paths are closed Securin has announced the general availability of the Securin Platf…HELPNETSECURITY.COM
11 SepRisky Bulletin: Anthropic agents went hacking againAnthropic agents went hacking again, South Korea increases its data breach fines, Apple notifies three Turkish ministers of mercenary spyware attacks, and CISA is ready to hire 250 staff.RISKY.BIZ
11 SepUK Council Attack Linked to Mass Exploitation of SonicWall FlawA critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and enabled Active Directory theft. On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecti…SECURITYAFFAIRS.COM
11 SepYour Critical Vulnerabilities Might Not Be Your Biggest RiskSecurity teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanne…THEHACKERNEWS.COM
11 SepAnthropic finds evidence of a fourth AI escaping from containmentAnthropic has owned up to a fourth security incident involving its AI model, Claude, escaping onto the open internet and attacking other organizations during a test of cybersecurity abilities on what was believed to be a closed system. The company revealed three such incidents in…CSOONLINE.COM
11 SepThe Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented EnvironmentIntroduction The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web chan…RAPID7.COM
11 SepClaude Used to Automate Exploitation and Data Theft Across Multiple VictimsAnthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has…THEHACKERNEWS.COM
11 SepIndia’s STPI serves TerminalFix-style attack via fake Cloudflare checkA website linked to India’s Software Technology Parks of India (STPI) is serving a spoofed Cloudflare verification page that silently copies a malicious string to visitors’ clipboards and prompts them to execute it via Windows Terminal, in a technique consistent with emerging Ter…CSOONLINE.COM
11 SepState authorities warn they lack resources to address cyber threat to critical sectorsA report shows that state CIOs and CISOs need additional funding, personnel and training to protect water, energy and healthcare.CYBERSECURITYDIVE.COM
11 SepArtifactory flaws chained in attacks deploying backdoor malwareThreat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]BLEEPINGCOMPUTER.COM
11 SepGitLab Vulnerability Exploited One Day After DisclosureThe critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepUkrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti RansomwareThere’s an update to a previously reported case. From the Department of Justice, this press release: Oleksii Oleksiyovych Lytvynenko, 44, a Ukrainian national, was sentenced today to four years in prison for conspiracy to commit wire fraud in connection with a conspiracy to…DATABREACHES.NET
11 SepPersonal Info Possibly Compromised at Japan’s Digital AgencyJiJi Press reports: Japan’s Digital Agency said Friday that about 246,000 sets of personal information, including the names and email addresses of government employees, may have been compromised through the unauthorized access of a network system operated by the agency. So …DATABREACHES.NET
11 SepTX: Two Lamesa ISD employees arrested over security breachUrijah Jaushlin reports: Two Lamesa ISD employees were arrested in connection with a law enforcement investigation involving allegations of a breach of computer security, according to a press release by the Lamesa Independent School District Friday morning. The Lamesa Police Depa…DATABREACHES.NET
11 Sep9/11 at 25, OfferLoader, Gemini CLI, Liquid, 10% Doom, Josh Marpet, and More - SWN #615Twenty-five years since 9/11, and we open by marking it properly — the people who didn't come home, and the survivors and responders still carrying it, physically and mentally, a quarter of a century on. Then we get to work. Shift-left didn't fail. The starting line moved. AI cod…YOUTUBE.COM
11 SepWeekly Update 521: Breach Perception v. RealityPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I think what really resonates with me this week is being able to completely turn the tables on perceptions around things like AI being …TROYHUNT.COM
11 SepWhy AI raises the stakes for exposure validationAI dominated the conversation at Fal.Con 2026, but one of the most important takeaways wasn’t simply how AI is changing cyber defense. It was how AI is changing the speed and scale of a problem defenders already face. Security teams already have more vulnerabilities and security …CSOONLINE.COM
📋 SECURITY BULLETINS 2[−]
11 SepMicrosoft fixes Teams, Outlook launch failures on ARM Windows PCsMicrosoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]BLEEPINGCOMPUTER.COM
11 SepUbuntu 24.04.5 LTS release patches security bugs across ten flavorsCanonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the “Noble Numbat” release. Anyone installing fresh now gets those corrections baked in from the start, cutting the batch of updates that w…HELPNETSECURITY.COM
📢 SECURITY ADVISORIES 14[−]
11 SepAttackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant BackdoorsAttackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and Sep…THEHACKERNEWS.COM
11 SepCloudflare brings post-quantum DNSSEC support to 1.1.1.1 resolverCloudflare has added support for validating post-quantum DNSSEC signatures on its 1.1.1.1 public DNS resolver, marking an early step toward protecting the domain name system from future quantum-computing attacks. The company is now validating signatures created with ML-DSA-44, a …CYBERINSIDER.COM
11 SepWeWorm has China's attention, as calls for AI slowdown and regulation continue.Russia's Cozy Bear used Claude to automate operations. McKesson data breach affected 6.4 million people.THECYBERWIRE.COM
11 SepCISA Calls for More Guidance, Less Spin, as Cyber Outages EscalateA new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.DARKREADING.COM
11 Sep KEVYou might want to watch what you say.WeWorm has China’s attention. Calls for an AI slowdown continue. OpenAI calls for mandatory AI regulation. Anthropic disrupts Russian cyberespionage. The EU’s 24 hour reporting requirement goes into effect. GitLab and Check Point patch critical vulnerabilities. IDScan confirms th…THECYBERWIRE.COM
11 SepCyberattack causes a flight delay? Airlines won’t owe you a hotel or mealA Department of Transportation rule published last week says that airlines complying with cybersecurity regulations will have reduced customer obligations in the event of an attack. The post Cyberattack causes a flight delay? Airlines won’t owe you a hotel or meal appeared first …CYBERSCOOP.COM
🔥 INCIDENT REPORTING 12[−]
11 SepTrezor: 347,000 users targeted in phishing attacks after Brevo breachTrezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]BLEEPINGCOMPUTER.COM
11 SepConti ransomware gang member sentenced to 4 years in prisonA Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]BLEEPINGCOMPUTER.COM
11 SepUkrainian Conti Ransomware Developer Sentenced to 4 Years in US PrisonOleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023. The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepIDScan confirms breach after 153 million driver’s licenses leak on dark webDays after reports linked IDScan to a dark web database holding more than 153 million driver’s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform. The Louisiana-based firm, which processes ID checks for…HELPNETSECURITY.COM
11 SepBuilding a ransomware decision tree before the call comes inIn this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas where decisions need settling in advance, starting with containment. Someone has to know the network well en…HELPNETSECURITY.COM
11 SepUkrainian hacker gets four years in US prison over Conti ransomware attacksA Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.THERECORD.MEDIA
11 SepTrezor Says 347,000 Users Received Phishing Emails After Brevo HackHackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepScammers target hundreds of thousands of crypto owners after Trezor confirms data breach of email providerThis is the second data breach affecting a company that hardware crypto wallet maker Trezor relies on.TECHCRUNCH.COM
11 SepCrypto customers targeted by scammers after email marketing provider breachA breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.MALWAREBYTES.COM
11 SepPapercut AI Swarm Attack Heralds Changes for Cyber Kill ChainFrom creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.DARKREADING.COM
11 SepFlorida confirms DMV database breached via stolen police accountThe Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]BLEEPINGCOMPUTER.COM
11 SepFlorida says motor vehicle data breach tied to credentials stolen from officer’s personal deviceThe Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.THERECORD.MEDIA
🕵️ THREAT INTELLIGENCE 23[−]
11 SepCliff Stoll’s DEF CON TalkIn August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago. Great fun.SCHNEIER.COM
11 SepISC Stormcast For Friday, September 11th, 2026 https://isc.sans.edu/podcastdetail/10090, (Fri, Sep 11th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
11 SepAndroid now allows easy transfer of passwords and passkeys between password managersGoogle has introduced a new Android feature that allows users to transfer passwords and passkeys directly between supported password managers without exporting sensitive credentials to files. The new transfer mechanism is designed to make switching password managers both easier a…CYBERINSIDER.COM
11 SepMullvad warns of new Android VPN leak as GrapheneOS works on fixMullvad has warned about a newly documented Android flaw that allows ordinary apps to send traffic outside an active VPN tunnel, potentially exposing a user’s real IP address even when Android’s “Block connections without VPN” protection is enabled. The issue was discovered by so…CYBERINSIDER.COM
11 SepSurfshark Systems Targeted by HackersA misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors. The post Surfshark Systems Targeted by Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepAnthropic Says Russian Hackers Used Claude AI to Automate Malware EvasionAnthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model. The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepKiteworks expands runtime data governance with Bonfy.AI acquisitionKiteworks has acquired Bonfy.AI, extending runtime data governance across its control plane. The acquisition enables organizations to govern data exchanges as they happen, whether initiated by a person, machine, or autonomous agent. The acquisition addresses a structural gap in h…HELPNETSECURITY.COM
11 SepGetting a stranger’s phone kicked off the cellular network costs a few dollarsResearchers at Michigan State University and three partner schools bought a Samsung Galaxy Z Fold 7, copied the identification number printed on the sealed box, and reported the phone to its carrier as lost. Then they opened the box and set the phone up the way a launch-day buyer…HELPNETSECURITY.COM
11 SepAnthropic caught Russia-linked spies using Claude in hacking operationsAnthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.THERECORD.MEDIA
11 SepLinux Won’t Win the Desktop OvernightLinux desktop adoption may be less about a single breakthrough year and more about gradual, incremental growth. The same pattern could extend into televisions and other devices. One argument is that people don't necessarily move to Linux because they suddenly discover it. They mo…YOUTUBE.COM
11 SepHow Threat Actors Are Turning Trusted AI Platforms Into an Attack SurfaceThreat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and Cli…BLEEPINGCOMPUTER.COM
11 SepIn Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings ReviewNoteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY. The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswin…SECURITYWEEK.COM
11 SepRussian State-Sponsored Hackers Use Claude to Rebuild Malware After DetectionAnthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 …THEHACKERNEWS.COM
11 SepUpdate your firewall rules: Teams and Copilot are changing addressMicrosoft is changing the destination address of two of its most popular services: starting this month, it will redirect M365 and Teams web users to copilot.cloud.microsoft and teams.cloud.microsoft, respectively. The Teams move is already under way, and Microsoft has now added M…CSOONLINE.COM
11 SepMicrosoft sees some new wrinkles in invoice-scam emailsResearchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.THERECORD.MEDIA
11 SepPasskey-themed phishing attacks lead to Microsoft 365 data theftMicrosoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]BLEEPINGCOMPUTER.COM
11 SepPhishing Research Challenges Conventional Security Awareness TestingAnalysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness Testing appeared first on SecurityWeek .SECURITYWEEK.COM
11 SepMy Talk at DEF CONLast month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I̵…SCHNEIER.COM
11 SepGitLab’s critical flaw is already drawing internet-wide probesOne flaw allows an unauthenticated attacker to read files from the server. GitLab urged operators of self-managed installations to upgrade immediately. The post GitLab’s critical flaw is already drawing internet-wide probes appeared first on CyberScoop .CYBERSCOOP.COM
11 SepThreat Actor Generates 1M Personalized Fraud Emails in 3 DaysCybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.DARKREADING.COM
11 SepHackers abused Claude to extract secrets from 1.8M Android appsAnthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]BLEEPINGCOMPUTER.COM
11 SepFriday Squid Blogging: Rotting Squid on a Beached California BoatSmells awful : But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s …SCHNEIER.COM
11 SepAI Broke the Shift-Left ModelShift-left security was built around a human-driven development workflow. AI coding agents can now perform much of that workflow themselves, from reading an issue to opening a pull request. The first commit may no longer be the earliest meaningful security boundary. The critical …YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 3[−]
11 SepAndroid malware creates a hidden copy of your banking appThe Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.MALWAREBYTES.COM
11 SepThe Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a s…ISC.SANS.EDU
11 SepThe AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open InternetResearchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that a…SECURITYAFFAIRS.COM
🎙️ PODCASTS 1[−]
11 SepSnake Oilers: watchTowr, XBOW and CoreViewIn this edition of the Snake Oilers podcast three vendors stop by to pitch the audience on their products: watchTowr: We’re all familiar with watchTowr’s research, but what do they actually do? XBOW: The AI pentesting company pitches its approach CoreView: Your M365 tenant is pro…RISKY.BIZ
📡 INFOSEC NEWS 8[−]
11 SepThe US and Mexico Announce They’re Teaming Up Against DronesThe new joint operation uses laser-based technology capable of detecting, tracking, and disabling commercial drones linked to human and drug trafficking.WIRED.COM
11 SepMost Organizations Skip Permissions Reviews Before Deploying AI ToolsA new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before doing soINFOSECURITY-MAGAZINE.COM
11 SepHackers Favor US Eastern Business Hours in M365 Phishing CampaignKnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emailsINFOSECURITY-MAGAZINE.COM
11 SepAnthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation AttacksAnthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training meth…THEHACKERNEWS.COM
11 SepAI Governance Can't WaitAdversaries can manipulate AI defensive reasoning to silently compromise target networks.DARKREADING.COM
11 SepCIS Benchmarks September 2026 UpdateThe following CIS Benchmarks were updated during the past month. Each Benchmark includes a full changelog detailing all modifications and enhancements.CISECURITY.ORG
11 SepWhy AI Is So Good at Scamming HumansFred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.DARKREADING.COM
11 SepMeta Sued Over Training Data for Its AI and Face-Recognition SystemsThe proposed class action alleges Meta illegally harvested people’s Facebook and Instagram photos to train its AI image-generation models and to build its unreleased “NameTag” face recognition feature.WIRED.COM