🚨 CISA KEV 1[−]
12 Sep KEVCISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.…THEHACKERNEWS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 1[−]
12 SepDutch NCSC: Critical Check Point VPN flaws exploitation is imminentThe Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]BLEEPINGCOMPUTER.COM
⚠️ VULNERABILITY DISCLOSURE 8[−]
12 SepOpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc ServersThe "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply ch…THEHACKERNEWS.COM
12 SepBlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-DaysMultiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek .SECURITYWEEK.COM
12 SepTelegram Desktop bug lets poisoned messages steal exported chat historiesA vulnerability in Telegram Desktop could allow specially crafted bot messages to execute JavaScript inside HTML chat exports, potentially exposing the messages and metadata contained in those files. The flaw was fixed in July, roughly two months before its public disclosure, but…CYBERINSIDER.COM
12 SepRevolut confirms customer data breach through fake government requestsRevolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators.TECHCRUNCH.COM
12 SepAnthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and WeaponsAI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks. Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becomin…SECURITYAFFAIRS.COM
12 SepRevolut Exposed KYC Data After Fraudulent Government Email Passed Security ChecksRevolut handed over KYC documents, selfies, and Bitcoin transaction histories after a fake government email with valid domain credentials passed its checks. Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after rec…SECURITYAFFAIRS.COM
12 SepNot just Korea: Google leaked identifying info for sex crime victims across the worldShin Da-eun and Park Kang-su report: Korea was not the only country where victims who sent Google removal requests about illegally obtained sexual images ended up having their private information posted online, the Hankyoreh has confirmed. “Photos of me from when I was a minor we…DATABREACHES.NET
12 SepNYS DFS Issues New Cybersecurity Guidance on Risk Assessments for Financial Services EntitiesNew York State Department of Financial Services (DFS): September 10, 2026 New York State Department of Financial Services (DFS) Acting Superintendent Kaitlin Asrow today issued new cybersecurity guidance outlining the Department’s expectations for DFS-regulated entities’ on condu…DATABREACHES.NET
📋 SECURITY BULLETINS 1[−]
12 SepThreat actors move toward multi-agent AI frameworks as calls for regulation continue.Microsoft sets another Patch Tuesday record. FBI releases its first public cyber strategy.THECYBERWIRE.COM
🔥 INCIDENT REPORTING 2[−]
12 SepA beast by any other name.Today we are joined by Brigid O Gorman, Senior Intelligence Analyst on Symantec Threat Hunter team, discussing their work on “GodDamn Ransomware: Latest Beast Rebrand Uses Malicious Driver to Disable Defenses." GodDamn ransomware, the latest rebrand from the Hyadina group beh…THECYBERWIRE.COM
12 SepFrom Hacks to Bioweapons, Claude Misuse Is Now EverywherePlus: The US disrupts the internet’s biggest black market, a Conti ransomware hacker gets prison time, Meta fails to stop AI-generated videos of child abuse.WIRED.COM
🕵️ THREAT INTELLIGENCE 3[−]
12 SepResearchers say OpenAI agents were behind May hacking campaign targeting RubyGemsOpenAI confirmed their agents were behind a campaign in May that researchers say flooded the popular online code repository with malicious software packages. The post Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems appeared first on CyberScoop .CYBERSCOOP.COM
12 SepUsers in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic SaysAnthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket. The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek .SECURITYWEEK.COM
12 SepThird-Party Access Needs Hard LimitsThird-party credentials introduce another layer of access that organizations need to control. That means limiting scope, privileges, and what those credentials can reach. Vendor risk management doesn't stop at knowing which third parties you use. Organizations also need fundament…YOUTUBE.COM
📡 INFOSEC NEWS 1[−]
12 SepWhen the Whole Company Adopts AI: What It Does to Your SOCOver the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organizatio…THEHACKERNEWS.COM