What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,922 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 3h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 1d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 7h ago
-
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
-
[Virtual Event] Building a Secure AI Strategy for the Enterprise
-
Authorities seize popular, long-running DDoS-for-hire service domains
Cybercriminals used NightmareStresser to launch hundreds of thousands of DDoS attacks since at least 2022. Threat actors behind the operation claimed links to Russia. The post Authorities seize popular, long-running DDoS-for-hire …
-
Congress eyes new support for Cyber Command after recent suicide deaths
Congressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contributions to high-profile missions …
-
AI Hackers Are Dumb And They Can Wreak Havoc
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 17, 2026 – Watch the Video It s never been tougher for a practitioner to secure their environment, Snehal Antani, CEO at Horizon3, told Cy…
-
Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS sai…
-
Windows 11 24H2 Home and Pro reach end of support in October
Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]
-
A fake ChatGPT billing email is after your OpenAI password
A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense s Phishing Defense Center traced the email s payment button through a Go…
-
The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as "The Odyssey," and uses the Solana blockchain to hide its C2 infrastructure.
-
Download: The IT leader’s guide to AI code sprawl
AI hasn t just made building faster, it s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI tools, often without knowing they ve created something that needs governing a…
-
Comp AI Raises $34 Million for AI-Native Compliance and Security
The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek …
-
CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys
Cyber deception has long been the domain of well-resourced security teams, but CISA s latest guidance, titled Using Cyber Decoys to Strengthen Detection and Response , is an attempt to try and change that. Why decoys, and why now …
-
ISC Patches 14 Vulnerabilities in BIND 9 Security Update
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek .
-
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerab…
-
Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Ch…
-
Druva expands identity resilience with ransomware detection
Druva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral …
-
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution. The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek .
-
Israeli contractor BlackCore trained Angolan officials in online influence operations
An Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media personas and media outlets, researchers found.
-
In today's episode of Breach Please, I sit down with Ariful Huq from @ exaforceai and Patrick McKinney from Tu…
In today's episode of Breach Please, I sit down with Ariful Huq from @ exaforceai and Patrick McKinney from Turing and talk about the AI-powered SOC. Patrick has been an Exaforce customer for years and brings real-world experience…
-
Google’s new agent security system detects tool misuse, loops and rogue behavior
Google’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and built with the Agent Development Kit (ADK) for Python 1.2 …
-
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between dis…
-
FBI takes down one of the longest-running DDoS-for-hire services
The FBI has seized the domains behind NightmareStresser, a DDoS-for-hire service officials call one of the longest running booter operations in existence. The domain seizure notice (Source: US Department of Justice) Booter service…
-
US takes down NightmareStresser DDoS-for-hire platform
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. [...]
-
How Candidates Could Use AI for Good
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI s impacts …
-
CISO's Expert Guide to Agentic Pentesting for Websites
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closin…
-
Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE)…
-
Scammers leave AI fingerprints all over fake antivirus renewal page
AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page impersonating Avast, aimed at users in Belgium, that wa…
-
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2…
-
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital …
-
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
Ports, railroads, and utilities keep the military operational. They're all vulnerable to Iranian cyberattacks. The post America s cyber strategy overlooks the infrastructure that actually keeps the military moving appeared first o…
-
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misa…
-
Hackers reveal how Flock cameras really track cars and people
One hacked camera captured 1.6 million images and could detect people as well as cars.
-
Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...]
-
Flock Once Touted Its Cameras as ‘Made in the USA.’ Now It’s Not So Clear
Flock reveals little about where its license plate readers are assembled, but the answer could have geopolitical and cybersecurity implications.
-
The Karavshin roller coaster: a kilometer up, a kilometer down.
Our rambling along the Karavshin route in Kyrgyzstan continues… Next up for us was a three-day out-and-back leg toward some seriously contemplative views in the gorge that goes by the same name – Karavshin – plus the Asan-Usen gla…
-
Spain reports first data breach involving autonomous AI agent
Spain s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a company s network, found a way to alter personal records, and pulled in…
-
Microsoft shares workaround for Windows domain login issues
Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]
-
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answe…
-
Fake AI trading agent steals crypto wallet passwords
Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign…
-
CISA Releases Guidance on Deploying Cyber Decoys
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Guidance on Deploying Cyber Decoys appeared first on SecurityWeek .
-
AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared f…
-
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed a…
-
Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
-
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthent…
-
Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek .
-
Riverbed NPM 360 uses AI to predict and prevent network disruptions
Riverbed has announced new Riverbed intelligent network observability solutions that combine 360-degree network visibility with agentic AI to help network operations teams accelerate troubleshooting, identify root causes, predict …
-
Tuskira Vector brings autonomous red teaming to attack surface validation
Tuskira has announced Vector, its autonomous red teaming agentic capability, which identifies an organization s exploitable attack surface by simulating what an attacker can do from outside it. Tuskira validates every external fin…
-
The AI security question leaders should be asking instead
In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and wh…
-
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains in question…
-
A flat cybersecurity budget doesn’t have to mean weaker coverage
Cheri Hotman, Managing Partner of Hotman Group, works as a vCISO and vGRC leader. In this Help Net Security video, she talks about holding coverage steady when the CFO asks for a flat budget or a 12% cut. Her advice is to stop tri…
Last fetch 2m ago · 11 new · 2 source error(s)