What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,943 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 10h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 14h ago
-
You Can Now Destroy Flock Cameras for Cash in GTA V
A new GTA mod lets you smash and shoot Flock’s automatic license plate readers around the fictional Los Santos.
-
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
-
Driver’s License Data for Sale
A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail .
-
2026 EFF Award Winners: Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights
EFF is pleased to announce that Access Now, 7amleh – The Arab Center for the Advancement of Social Media, DeFlock, and New Media Rights have received 2026 EFF Awards for their vital work in ensuring that technology supports freedo…
-
CISOs are feeling the security burden of accelerated AI use
A report shows CISOs face increased pressures related to cyber resilience and business continuity.
-
Karavshin trekking: the beginning (and a satellite call for donkey-deliveries).
Hi folks! Ok, you ve had a couple of intro posts already; now let s get this started properly: the Karavshin trek – one of the most beautiful routes I ve ever walked with my own two feet – our first day First up: where is it? In t…
-
Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it
If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them. Every scan begins with the same question: which ports on this host are open? Everything after it, fro…
-
FBI cyber chief worries private sector not sharing enough cyber threat information
Brett Leatherman said that industry has the wrong idea about what the FBI does with the data it collects during incidents, which is used to help victims and investigations alike. The post FBI cyber chief worries private sector not…
-
New FBI cyber strategy promises increase in adversary disruptions
The document also focuses on helping victims, reflecting the bureau s goal of encouraging more companies to share information with it.
-
Identity-Based AI Attack Threatens Security of Enterprise Data
Workflow identity hijacking can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.
-
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information s…
-
AI researcher getting increasingly angry at their AI solving math problems: No, I want you to STROKE me.
AI researcher getting increasingly angry at their AI solving math problems: No, I want you to STROKE me.
-
Grand Theft Auto VI hype leads to malware
Threat actors are exploiting GTA6 hype with fake leaked downloads spread via SEO poisoning, packed with RATs, infostealers, and wiper ransomware. Here’s what Huntress found.
-
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy. The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basi…
-
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence
See how a browser-in-the-browser phishing attack led to rogue ScreenConnect persistence and evasion tactics Huntress caught in the act.
-
Ransomware Is The New Normal: Cybersecurity Considerations for Fiduciaries
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 9, 2026 – Read the Full Story from J.S. Held Court-appointed receivers, chief restructuring officers, distressed asset investors, and lend…
-
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud …
-
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an opera…
-
Claude Fable Solves a Historical Cipher
Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It s good at things that involve lots of searching and testing.
-
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self…
-
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appear…
-
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through…
-
Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score…
-
CRPx0 ransomware: what you need to know
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.
-
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrac…
-
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three applia…
-
Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (C…
-
Debtfix and Digital Future Aotearoa receive US$75k in GTIA grants
Two New Zealand charities have received US$75,000 in grants from the Global Technology Industry Association (GTIA) in its latest round of charitable giving. Auckland-based Debtfix Foundation received US$50,000 in a GTIA member-ref…
-
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability…
-
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 f…
-
N-able N-central Pre-Auth RCE Flaw Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executi…
-
Cisco bundles fixes for multiple vulnerabilities, some critical, into one patch
Cisco is looking to get ahead of attackers with a new set of more than a half-dozen fixes, some of them critical, for its IOS XR Linux-based network operating system (OS). As part of its regular testing, Cisco’s software engineeri…
-
Looking back at 40 years of Advantage
Advantage celebrates its 40th anniversary this year. In that time, it has evolved from a PC manufacturer based in Palmerston North to a fully-fledged managed services provider with a team of 70, as well as support for customers in…
-
ServiceNow promotes Carol Bowman to leading channel role
ServiceNow has promoted its Australia and New Zealand (A/NZ) channel and alliances lead, Carol Bowman, to the position of senior director global partners and channel for the region. Having worked at ServiceNow since 2023, she come…
-
Atturra focuses on packaging a decade of integration expertise for the AI era
Atturra is looking to turn a decade of Boomi integration experience into its next growth engine by embedding years of delivery knowledge, governance frameworks and intellectual property into AI-powered tools designed to accelerate…
-
Evergreen doubles down on A/NZ MSP market, eyes AI-led future as acquisitions accelerate
Evergreen is ramping up its Australian and New Zealand expansion plans, with the US-based holding company expecting to add several more MSPs to its portfolio before the end of the year while positioning AI advisory services as the…
-
Quoting Terence Tao
I wrote recently about how the collection of good, fruitful open problems is now being mined in a non-renewable fashion, leading to the potential scenario of these problems becoming scarce. [...] We have now seen that even the rum…
-
CVE-2026-19490: Citrix NetScaler — Citrix NetScaler Authentication Bypass Using an Alternate Path or Channel Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an authentication-bypass vulnerability involving an alternate path or channel. When the NetScaler appliance is configured as an AAA virtual server or as a Gateway (SSL VPN, ICA Pr…
-
CVE-2025-25249: Fortinet Multiple Products — Fortinet Multiple Products Heap-based Buffer Overflow Vulnerability
Fortinet FortiOS, FortiSwitchManager, and FortiSASE contain a heap-based buffer overflow vulnerability that allows an attacker to execute unauthorized code or commands via specially crafted packets.
-
CVE-2026-87491: Google Chromium V8 — Google Chromium V8 Out of Bounds Write Vulnerability
Google Chromium V8 contains an out of bounds write vulnerability that allows a remote attacker to execute arbitrary code inside the sandbox via a crafted HTML page. This vulnerability could affect multiple web browsers that utiliz…
-
CVE-2026-20079: Cisco Secure Firewall Management Center (FMC) and Security Cloud Control (SCC) Firewall Management — Cisco Firewall Management Center Authentication Bypass Using an Alternate Path or Channel Vulnerability
Cisco Secure Firewall Management Center (FMC) Software and Cisco Security Cloud Control (SCC) Firewall Management contain an authentication Bypass using an alternate path or channel vulnerability that could allow an unauthenticate…
-
On the Navier–Stokes Millennium Prize Problem
On the Navier–Stokes Millennium Prize Problem Impressive result from OpenAI, who used an unreleased model to produce a resolution to the Navier–Stokes existence and smoothness problem , one of the seven Millennium Prize Problems t…
-
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
While the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk and exposure. The post Microsoft discloses two actively exploi…
-
Introducing ChatGPT Images 2.5
Introducing ChatGPT Images 2.5 OpenAI's image generation models are apparently used "more than 3 billion images across ChatGPT Images and the GPT‑Image models in the API". This latest release improves their instruction-following a…
-
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical."
-
Survival of the Basics: Which Security Fundamentals Were Secretly Relying on Lazy Attackers?
A few weeks ago I asked on X and LinkedIn a deceptively simple question: which “security basics” matter more against AI-armed attackers, and which ones don’t matter anymore? What Gemini think of this blog [before you freak out abo…
-
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed t…
-
Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilit…
-
Patch Tuesday Sets Another Record With 974 CVEs
Attackers are actively exploiting two of the vulnerabilities, and another 58 are more likely to be exploited, according to Microsoft.
-
Why this month's Microsoft patch release is a doozy
Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks.
Last fetch 18m ago · 1 new · 2 source error(s)