What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,947 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1h ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 11h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
-
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed t…
-
Patch Tuesday - September 2026
Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilit…
-
Patch Tuesday Sets Another Record With 974 CVEs
Attackers are actively exploiting two of the vulnerabilities, and another 58 are more likely to be exploited, according to Microsoft.
-
Why this month's Microsoft patch release is a doozy
Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks.
-
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
-
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
Researchers and OpenAI disagree on whether an earlier incident involving DseWiki, which the company did not disclose, was a “hack.
-
Muse, Meta’s New Personal AI Agent, Needs You to Trust It
Designed to compete with OpenClaw and Instinct, the company says Muse can do everything from sell your car to book you a plane ticket.
-
New Records Reveal Problems with Medicare’s AI Prior Authorization Experiment
EFF sued the government back in March for information about the Wasteful and Inappropriate Service Reduction (WISeR) model , a new Medicare program that uses AI to evaluate prior authorization requests for certain medical services…
-
The Socrates Agent
A charcoal sketch of four slumped people being fed sheets of paper by a tall purple machine, while across the room one person writes at a wooden desk and a small purple Socrates leans in with open, empty hands/images/the-socrates-…
-
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
-
AIs as Modern Genies
This essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the…
-
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity …
-
N-able issues patch for zero-day flaw
Security researchers warned the company of unusual threat activity in a recently patched N-able environment.
-
The US military just turned off ad tracking on its phones. Maybe you should too
Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours. Read more in my article on the Ho…
-
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds re…
-
ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's p…
-
Don’t let AI distract from cybersecurity basics, officials and executives warn
Government and industry leaders said simple attacks remain far more consequential than anything AI is doing.
-
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale cr…
-
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT
Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and a…
-
The Numbers Behind CISO Burnout And Turnover
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 8, 2026 – Read the Report The 2026 CISO Report from Cybercrime Magazine in partnership with Sophos looks at how security Chiefs are faring…
-
A human approach to making cybersecurity stronger
One of my first cybersecurity roles focused on awareness and it taught me that cybersecurity is as much about behaviour, communication, and culture, as technology. Human judgement matters. For me, effective human cyber resilience …
-
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
-
Meta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real Kids
Images of real children—including a member of a European royal family—were used to create some of the 350 ads containing child sexual abuse. Lawmakers say they plan to investigate.
-
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their p…
-
What It Took to Reach 1 Billion Build Manifests
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the head…
-
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in ac…
-
CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)
Overview While conducting research into a recent N-able N-central authentication bypass vulnerability ( CVE-2026-18577 ), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained toget…
-
Stealing AI Reasoning Traces
Interesting research: Stealing Reasoning Traces from Proprietary LLM APIs : Abstract: Leading large language model providers now conceal their models step-by-step reasoning, or chain-of-thought, to protect intellectual property an…
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.
-
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it i…
-
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (C…
-
Essential AI agent security questions
AI agents are outpacing legacy IAM. Discover the 3 questions every CISO must ask to secure them.
-
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in M…
-
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is th…
-
Testing race conditions with memory access tracing and stack-based delay injection
Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: Confirming bug candidates that have be…
-
AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance
Active Directory Rights Management Services still ships in Windows Server 2025, years after Microsoft began steering customers to the cloud, and it remains fully supported on-premises. Part 1 maps the AD RMS trust model (the Serve…
-
Watch the Plot
Charcoal cutaway of a three-story building: a small purple glass lab on top where researchers admire a humanoid robot, and two much larger sienna floors below crowded with a family at a kitchen table, an old man in a sickbed, a ch…
-
Dell’s $95B AI backlog shows the infrastructure crunch is far from over
Dell Technologies is acknowledging that infrastructure and storage supply still can’t keep up with agentic AI’s insatiable appetite for resources. The company this week reported a “record” AI backlog, with $95 billion in orders wa…
-
HPE’s record Q3: AI infrastructure, networking demands drive growth, but supply constraints tap the brakes
Demand for AI, networking, and servers drove HPE to a record quarter, the company reported during its third-quarter earnings call with financial analysts. “AI has become a multi-year growth driver, expanding demand across our HPE …
-
The Good Person Bank
A charcoal sketch of a man whose head is an open purple ledger with a rubber stamp on it, dropping coins into a donation box held by a smiling person on his left while his other arm shoves a startled waiter away on his right/image…
-
Humans Aren't Aligned Either
Charcoal sketch of a man in a long coat holding a carpenter's level against an upright purple machine, while behind him a toppled column smokes and small figures huddle in the rubble/images/humans-arent-aligned-either-header.webp/…
-
CVE-2026-75650: Adobe Commerce and Magento — Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability
Adobe Commerce and Magento Open Source contain an improper neutralization of special elements used in a template engine vulnerability that could allow an attacker to execute arbitrary code.
-
CVE-2026-81963: Microsoft Windows — Microsoft Windows Link Following Vulnerability
Microsoft Windows Update Stack contains a link following vulnerability that allows a local attacker to escalate privileges locally up to SYSTEM.
-
CVE-2026-86218: N-able N-central — N-able N-central Static Code Injection Vulnerability
N-able N-central contains a static code injection vulnerability that could allow for pre-authentication remote code execution.
-
CVE-2026-85880: Microsoft Windows — Microsoft Windows Heap-Based Buffer Overflow Vulnerability
Microsoft Windows Advanced Local Procedure Call contains a heap-based buffer overflow vulnerability that allows an attacker to elevate privileges locally.
-
llm 0.35
Release: llm 0.35 New OpenAI model: gpt-6-astra for GPT-6 Astra . Tags: openai , llm , gpt-6-astra
-
Creepy crawlies
Creepy crawlies Konstantin Ryabitsev discusses how bad the "background radiation" of abusive crawlers has become from the perspective of git.kernel.org , the official Git repository for the Linux kernel: TL;DR: we spend more CPU c…
-
Lack of dedicated AI leadership roles holding back transformation: Datacom
A leadership vacuum threatens New Zealand’s AI transformation, with only of 4 per cent of local business leaders saying AI has transformed their core operations – down from 8 per cent in 2025. This is according to research from Da…
-
Quoting Jakub Pachocki
The strongest argument I see for continuing to train much smarter models quickly is the need to build defensive systems against the dangers posed by other AI. [...] We will need powerful, aligned AI for defense; to secure infrastr…
-
Video compressor
Tool: Video compressor I recorded a short demo video of my Equal Earth animation on my phone and wanted to publish an optimized version of that video (using FFMPEG) on my blog, so I had Claude Fable 5.1 in Claude Code for web buil…
Last fetch 12m ago · 1 new · 2 source error(s)