What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,022 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 1d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 2d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 3d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 3d ago
-
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed …
-
WatchGuard Patches Critical Vulnerabilities
Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely. The post WatchGuard Patches Critical Vulnerabilities appeared first on SecurityWeek .
-
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligen…
-
Recently patched PaperCut zero-days used in data theft attacks
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]
-
Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper …
-
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
-
LastPass enhancements improve visibility, governance, and control
LastPass announced a series of strategic product innovations, customer experience enhancements, and industry milestones. These advancements reflect the company’s continued focus on providing practical tools to protect access and i…
-
Askeal, the AI cybersecurity assistant that gives verifiable, expert-backed answers
Askeal takes the opposite approach to omniscient Gen AI: rather than pretending to know everything, it combines AI with community expertise. Vetted vendors, researchers, and practitioners contribute their intelligence and tools to…
-
PaperCut Exploitation Escalates to Active Intrusions
CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek .
-
Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes
Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which addresses are misbehaving, and hands the block to a separate re…
-
NIS2 compliance: Fixing IAM and access control before the 2026 audit
The NIS2 Directive places direct obligations on organizations across supply chain risk management, incident reporting, and board-level accountability. October brings a new wave of legally binding deadlines across the EU, as member…
-
Questel: 1,226,209 accounts breached
Data exposed: Email addresses, Employers, Job titles, Names, Phone numbers, Physical addresses, Support tickets. In August 2026, the French intellectual property software and services company Questel was the target of a ShinyHunte…
-
What your vendor says about PQC tells you if they are ready
In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, includi…
-
Cybersecurity jobs available right now: September 1, 2026
Security Engineer, PSO Google USA On-site View job details As a Security Engineer, you will provide technical guidance to customers adopting Google Cloud Platform, helping them navigate their cloud journey with the Professional Se…
-
The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT
Exodus crypto wallet analysis by Huntress uncovered tampered installers hiding a modular RAT focused on stealing credentials, not coins.
-
RMM Tools for MSPs: Features, Risks & How to Stay Secure
Four years after the Kaseya supply chain attack, a recent incident shows how threat actors still successfully target MSPs’ downstream customers through RMM software.
-
Introducing wrapture
Introducing wrapture New from Graham Dumpleton (of wrapt , mod_wsgi, and New Relic's Python agent fame), who describes Wrapture as taking the monkeypatching ideas from wrapt and extending them to apply to testing and tracing at th…
-
EFF to Governor Newsom: Veto California’s AB 1709
The California legislature passed Assembly Bill 1709 (A.B. 1709) today, which functions as a sweeping ban on social media use for young people under the age of 16. This well-intentioned, but deeply flawed piece of legislation, cut…
-
AoFrio hires for APAC SaaS growth
NZX-listed smart refrigeration tech company AoFrio has appointed Peg Tsai to the role of commercial and customer success manager to help drive customer growth across the Asia Pacific (APAC) and East Asia region Based in Auckland, …
-
Quoting Andrew Digby
325 #kakapo! The chicks from this year's record breeding season are now juveniles and so have been added to the population. In 1995 there were just 51 kākāpō left. Recovery of critically endangered species is possible with sustain…
-
McKesson copes with fallout from data theft extortion attack
The major healthcare sector vendor did not identify the attackers, but ShinyHunters, a prolific group increasingly targeting the sector, claimed responsibility. The post McKesson copes with fallout from data theft extortion attack…
-
Anthropic Users Hit by Infostealer Attacks, Session Thefts
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
-
Daisy-Chaining Trust: Investigating Faronics Deploy Abuse
Bad actors are abusing Faronics Deploy in phishing campaigns to run PowerShell, deploy ScreenConnect, and evade detection by using trusted tools.
-
Cronos blockchain restarts after $74 million Tectonic exploit
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]
-
Five plead guilty in latest federal ATM jackpotting case
Federal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.
-
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
-
The Guardrails Debate: Security Researcher Changes His Mind
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.
-
EFF to Courts: Don’t Rewrite Copyright Over AI Hype
The history of technology is rife with copyright panics. In the 1980s, major rightsholders ran to Congress and the courts, claiming that videotape recorders (VTR) were “to the American film producer and the American public as the …
-
Fraudsters steal $6 million from Tectonic crypto platform after inflating token price
At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.
-
Doxxing Safety Part II: Incident Response
Doxxing, also known as the deliberate sharing of personal information to harass or endanger someone, is a tricky thing to protect against. It often happens by some ill-intentioned person accessing publicly available information, t…
-
Doxxing Safety Pt I: Prevention and Footprint Management
Doxxing is the deliberate disclosure of personal information in order to bully, harass, intimidate, or instigate a chain of harms against someone. It's a tricky thing to protect against when the jerk doing it is often able to use …
-
Microsoft warns of TerminalFix attacks deploying reverse tunnels
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
-
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
The six-month program will be overseen by the Office of the National Cyber Director and Texas Cyber Command to “find out what works.” The post ‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity h…
-
Is Someone Hacking DoD Refrigerators?
It sure seems like it. The stores confirmed to be affected include Fort Irwin , Calif.; F.E. Warren Air Force Base , Wyo.; Fort Huachuca , Ariz.; Naval Station Newport , R.I.; Columbus Air Force Base , Miss.; and Travis Air Force …
-
In today's Breach Please, me and @ Secitup talk about the (probable) ransomware attack on Boston Scientific an…
In today's Breach Please, me and @ Secitup talk about the (probable) ransomware attack on Boston Scientific and then discuss ransomware response more generally. Lots of learnings and lots of hot takes from people who've lived thro…
-
AI Model Rules Are Not Security Controls
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
-
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying susp…
-
RingCentral expands into NZ channel with Digital Island
Cloud communications and IT service provider Digital Island has secured a strategic partnership with RingCentral to introduce the vendor’s agentic voice AI offerings to New Zealand businesses. The collaboration will see Digital Is…
-
Microsoft Exchange Online outage causes email failures, auth issues
Microsoft is investigating a widespread service issue causing authentication issues and email delays and failures for Exchange Online customers. [...]
-
OpenAI confirms ChatGPT outage as users report errors
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...]
-
Privacy on the Map (Part 2): Progress, Pitfalls, and the Fight for Enforceable Location Data Protections
Regulating commercial location tracking has reached a turning point. Last year, we published our rubric for what comprehensive and protective location privacy laws should look like, outlining the baseline standards states should m…
-
Who’s the fairest, most Patagonian, and most contemplative of them all?
It s time to move on to fuller accounts of our July-August adventures in Kyrgyzstan and the Sayan Mountains, and I figure that their telling should go in chronological order: first, the Karavshin trek in the Pamir Mountains, and t…
-
Think twice before installing this device promising free movies
In exchange for free stuff, devices make home connections part of a proxy network.
-
Onyxia Expands Cross-Industry Benchmarks To Five Sectors
Starting today, industry benchmarks in Onyxia’s Operational Resilience Platform cover five sectors: IT & Tech, Financial Services, Healthcare, Critical Infrastructure, and Retail & eCommerce – expanded from IT and Finance.
-
LGBT Q&A: What’s One Thing I Can Do Today to Improve My Safety and Security Online as an LGBTQ+ Person?
This post is adapted from a video recorded by EFF and the Trevor Project. Head over to our TikTok or Instagram to watch! EFF answers all the queer digital rights questions you submit to us through our LGBT Q A . You asked us: What…
-
PaperCut issues emergency patches as threat actors target chained vulnerabilities
The print management software maker faced a wave of attacks in 2023 aimed at higher education customers.
-
State-linked actor targets Cisco routers for espionage
An actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth.
-
Chinese Fire Ant hackers turn Cisco routers into spying platforms
The researchers discovered Fire Ant's new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. [...]
-
Berlin says it won’t pay ransom after hackers steal government data
Governing Mayor Kai Wegner said on Friday that Berlin had received an extortion demand following the cyberattack, which was discovered in mid-August.
-
Threat actors are posing as AI crawlers to hunt for exposed credentials
Attackers are disguising automated scanning as traffic from AI crawlers operated by OpenAI, Anthropic, Google, Perplexity and other companies while searching websites for exposed credentials and configuration files, according to G…
Last fetch 7m ago · 0 new · 2 source error(s)