What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 3,026 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Cisco alerts customers to second actively exploited zero-day in as many days — CyberScoop, 1d ago
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 2d ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 3d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 3d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 3d ago
-
CVE-2015-3246: Red Hat Libuser — Red Hat Libuser Race Condition Vulnerability
Red Hat libuser contains a race condition vulnerability that allows authenticated local users to corrupt the /etc/passwd file to cause a denial of service or privilege escalation.
-
CVE-2015-5287: Red Hat Automatic Bug Reporting Tool — Red Hat Automatic Bug Reporting Tool Privilege Escalation Vulnerability
Red Hat Automatic Bug Reporting Tool (ABRT) contains a privilege escalation vulnerability that could allow local users with certain permissions to gain privileges via a symlink attack on a file with a predictable name. The impacte…
-
CVE-2022-0995: Linux Kernel — Linux Kernel Out-of-Bounds Write Vulnerability
Linux Kernel contains an out-of-bounds memory write vulnerability which could allow a local user to gain privileged access or cause a denial of service on the system.
-
CVE-2026-8452: Citrix NetScaler ADC and NetScaler Gateway — Citrix NetScaler ADC and NetScaler Gateway Improper Restriction of Operations within the Bounds of a Memory Buffer Vulnerability
Citrix NetScaler ADC and NetScaler Gateway contain an improper restriction of operations within the bounds of a memory buffer vulnerability which could lead to denial of service.
-
CVE-2019-1068: Microsoft SQL Server — Microsoft SQL Server Remote Code Execution Vulnerability
Microsoft SQL Server contains a remote code execution vulnerability that could allow an attacker to execute code in the context of the SQL Server Database Engine service account.
-
EVE Online: The Move to Python 3 Begins!
EVE Online: The Move to Python 3 Begins! EVE Online has been one of the most interesting case studies in Python at scale for over twenty years now. They've been running on Stackless Python since their launch in 2003, and their las…
-
LACMA data breach last year exposed social security and medical data
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]
-
A Cautionary Tale About Data Breach Claims, Verification and Carhartt
You re not going to believe this, but turns out you can t always take criminals at their word. Actually, I ll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here: Cyber
-
Hackers abuse npm mirrors to host phishing redirect pages
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]
-
Carhartt: 12,933,413 accounts breached
Data exposed: Email addresses, Names, Phone numbers, Physical addresses. In August 2026, clothing retailer Carhartt was the target of a ShinyHunters "pay or leak" extortion campaign . The group subsequently published data allegedl…
-
Hidden Prompts Trick AI Into False Email Summaries
With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.
-
The GTA VI leaks are breaking the internet. Security researchers have seen this before.
A memecoin, a manifesto, and a week of daily leaks — but to researchers, it's a familiar extortion playbook with an unusually large audience. The post The GTA VI leaks are breaking the internet. Security researchers have seen this…
-
Perplexity’s on-device AI offering promises data control and lower token costs
Perplexity on Tuesday rolled out an offering that runs the AI entirely on a local machine, and that, it said, will keep “private data local and escalating to the cloud only when a task needs it.” The service, called simply Portabl…
-
58 arrested in international cybercrime crackdown
Interpol officials said it uncovered a crime-as-a-service network in Argentina run by 196 people that provided website domains and money laundering support to West African organized crime groups like Black Axe.
-
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
-
Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw
Attackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.
-
Employee benefits platform Paylogix says hackers stole financial and health data
The benefits management firm Paylogix told regulators that hackers stole sensitive information on tens of thousands of people from its systems.
-
Arrested man allegedly impersonated NSA elite hacking unit, Supreme Court chief justice
Joshua Culver, aka “Maverick Young,” is accused of imitating the head of the NSA’s Tailored Access Operations unit during a time it wasn’t called that. The post Arrested man allegedly impersonated NSA elite hacking unit, Supreme C…
-
U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching …
-
Water sector passes, government sector fails attempts to spot and halt simulated CISA attack
Agency red-teamers got initial access to both organizations they tested, but one quickly isolated and shut down the attempts from going further. The post Water sector passes, government sector fails attempts to spot and halt simul…
-
Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation
TRACE was developed by AMD, Intel, Microsoft, OPAQUE, and TII and contributed to the Linux Foundation. The post Linux Foundation to Govern TRACE, an Open Standard for AI Runtime Attestation appeared first on SecurityWeek .
-
The patch window is collapsing: Why security needs a new control plane
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog .
-
Massive DDoS attack disrupts Norway’s government digital services
A large distributed denial-of-service (DDoS) attack has disrupted Norway's shared government digital infrastructure since Monday, affecting services used by the public sector. [...]
-
Researchers warn about chained SharePoint sequence
An authentication bypass flaw is already under exploitation, the latest in a series of recent SharePoint attacks.
-
In today's episode of Breach Please, me and @ Secitup talk about how agents reportedly settled disputes in Ant…
In today's episode of Breach Please, me and @ Secitup talk about how agents reportedly settled disputes in Anthropic's testing. TL;DR: none of the outcomes we saw seemed particularly conducive to security and we're pretty sure we'…
-
The Path to the Autonomous SOC: The Early Returns of AI & What It Means for Cybersecurity
Discover how early-stage AI yields rapid SOC returns, driving platform consolidation and reducing analyst burnout in this blog post.
-
CISA orders agencies to fix exploited Zimbra vulnerability
The collaboration software s developer took almost a full month to patch the flaw after disclosing it.
-
Is Cyber Facing an Affordability Crisis?
As breach costs reach record highs and defense spending nears $240 billion, small businesses are dangerously exposed, threatening supply chain security.
-
Hospital operator Nutex Health says data stolen in cyberattack
Healthcare and services provider Nutex is investigating a data breach incident where an unauthorized third party exfiltrated information from company servers. [...]
-
Interpol targets Black Axe’s illicit financial web in latest international sting
The multi-country sting targeted Black Axe financial networks, seizing millions in assets and uncovering Crime-as-a-Service infrastructure across four continents. The post Interpol targets Black Axe’s illicit financial web in late…
-
Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails
The company, previously known as ActiveFence, has raised a total of $280 million from investors. The post Alice Raises $140M to Expand AI Model Defenses and Enterprise Guardrails appeared first on SecurityWeek .
-
A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model …
-
From Fake Workers to Account Recovery: The Growing Identity Verification Risk
Attackers are increasingly targeting the processes used to establish or recover identity rather than attacking the login itself. Specops explains how stronger identity verification can help organizations prevent fake workers and s…
-
INTERPOL crackdown on West African crime rings uncovers troubling new trend
Police across 22 countries arrested 58 people and identified 263 suspects during an eight-month INTERPOL operation targeting West African organized crime groups. Suspects detained in an operation targeting West African crime group…
-
Ukraine to give Britain access to battlefield data to train AI
Ukraine will give Britain access to a vast trove of battlefield data collected during the war with Russia, allowing U.K. companies and researchers to use it to train and test artificial intelligence systems.
-
Microsoft PowerToys adds Alt+Tab-style switching for an app's windows
Microsoft updated its Windows PowerToys toolset with a new utility dubbed "Window Hopper" that lets users switch between an app's windows more quickly. [...]
-
WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities
CVE-2026-61979 and CVE-2026-15981 are authentication bypass vulnerabilities affecting the MiniOrange SAML 2.0 SSO plugin. The post WordPress Websites Targeted via MiniOrange Plugin Vulnerabilities appeared first on SecurityWeek .
-
WhatsApp Adds Multiple Passkeys for Phishing-Resistant Sign-Ins Across iOS and Android
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resista…
-
Citrix UniconOS dual boot turns Windows endpoints into their own recovery device
Citrix announced Citrix UniconOS dual boot, a new endpoint resiliency capability designed to help organizations recover access to work in minutes — without spare hardware, central reimaging or prolonged business downtime. Availabl…
-
Fideo Lens reveals connections across identities, accounts and devices
Fideo Intelligence introduced Fideo Lens, an investigative intelligence platform that helps fraud and financial crime teams discover hidden relationships among identities, accounts, devices and behaviors. Starting with a single id…
-
The Security Poverty Line: Fireside Chat At Black Hat USA 2026
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Aug. 25, 2026 – Watch the Video In 2011, when Wendy Nather was at 451 Research, she coined the term Security Poverty Line, the line below which…
-
WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update
When Android users get a call from a non-contact, they will see more information about the caller, including their country. The post WhatsApp Adds Multiple Passkeys and Stronger 2SV in Account Security Update appeared first on Sec…
-
WhatsApp adds stronger two-step verification, multiple passkeys
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]
-
What Good Identity Hardening Looks Like
MFA is just the starting line. Learn what mature identity hardening actually looks like, from closing MFA exceptions to catching drift before attackers do.
-
Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference
Hands-on Cyber Attack Methods course returns to SecurityWeek’s ICS Cybersecurity Conference, October 6–8 at the W Nashville. The post Hands-On Cyber-Physical Systems Training Returns to ICS Cybersecurity Conference appeared first …
-
UK government seeks powers to secretly block risky tech suppliers
The British government is seeking new powers to ban certain technology vendors from supplying companies working in the country’s critical sectors — potentially doing so in secret.
-
Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CV…
-
Fake OpenAI Codex download tricks macOS users into installing malware
A malware campaign using a sponsored search ad and a fake OpenAI Codex download page to trick macOS users into pasting a malicious command into Terminal has been uncovered by Cato Networks. It s a variation of ClickFix, a popular …
-
Hackers breached over 270 Zimbra servers in ongoing attacks
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]
-
Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authenti…
Last fetch 2m ago · 0 new · 2 source error(s)