What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,922 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 3h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 1d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 7h ago
-
Treasury’s Scott Bessent says no liability exemptions for AI labs
The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.” The post Treasury’s Scott Bessent says no liability e…
-
The true cost of a ransomware attack, with and without BCDR
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downt…
-
Flock camera use by internal affairs unit puts DC police at odds with officers’ union
Washington, D.C.'s police department has used information from Flock cameras for misconduct investigations, prompting a formal complaint from its officers' union.
-
AIUC Raises $40 Million to Certify Enterprise AI Agents
The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared first on Securit…
-
Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assis…
-
Blake Benthall aka “Defcon”, Former Operator of Silk Road 2.0, Tells His Story
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 16, 2026 – Listen to the Podcast Silk Road 2.0 was a dark web marketplace launched in Nov. 2013, approximately five weeks after the FBI sh…
-
Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine as a norm…
-
EU chief wants joint response to cyberattacks, sabotage
Delivering her annual State of the Union address in Strasbourg, Ursula von der Leyen said threats were “mounting on our soil,” pointing to recent incidents in Denmark, Lithuania and Poland and an attempted drone attack in Leipzig.
-
Pixel Modem Zero-Day Exploited in Targeted Attacks
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek .
-
Ukraine moves to crack down on scam call centers after corruption scandal
Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect s…
-
Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)
A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed ParaShells, can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The dang…
-
Microsoft says Copilot buttons still missing in classic Outlook
Microsoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. [...]
-
Webinar: What happens in the first hours of a Google Workspace breach
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters wo…
-
US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C C. The post US, UK, Dutch Agencies Expose Iranian Chosen Brick Surveillance Malware appeared first o…
-
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid account…
-
Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek .
-
Self-improving AI should slow down, von der Leyen tells EU lawmakers
European Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can support their own efforts to do that. In her State o…
-
Fake CAPTCHA Scams
New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.
-
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellu…
-
Threat Intelligence Alone Won't Close the Exploitation Gap
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combini…
-
Critical ScreenConnect flaw now actively exploited in attacks
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
-
Hackuity Raises $19 Million for AI-Powered Vulnerability Management
The company will use the new capital to expand its vulnerability operations platform and support international growth. The post Hackuity Raises $19 Million for AI-Powered Vulnerability Management appeared first on SecurityWeek .
-
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is descri…
-
Cohesity adds recovery capabilities for AI agents and the data they manage
Cohesity has introduced Cohesity Agent Resilience. This new Cohesity Data Cloud capability will discover, protect, and recover the infrastructure behind enterprise AI agents. A unified view of an agent and the state it depends on.…
-
280,000 Impacted by Premier Medical Group Data Breach
In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information. The post 280,000 Impacted by Premier Medical Group Data Breach appeared first on SecurityWe…
-
Rubrik MCP gives AI agents controlled access to security intelligence
Rubrik has announced Rubrik MCP (Model Context Protocol), giving an organization’s AI agents a secure, programmable path to Rubrik’s data, identity, and application intelligence. Support for MCP expands Rubrik AI, which is now tru…
-
CenterPoint Energy confirms data breach following claims on hacking forum
CenterPoint Energy disclosed that an unauthorized third party got into customer data through one of its external systems, after online claims by a hacker that millions of records had been stolen from the company. CenterPoint Energ…
-
Hackers Got Inside a Flock Camera. Its Data Shows How the System Really Works
A hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images of 50,000 vehicles in 21 days.
-
Chrome, Firefox Updates Patch 115 Vulnerabilities
Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox. The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek .
-
Nozomi Compass helps industrial teams manage OT assets and vulnerabilities
Nozomi Networks announced Nozomi Compass, an OT asset and service management platform designed to help organizations manage industrial assets, vulnerabilities, and exposures. The platform brings asset data, remediation workflows, …
-
Citrix adds AI-powered browser activity analysis to SecurAccess
Citrix has announced Citrix Session Insights, a new AI-powered capability for Citrix SecurAccess with Chrome Enterprise that helps organizations capture, analyze and understand browser activity from users and autonomous agents. By…
-
Securing the unpatchable in an age of AI-driven vulnerabilities
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/I…
-
NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
-
Atomic macOS (AMOS) Stealer Activity
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42 .
-
Karavshin: off-the-charts contemplativeness after the rainy gloom.
What a joy it was to wake up to rays of bright sun after a rainy, foggy day of lousy weather on the Karavshin trek in Kyrgyzstan! The weather, clearly, had seen the error of its ways and decided to make amends. Bless. Bliss! Break…
-
Acronis Patches Exploited Vulnerability in cPanel Backup Plugin
CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation. The post Acronis Patches Exploited Vulnerability in cPanel Backup Plugin appeared first on SecurityWeek .
-
One runaway AI agent racked up a $50,000 cloud bill
Organizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud environments. At the same time, attacks are expanding from direct prompts to i…
-
Acronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)
A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by attackers, the backup and recovery company warns. Exploitation of …
-
Windows Server 2022 reaches end of mainstream support next month
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. [...]
-
Iranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalists
Iranian state cyber actors are deploying malware called CHOSEN BRICK against individuals they see as a threat to the regime, reaching victims through social messaging apps and infecting their Windows devices, three Western intelli…
-
Enterprises Warned of Attacks Exploiting WSO2 Vulnerability
The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability appeared first on SecurityWeek .
-
Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws. The post Oracle Patches 800+ Vulnerabilities in September 2026 Security Update appeared first on Securit…
-
NIST and CISA finalize playbook to stop token theft and forgery
NIST and CISA have finalized guidelines to help federal agencies and cloud service providers (CSPs) protect identity and access tokens from forgery, theft, and misuse. The guidance, Protecting Tokens and Assertions from Forgery, T…
-
Google fixes actively exploited Android zero-day on Pixel devices
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]
-
Design it right. Deliver it fast. Win with Lenovo TCE
Design It Right. Deliver It Fast: How Ingram Micro NZ and Lenovo TCE Win Business In today’s technology market, customers want solutions that are built around their specific business requirements, but they also want those solution…
-
What happens when AI agent governance is missing at scale
In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what an agent does,…
-
Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to…
-
DeepZero: Open-source hunting for vulnerable Windows drivers
DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a langua…
-
Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verificat…
-
The modern attack chain: Rethinking Google Workspace security in the age of AI
Over the past two months, I ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same observation: these aren t isola…
Last fetch just now · 11 new · 2 source error(s)