What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,938 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 8h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 12h ago
-
GitLab urges users to patch max severity path traversal flaw
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2023-2825. [...]
-
Check Point Patches Critical VPN Vulnerabilities
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek .
-
Cliff Stoll’s DEF CON Talk
In August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago. Great fun.
-
Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance
Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars. The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek .
-
AI agents exploited PaperCut flaws to breach 395 organizations
A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise. The result …
-
Surfshark Systems Targeted by Hackers
A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors. The post Surfshark Systems Targeted by Hackers appeared first on SecurityWeek .
-
Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]
-
The US and Mexico Announce They’re Teaming Up Against Drones
The new joint operation uses laser-based technology capable of detecting, tracking, and disabling commercial drones linked to human and drug trafficking.
-
Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion
Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model. The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion app…
-
IDScan confirms breach after 153 million driver’s licenses leak on dark web
Days after reports linked IDScan to a dark web database holding more than 153 million driver s license scans, the identity verification company has confirmed hackers accessed customer data stored on its cloud platform. The Louisia…
-
PaperCut Flaws Exploited in AI-Powered Attacks
A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide. The post PaperCut Flaws Exploited in AI-Powered Attacks appeared first on SecurityWeek .
-
Kiteworks expands runtime data governance with Bonfy.AI acquisition
Kiteworks has acquired Bonfy.AI, extending runtime data governance across its control plane. The acquisition enables organizations to govern data exchanges as they happen, whether initiated by a person, machine, or autonomous agen…
-
Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]
-
Automox Mitigation Worklets cut endpoint exposure to unpatchable flaws
Automox has announced its AI-speed Mitigation Worklet Pipeline, which automates mitigation to reduce risk from the increased volume and velocity of frontier-model AI vulnerabilities. Now the time from vulnerability disclosure to e…
-
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. …
-
China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in res…
-
Conti ransomware gang member sentenced to 4 years in prison
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
-
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software develo…
-
Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-20…
-
Getting a stranger’s phone kicked off the cellular network costs a few dollars
Researchers at Michigan State University and three partner schools bought a Samsung Galaxy Z Fold 7, copied the identification number printed on the sealed box, and reported the phone to its carrier as lost. Then they opened the b…
-
Recorded Future undergoing channel ‘recentering’ with A/NZ push
Cyber threat intelligence platform Recorded Future is looking to reinvigorate its approach to the channel, including in Australia and New Zealand, with plans to introduce a newly developed partner programme soon. Servicing around …
-
Okta appoints Sunil Kedaraji to head up APJ channel
Okta has hired Sunil Kedaraji as vice president of channel and strategic alliances for the Asia Pacific and Japan (APJ) region. Based in Singapore, Kedaraji’s focus will be Okta’s APJ partner business and will work closely with sa…
-
Building a ransomware decision tree before the call comes in
In this Help Net Security video, Kerri Shafer-Page, VP of Incident Response at Arctic Wolf, walks through the ransomware decision tree in this video. She covers four areas where decisions need settling in advance, starting with co…
-
Companies may be measuring phishing resilience the wrong way
Companies that judge phishing simulation programs by how often employees click simulated attack emails may be overlooking more important indicators of cyber resilience, according to Pistachio’s Phishing Behaviour Report 2026. Exam…
-
DyFlex Solutions Opens New Zealand Doors With New Auckland Office
DyFlex’s new Auckland office is less about an address than about permanence. It gives an established local team a home base, backed by a business that has grown to more than 300 people across Australia and New Zealand, with capabi…
-
AI is changing what Salesforce security needs to govern
Existing security and governance practices have largely focused on identities, permissions, access, configurations and controls. WithSecure’s Navigating Trust in the Modern Salesforce Ecosystem paper says Salesforce environments a…
-
Ubuntu 24.04.5 LTS release patches security bugs across ten flavors
Canonical shipped Ubuntu 24.04.5 LTS, bundling security updates and fixes for high-severity bugs into new installation media for the Noble Numbat release. Anyone installing fresh now gets those corrections baked in from the start,…
-
New infosec products of the week: September 11, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Akeyless, Orchid Security, Scytale, and Securin. Securin Platform helps security teams prove when attack paths are closed Securin has annou…
-
Datasette 1.0a39 and 0.65.4 security releases
Datasette 1.0a39 and 0.65.4 security releases Today we're releasing two new security patch versions of Datasette: 1.0a39 and 0.65.4 - one for the current alpha series and one for the stable 0.65.x family. These are security fixes …
-
datasette-publish-fly 1.4
Release: datasette-publish-fly 1.4 Sets force_https=true in fly.toml . #31 Fix for Volume could not be found bug. #32 Compatible with app-scoped deploy tokens. #34 Tags: datasette , fly
-
Indonesia Hit by Android Banking App-Cloning Campaign
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
-
github-to-sqlite 2.9.1
Release: github-to-sqlite 2.9.1 Fix for compatibility with sqlite-utils 4.x . #85 Tags: github , sqlite
-
datasette 0.65.4
Release: datasette 0.65.4 See Datasette 1.0a39 and 0.65.4 security releases on the Datasette blog. Tags: security , datasette
-
datasette 1.0a39
Release: datasette 1.0a39 See Datasette 1.0a39 and 0.65.4 security releases on the Datasette blog. Tags: security , datasette
-
CVE-2026-84869: ConnectWise ScreenConnect — ConnectWise ScreenConnect Improper Privilege Management and Missing Authorization Vulnerability
ConnectWise ScreenConnect contains both an improper privilege management and missing authorization vulnerability that may allow an attacker to file transfer and execution through an active remote sessions without authorization or …
-
CVE-2026-42016: JFrog Artifactory — JFrog Artifactory Incorrect Authorization Vulnerability
JFrog Artifactory contains an incorrect authorization vulnerability that allows leads to privilege escalation attack due to a validation check of the token signature/issuer and not the token’s scope.
-
CVE-2026-42018: JFrog Artifactory — JFrog Artifactory Improper Authentication Vulnerability
JFrog Artifactory contains an improper authentication vulnerability that could return an internal anonymous-user token to an unauthenticated caller when anonymous access is disabled, potentially exposing sensitive resources.
-
CVE-2026-85706: GitLab Community Edition and Enterprise Edition — GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability
GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the …
-
Any Nix package, live in your browser
Any Nix package, live in your browser Farid Zakaria calls this his " magnum opus of Nix work", and I can see why. trynix.dev provides a qemu-wasm powered x86_64 Linux virtual machine running entirely in your browser through WebAss…
-
Most NZ organisations using AI for cyber security still rely on manual responses
While New Zealand is ahead of countries like Australia when it comes to adopting AI for cyber security, there remains an alarming disconnect between adoption and outcomes. This is according to new research from AI search vendor El…
-
New Android malware encrypts files, steals data, and harasses victims
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]
-
Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023
As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers.
-
Native is now the future of mobile at Shopify
Native is now the future of mobile at Shopify Shopify are moving from React Native back to separate Swift and Kotlin codebases for their native apps, for the exact reason you would expect: We decided to switch from native to React…
-
Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data
Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
-
September Windows Server updates break Remote Desktop Services
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a har…
-
Conti ransomware crew member sentenced to four years in prison
Oleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies. The post Conti ransomware crew member sentenced to four years in prison appeared first on CyberScoop .
-
Mandiant Founder Kevin Mandia Joins Amazon Board
Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board. The post Mandiant Founder Kevin Mandia Joins Amazon Board appeared first on SecurityWeek .
-
Hawley probes OpenAI over Hugging Face breach
The Republican lawmaker called OpenAI’s leadership decisions “reckless,” and used recent warnings about the existential risk of AI to bolster his inquiry. The post Hawley probes OpenAI over Hugging Face breach appeared first on Cy…
-
AI lets small actors run state-level hacking campaigns, Anthropic report finds
The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations. The post AI lets …
-
Surfshark VPN says hackers breached internal testing, proxy servers
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. [...]
Last fetch 2m ago · 1 new · 2 source error(s)