What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,931 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 6h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 10h ago
-
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appear…
-
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrac…
-
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three applia…
-
ServiceNow promotes Carol Bowman to leading channel role
ServiceNow has promoted its Australia and New Zealand (A/NZ) channel and alliances lead, Carol Bowman, to the position of senior director global partners and channel for the region. Having worked at ServiceNow since 2023, she come…
-
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
-
The Socrates Agent
A charcoal sketch of four slumped people being fed sheets of paper by a tall purple machine, while across the room one person writes at a wooden desk and a small purple Socrates leans in with open, empty hands/images/the-socrates-…
-
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
-
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity …
-
The US military just turned off ad tracking on its phones. Maybe you should too
Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours. Read more in my article on the Ho…
-
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds re…
-
The Numbers Behind CISO Burnout And Turnover
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 8, 2026 – Read the Report The 2026 CISO Report from Cybercrime Magazine in partnership with Sophos looks at how security Chiefs are faring…
-
A human approach to making cybersecurity stronger
One of my first cybersecurity roles focused on awareness and it taught me that cybersecurity is as much about behaviour, communication, and culture, as technology. Human judgement matters. For me, effective human cyber resilience …
-
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
-
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their p…
-
What It Took to Reach 1 Billion Build Manifests
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the head…
-
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in ac…
-
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager
We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload.
-
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2
Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it i…
-
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in M…
-
Testing race conditions with memory access tracing and stack-based delay injection
Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: Confirming bug candidates that have be…
-
AD Rights Management Service (Part 1): Architecture, Deprecation, and Reconnaissance
Active Directory Rights Management Services still ships in Windows Server 2025, years after Microsoft began steering customers to the cloud, and it remains fully supported on-premises. Part 1 maps the AD RMS trust model (the Serve…
-
Watch the Plot
Charcoal cutaway of a three-story building: a small purple glass lab on top where researchers admire a humanoid robot, and two much larger sienna floors below crowded with a family at a kitchen table, an old man in a sickbed, a ch…
-
The Good Person Bank
A charcoal sketch of a man whose head is an open purple ledger with a rubber stamp on it, dropping coins into a donation box held by a smiling person on his left while his other arm shoves a startled waiter away on his right/image…
-
Humans Aren't Aligned Either
Charcoal sketch of a man in a long coat holding a carpenter's level against an upright purple machine, while behind him a toppled column smokes and small figures huddle in the rubble/images/humans-arent-aligned-either-header.webp/…
-
Creepy crawlies
Creepy crawlies Konstantin Ryabitsev discusses how bad the "background radiation" of abusive crawlers has become from the perspective of git.kernel.org , the official Git repository for the Linux kernel: TL;DR: we spend more CPU c…
-
7th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a b…
-
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was …
-
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and…
-
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three…
-
Automobile Camouflage to Hide from Flock Cameras
Not sure it s practical, but it s certainly striking .
-
How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed. Read more in my article on the Hot for Security blog.
-
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfu…
-
2degrees steps in as Mercury winds down Now NZ
2degrees will be taking on business customers from Mercury Energy’s regional telco subsidiary Now New Zealand, as it prepares to shut up shop. Mercury announced in July it would close Now New Zealand later this year – less than fo…
-
Weekly Update 520: The Unscripted Edition
I ve started playing around with YouTube s create video thumbnail , which hopefully will give me back a bit of time in my day (it used to be a manual job in Photoshop) and be a bit more interesting. And on that note, the imagery i…
-
The purpose of DNS is to spread scams
The purpose of DNS is to spread scams Terence Eden shares some daunting statistics in support of his take that "the Domain Name System's purpose seems to be a vector for criminals to run scams on people at a terrifyingly high rate…
-
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack war…
-
There's No Limit to How Bad Code Can Get
My comment on There s No Limit to How Bad Code Can Get Lobste.rs. [In reply to a comment about burning it down to start from scratch when technical debt becomes overwhelming] In my experience it's so rare for that to work. You ann…
-
Quoting Zach Kehs
If you continue to add floors and rooms to a building forever, it will collapse. Software faces no such constraint. The code can always get worse. There can always be a new layer of indirection or a reduction in performance. Zach …
-
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switche…
-
Everyone Did Their Job. Nobody Did the Calculation.
My father is a Chartered Civil Engineer and a Fellow of the Royal Academy of Engineering. These days, he acts as an expert witness in litigation, which means he spends a good deal of his time examining how things went wrong and wh…
-
Friday Squid Blogging: Squid on a Stick at the New York State Fair
Looks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven t covered. Blog moderation policy.
-
Cliff's Notes for Everything
A sienna sketch of a man squatting under a giant open book he is lifting overhead, while a purple robot arm on a desk hands a striped summary sheet to a faint gray figure/images/cliffs-notes-for-everything.webp/images/cliffs-notes…
-
Breach of Confidence — 04 September 2026
I ve spent this week watching a scam artist successfully impersonate a friend on LinkedIn, complete with his job title and a slightly better headshot. It was reported four days ago. The account is still up. LinkedIn s verification…
-
Nvidia’s $12.9B Hugging Face deal could benefit enterprises
The chipmaker s acquisition could eventually bring additional security resources and model evaluation tools to the platform, according to experts.
-
Early Bird Registration For Black Hat Europe 2026 In London
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 4, 2026 Black Hat Europe returns to the Excel in London with a four-day program, Dec. 7-10. The event will open with two-and four-day opti…
-
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors
Overview A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor…
-
ICE Wants to Know Everyone Who Bought a Certain Green Beanie From REI in the Last 2 Years
Homeland Security Investigations agents hit the outdoor retailer with a controversial subpoena as part of a dragnet search for the identities of protesters who entered a Minnesota church in March.
-
Angry Birds: Toy Ghouls’ new toys
Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger.
-
Peak Human Readership
A lone writer in warm sienna works at a desk on top of a purple machine that crushes his pages into tiny slips for a crowd below staring at their phones, while one person in sienna stands apart reading a full page/images/peak-huma…
-
Lenovo A/NZ’s Pam Caldwell closes chapter with vendor
Lenovo Australia and New Zealand (A/NZ) head of sales operations Pam Caldwell has announced that she is “closing an incredible chapter” with the global technology vendor. In a post on LinkedIn, Caldwell wrote that “coming back to …
Last fetch just now · 0 new · 2 source error(s)