What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,932 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 6h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 2d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 10h ago
-
Lenovo A/NZ’s Pam Caldwell closes chapter with vendor
Lenovo Australia and New Zealand (A/NZ) head of sales operations Pam Caldwell has announced that she is “closing an incredible chapter” with the global technology vendor. In a post on LinkedIn, Caldwell wrote that “coming back to …
-
REANNZ appoints Jane McGale as first CTO and Dougal Macdiarmid as partnerships director
REANNZ has filled two newly created executive roles with appointments from the private sector as it seeks to boost access to its services and build a more scalable model for growth. The organisation, which operates the country’s n…
-
Lumify bolsters leadership team with new CEO, COOs
Corporate IT and process training organisation Lumify Group has shaken up its executive team with a new CEO in the form of Darren Cook as well as two chief operating officers (COO). Joining Cook’s appointment is Ayisha Tufail, who…
-
ConnectWise rebuilds trust to ready A/NZ partners for the future
ConnectWise has worked towards building trust after it was attacked by what it believed to be a nation state actor, with CEO Manny Rivelo noting transparency was vital after the fact. Last year, ConnectWise flagged that it noticed…
-
Managed EDR: What It Is & How to Choose a Provider
Huntress breaks down what managed EDR is, how it differs from unmanaged, and what to look for when choosing a provider for your business.
-
Large Enterprises Targeted in Fake Merger & Acquisition Scams
Threat actors behind the Phantom Deal campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
-
Confused about which VPN is right, US senator asks the NSA for guidance
Open source, commercial, single-hop, multi-hop, mixnet? The array of options is dizzying.
-
Court Rules Against Citizen Journalists in DMCA Takedown Case—EFF Will Appeal
A federal court in Massachusetts has ruled that copyright holders can issue online takedown notices based on a subjective belief of copyright infringement, even when that belief is unreasonable and self-serving. The case was broug…
-
The story behind the intelligence
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.
-
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.
-
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity
Huntress is tracking a pattern across multiple customer environments where rogue ScreenConnect clients repeatedly spawn the Windows Script Host to execute a series of four VBScript files.
-
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers m…
-
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers m…
-
Texas and Florida Step Back from ALPRs
Within the last few days, two important state actions have dealt a big blow to automated license plate reader (ALPR) networks. This is just the latest proof of the growing tide of public opposition to mass surveillance. After year…
-
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The Spring Ring operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
-
CMMC Hit Pause, the FAR Council Hit Play
CMMC Phase 2 is paused, but the FAR CUI proposed rule pushes NIST 800-171 obligations past the defense industrial base. Here's what changed, what didn't, and the 32 requirements you can't defer.
-
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls. Because local police on the largest of the Channel Islands have warned that over a single four-week period, an astonishing 75% of a…
-
Inside Knight Office, a New M365 AiTM Phishing Kit
An inside look at Knight Office, a newly discovered AiTM phishing kit featuring custom control panels, Cloudflare Turnstile, and M365 Token theft.
-
BGP hijack infecting networks caused by a comedy of errors that’s not funny at all
What can we learn from a BGP hijacking that poisoned production software? Plenty.
-
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon
Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Ear…
-
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR de…
-
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR de…
-
FBI Probes Service Selling 153M+ Drivers Licenses
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses ar…
-
Weekly Update 519: Breaches & Data Integrity
It does feel like I ve bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the normal NDC infosec talk, the cyber-broken talk with Scott in Copenhagen and then those ratbag hackers …
-
Meta's $17 Billion Settlement is a Bad Deal for Teens and All Social Media Users
Meta’s settlement with 52 state attorneys general is a bad deal for all internet users, and especially for teens. That’s what we said the day the settlement was announced. In this post, we go through the Settlement’s provisions in…
-
Cybersecurity IR Workshop: The workshop you shouldn’t miss
Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog .
-
Cybersecurity IR Workshop: The workshop you shouldn’t miss
Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog .
-
2026 Cyber Insurance Trends Report: What's Changed and What You Need to Know
New regulations, data exfiltration tactics, and shifting premiums are reshaping cyber insurance. Our 2026 report reveals what businesses need to know now.
-
Securing Your Business: The Vital Role of Cyber Insurance | Huntress
Understand the critical role of cyber insurance in safeguarding your business from cyber threats. Learn how this coverage can protect your assets.
-
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
-
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate …
-
Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks
A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Pa…
-
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help orga…
-
Hackers Frequently Target Healthcare and Finance Orgs
Healthcare organizations and banks handle highly personal information. But a new Huntress survey shows many threat actors frequently target these companies.
-
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
The Federal Ballot Mail Portal is described by a federal official as one of several IT systems that will be used to potentially deny thousands of mail-in ballots or more to states. The post Whistleblower says USPS deploying new, ‘…
-
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
-
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and App…
-
Recorded Future: The World’s Largest Pure-Play Threat Intelligence Company
This week in cybersecurity from the editors at Cybercrime Magazine Sausalito, Calif. – Sep. 1, 2026 – Watch the YouTube video When we were at Black Hat USA 2026 with Mastercard, Cybercrime Magazine met Levi Gundert, Chief Security…
-
Iranian cyber spies target aviation, fintech developers with new malware
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
-
Using High-Energy Laser, US Shoots Down Drones Near Mexico Border
The US Army’s laser system is part of a new generation of directed-energy weapons capable of detecting, tracking, and destroying drones with a concentrated beam of light.
-
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through open…
-
Five Venezuelans Plead Guilty in US Court to ATM Jackpotting
The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash. The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek .
-
Five Venezuelans plead guilty to ATM jackpotting attacks in US
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]
-
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
-
Bot detection arrives in CrowdSec 1.8.0, along with two DoS fixes
Failed SSH logins pile up in an auth log, and a scanner walks a website looking for exposed admin paths. CrowdSec reads log sources and HTTP requests, works out which addresses are misbehaving, and hands the block to a separate re…
-
What your vendor says about PQC tells you if they are ready
In this interview with Help Net Security, Dr. Yaakov Stein, VP CTO of Allot, discusses what post-quantum readiness looks like inside a mobile network. The discussion covers which operator traffic stays sensitive for years, includi…
-
Cybersecurity jobs available right now: September 1, 2026
Security Engineer, PSO Google USA On-site View job details As a Security Engineer, you will provide technical guidance to customers adopting Google Cloud Platform, helping them navigate their cloud journey with the Professional Se…
-
The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT
Exodus crypto wallet analysis by Huntress uncovered tampered installers hiding a modular RAT focused on stealing credentials, not coins.
-
RMM Tools for MSPs: Features, Risks & How to Stay Secure
Four years after the Kaseya supply chain attack, a recent incident shows how threat actors still successfully target MSPs’ downstream customers through RMM software.
-
Introducing wrapture
Introducing wrapture New from Graham Dumpleton (of wrapt , mod_wsgi, and New Relic's Python agent fame), who describes Wrapture as taking the monkeypatching ideas from wrapt and extending them to apply to testing and tracing at th…
Last fetch 6m ago · 0 new · 2 source error(s)