[{"author":null,"category":"ai","fetched_at":"2026-08-28T23:22:36+00:00","guid":"darkreading:380057f0504a39b0b1f450925c15494e87f74b49","id":3244,"is_nz":0,"published_at":"2026-11-12T16:00:00+00:00","score":8,"source_handle":null,"source_name":"Dark Reading","source_slug":"darkreading","summary":"","title":"[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI","url":"https://www.darkreading.com/events/virtual-event-what-every-enterprise-know-securing-cloud-2026"},{"author":null,"category":"ai","fetched_at":"2026-08-28T23:22:36+00:00","guid":"darkreading:fa357236e138c97c511e12b7ebf73925e1295122","id":3245,"is_nz":0,"published_at":"2026-10-08T15:00:00+00:00","score":8,"source_handle":null,"source_name":"Dark Reading","source_slug":"darkreading","summary":"","title":"[Virtual Event] Building a Secure AI Strategy for the Enterprise","url":"https://www.darkreading.com/events/virtual-event-building-secure-ai-strategy-enterprise-2026"},{"author":"Ionut Arghire","category":"vuln","fetched_at":"2026-09-17T12:52:23+00:00","guid":"securityweek:1efbc18bca82ff44e4add06a45f2c6f864362ba5","id":4135,"is_nz":0,"published_at":"2026-09-17T12:39:28+00:00","score":8,"source_handle":"@ryanaraine","source_name":"SecurityWeek","source_slug":"securityweek","summary":"Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek .","title":"ISC Patches 14 Vulnerabilities in BIND 9 Security Update","url":"https://www.securityweek.com/isc-patches-14-vulnerabilities-in-bind-9-security-update/"},{"author":"Kevin Townsend","category":"ransomware","fetched_at":"2026-09-17T12:30:25+00:00","guid":"securityweek:82af785eedcf8a1db40683b5e84f9ca4c5a4b82b","id":4133,"is_nz":0,"published_at":"2026-09-17T12:29:53+00:00","score":25,"source_handle":"@ryanaraine","source_name":"SecurityWeek","source_slug":"securityweek","summary":"Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek .","title":"Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows","url":"https://www.securityweek.com/ransomware-attacks-on-manufacturers-surge-as-supply-chain-risk-grows/"},{"author":"Industry News","category":"ransomware","fetched_at":"2026-09-17T12:52:25+00:00","guid":"helpnetsecurity:b361d1fc9c2fcef6d4455eedf137c334d7374c57","id":4136,"is_nz":0,"published_at":"2026-09-17T12:29:26+00:00","score":10,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"Druva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspicious behavior into actionable evidence, definitively confirm impact, and accelerate precise containment and clean recovery. AI is making it harder for security teams to distinguish real compromise from normal behaviors and activity. Attackers are using More The post Druva expands identity resilience with ransomware de","title":"Druva expands identity resilience with ransomware detection","url":"https://www.helpnetsecurity.com/2026/09/17/druva-identity-resilience-ransomware-detection/"},{"author":"Ionut Arghire","category":"vuln","fetched_at":"2026-09-17T12:30:25+00:00","guid":"securityweek:dafe6af4c70e17b79d246bf1d2495bb4d867436c","id":4134,"is_nz":0,"published_at":"2026-09-17T12:17:40+00:00","score":8,"source_handle":"@ryanaraine","source_name":"SecurityWeek","source_slug":"securityweek","summary":"The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution. The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek .","title":"Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard","url":"https://www.securityweek.com/cisco-fixes-dozens-of-flaws-across-fmc-ise-and-nexus-dashboard/"},{"author":null,"category":"general","fetched_at":"2026-09-17T12:30:22+00:00","guid":"therecord:9091ab0a338cbe0e9f1e244e933cf084d3fae632","id":4132,"is_nz":0,"published_at":"2026-09-17T12:15:00+00:00","score":0,"source_handle":null,"source_name":"The Record","source_slug":"therecord","summary":"An Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media personas and media outlets, researchers found.","title":"Israeli contractor BlackCore trained Angolan officials in online influence operations","url":"https://therecord.media/angola-israel-influence-operations-blackcore"},{"author":null,"category":"ai","fetched_at":"2026-09-17T12:11:24+00:00","guid":"mstdn-malwarejake:fcd4f9dd7d0216f3bac2f31bc1ab8e6453df283d","id":4131,"is_nz":0,"published_at":"2026-09-17T12:00:19+00:00","score":8,"source_handle":"@malwarejake","source_name":"Jake Williams (Mastodon)","source_slug":"mstdn-malwarejake","summary":"In today's episode of Breach Please, I sit down with Ariful Huq from @ exaforceai and Patrick McKinney from Turing and talk about the AI-powered SOC. Patrick has been an Exaforce customer for years and brings real-world experience to the conversation. We talk specifically about why having an underlying data model matters and why API alone won't cut it for many advanced detections. @ Secitup will be back tomorrow for more security banter. https:// youtu.be/8YwAdBow9eM","title":"In today's episode of Breach Please, I sit down with Ariful Huq from @ exaforceai and Patrick McKinney from Tu\u2026","url":"https://infosec.exchange/@malwarejake/117286267746502283"},{"author":"Anamarija Pogorelec","category":"ai","fetched_at":"2026-09-17T12:10:04+00:00","guid":"helpnetsecurity:b7e11e94953f50d3baeacee1aed2e8b10241d0d2","id":4130,"is_nz":0,"published_at":"2026-09-17T11:57:31+00:00","score":8,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"Google\u2019s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and built with the Agent Development Kit (ADK) for Python 1.2 or later. Google recommends ADK 2.1.0 or later. It is available in Private Preview. What Agent Anomaly Detection monitors Agent Anomaly Detection evaluates traces emitted by agents to determine whether they are operating outside their intended boundaries. It flags behavioral More The post Google\u2019s new agent security system detects tool misuse, loops and rogue behavior","title":"Google\u2019s new agent security system detects tool misuse, loops and rogue behavior","url":"https://www.helpnetsecurity.com/2026/09/17/google-agent-anomaly-detection-audit-layer/"},{"author":"Sinisa Markovic","category":"general","fetched_at":"2026-09-17T11:49:25+00:00","guid":"helpnetsecurity:943e8c78084389dd7880c4e822ef8d0f3c9eed46","id":4129,"is_nz":0,"published_at":"2026-09-17T11:40:11+00:00","score":0,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"The FBI has seized the domains behind NightmareStresser, a DDoS-for-hire service officials call one of the longest running booter operations in existence. The domain seizure notice (Source: US Department of Justice) Booter services such as those named in this action allegedly facilitate attacks on a wide array of victims in the United States and abroad, including educational institutions, government agencies, gaming platforms and millions of people, US DoJ said in its announcement. These attacks are More The post FBI takes down one of the longest-running DDoS-for-hire services appeared first o","title":"FBI takes down one of the longest-running DDoS-for-hire services","url":"https://www.helpnetsecurity.com/2026/09/17/fbi-nightmarestresser-ddos-for-hire-service-seized/"},{"author":"Sergiu Gatlan","category":"general","fetched_at":"2026-09-17T11:49:15+00:00","guid":"bleepingcomputer:b4632f89e85fdab3a77306b88a7b618e85ed6445","id":4128,"is_nz":0,"published_at":"2026-09-17T11:33:35+00:00","score":0,"source_handle":null,"source_name":"BleepingComputer","source_slug":"bleepingcomputer","summary":"The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. [...]","title":"US takes down NightmareStresser DDoS-for-hire platform","url":"https://www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-thousands-of-ddos-attacks/"},{"author":"Bruce Schneier","category":"ai","fetched_at":"2026-09-17T11:27:17+00:00","guid":"schneier:b1db3f771db1ce01d24f18ea8b054cf861428aaf","id":4127,"is_nz":0,"published_at":"2026-09-17T11:06:31+00:00","score":8,"source_handle":"@schneierblog","source_name":"Schneier on Security","source_slug":"schneier","summary":"This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI s impacts on the country. Politicos are using AI deepfakes to spread lies. The White House is posting slopaganda . Meanwhile, candidates are missing a real opportunity to use AI to make campaigning better. The technology can help candidates listen more deeply to voters concerns, engage constituents more inclusively, and formulate policy platforms that are more responsive to our","title":"How Candidates Could Use AI for Good","url":"https://www.schneier.com/blog/archives/2026/09/how-candidates-could-use-ai-for-good.html"},{"author":"Zeljka Zorz","category":"vuln","fetched_at":"2026-09-17T10:44:13+00:00","guid":"helpnetsecurity:ffdf757e7762f6be9194eee26fdbda7e6076f921","id":4126,"is_nz":0,"published_at":"2026-09-17T10:24:08+00:00","score":58,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE). About CVE-2026-76460 Cisco ISE is an identity-based network access control and policy platform. It checks connecting users identity, profiles devices and checks their security posture, grants users the right type of access, and logs it all. [CVE-2026-76460] is due to More The post Unauthenticated attackers are bypassing Cisco ISE s management interface (CVE-2026-764","title":"Unauthenticated attackers are bypassing Cisco ISE\u2019s management interface (CVE-2026-76460)","url":"https://www.helpnetsecurity.com/2026/09/17/cisco-ise-vulnerability-exploited-cve-2026-76460/"},{"author":"Sinisa Markovic","category":"ai","fetched_at":"2026-09-17T10:22:23+00:00","guid":"helpnetsecurity:e6bc20b050ffd6052664510f3b7592ca3c09e690","id":4125,"is_nz":0,"published_at":"2026-09-17T10:10:31+00:00","score":8,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page impersonating Avast, aimed at users in Belgium, that was more polished than most sites of its kind. The page told visitors their Avast Premium Security subscription had renewed for \u20ac129.99, covered five devices, and would renew again in February. A green checkmark sat beside a badge reading Active, and a More The post Scammers leave AI fingerprints all over fake antivirus renewal page appeared first on Help Net Security .","title":"Scammers leave AI fingerprints all over fake antivirus renewal page","url":"https://www.helpnetsecurity.com/2026/09/17/ai-antivirus-renewal-scam-fake-pages/"},{"author":"Takahiro Takeda","category":"ransomware","fetched_at":"2026-09-17T10:02:02+00:00","guid":"talos:35767ec30857dac3ae40aa6018cc49f5747e0d00","id":4123,"is_nz":0,"published_at":"2026-09-17T10:00:43+00:00","score":50,"source_handle":null,"source_name":"Cisco Talos","source_slug":"talos","summary":"Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.","title":"Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen\u2019s infrastructure and evidence of Qilin's AI use","url":"https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/"},{"author":"Greg Otto","category":"general","fetched_at":"2026-09-17T10:22:22+00:00","guid":"cyberscoop:9eadcf18837c649eb5271fef52d117e2a5c70616","id":4124,"is_nz":0,"published_at":"2026-09-17T10:00:00+00:00","score":0,"source_handle":"@timstarks","source_name":"CyberScoop","source_slug":"cyberscoop","summary":"Ports, railroads, and utilities keep the military operational. They're all vulnerable to Iranian cyberattacks. The post America s cyber strategy overlooks the infrastructure that actually keeps the military moving appeared first on CyberScoop .","title":"America\u2019s cyber strategy overlooks the infrastructure that actually keeps the military moving","url":"https://cyberscoop.com/us-cyber-strategy-iranian-threats-infrastructure-op-ed/"},{"author":"Dhruv Mehrotra, Joseph Cox, wired.com","category":"breach","fetched_at":"2026-09-17T10:01:48+00:00","guid":"arstechnica-sec:774b93474be4400f6ad1287319d4a58321439c9f","id":4122,"is_nz":0,"published_at":"2026-09-17T09:43:46+00:00","score":40,"source_handle":"@dangoodin001","source_name":"Ars Technica Security","source_slug":"arstechnica-sec","summary":"One hacked camera captured 1.6 million images and could detect people as well as cars.","title":"Hackers reveal how Flock cameras really track cars and people","url":"https://arstechnica.com/security/2026/09/hackers-reveal-how-flock-cameras-really-track-cars-and-people/"},{"author":"Bill Toulas","category":"general","fetched_at":"2026-09-17T09:20:15+00:00","guid":"bleepingcomputer:0c9ce14ba6c6f51962df1f29a83e134a3aef0dcb","id":4120,"is_nz":0,"published_at":"2026-09-17T09:00:00+00:00","score":0,"source_handle":null,"source_name":"BleepingComputer","source_slug":"bleepingcomputer","summary":"The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...]","title":"Chinese hackers use SparroWocky malware in govt espionage attacks","url":"https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/"},{"author":"Paresh Dave","category":"general","fetched_at":"2026-09-17T09:20:25+00:00","guid":"wired-security:af83c53d86e33dfd2876f85f48796d675958e23c","id":4121,"is_nz":0,"published_at":"2026-09-17T09:00:00+00:00","score":0,"source_handle":null,"source_name":"WIRED Security","source_slug":"wired-security","summary":"Flock reveals little about where its license plate readers are assembled, but the answer could have geopolitical and cybersecurity implications.","title":"Flock Once Touted Its Cameras as \u2018Made in the USA.\u2019 Now It\u2019s Not So Clear","url":"https://www.wired.com/story/flock-once-touted-its-cameras-as-made-in-the-usa-now-its-not-so-clear/"},{"author":"Eugene Kaspersky","category":"general","fetched_at":"2026-09-17T08:58:57+00:00","guid":"eugenekaspersky:23abee933fa1ca86e431919e8cb090fdfb077cd9","id":4119,"is_nz":0,"published_at":"2026-09-17T08:58:05+00:00","score":0,"source_handle":"@e_kaspersky","source_name":"Eugene Kaspersky","source_slug":"eugenekaspersky","summary":"Our rambling along the Karavshin route in Kyrgyzstan continues\u2026 Next up for us was a three-day out-and-back leg toward some seriously contemplative views in the gorge that goes by the same name \u2013 Karavshin \u2013 plus the Asan-Usen glacier, plus some plain old mind-blowing granite peaks. First, we got ourselves to our next camp (name: [ ]","title":"The Karavshin roller coaster: a kilometer up, a kilometer down.","url":"https://eugene.kaspersky.com/2026/09/17/the-karavshin-roller-coaster-a-kilometer-up-a-kilometer-down/"},{"author":"Sinisa Markovic","category":"breach","fetched_at":"2026-09-17T08:58:25+00:00","guid":"helpnetsecurity:aebaa16cc2bd9310cea5afc86e0955c5d2126984","id":4118,"is_nz":0,"published_at":"2026-09-17T08:39:44+00:00","score":15,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"Spain s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a company s network, found a way to alter personal records, and pulled invoice data. \u201cBefore drawing any conclusions, it should be noted that the available information comes from the notification submitted by the affected organization and will require further analysis,\u201d said Francisco P\u00e9rez Bes, deputy director of the AEPD. More The post Spain reports first data breach involving autonomous AI agent appeared first on Help Net Security .","title":"Spain reports first data breach involving autonomous AI agent","url":"https://www.helpnetsecurity.com/2026/09/17/spain-ai-agent-data-breach/"},{"author":"Sergiu Gatlan","category":"general","fetched_at":"2026-09-17T08:37:04+00:00","guid":"bleepingcomputer:9efac17a7889488fb36419e79d25ea9329c54ba4","id":4117,"is_nz":0,"published_at":"2026-09-17T08:24:48+00:00","score":0,"source_handle":null,"source_name":"BleepingComputer","source_slug":"bleepingcomputer","summary":"Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]","title":"Microsoft shares workaround for Windows domain login issues","url":"https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-workaround-for-windows-domain-login-authentication-issues/"},{"author":"Anamarija Pogorelec","category":"ai","fetched_at":"2026-09-17T08:15:24+00:00","guid":"helpnetsecurity:bb4265d839cdca6c8bd20970448e51d956a3591b","id":4116,"is_nz":0,"published_at":"2026-09-17T08:00:09+00:00","score":8,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle campaign targets people who download AI agents from search results or ads, and users of seven browser wallet extensions, among them MetaMask, Coinbase Wallet and Phantom. HP also More The post Fake AI trading agent steals crypto wallet passwords appeared first on Help Net Security .","title":"Fake AI trading agent steals crypto wallet passwords","url":"https://www.helpnetsecurity.com/2026/09/17/fake-ai-trading-agent-research/"},{"author":"Ionut Arghire","category":"policy","fetched_at":"2026-09-17T07:54:22+00:00","guid":"securityweek:45f44f51026b7749bd460e7a69cd5699dddfa21c","id":4114,"is_nz":0,"published_at":"2026-09-17T07:53:43+00:00","score":0,"source_handle":"@ryanaraine","source_name":"SecurityWeek","source_slug":"securityweek","summary":"Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Guidance on Deploying Cyber Decoys appeared first on SecurityWeek .","title":"CISA Releases Guidance on Deploying Cyber Decoys","url":"https://www.securityweek.com/cisa-releases-guidance-on-deploying-cyber-decoys/"},{"author":"Eduard Kovacs","category":"ai","fetched_at":"2026-09-17T07:54:22+00:00","guid":"securityweek:de637fca529332c67ce05ecf4b289769ec14e484","id":4115,"is_nz":0,"published_at":"2026-09-17T07:41:29+00:00","score":8,"source_handle":"@ryanaraine","source_name":"SecurityWeek","source_slug":"securityweek","summary":"New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek .","title":"AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals","url":"https://www.securityweek.com/ai-agents-can-retrain-own-models-mid-task-leaking-secrets-and-erasing-refusals/"},{"author":"Sergiu Gatlan","category":"vuln","fetched_at":"2026-09-17T07:33:44+00:00","guid":"bleepingcomputer:7238e34645fcb6eef20727ead814deb036641c47","id":4113,"is_nz":0,"published_at":"2026-09-17T07:20:54+00:00","score":28,"source_handle":null,"source_name":"BleepingComputer","source_slug":"bleepingcomputer","summary":"Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]","title":"Cisco warns of max severity ISE zero-day exploited in attacks","url":"https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/"},{"author":"Ionut Arghire","category":"vuln","fetched_at":"2026-09-17T06:31:13+00:00","guid":"securityweek:60b38245599603a0a38dc4aecd88e2f9a900d4e7","id":4111,"is_nz":0,"published_at":"2026-09-17T06:19:52+00:00","score":53,"source_handle":"@ryanaraine","source_name":"SecurityWeek","source_slug":"securityweek","summary":"Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek .","title":"Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day","url":"https://www.securityweek.com/active-exploitation-triggers-emergency-patch-for-cisco-ise-zero-day/"},{"author":"Industry News","category":"ai","fetched_at":"2026-09-17T06:31:15+00:00","guid":"helpnetsecurity:3c380074d040d4bca76376117bc99a508be3f941","id":4112,"is_nz":0,"published_at":"2026-09-17T06:13:00+00:00","score":8,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"Riverbed has announced new Riverbed intelligent network observability solutions that combine 360-degree network visibility with agentic AI to help network operations teams accelerate troubleshooting, identify root causes, predict emerging issues and increasingly prevent disruptions before they impact users. The new Riverbed Network 360 offerings natively integrate the powerful agentic AI capabilities of Riverbed IQ and Q into Riverbed\u2019s AppResponse and NetProfiler solutions while extending network visibility across remote users, zero trust and public cloud environments More The post Riverbed N","title":"Riverbed NPM 360 uses AI to predict and prevent network disruptions","url":"https://www.helpnetsecurity.com/2026/09/17/riverbed-network-360-observability-solutions/"},{"author":"Industry News","category":"vuln","fetched_at":"2026-09-17T06:09:16+00:00","guid":"helpnetsecurity:62deece8a412cfb979b4dad5e16d8a402aa58dd3","id":4110,"is_nz":0,"published_at":"2026-09-17T06:01:47+00:00","score":8,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"Tuskira has announced Vector, its autonomous red teaming agentic capability, which identifies an organization s exploitable attack surface by simulating what an attacker can do from outside it. Tuskira validates every external finding against the organization s deployed compensating controls, the internal risks already reported by its security tools, and the architecture of its application and infrastructure topologies. The result is autonomous adversarial exposure validation across vulnerabilities, identities, and control configurations, so security teams act only on More The post Tuskira Vec","title":"Tuskira Vector brings autonomous red teaming to attack surface validation","url":"https://www.helpnetsecurity.com/2026/09/17/tuskira-vector-autonomous-red-teaming/"},{"author":"Mirko Zorz","category":"vuln","fetched_at":"2026-09-17T05:48:25+00:00","guid":"helpnetsecurity:61f824bfec3096d24dc2b8db3ae6fb22f4159080","id":4109,"is_nz":0,"published_at":"2026-09-17T05:30:48+00:00","score":8,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why least privilege and access controls still matter for AI agents. It also looks at how AI has narrowed the skill gap between attackers and defenders, how the team handled about nine times as many vulnerabilities More The post The AI security question leaders should be asking instead appeared first on Help Net Security .","title":"The AI security question leaders should be asking instead","url":"https://www.helpnetsecurity.com/2026/09/17/frederic-bull-gremlin-ai-in-cybersecurity-gap/"},{"author":"Help Net Security","category":"general","fetched_at":"2026-09-17T05:06:45+00:00","guid":"helpnetsecurity:d2857fe84ed3416915df8cec98e413066add8512","id":4107,"is_nz":0,"published_at":"2026-09-17T05:00:57+00:00","score":0,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"Cheri Hotman, Managing Partner of Hotman Group, works as a vCISO and vGRC leader. In this Help Net Security video, she talks about holding coverage steady when the CFO asks for a flat budget or a 12% cut. Her advice is to stop trimming every line by the same percentage. Instead, sort each security expense into four buckets: what works and protects something the business cares about, what could add value but was never operationalized, More The post A flat cybersecurity budget doesn t have to mean weaker coverage appeared first on Help Net Security .","title":"A flat cybersecurity budget doesn\u2019t have to mean weaker coverage","url":"https://www.helpnetsecurity.com/2026/09/17/flat-cybersecurity-budget-video/"},{"author":"Sinisa Markovic","category":"general","fetched_at":"2026-09-17T05:06:45+00:00","guid":"helpnetsecurity:2e4887661a56a7b156114383a9d390d70fa24c45","id":4108,"is_nz":0,"published_at":"2026-09-17T04:51:04+00:00","score":0,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"New AWS customers can now sign up with a Google, GitHub, or Apple login, start with $100 in Free Tier credits, and build inside a project where AWS and coding agents set up permissions automatically. Paid projects get a monthly spend limit, starting at $20, and a project that reaches its limit is halted instead of running up more charges. Owners who later need multiple Regions or central governance can turn on the full AWS More The post AWS s new sign-up gives accounts spend caps, email invites, and agent-set permissions appeared first on Help Net Security .","title":"AWS\u2019s new sign-up gives accounts spend caps, email invites, and agent-set permissions","url":"https://www.helpnetsecurity.com/2026/09/17/aws-spend-limit-agent-set-permissions/"},{"author":"Anamarija Pogorelec","category":"general","fetched_at":"2026-09-17T04:45:26+00:00","guid":"helpnetsecurity:966cab2fa6b6a571e4b37ac353cc1c82bd955293","id":4105,"is_nz":0,"published_at":"2026-09-17T04:36:56+00:00","score":0,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"GNOME 51, the new version of the Linux desktop, came out on September 16 under the codename A Coru\u00f1a. The release adds offline maps and live transit information to Maps, new login options at the login screen, hand-drawn signatures in the Papers document viewer, and smoother animations when the system is under load. Fedora 45 and Ubuntu 26.10 will ship it. The update also takes something away. Owners of older NVIDIA graphics cards, such as More The post GNOME 51 adds passkey logins, offline maps and drawn PDF signatures appeared first on Help Net Security .","title":"GNOME 51 adds passkey logins, offline maps and drawn PDF signatures","url":"https://www.helpnetsecurity.com/2026/09/17/gnome-51-new-features/"},{"author":"Mirko Zorz","category":"ai","fetched_at":"2026-09-17T04:45:26+00:00","guid":"helpnetsecurity:7857adc2608759a778c8bf1c5e68ab6b540cd93c","id":4106,"is_nz":0,"published_at":"2026-09-17T04:30:21+00:00","score":8,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"AI coding tools are making open source software harder to maintain and secure, according to six authors writing for the Association for Computing Machinery s Technology Policy Council, among them Simson Garfinkel and Josiah Dykstra. The tools write code and find security flaws quickly. The maintainers who decide what enters a project s official release still have to judge that output themselves. That burden reaches anyone who runs software. Open source code sits inside phones, cars, cloud More The post AI is adding to the review load on open-source projects, many of them thinly funded appeared","title":"AI is adding to the review load on open-source projects, many of them thinly funded","url":"https://www.helpnetsecurity.com/2026/09/17/ai-and-open-source-projects/"},{"author":"Help Net Security","category":"ai","fetched_at":"2026-09-17T04:22:57+00:00","guid":"helpnetsecurity:983a504d45c291cc74334ab9b30474396652b999","id":4104,"is_nz":0,"published_at":"2026-09-17T04:00:36+00:00","score":8,"source_handle":null,"source_name":"Help Net Security","source_slug":"helpnetsecurity","summary":"AI is transforming warfare and international conflict. Autonomous weapon systems pose a genuine threat to civilians. The war in Ukraine has become a proving ground for weapons that can navigate, identify targets, resist electronic countermeasures, and pursue and engage targets autonomously without the need for human control. That evolution should concern technology professionals, regulators, policymakers, and citizens everywhere. Recent reporting by The New York Times documented a particularly disturbing development. In July 2026, a Russian More The post The world must establish red lines for ","title":"The world must establish red lines for autonomous AI weapons","url":"https://www.helpnetsecurity.com/2026/09/17/autonomous-ai-weapons-future/"},{"author":"Mayank Parmar","category":"ai","fetched_at":"2026-09-17T00:48:15+00:00","guid":"bleepingcomputer:d1d8144ffdd8975a99f6d4c001dfae10eaa101d1","id":4103,"is_nz":0,"published_at":"2026-09-17T00:35:48+00:00","score":8,"source_handle":null,"source_name":"BleepingComputer","source_slug":"bleepingcomputer","summary":"Anthropic is testing a new personal finance feature called \"Claude Money\" that will allow you to connect your bank accounts directly to Claude and \"understand your money.\" [...]","title":"Anthropic wants Claude to analyze your bank account and financial data","url":"https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-wants-claude-to-analyze-your-bank-account-and-financial-data/"},{"author":null,"category":"ai","fetched_at":"2026-09-17T00:08:51+00:00","guid":"mstdn-sawaba:47ede5a407174cad9c9a962ef80f1051a7040a2c","id":4100,"is_nz":0,"published_at":"2026-09-16T23:58:56+00:00","score":8,"source_handle":"@sawaba","source_name":"Adrian Sanabria (Mastodon)","source_slug":"mstdn-sawaba","summary":"Whoa. I explored the site a bit more. They\u2019re trying to sell licenses to this AI slop. Whaaaaat","title":"Whoa. I explored the site a bit more. They\u2019re trying to sell licenses to this AI slop. Whaaaaat","url":"https://infosec.exchange/@sawaba/117283431184519440"},{"author":null,"category":"general","fetched_at":"2026-09-17T00:28:09+00:00","guid":"simonwillison:738877fde7567c89428a94f5355467904114cbd4","id":4101,"is_nz":0,"published_at":"2026-09-16T23:51:43+00:00","score":0,"source_handle":null,"source_name":"Simon Willison (AI)","source_slug":"simonwillison","summary":"Release: datasette 1.0a40 Same security fix as 0.65.5 , plus some neat new features and bug fixes: Plugins can now launch and manage background tasks using the new datasette.add_background_task() method. Thanks, Alex Garcia . I've migrated Datasette to httpx2 for features like the internal datasette.client.get() method. A whole lot of bug fixes , many of them stemming from a recent effort to triage issues for a 1.0 stable release. Tags: security , datasette","title":"datasette 1.0a40","url":"https://simonwillison.net/2026/Sep/16/datasette/"},{"author":null,"category":"general","fetched_at":"2026-09-17T00:28:09+00:00","guid":"simonwillison:2105625f58a47d5420c2b9e179c6aae45e64dc91","id":4102,"is_nz":0,"published_at":"2026-09-16T23:51:08+00:00","score":0,"source_handle":null,"source_name":"Simon Willison (AI)","source_slug":"simonwillison","summary":"Release: datasette 0.65.5 Security fix for an issue where a trailing newline in a requested table name could bypass table permissions and expose private rows, reported by dpfkdlemtp in GHSA-h547-rmjf-5m2m . Tags: security , datasette","title":"datasette 0.65.5","url":"https://simonwillison.net/2026/Sep/16/datasette-2/"},{"author":null,"category":"vuln","fetched_at":"2026-09-16T23:47:53+00:00","guid":"mstdn-sawaba:a0a6f6d23bcbf0ae85a6db51f636a353f0140b50","id":4095,"is_nz":0,"published_at":"2026-09-16T23:43:27+00:00","score":8,"source_handle":"@sawaba","source_name":"Adrian Sanabria (Mastodon)","source_slug":"mstdn-sawaba","summary":"A Fortinet flaw that entered the exploited catalog on September 9 had carried its identifier since February 2025. A ha! A Fortinet flaw! We\u2019re talking about vulnerabilities! Finally, a shred of context. The Fortinet vulnerability \u201centered the exploited catalog\u201d - maybe we\u2019re talking about CISA KEV? Maybe CHQ has its own catalog? Maybe it\u2019s in the Structural Conditions Registry ? I\u2019ve got to make a lot of assumptions here, but the next bit mentions an identifier from Feb 2025. The only explanation I can think of is that there\u2019s a Fortinet vulnerabilities with a CVE coined in Feb 2025, but is ju","title":"A Fortinet flaw that entered the exploited catalog on September 9 had carried its identifier since February 20\u2026","url":"https://infosec.exchange/@sawaba/117283370266981235"},{"author":null,"category":"vuln","fetched_at":"2026-09-16T23:47:53+00:00","guid":"mstdn-sawaba:f1447cbd6141ae678fd441a713dff1942be9b6c6","id":4096,"is_nz":0,"published_at":"2026-09-16T23:36:35+00:00","score":8,"source_handle":"@sawaba","source_name":"Adrian Sanabria (Mastodon)","source_slug":"mstdn-sawaba","summary":"OKAY. Next paragraph. SC-2026-006 \u00b7 Exploitation Precedes Defender Awareness: rating under review after the criterion supporting this cycle's scheduled upgrade failed construct validation. The upgrade action is voided. Prior state, STRENGTHENING, stands. I got nothing. Why is STRENGTHENING in all caps, like it is one of several selectable states? How would I know this? Who scheduled what upgrade? What criterion failed construct validation? FML, let\u2019s move on to the next paragraph.","title":"OKAY. Next paragraph. SC-2026-006 \u00b7 Exploitation Precedes Defender Awareness: rating under review after the cr\u2026","url":"https://infosec.exchange/@sawaba/117283343261807588"},{"author":null,"category":"ai","fetched_at":"2026-09-16T23:47:53+00:00","guid":"mstdn-sawaba:5a4cbb90605fb25674f4bb0bb38616df3e3cbf1e","id":4097,"is_nz":0,"published_at":"2026-09-16T23:29:01+00:00","score":8,"source_handle":"@sawaba","source_name":"Adrian Sanabria (Mastodon)","source_slug":"mstdn-sawaba","summary":"Let\u2019s break down this first paragraph. CHQ maintains ratings on a standing set of structural security conditions. CHQ is the website. Okay. What is a standing set of structural security conditions? I have no idea. Why does the set need to be standing? Why are the conditions structural? Couldn\u2019t you just say \u201cCHQ maintains ratings on a set of security conditions?\u201d Is AI trying to \u2018juice\u2019 the token use here so you needlessly pay extra? Each rating reflects the current maturity and confirmation of a condition, not a forecast. Nobody said it was a forecast, why so defensive? So we\u2019ve got ratings t","title":"Let\u2019s break down this first paragraph. CHQ maintains ratings on a standing set of structural security conditio\u2026","url":"https://infosec.exchange/@sawaba/117283313528109691"},{"author":null,"category":"ai","fetched_at":"2026-09-16T23:26:49+00:00","guid":"mstdn-sawaba:d15c271f3ac98462ce5e739dd51c3833ff23be2c","id":4094,"is_nz":0,"published_at":"2026-09-16T23:16:02+00:00","score":8,"source_handle":"@sawaba","source_name":"Adrian Sanabria (Mastodon)","source_slug":"mstdn-sawaba","summary":"I\u2019m not sure how I ended up on the mailing list, but this is a shining jewel in my collection of \u201creasons why you should not let AI do your writing\u201d. It is breathtakingly unreadable. Even the title is unintelligible. https:// dispatch.cybersecurityhq.com/p /escalation-voided-on-construct-failure-timing-condition-placed-under-review","title":"I\u2019m not sure how I ended up on the mailing list, but this is a shining jewel in my collection of \u201creasons why \u2026","url":"https://infosec.exchange/@sawaba/117283262448839636"},{"author":"Graham Cluley","category":"general","fetched_at":"2026-09-17T00:07:23+00:00","guid":"grahamcluley:49b21151d74803bc6bab63f63afe2b06e483a007","id":4099,"is_nz":0,"published_at":"2026-09-16T23:07:19+00:00","score":0,"source_handle":null,"source_name":"Graham Cluley","source_slug":"grahamcluley","summary":"Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound to a contract you agreed to while drunk. What they discovered will make you look at your TV rather differently... Meanwhile, awful Android malware with the audacious name \"Awesome\" (in Indonesian) is doing the rounds, stealing your data, demanding a ransom, and then giving you a \"jump scare\"... Plus, in our featured int","title":"Smashing Security podcast #485: These researchers got drunk to hack an LG TV","url":"https://grahamcluley.com/smashing-security-podcast-485/"},{"author":"Joe Mullin","category":"ai","fetched_at":"2026-09-16T23:05:58+00:00","guid":"eff:2fcbbc278aa846d2bf02e1807bdf0c9eff79d9c0","id":4093,"is_nz":0,"published_at":"2026-09-16T22:47:35+00:00","score":8,"source_handle":null,"source_name":"EFF","source_slug":"eff","summary":"The U.S. Court of Appeals for the Ninth Circuit handed internet users and programmers a big win today, by rejecting an attempt to stretch a narrow provision of the Digital Millennium Copyright Act (DMCA) into a new source of copyright liability. The case involves Section 1202 of the DMCA, which prohibits intentionally removing copyright management information (CMI) like an author\u2019s name or a copyright notice, from a copyrighted work. Open AI and Microsoft used code from Github as part of the training data for their LLMs, along with billions of other works. A group of anonymous Github contribut","title":"Victory! Appeals Court Rejects Expansive New Copyright Claim","url":"https://www.eff.org/deeplinks/2026/09/victory-appeals-court-rejects-expansive-new-copyright-claim"},{"author":"Jai Vijayan","category":"ai","fetched_at":"2026-09-16T22:00:20+00:00","guid":"darkreading:2399ff8c39b4823043a1b8294650cc5704e9f897","id":4092,"is_nz":0,"published_at":"2026-09-16T21:26:55+00:00","score":8,"source_handle":null,"source_name":"Dark Reading","source_slug":"darkreading","summary":"CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?","title":"AI Security Spending Jumps as Fear Outpaces Proof of Value","url":"https://www.darkreading.com/cybersecurity-operations/ai-security-spending-jumps-fear-outpaces-proof-value"},{"author":"Dan Goodin","category":"general","fetched_at":"2026-09-16T21:17:09+00:00","guid":"arstechnica-sec:c60fc05e1d0d16b4d074b1228405d7242daa9d1d","id":4090,"is_nz":0,"published_at":"2026-09-16T21:08:14+00:00","score":10,"source_handle":"@dangoodin001","source_name":"Ars Technica Security","source_slug":"arstechnica-sec","summary":"Group plans to be largely out of commission for several weeks.","title":"Nonprofit that tracks meteors taken down by \"critical blow\" from a cyberattack","url":"https://arstechnica.com/security/2026/09/nonprofit-that-tracks-meteors-taken-down-by-critical-blow-from-a-cyberattack/"},{"author":null,"category":"ai","fetched_at":"2026-09-16T21:39:20+00:00","guid":"therecord:721b02aaafe73b0602d684278b02131ee4e402a1","id":4091,"is_nz":0,"published_at":"2026-09-16T21:07:00+00:00","score":8,"source_handle":null,"source_name":"The Record","source_slug":"therecord","summary":"\u201cIt's really complicated, and I wouldn't want to do something in a lame duck session to do it quickly and not get it right,\u201d said House Energy and Commerce Chairman Brett Guthrie about the FRONTIER Act.","title":"Key lawmaker suggests action on AI safety legislation will wait until 2027","url":"https://therecord.media/frontier-act-ai-bill-house-brett-guthrie"},{"author":"Lawrence Abrams","category":"general","fetched_at":"2026-09-16T20:56:15+00:00","guid":"bleepingcomputer:5a488cdb304d33ff15bbfdca082d351007955126","id":4089,"is_nz":0,"published_at":"2026-09-16T20:39:29+00:00","score":0,"source_handle":null,"source_name":"BleepingComputer","source_slug":"bleepingcomputer","summary":"Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]","title":"Windows 11 KB5124008 update breaks domain trust for some users","url":"https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124008-update-breaks-domain-trust-for-some-users/"},{"author":"Bill Toulas","category":"general","fetched_at":"2026-09-16T20:35:15+00:00","guid":"bleepingcomputer:fdd187455edb9b1d8d3c8db32959faa31c631460","id":4086,"is_nz":0,"published_at":"2026-09-16T20:24:55+00:00","score":0,"source_handle":null,"source_name":"BleepingComputer","source_slug":"bleepingcomputer","summary":"Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]","title":"Iranian hackers use CHOSEN BRICK Windows malware to spy on targets","url":"https://www.bleepingcomputer.com/news/security/iranian-hackers-use-chosen-brick-windows-malware-to-spy-on-targets/"}]
