2026-09-18 12:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 13:55 UTC
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"
P15
2026-09-18 10:57 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-18 11:10 UTC
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.
P10
2026-09-18 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Niv Rabin · indexed 2026-09-18 10:10 UTC
Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.
P0
2026-09-17 21:19 UTC
Vendor Research
AWS Security Blog · Marta Taggart · indexed 2026-09-17 21:40 UTC
European organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can now run generative AI workloads on open weight models on Amazon Bedrock in the AWS European Sovereign Cloud. We’re excited to announce the general availability of the first open weight […]
P0
2026-09-17 19:18 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-17 19:25 UTC
Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/17/2026 12:00 PM PDT Description: AWS IoT Device SDK for Python (AWSIoTPythonSDK) is an open source SDK that lets IoT devices and gateways connect to AWS IoT Core over MQTT. We identified CVE-2026-92943 in the MQTT client TLS connection layer, where the client did not validate that the server certificate matched the AWS IoT Core endpoint hostname. On Python 3.7 and later, an adversary-in-the-m…
P5
2026-09-17 17:32 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just
P0
2026-09-17 12:39 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-17 12:50 UTC
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek.
P5
2026-09-17 12:17 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-17 12:30 UTC
The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution. The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek.
P15
2026-09-17 10:50 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TL;DR Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR
P0
2026-09-17 09:26 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-17 10:20 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw […]
P45
2026-09-17 08:00 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG
P0
2026-09-16 21:20 UTC
Vendor Research
AWS Security Blog · Pablo Pagani · indexed 2026-09-16 21:50 UTC
The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AWS partition (aws-eusc), with its own control plane, AWS Identity and […]
P0
2026-09-16 20:16 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-16 20:20 UTC
Bulletin ID: 2026-113-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/16/2026 12:30 PM PDT Description: Network Policy Agent is an EKS Policy management feature. We identified CVE-2026-86831, a cross-namespace NetworkPolicy bypass in Amazon EKS Network Policy Agent (aws-network-policy-agent) before v1.4.0. Pod identifiers are constructed by concatenating the pod name and namespace with a hyphen delimiter, which is a legal character in both Kubernetes pod names a…
P5
2026-09-16 18:14 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-09-16 18:25 UTC
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge …
P0
2026-09-16 11:32 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-16 11:40 UTC
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek.
P15
2026-09-16 08:06 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-16 08:20 UTC
The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws. The post Oracle Patches 800+ Vulnerabilities in September 2026 Security Update appeared first on SecurityWeek.
P5
2026-09-15 22:21 UTC
Vendor Research
AWS Security Blog · Rishi Tripathy · indexed 2026-09-15 22:45 UTC
AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token size limits with a single token size limit of 4,096 bytes. STS now reports session token size in API responses, […]
P0
2026-09-15 16:00 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-15 16:00 UTC
AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage. The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek.
P0
2026-09-15 15:53 UTC
Vendor Research
AWS Security Blog · Luis Pastor · indexed 2026-09-15 16:05 UTC
The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s faster to get things working, and the plan is always to tighten permissions later. But later rarely comes. Permissions accumulate, AWS Identity and Access […]
P0
2026-09-15 13:32 UTC
Vendor Research
Tenable Blog · Ben Mudie · indexed 2026-09-15 13:40 UTC
Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a solid security posture.Key takeawaysThe Australian Signals Directorate (ASD) is moving from the Essential Eight cybersecurity framework to a new outcomes-focused Essentials series covering enterprise IT, cloud, operational technology (OT), and potentially agentic AI.The Essential Eig…
P0
2026-09-15 11:52 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 12:25 UTC
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH
P0
2026-09-15 11:12 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 12:25 UTC
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The
P0
2026-09-15 09:40 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-15 09:50 UTC
The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints appeared first on SecurityWeek.
P0
2026-09-15 05:31 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-15 06:25 UTC
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The
P25
2026-09-14 18:04 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-14 18:10 UTC
Bulletin ID: 2026-112-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/14/2026 10:45 AM PDT Description: Temporary Elevated Access Management (TEAM) is an open source AWS sample solution for managing temporary elevated access via AWS IAM Identity Center. We identified CVE-2026-86830, where an authenticated user with application-level access could gain unintended temporary elevated access to AWS accounts managed by TEAM. Impacted versions:
P5
2026-09-14 17:46 UTC
Vendor Research
AWS Security Blog · Avik Mukherjee · indexed 2026-09-14 18:10 UTC
Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive. This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance for organizations that store, process, or transmit cardholder data on AWS. Organizations subject to […]
P0
2026-09-14 16:15 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-14 16:30 UTC
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]
P0
2026-09-14 14:08 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-14 14:25 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Two of the above vulnerabilities affect JFrog Artifactory. CVE-2026-42016 can allow attackers to bypass authorization checks and […]
P35
2026-09-14 09:43 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-14 09:50 UTC
Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If you use Check Point VPN, you should […]
P45
2026-09-14 09:27 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-14 09:30 UTC
The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator. The post Three JFrog Artifactory Flaws Exploited for Backdoor Deployment appeared first on SecurityWeek.
P0