2026-09-29 06:08 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 06:50 UTC
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code, and the PKCE proof key to a token endpoint the attacker controlled. The fix is in versions 1.30.0 and
P0
2026-09-29 05:12 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 06:50 UTC
OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall Street Journal. The move "marks a rare case of a major AI developer ditching a new release because of safety concerns," the news publication said.
P0
2026-09-29 04:45 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 06:50 UTC
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent attempting to complete a search-based training task queried a public chatbot service through a gap in our internet-access restrictions:
P0
2026-09-29 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-29 02:10 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-28 22:35 UTC
Community
SANS Internet Storm Center · indexed 2026-09-28 22:10 UTC
Apple today released patches for all of its operating systems. However, only patches for older branches include a security fix. The vulnerability being addressed in iOS 26, macOS 26 and macOS 15 is already being exploited. iOS and macOS 27 are not affected. Today's update for the current "27" branch does not address security issues, but fixes some functional issues that got caught after the release two weeks ago. A 27.1 version was also expected to support the new foldable iPhone and w…
P5
2026-09-28 22:02 UTC
Security Journalism
Dark Reading · Agam Shah · indexed 2026-09-29 16:35 UTC
The Open Agent Safety Platform relies on hardware and software components to monitor agent activities and quarantine unruly agents before they can cause harm.
P0
2026-09-28 21:13 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-28 21:25 UTC
A high-severity vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments, and orgs should patch right away.
P0
2026-09-28 20:56 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-28 21:05 UTC
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]
P15
2026-09-28 20:31 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-28 20:40 UTC
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]
P0
2026-09-28 20:23 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-28 20:55 UTC
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.
P0
2026-09-28 20:14 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-28 21:25 UTC
Infostealers are exposing corporate AI accounts, sessions and API keys, giving attackers access to sensitive data, compute and connected systems. SOCRadar analyzed stealer log data from the last 90 days and found 482 companies with exposed AI accounts and credentials. Of those, 295 appeared in active logs during that period, suggesting the exposure is recent […]
P0
2026-09-28 20:00 UTC
Security Journalism
Huntress · indexed 2026-09-29 07:55 UTC
Huntress researchers reveal how attackers are exploiting ChatGPT Custom GPTs to spread ClickFix lures and DLL-sideloaded malware. See the full breakdown.
P0
2026-09-28 19:49 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-28 19:55 UTC
Dutch police have confirmed that a 24-year-old Amsterdam man arrested earlier this month was detained as part of an investigation into the ShinyHunters hacking group. [...]
P0
2026-09-28 19:30 UTC
Security Journalism
The Record · indexed 2026-09-28 19:40 UTC
A vulnerability in a popular line of products from Oracle is being used in a new campaign by the prolific ShinyHunters hacking group, which recently claimed credit for an attack on the FBI’s jobs site.
P0
2026-09-28 19:18 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 20:10 UTC
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to arbitrary code execution when processing a maliciously crafted file. The iPhone maker said the
P5
2026-09-28 18:50 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-28 18:55 UTC
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]
P0
2026-09-28 18:44 UTC
Security Journalism
Dark Reading · Ravi Sharma · indexed 2026-09-28 19:10 UTC
Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider threats.
P0
2026-09-28 18:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 20:10 UTC
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonprofits, intergovernmental organizations, and government contractors. Its use goes back to at least
P0
2026-09-28 18:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 18:40 UTC
What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional provisioning, the components that matter, how to evaluate framework choices, and what runtime evidence proves an agent behaved as intended.
P0
2026-09-28 17:42 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 18:40 UTC
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then, on September 24, used them to send fraudulent withdrawal commands to Bitget's wallet system. Exchanges keep most
P0
2026-09-28 17:38 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-28 18:40 UTC
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in which each customer runs a separate copy. The console stores what the malware collects from each phone,
P0
2026-09-28 17:30 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-28 17:50 UTC
The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention. The post Modulate Raises $25 Million to Advance Deepfake Detection appeared first on SecurityWeek.
P0
2026-09-28 17:15 UTC
Security Journalism
The Record · indexed 2026-09-28 17:25 UTC
A New Mexico jury found Facebook violated the law nearly 44 million times by lying to consumers about its data privacy practices.
P0
2026-09-28 17:05 UTC
Vendor Research
AWS Security Blog · Stéphane Israël · indexed 2026-09-28 17:40 UTC
On Saturday, October 24, 2026, we will conduct an exercise demonstrating that the AWS European Sovereign Cloud can operate without depending on any infrastructure outside of the European Union (EU). For several hours, the AWS European Sovereign Cloud will operate without a connection to the AWS Global Network backbone. The backbone is the private network […]
P0
2026-09-28 17:00 UTC
Security Journalism
Huntress · indexed 2026-09-29 07:55 UTC
Learn what good privilege hygiene looks like, from local admin sprawl to accidental access, plus least privilege best practices you can start today.
P0
2026-09-28 16:51 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-28 17:40 UTC
A purported ad-blocker exfiltrates reams of sensitive information and benefits from having Google's stamp of approval despite researcher warnings.
P0
2026-09-28 16:19 UTC
Security Journalism
The Record · indexed 2026-09-28 16:25 UTC
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix itself confirmed eight new vulnerabilities.
P25
2026-09-28 15:49 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-28 15:55 UTC
The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...]
P15
2026-09-28 15:33 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-28 15:40 UTC
The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.
P0
2026-09-28 15:15 UTC
Security Journalism
Security Week · Mike Lennon · indexed 2026-09-28 15:30 UTC
SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address the strategic challenges facing today’s enterprise security programs. The post Call for Presentations Open for 2026 CISO Forum Virtual Summit appeared first on SecurityWeek.
P0