2026-09-25 13:00 UTC
Vendor Research
Cloudflare Security · Jules Lemee · indexed 2026-09-25 13:10 UTC
Misconfiguring Turnstile by skipping backend validation leaves sites exposed to bots. Turnstile Spin fixes incomplete setups by using your preferred AI coding agent to wire up server-side verification.
P0
2026-09-25 12:45 UTC
Community
SANS Internet Storm Center · indexed 2026-09-25 06:40 UTC
Introduction
P0
2026-09-25 12:40 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-25 12:55 UTC
Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. [...]
P0
2026-09-25 12:39 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-25 12:40 UTC
Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. The post CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks appeared first on SecurityWeek.
P0
2026-09-25 12:16 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-25 12:20 UTC
Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services. The post Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court appeared first on SecurityWeek.
P0
2026-09-25 12:00 UTC
Security Journalism
The Record · indexed 2026-09-25 12:15 UTC
Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.
P0
2026-09-25 11:35 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-25 11:50 UTC
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]
P0
2026-09-25 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 13:10 UTC
Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like this. An attacker lands on a low-privilege cloud account, and the first try at privilege escalation goes nowhere. That dead end used to cost hours of documentation reading,
P10
2026-09-25 10:53 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-25 11:00 UTC
Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events. The post Windows, Linux, Android File Notification Systems Leak User Activity appeared first on SecurityWeek.
P0
2026-09-25 10:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 11:15 UTC
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," Bitget said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain
P0
2026-09-25 10:30 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-25 10:35 UTC
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]
P0
2026-09-25 10:14 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 10:15 UTC
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash
P50
2026-09-25 09:55 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-25 10:40 UTC
CARBONATO exploits exposed Docker daemons, installs an AI agent, steals API keys and spreads across networks with autonomous command execution. CARBONATO is a Docker-based botnet that has been active since at least October 2024. ThreatDown discovered the operation after finding an unauthenticated container registry exposed to the internet. The registry contained the attackers’ entire toolchain […]
P0
2026-09-25 09:27 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-25 09:40 UTC
Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks. The post ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration appeared first on SecurityWeek.
P0
2026-09-25 09:00 UTC
Other
ESET · indexed 2026-09-26 13:10 UTC
As AI lets anyone build software, here’s how to vet that shiny new app before it exposes your data
P0
2026-09-25 08:33 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-25 08:45 UTC
Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]
P0
2026-09-25 08:22 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-25 08:25 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: The first flaw added to the catalog, tracked as CVE-2026-5430 (CVSS score 10.0), is an authentication bypass in multiple WSO2 products […]
P45
2026-09-25 07:00 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-25 07:15 UTC
A storm is raging in the form of cyber sabotage, disinformation, and drone attacks on European nations, particularly those that provide material support to Ukraine.
P0
2026-09-25 06:57 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-25 07:05 UTC
Tracked as CVE-2026-48842, the exploited bug is an SQL injection that can be exploited without authentication. The post Roundcube Webmail Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
P5
2026-09-25 04:49 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 06:35 UTC
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company
P0
2026-09-25 04:46 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 06:35 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,
P55
2026-09-25 03:45 UTC
Community
SANS Internet Storm Center · indexed 2026-09-25 04:05 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-24 21:04 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-24 21:15 UTC
Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels.
P0
2026-09-24 20:53 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-24 20:55 UTC
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]
P0
2026-09-24 20:50 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-24 21:35 UTC
Ryuk member Karen Vardanyan was sentenced to 24 months in U.S. prison after extradition from Ukraine and ordered to pay $1.2M in restitution. Karen Vardanyan, a 35-year-old Armenian citizen who went by “Maneeken” and, oddly, “Karl Lagerfeld” online, was extradited from Ukraine and sentenced to 24 months in federal prison plus three years of supervised […]
P0
2026-09-24 20:35 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-24 20:40 UTC
The prospect of legal accountability is unclear. Lawsuits are a possibility, but some legal experts believe any criminal investigations would face an extremely high burden. The post Autonomous AI Hacks Raise Thorny Questions of Legal Accountability appeared first on SecurityWeek.
P0
2026-09-24 20:32 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-24 21:00 UTC
The latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.
P0
2026-09-24 20:30 UTC
Security Journalism
The Record · indexed 2026-09-24 20:45 UTC
Two executives at a data extraction and digital forensics company that sold several U.S. agencies its software were arrested for allegedly lying about the fact that its technology is made in Russia.
P0
2026-09-24 20:15 UTC
Security Journalism
The Record · indexed 2026-09-24 20:30 UTC
U.S. Sens. Mark Warner (D-VA) and Ted Cruz (R-TX) introduced the Telecommunications Cybersecurity and Resilience Act on Thursday, arguing that the new effort was necessary in light of the Salt Typhoon attacks which saw Chinese hackers breach nearly all of the major telecommunications giants in the U.S.
P0
2026-09-24 20:10 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-24 20:25 UTC
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]
P0