2026-09-24 19:17 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-24 19:35 UTC
Bulletin ID: 2026-118-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 12:00 PM PDT Description: pgcollection is an open source extension to PostgreSQL. We identified CVE-2026-96883, an issue in pgcollection's type coercion logic. When requesting a stored icollection value as a type incompatible with how it was actually stored causes the extension to misinterprets the datum's representation, allowing an authenticated database user to crash the PostgreSQL …
P20
2026-09-24 18:57 UTC
Security Journalism
The Record · indexed 2026-09-24 19:15 UTC
Ardit Kutleshi, 28, was extradited from his home country of Kosovo last year after prosecutors accused him and his older brother of running Rydox — an illicit platform used by cybercriminals to sell stolen personal information, illegal access to devices and other tools for carrying out fraud.
P0
2026-09-24 18:16 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-24 19:20 UTC
MikroTrick chains two RouterOS flaws to bypass authentication and gain admin access. AI helped researchers uncover the attack chain within days. MikroTik pushed out patches on September 3, 2026 for several RouterOS issues at once, calling it an important security update without saying what it actually fixed. That silence was deliberate, and it didn’t last […]
P5
2026-09-24 18:10 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 19:00 UTC
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not
P0
2026-09-24 18:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Martin Lee · indexed 2026-09-24 18:30 UTC
In this week’s newsletter Martin muses over a very suspicious elicitation over social media and the true value of trust within the cyber ecosystem. Hubris might be the real vulnerability that the cyber industry must worry about.
P0
2026-09-24 17:52 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 19:00 UTC
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just
P0
2026-09-24 17:47 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-24 17:55 UTC
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]
P0
2026-09-24 17:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-24 18:00 UTC
Bulletin ID: 2026-117-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/24/2026 10:00 AM PDT Description: Kiro is an agentic IDE that users install on their desktop. We identified CVE-2026-95985. The file write tool in Kiro IDE before version 1.0.242 might allow remote unauthenticated actors to execute arbitrary commands and to inject crafted instructions into the agent's context. When a user runs the agent in a crafted repository as an untrusted workspace, sendin…
P5
2026-09-24 17:16 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow a remote attacker to access or manipulate data, obtain sensitive information, or cause a reload of certificate and key material on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilit…
P15
2026-09-24 16:00 UTC
Vendor Research
Microsoft Security Blog · Alym Rayani · indexed 2026-09-24 18:00 UTC
This month's updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations. The post What’s new in Microsoft Security: September 2026 appeared first on Microsoft Security Blog.
P0
2026-09-24 16:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-24 18:00 UTC
Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect and disrupt this activity before ransomware deployment. The post Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments appeared first on Microsoft Security Blog.
P15
2026-09-24 15:52 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-24 16:00 UTC
The startup’s runtime enforcement platform evaluates AI agents in real time to provide visibility and control over their actions. The post Kontext Security Emerges With $4 Million for AI Agent Runtime Controls appeared first on SecurityWeek.
P0
2026-09-24 15:27 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 16:35 UTC
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays," Manifold Security's Head of Research, Ax Sharma, said. "Unlike 'example[.]com,' third-party[.]com
P0
2026-09-24 15:00 UTC
Vendor Research
Cloudflare Security · Rushil Mehra · indexed 2026-09-25 00:05 UTC
External security researchers at Accomplish identified a vulnerability in Cloudflare Containers that could expose residual disk data from previous workloads. We explain how the issue worked, how we investigated it, and the steps we took to remediate it.
P0
2026-09-24 14:44 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-09-24 15:45 UTC
This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
P15
2026-09-24 14:43 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-24 14:45 UTC
Australia disclosed that an OpenAI agent gained unauthorized access to non-public government information. The post OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data appeared first on SecurityWeek.
P0
2026-09-24 14:29 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 15:10 UTC
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the
P0
2026-09-24 14:02 UTC
Security Journalism
Dark Reading · George V. Hulme, Contributing Writer · indexed 2026-09-24 14:30 UTC
Securing edge computing requires organizations to fundamentally rethink security governance. This step-by-step guide to building a SASE framework provides the path forward. (Third in a three-part series.)
P0
2026-09-24 14:02 UTC
Security Journalism
BleepingComputer · Sponsored by Anecdotes · indexed 2026-09-24 14:15 UTC
FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]
P0
2026-09-24 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-24 15:25 UTC
Managed ISPM now offers two deployment modes. Choose fully automated hardening or full control over which Microsoft 365 controls roll out, and when. See how it works.
P0
2026-09-24 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-24 15:25 UTC
Introduction The landscape of software supply chain security has undergone a significant shift. Recent campaigns demonstrate that sophisticated threat actors are systematically targeting the engineering lifecycle by compromising trusted security and programming tools. These intrusions reveal three key tactics: Attackers target trusted security scanners, utility libraries, and AI developer tools to exploit the elevated privileges granted to these systems within build pipelines. Adversaries targe…
P0
2026-09-24 13:30 UTC
Security Journalism
The Record · indexed 2026-09-24 13:50 UTC
At least four internet providers serving Kyiv and other parts of Ukraine suffered partial connectivity losses following Wednesday’s drone attack, according to internet monitoring group NetBlocks.
P0
2026-09-24 13:30 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-24 13:35 UTC
Even if the organization locks down employee accounts, forgotten and lost service accounts can still undo the organization's entire M365 environment.
P0
2026-09-24 13:27 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-24 13:35 UTC
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]
P45
2026-09-24 13:15 UTC
Security Journalism
The Record · indexed 2026-09-24 13:35 UTC
The healthcare firm Astrana warned regulators that hackers accessed confidential information by impersonating company personnel.
P0
2026-09-24 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-24 15:25 UTC
Threat actors exploited Samsung MagicINFO to install AnyDesk, disable Defender, and compile a Monero miner directly on a victim endpoint. Learn the detection signals.
P0
2026-09-24 13:00 UTC
Vendor Research
Rapid7 · Douglas McKee, Director, Vulnerability Intelligence · indexed 2026-09-24 13:20 UTC
Business Email Compromise (BEC) operates on a familiar playbook. Threat actors breach a mailbox, silently monitor operations, map approval chains, and ultimately exploit that access to divert funds or exfiltrate sensitive assets.This dynamic is central to our analysis as we kick off a series around Rapid7's collaborative research with Zimbra; upcoming installments will explore technical details and broader findings based within the Zimbra Collaboration Suite. Our investigation disrupted the tra…
P70
2026-09-24 13:00 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-24 13:05 UTC
AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage.
P0
2026-09-24 12:48 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-24 13:05 UTC
A threat actor is using three AI harnesses for vulnerability research, exploitation, and attack orchestration. The post AI-Powered Campaign Targets Hundreds of Online Retailers appeared first on SecurityWeek.
P0
2026-09-24 12:30 UTC
Security Journalism
The Record · indexed 2026-09-24 12:35 UTC
An OpenAI agent gained “unauthorized access” to “non-public files” from an Australian government health website in June, Prime Minister Anthony Albanese said.
P0