2026-09-24 12:16 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-24 12:25 UTC
Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]
P0
2026-09-24 12:05 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 12:15 UTC
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name "com.corp.mdm" Corp MDM
P0
2026-09-24 11:39 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-09-24 11:45 UTC
The enterprise security firm has raised more than $1 billion since its launch in 2020; Evolution Equity Partners led the latest funding round. The post Island Raises $400 Million at $6.4 Billion Valuation appeared first on SecurityWeek.
P0
2026-09-24 11:05 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-24 11:25 UTC
Revision 4 of NIST’s operational technology security guide is open for public comments until November 30. The post OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators appeared first on SecurityWeek.
P0
2026-09-24 11:00 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 12:15 UTC
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI
P0
2026-09-24 11:00 UTC
Security Journalism
Security Week · Nadir Izrael · indexed 2026-09-24 11:05 UTC
Agentic remediation is not an act of faith. We are talking about fixing known problems, not judgment calls about unfamiliar risk. The post Begin at the End: How to Enable Agentic Remediation appeared first on SecurityWeek.
P0
2026-09-24 10:42 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-24 10:45 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]
P15
2026-09-24 10:40 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-24 10:45 UTC
The vulnerabilities, tracked as CVE-2026-28324 and CVE-2026-28325, can be exploited without authentication. The post SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted appeared first on SecurityWeek.
P20
2026-09-24 10:31 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-24 11:45 UTC
OpenAI’s AI agent bypassed controls on an Australian health portal, accessed non-public files and triggered a government investigation. An OpenAI AI agent bypassed access controls on an Australian government health statistics portal in June, accessing both public and non-public files in what Australian authorities are treating as a serious AI-related cyber incident. The case was […]
P0
2026-09-24 09:56 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-24 10:05 UTC
Hackers impersonated the company’s personnel and contacted its employees to gain access to Astrana Health’s servers. The post Astrana Health Data Breach Impacts Private, Confidential Information appeared first on SecurityWeek.
P0
2026-09-24 09:38 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-24 09:45 UTC
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. [...]
P0
2026-09-24 09:14 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 11:05 UTC
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense. Read
P0
2026-09-24 09:00 UTC
Other
ESET · indexed 2026-09-25 12:20 UTC
Crypto ATM scams often follow a predictable script – here’s how to recognize it and what to do if you’ve already been caught out
P0
2026-09-24 08:38 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-24 08:45 UTC
Karen Vardanyan has also been ordered to pay over $1.2 million in restitution to victims. The post US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks appeared first on SecurityWeek.
P15
2026-09-24 08:14 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-24 08:25 UTC
Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. [...]
P5
2026-09-24 07:12 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-24 07:30 UTC
Tracked as CVE-2026-87902, the path traversal flaw allows remote, unauthenticated attackers to execute arbitrary code. The post Critical WordPress Vulnerability Exploited Immediately After Disclosure appeared first on SecurityWeek.
P5
2026-09-24 07:07 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 08:35 UTC
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal
P0
2026-09-24 06:32 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 08:35 UTC
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses. "The campaign compromised 7 accounts –
P0
2026-09-24 06:25 UTC
Community
SANS Internet Storm Center · indexed 2026-09-24 06:45 UTC
Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:
P0
2026-09-24 06:24 UTC
Other
Group-IB · indexed 2026-09-24 09:10 UTC
One employee reaches a phishing page. The tab closes, the domain is blocked for every browser in the company, and the targeted password is already being reset. The new Group-IB Browser Agent brings the corporate browser under XDR coverage, checking every page against predictive Threat Intelligence in real time.
P0
2026-09-24 05:44 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-24 05:50 UTC
Cisco Talos finds CLOSEDQUORUM, malware that lets four commercial AI models vote on its next move, with no human operator required. Cisco Talos found malware, dubbed CLOSEDQUORUM, that holds a vote before deciding what to steal from you. Four AI models vote on its next move, without any human interaction. CLOSEDQUORUM is the first Windows […]
P0
2026-09-24 05:36 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-24 08:35 UTC
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file
P20
2026-09-24 03:50 UTC
Community
SANS Internet Storm Center · indexed 2026-09-24 04:10 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-24 01:00 UTC
Vendor Research
Google Security Blog · Michał Bentkowski · indexed 2026-09-24 13:45 UTC
Security landscape in 2026The application of Large Language Models (LLMs) to security scanning has revolutionized the vulnerability management landscape. But, it has als…
P0
2026-09-23 23:07 UTC
Vendor Research
AWS Security Blog · Rodolfo Brenes · indexed 2026-09-23 23:25 UTC
Read all about the latest AWS security features, compliance updates, and hands-on resources in our monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts August brought 20 AWS Security Blog posts organized across seven categories. Identity and access management led the month with five posts […]
P0
2026-09-23 22:46 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-23 22:50 UTC
The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. [...]
P0
2026-09-23 22:29 UTC
Security Journalism
Dark Reading · George V. Hulme, Contributing Writer · indexed 2026-09-24 13:05 UTC
Enterprise computing is moving to the edge. Keeping it secure requires tactics far beyond putting up firewalls. (Second in a three-part series.)
P0
2026-09-23 21:25 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-23 21:40 UTC
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]
P0
2026-09-23 21:03 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-23 21:10 UTC
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
P0
2026-09-23 20:53 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-09-23 20:55 UTC
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
P0