2026-09-22 17:10 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-22 17:20 UTC
Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/22/2026 10:00 AM PDT Description: Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) is a Serverless Application Repository application that provides Lambda functions for integrating Amazon Connect with Salesforce. We identified CVE-2026-94384, a missing authorization issue in the sfExecuteAWSService Lambda function, which is used only during initial setup. The function dispatche…
P5
2026-09-22 17:03 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver
P0
2026-09-22 16:52 UTC
Government
CERT-EU Security Advisories · indexed 2026-09-22 17:10 UTC
On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.
P30
2026-09-22 16:41 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is
P15
2026-09-22 16:32 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-22 16:40 UTC
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. [...]
P45
2026-09-22 16:14 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 17:55 UTC
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in
P25
2026-09-22 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-22 21:10 UTC
Three changes to the Huntress coding harnesses doubled Claude Fable 5.1’s API recall evaluation accuracy rate.
P0
2026-09-22 15:51 UTC
Security Journalism
The Record · indexed 2026-09-22 16:00 UTC
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access through fraud.
P0
2026-09-22 15:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Threat Intelligence, Microsoft Defender Experts and Microsoft Security Research · indexed 2026-09-22 16:30 UTC
EvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens infrastructure and operations. The post Unmasking EvilTokens: Getting to the root of device code phishing appeared first on Microsoft Security Blog.
P0
2026-09-22 15:00 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-22 15:05 UTC
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [...]
P0
2026-09-22 14:29 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-09-22 14:30 UTC
The data security company received the new investment from Goldman Sachs Alternatives, extending its Series G funding round. The post Cyera Raises $400 Million at $12+ Billion Valuation appeared first on SecurityWeek.
P0
2026-09-22 14:04 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-22 14:10 UTC
The researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Microsoft Defender. The researcher named the exploit BigDiskBuster, it triggers a Denial of Service Vulnerability in Windows Defender Update. The security researcher […]
P25
2026-09-22 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-22 21:10 UTC
AI hasn't changed attacker tradecraft, just the speed. See how Huntress built Athena, an agentic SOC partner, to help analysts keep pace.
P0
2026-09-22 13:26 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-22 13:30 UTC
Abdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse. The post Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity appeared first on SecurityWeek.
P0
2026-09-22 13:10 UTC
Community
SANS Internet Storm Center · indexed 2026-09-17 15:05 UTC
At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company.
P0
2026-09-22 13:05 UTC
Security Journalism
The Record · indexed 2026-09-22 13:20 UTC
Dave Chismon, the NCSC’s chief technology officer for architecture, said in a blog post that the imbalance in AI means cyberattacks would likely grow as automated defenses struggle to keep pace.
P0
2026-09-22 13:00 UTC
Security Journalism
The Record · indexed 2026-09-22 11:40 UTC
Russia’s growing restrictions on mobile internet and cellular service are making it harder for people to receive warnings about incoming Ukrainian drone and missile attacks.
P0
2026-09-22 12:57 UTC
Security Journalism
BleepingComputer · BleepingComputer · indexed 2026-09-22 13:10 UTC
Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. [...]
P0
2026-09-22 12:48 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-22 12:55 UTC
D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. [...]
P30
2026-09-22 12:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 13:40 UTC
Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May
P0
2026-09-22 12:29 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 13:40 UTC
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are
P30
2026-09-22 12:24 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-22 12:30 UTC
Forescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets. The post Only 13% of OT Network Segments Are Fully Isolated: Analysis appeared first on SecurityWeek.
P0
2026-09-22 12:00 UTC
Security Journalism
Dark Reading · indexed 2026-09-22 12:05 UTC
Industrial companies are increasing cybersecurity investment as connected operations, AI adoption, and IT/OT convergence expand operational risk.
P0
2026-09-22 11:55 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-22 12:10 UTC
A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches. The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek.
P0
2026-09-22 11:45 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows. Now in its second year, the harder part of DORA is
P0
2026-09-22 11:38 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC
A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.
P5
2026-09-22 11:33 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-22 11:50 UTC
Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method. The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek.
P0
2026-09-22 11:17 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-22 12:10 UTC
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been
P20
2026-09-22 11:00 UTC
Other
Proofpoint Threat Insight · indexed 2026-09-22 18:05 UTC
P0
2026-09-22 11:00 UTC
Other
Proofpoint Threat Insight · indexed 2026-09-22 18:05 UTC
P0