2026-09-17 21:19 UTC
Vendor Research
AWS Security Blog · Marta Taggart · indexed 2026-09-17 21:40 UTC
European organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can now run generative AI workloads on open weight models on Amazon Bedrock in the AWS European Sovereign Cloud. We’re excited to announce the general availability of the first open weight […]
P0
2026-09-17 21:13 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-02 16:10 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …
P30
2026-09-17 20:36 UTC
Security Journalism
The Record · indexed 2026-09-17 20:55 UTC
The proposal, known as the EU KIDS Act, would block social media platforms from offering accounts to children younger than 13 and establish a bloc-wide minimum age of 15 for account creation.
P0
2026-09-17 20:00 UTC
Vendor Research
Google Security Blog · Maunik Shah · indexed 2026-09-17 20:25 UTC
Security State Library
P5
2026-09-17 19:18 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-17 19:25 UTC
Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/17/2026 12:00 PM PDT Description: AWS IoT Device SDK for Python (AWSIoTPythonSDK) is an open source SDK that lets IoT devices and gateways connect to AWS IoT Core over MQTT. We identified CVE-2026-92943 in the MQTT client TLS connection layer, where the client did not validate that the server certificate matched the AWS IoT Core endpoint hostname. On Python 3.7 and later, an adversary-in-the-m…
P5
2026-09-17 19:15 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-17 19:50 UTC
Amid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.
P0
2026-09-17 18:55 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-17 19:00 UTC
OpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]
P0
2026-09-17 18:08 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw
P10
2026-09-17 18:06 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-17 18:45 UTC
Cyberattacks on oil tankers show how connected ships can expose navigation and critical systems, threatening safety, ports and global trade. U.S. Coast Guard personnel and FBI agents boarded two Texas‑bound energy tankers last month after cyberattacks hit the vessels while they were underway, according to U.S. officials. One of the ships was the VL Prosperity, […]
P0
2026-09-17 18:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · David J. Bianco · indexed 2026-09-17 18:20 UTC
In this week's Threat Source, David talks about why focusing on your security basics is still your best bet, even in a world with rapid AI advancements.
P0
2026-09-17 17:32 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just
P0
2026-09-17 17:25 UTC
Security Journalism
Dark Reading · indexed 2026-09-17 17:25 UTC
drve-dec2026.jpg
P0
2026-09-17 17:11 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-17 17:20 UTC
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]
P0
2026-09-17 17:09 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-17 17:10 UTC
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran. The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first on SecurityWeek.
P0
2026-09-17 17:00 UTC
Vendor Research
Microsoft Security Blog · Ron Pessner · indexed 2026-09-17 18:45 UTC
AI has made fundamental changes to the operating environment for cybersecurity. Explore exposure management guidance on recommended controls and take action and stay ahead of cyberthreats. The post From guidance to action: Security fundamentals that materially reduce risk appeared first on Microsoft Security Blog.
P0
2026-09-17 16:47 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-14 16:20 UTC
A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on the underlying operating system. This vulnerability is due to insufficient validation in the email parsing logic. An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device. A successful exploit could allow the attac…
P5
2026-09-17 16:30 UTC
Security Journalism
The Record · indexed 2026-09-17 16:40 UTC
Alleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.”
P0
2026-09-17 16:00 UTC
Vendor Research
Microsoft Security Blog · Rob Lefferts · indexed 2026-09-17 18:05 UTC
The latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve. The post Improving email security outcomes with real-world Microsoft Defender insights appeared first on Microsoft Security Blog.
P0
2026-09-17 15:45 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-17 15:50 UTC
OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior. The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek.
P0
2026-09-17 15:37 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions
P5
2026-09-17 14:41 UTC
Other
Check Point Research · matthewsu@checkpoint.com · indexed 2026-09-17 15:10 UTC
The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions: models now act as attack operators, an underground […] The post AI Threat Landscape Digest: July–August 2026 appeared first on Check Point Research.
P20
2026-09-17 14:28 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-17 14:30 UTC
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.
P0
2026-09-17 14:16 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-17 14:30 UTC
Hunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefender’s August 2026 SilkParasite report. The work doesn’t dissect malware samples; it maps the network side of the […]
P0
2026-09-17 14:03 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 03:55 UTC
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,
P0
2026-09-17 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Specops Software · indexed 2026-09-17 14:10 UTC
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. [...]
P0
2026-09-17 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-22 07:50 UTC
An incident response plan only works if it’s tested. Learn the 5 pillars of operational resilience and how to turn your plan into muscle memory before an attack hits.
P0
2026-09-17 13:57 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-17 14:10 UTC
Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.
P0
2026-09-17 13:45 UTC
Security Journalism
The Record · indexed 2026-09-17 14:10 UTC
An anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament.
P0
2026-09-17 13:32 UTC
Security Journalism
The Record · indexed 2026-09-17 13:55 UTC
Congressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contributions to high-profile missions against Iran and Venezuela.
P0
2026-09-17 13:09 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 13:15 UTC
Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]
P0