2026-09-17 08:24 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 08:30 UTC
Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]
P5
2026-09-17 08:00 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG
P0
2026-09-17 07:53 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-17 07:55 UTC
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses appeared first on SecurityWeek.
P0
2026-09-17 07:41 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-17 07:55 UTC
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.
P0
2026-09-17 07:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links. Helpfeel said
P0
2026-09-17 07:25 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-17 08:00 UTC
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]
P0
2026-09-17 07:20 UTC
Other
Group-IB · indexed 2026-09-17 08:35 UTC
Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.
P0
2026-09-17 07:20 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 07:25 UTC
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
P50
2026-09-17 06:39 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker
P30
2026-09-17 06:19 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-17 06:35 UTC
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.
P25
2026-09-17 05:59 UTC
Other
Group-IB · indexed 2026-09-17 08:35 UTC
Most fraud platforms only see a threat once it becomes a transaction. This guide compares the top 5 fraud prevention platforms for banks and fintechs in 2026, including Group-IB, Feedzai, Sift, DataVisor, and Kount, and what actually separates them.
P0
2026-09-17 05:13 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the sites are now greeted by a seizure banner that states - "This domain has been seized by
P0
2026-09-17 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-17 14:55 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91826.
P20
2026-09-17 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-17 02:15 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-17 00:35 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-17 00:45 UTC
Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]
P0
2026-09-16 21:26 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-16 22:00 UTC
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
P0
2026-09-16 21:20 UTC
Vendor Research
AWS Security Blog · Pablo Pagani · indexed 2026-09-16 21:50 UTC
The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AWS partition (aws-eusc), with its own control plane, AWS Identity and […]
P0
2026-09-16 21:07 UTC
Security Journalism
The Record · indexed 2026-09-16 21:30 UTC
“It's really complicated, and I wouldn't want to do something in a lame duck session to do it quickly and not get it right,” said House Energy and Commerce Chairman Brett Guthrie about the FRONTIER Act.
P0
2026-09-16 20:39 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-16 20:50 UTC
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]
P5
2026-09-16 20:24 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 20:35 UTC
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]
P0
2026-09-16 20:20 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-16 21:00 UTC
Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control […]
P0
2026-09-16 20:16 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-16 20:20 UTC
Bulletin ID: 2026-113-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/16/2026 12:30 PM PDT Description: Network Policy Agent is an EKS Policy management feature. We identified CVE-2026-86831, a cross-namespace NetworkPolicy bypass in Amazon EKS Network Policy Agent (aws-network-policy-agent) before v1.4.0. Pod identifiers are constructed by concatenating the pod name and namespace with a hyphen delimiter, which is a legal character in both Kubernetes pod names a…
P5
2026-09-16 18:50 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 19:00 UTC
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]
P0
2026-09-16 18:46 UTC
Security Journalism
The Record · indexed 2026-09-16 19:05 UTC
U.S. personnel boarded an oil tanker in the Gulf of Mexico to “ensure integrity of the vessel’s operational and information technology systems," after an apparent cyberattack, the U.S. Coast Guard said.
P0
2026-09-16 18:44 UTC
Community
SANS Internet Storm Center · indexed 2026-09-16 19:00 UTC
Earlier today, I noted an odd request showing up in our "First Seen" report:
P0
2026-09-16 18:28 UTC
Security Journalism
The Record · indexed 2026-09-16 18:35 UTC
The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped to properly investigate them.
P0
2026-09-16 18:14 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-09-16 18:25 UTC
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge …
P0
2026-09-16 18:00 UTC
Security Journalism
Dark Reading · Dark Reading Editorial Team · indexed 2026-09-16 18:20 UTC
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.
P0
2026-09-16 17:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 17:45 UTC
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
P0
2026-09-16 17:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 17:30 UTC
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
P0