2026-09-14 20:52 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-14 20:55 UTC
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]
P5
2026-09-14 20:36 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-14 20:40 UTC
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]
P0
2026-09-14 20:35 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-14 20:45 UTC
Frontier AI is compressing the attack lifecycle from vulnerability discovery to exploitation, forcing defenders to detect, patch and respond at machine speed. Cybersecurity has always been a race between attackers and defenders. ENISA’s latest assessment suggests that frontier AI is changing the speed of that race, and the gap between discovering a vulnerability and exploiting […]
P0
2026-09-14 20:19 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-09-14 20:40 UTC
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.
P5
2026-09-14 19:51 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-14 19:55 UTC
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]
P0
2026-09-14 19:40 UTC
Security Journalism
The Record · indexed 2026-09-14 20:00 UTC
Prosecutors unsealed a 2021 indictment accusing the five men of conducting lucrative romance scams that stole thousands of dollars from more than 100 people.
P0
2026-09-14 19:03 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-14 19:15 UTC
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service. [...]
P0
2026-09-14 18:34 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-14 18:45 UTC
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]
P0
2026-09-14 18:33 UTC
Community
SANS Internet Storm Center · indexed 2026-09-14 18:50 UTC
Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors' "post-AI" patch releases. 
P0
2026-09-14 18:11 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-14 18:45 UTC
China rejects Amodei’s AI slowdown proposal, calling it fearmongering and a US attempt to contain China’s technology sector. The debate over whether the world should slow down the development of advanced AI has quickly turned into something bigger than a technology argument. Dario Amodei, CEO of Anthropic, has called for a slower pace of development, […]
P0
2026-09-14 18:04 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-14 18:10 UTC
Bulletin ID: 2026-112-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/14/2026 10:45 AM PDT Description: Temporary Elevated Access Management (TEAM) is an open source AWS sample solution for managing temporary elevated access via AWS IAM Identity Center. We identified CVE-2026-86830, where an authenticated user with application-level access could gain unintended temporary elevated access to AWS accounts managed by TEAM. Impacted versions:
P5
2026-09-14 18:02 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 17:30 UTC
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit
P0
2026-09-14 18:01 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 19:45 UTC
An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of
P0
2026-09-14 17:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 19:45 UTC
A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to
P0
2026-09-14 17:46 UTC
Vendor Research
AWS Security Blog · Avik Mukherjee · indexed 2026-09-14 18:10 UTC
Amazon Web Services (AWS) is excited to announce the publication of the AWS Security Reference Architecture (AWS SRA) Payment Card Industry (PCI) Data Security Standard (DSS) Deep Dive. This new guide extends the core AWS SRA to provide prescriptive, architecture-level guidance for organizations that store, process, or transmit cardholder data on AWS. Organizations subject to […]
P0
2026-09-14 16:56 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 17:30 UTC
A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU)
P15
2026-09-14 16:41 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-14 17:10 UTC
Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?
P0
2026-09-14 16:15 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-14 16:30 UTC
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]
P0
2026-09-14 16:15 UTC
Security Journalism
The Record · indexed 2026-09-14 16:15 UTC
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.
P0
2026-09-14 16:02 UTC
Security Journalism
The Record · indexed 2026-09-14 16:30 UTC
The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices.
P0
2026-09-14 16:00 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 17:00 UTC
WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin
P0
2026-09-14 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-14 16:20 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco Secure Email Gateway SQL …
P30
2026-09-14 14:51 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-14 15:25 UTC
The managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detection and moved to a world with a convergence of exposure management and response to deliver measurable, outcome-based defenses of a larger, AI-driven attack surface.For anyone evaluating MDR right now, the Managed Detection and Response Services Landscape, Q3 2026 report by Forrester is a useful map that lays out where the market is heading…
P0
2026-09-14 14:40 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 15:35 UTC
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of
P0
2026-09-14 14:28 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-14 14:45 UTC
China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI. The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on SecurityWeek.
P0
2026-09-14 14:08 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-14 14:25 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Two of the above vulnerabilities affect JFrog Artifactory. CVE-2026-42016 can allow attackers to bypass authorization checks and […]
P35
2026-09-14 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Action1 · indexed 2026-09-14 14:15 UTC
Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control. [...]
P0
2026-09-14 13:31 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-14 13:45 UTC
Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims. The post New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate appeared first on SecurityWeek.
P0
2026-09-14 13:03 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-14 13:10 UTC
The company unintentionally disclosed users’ information to a third party impersonating a government agency. The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek.
P0
2026-09-14 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-14 19:45 UTC
Attackers exploit Volume Shadow Copy for credential theft and ransomware defense evasion. See how Huntress spots the difference from routine IT activity.
P15