2026-09-12 01:50 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-12 02:10 UTC
Anthropic said the users did not succeed in “fielding an operational device” but did carry out a failed test of a guided rocket. The post Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says appeared first on SecurityWeek.
P0
2026-09-11 20:19 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-11 20:20 UTC
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]
P0
2026-09-11 20:00 UTC
Security Journalism
The Record · indexed 2026-09-11 20:20 UTC
The Florida Department of Motor Vehicles confirmed a data breach claimed by the cybercrime group ShinyHunters, saying it originated with the theft of credentials stored on a police officer's personal device.
P0
2026-09-11 19:21 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-11 19:50 UTC
Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.
P0
2026-09-11 19:08 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 19:15 UTC
Bulletin ID: 2026-111-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 12:00 PM PDT Description: Kiro IDE is an agentic development environment that makes it easy for developers to ship real engineering work with the help of AI agents. We identified CVE-2026-89332, where the Kiro agent could modify a workspace's settings file in an untrusted workspace in Kiro IDE. A specially crafted repository could use this to point the Kiro Powers registry URL, which K…
P5
2026-09-11 19:00 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-11 19:05 UTC
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. [...]
P0
2026-09-11 18:44 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-09-11 18:50 UTC
A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.
P0
2026-09-11 18:40 UTC
Security Journalism
The Record · indexed 2026-09-11 17:50 UTC
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.
P0
2026-09-11 18:27 UTC
Security Journalism
Dark Reading · Agam Shah · indexed 2026-09-14 13:20 UTC
The Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities.
P25
2026-09-11 18:14 UTC
Security Journalism
Dark Reading · indexed 2026-09-11 18:35 UTC
Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.
P0
2026-09-11 17:27 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-11 17:40 UTC
Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that advantage disappears quickly when the infrastructure itself is exposed to the public […]
P0
2026-09-11 17:26 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-11 17:35 UTC
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]
P0
2026-09-11 17:23 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-11 17:25 UTC
Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks. The post Phishing Research Challenges Conventional Security Awareness Testing appeared first on SecurityWeek.
P0
2026-09-11 17:10 UTC
Security Journalism
Dark Reading · Tony Anscombe · indexed 2026-09-11 17:50 UTC
Adversaries can manipulate AI's defensive reasoning to silently compromise target networks.
P0
2026-09-11 17:09 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 17:20 UTC
Bulletin ID: 2026-110-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 10:00 AM PDT Description: An issue exists in the the EventStream header decoder in AWS SDK for Go v2 in versions predating 2026-03-23. An actor can send a malformed EventStream response frame containing a crafted header value type byte outside the valid range, which can cause the host process to terminate. Impacted versions: < 2026-03-23 Please refer to the article below for the most u…
P5
2026-09-11 16:37 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 16:40 UTC
Bulletin ID: 2026-109-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:30 AM PDT Description: The AWS Advanced JDBC Wrapper is an open-source library that enhances existing JDBC drivers with AWS-specific capabilities such as Aurora failover, IAM authentication, and automated SQL query caching for applications connecting to Amazon Aurora, RDS MySQL, and RDS MariaDB. We identified CVE-2026-18061, an improper restriction of XML external entity (XXE) refer…
P5
2026-09-11 16:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 17:25 UTC
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
P5
2026-09-11 16:29 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-11 16:40 UTC
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]
P0
2026-09-11 16:15 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 17:25 UTC
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a "teacher" to
P0
2026-09-11 16:11 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-11 16:30 UTC
The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server. The post GitLab Vulnerability Exploited One Day After Disclosure appeared first on SecurityWeek.
P0
2026-09-11 16:10 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-11 16:25 UTC
Bulletin ID: 2026-108-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/11/2026 09:00 AM PDT Description: projen is an open-source tool for defining and synthesizing software project configurations as code. AWS identified two issues in projen affecting the generated file manifest cleanup component and the task synthesis component. - CVE-2026-89065 — Relative path traversal in the generated file manifest cleanup component in projen before 0.101.37 might allow conte…
P5
2026-09-11 15:48 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-09-11 16:05 UTC
From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.
P0
2026-09-11 14:40 UTC
Community
SANS Internet Storm Center · indexed 2026-09-11 14:45 UTC
I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own.
P0
2026-09-11 14:29 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 15:30 UTC
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial
P0
2026-09-11 14:19 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-09-11 14:30 UTC
Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY. The post In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review appeared first on SecurityWeek.
P0
2026-09-11 14:10 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 15:30 UTC
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight
P0
2026-09-11 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Huntress Labs · indexed 2026-09-11 14:10 UTC
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. [...]
P0
2026-09-11 13:35 UTC
Vendor Research
Rapid7 · Brendan Watters · indexed 2026-09-11 14:05 UTC
This One Goes to Sixteen!Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers!New module content (16)Elasticsearch ingest-attachment Apache Tika XFA XXE Local File ReadAuthors: Bourbon Offensive Security Services and Jean-Marie BourbonType: AuxiliaryPull request: #21739 cont…
P100
2026-09-11 13:33 UTC
Vendor Research
Rapid7 · Gal Givon · indexed 2026-09-11 15:05 UTC
IntroductionThe surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal …
P0
2026-09-11 12:48 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-11 12:55 UTC
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking. The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.
P0