2026-09-11 12:45 UTC
Security Journalism
The Record · indexed 2026-09-11 12:55 UTC
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.
P0
2026-09-11 12:00 UTC
Security Journalism
The Record · indexed 2026-09-11 12:10 UTC
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.
P15
2026-09-11 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 13:50 UTC
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker
P10
2026-09-11 11:29 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-11 11:35 UTC
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023. The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appeared first on SecurityWeek.
P15
2026-09-11 11:15 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-11 11:25 UTC
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]
P5
2026-09-11 11:10 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-11 11:15 UTC
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution. The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek.
P20
2026-09-11 10:56 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-11 11:15 UTC
Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars. The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek.
P0
2026-09-11 10:14 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-11 10:55 UTC
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run […]
P30
2026-09-11 09:41 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-11 09:45 UTC
A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors. The post Surfshark Systems Targeted by Hackers appeared first on SecurityWeek.
P0
2026-09-11 09:39 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-11 09:40 UTC
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]
P0
2026-09-11 08:47 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-11 09:05 UTC
Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model. The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek.
P0
2026-09-11 08:18 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-11 08:25 UTC
A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide. The post PaperCut Flaws Exploited in AI-Powered Attacks appeared first on SecurityWeek.
P0
2026-09-11 07:55 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-11 08:10 UTC
Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]
P0
2026-09-11 07:31 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.
P0
2026-09-11 07:14 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns
P0
2026-09-11 07:11 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-11 07:45 UTC
A critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and enabled Active Directory theft. On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecting council services. Hunt.io has since published a detailed technical analysis linking […]
P20
2026-09-11 06:48 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-11 06:55 UTC
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
P15
2026-09-11 06:46 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that
P25
2026-09-11 06:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass
P30
2026-09-11 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-11 02:05 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-11 01:00 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-11 01:15 UTC
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
P0
2026-09-10 21:40 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-10 21:45 UTC
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]
P15
2026-09-10 21:15 UTC
Security Journalism
The Record · indexed 2026-09-10 21:30 UTC
As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers.
P0
2026-09-10 20:36 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-10 21:00 UTC
Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
P0
2026-09-10 20:34 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 20:45 UTC
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. [...]
P5
2026-09-10 20:30 UTC
Security Journalism
Security Week · Mike Lennon · indexed 2026-09-10 20:40 UTC
Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board. The post Mandiant Founder Kevin Mandia Joins Amazon Board appeared first on SecurityWeek.
P0
2026-09-10 19:15 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-10 19:30 UTC
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. [...]
P0
2026-09-10 19:07 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 19:15 UTC
Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. [...]
P5
2026-09-10 18:57 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-10 19:25 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20079 (CVSS score of 10.0) is an authentication bypass issue. The flaw resides in Cisco Secure […]
P45
2026-09-10 18:55 UTC
Security Journalism
The Record · indexed 2026-09-10 19:00 UTC
A notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected.
P0