2026-09-10 18:44 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-10 19:00 UTC
Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT Description: AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances, on-premises servers, and other supported machines) and processes requests from the AWS Systems Manager service, enabling capabilities including Session Manager port forwarding to remote hosts. We identified CVE-2026-89049, a server-side request forgery issue in the rem…
P5
2026-09-10 18:25 UTC
Security Journalism
The Record · indexed 2026-09-10 18:45 UTC
Ronzelle Green, most recently a senior official at the National Geospatial-Intelligence Agency, will be U.S. Cyber Command's chief AI officer.
P0
2026-09-10 18:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Joe Marshall · indexed 2026-09-10 18:30 UTC
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.
P0
2026-09-10 17:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 19:00 UTC
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already
P0
2026-09-10 17:23 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research · indexed 2026-09-10 19:15 UTC
Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security Blog.
P0
2026-09-10 17:13 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-10 17:25 UTC
Bulletin ID: 2026-106-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 10:00 AM PDT Description: Deep Java Library (DJL) is an open-source, engine-agnostic Java framework for deep learning, developed and maintained by Amazon. AWS identified CVE-2026-85228, an integer overflow in the tensor buffer validation component of DJL on all platforms. A crafted tensor payload declaring a shape whose computed byte size exceeds the 32-bit signed integer range causes …
P5
2026-09-10 16:14 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-10 16:25 UTC
Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa. The post Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 appeared first on SecurityWeek.
P0
2026-09-10 16:00 UTC
Vendor Research
Microsoft Security Blog · Rob Lefferts · indexed 2026-09-10 18:15 UTC
See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.
P0
2026-09-10 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn what credential theft is, how attackers steal credentials, and how to prevent credential-based attacks with identity-focused defenses from Huntress.
P0
2026-09-10 15:55 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-10 16:10 UTC
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]
P0
2026-09-10 15:43 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 15:55 UTC
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]
P15
2026-09-10 15:29 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-10 16:00 UTC
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
P25
2026-09-10 15:19 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-10 16:25 UTC
AI agents are gaining real-world access faster than safeguards can mature, making permissions, isolation and oversight critical to prevent harmful actions. Jacob Coxon, a researcher who spent three years working on model training at OpenAI and later Anthropic, left Anthropic this week with a blunt warning: AI companies are moving toward increasingly capable systems faster […]
P0
2026-09-10 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-11 16:45 UTC
Learn what endpoint hardening is, why it matters, and best practices to reduce attack surface, control access, & stop common intrusion paths.
P0
2026-09-10 14:55 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 15:00 UTC
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. [...]
P0
2026-09-10 14:52 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-10 15:10 UTC
Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns. The post Anthropic Researcher Resigns With Warning About the Dangers of AI Development appeared first on SecurityWeek.
P0
2026-09-10 14:36 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 14:45 UTC
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their
P0
2026-09-10 14:32 UTC
Other
Check Point Research · shlomoo@checkpoint.com · indexed 2026-09-10 14:50 UTC
Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. An LLM with limited […] The post PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector appeared first on Check Point…
P0
2026-09-10 14:30 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-10 14:50 UTC
Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox. The post Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster appeared first on SecurityWeek.
P0
2026-09-10 14:11 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-10 14:15 UTC
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]
P25
2026-09-10 14:00 UTC
Security Journalism
BleepingComputer · Sponsored by Prophet Security · indexed 2026-09-10 14:15 UTC
Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. [...]
P0
2026-09-10 13:39 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-10 13:50 UTC
Deceptive apps in Early Access are being used by dishonest developers for their own benefit. The post Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews appeared first on SecurityWeek.
P0
2026-09-10 13:31 UTC
Security Journalism
The Record · indexed 2026-09-10 13:50 UTC
Wildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to track and withdraw their earnings.
P0
2026-09-10 13:30 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-09-10 13:50 UTC
Join the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT operations accelerate. The post Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation appeared first on SecurityWeek.
P0
2026-09-10 13:21 UTC
Other
Proofpoint Threat Insight · indexed 2026-09-10 09:20 UTC
P0
2026-09-10 13:00 UTC
Vendor Research
Cloudflare Security · Sebastiaan Neuteboom · indexed 2026-09-10 13:30 UTC
1.1.1.1 now validates DNSSEC signatures using NIST’s post-quantum ML-DSA-44 algorithm. Here is how we manage 2,420-byte signatures and downgrade risks at scale.
P0
2026-09-10 13:00 UTC
Vendor Research
Tenable Blog · Raj Agrawal · indexed 2026-09-10 13:05 UTC
Learn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environmentKey takeawaysAI models can quickly understand data, but not your business. While modern AI models are great at reasoning, they don’t automatically understand your unique environment or who is allowed to do what. The “harness” is the custom-built layer that translates AI intelligence into safe, controlled actions spec…
P25
2026-09-10 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See this year's most common passwords, why they're so easy to crack, and how a stronger password (or passphrase) habit keeps your accounts protected.
P0
2026-09-10 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
The top password statistics might surprise you. Learn how common poor password hygiene is, plus tips to better protect your precious credentials.
P0
2026-09-10 12:58 UTC
Community
SANS Internet Storm Center · indexed 2026-09-10 13:05 UTC
[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
P0