2026-09-09 16:22 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 16:30 UTC
Major chipmakers announced patches for vulnerabilities recently discovered in their products. The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek.
P0
2026-09-09 16:08 UTC
Vendor Research
Cisco Talos Intelligence Blog · Cisco Talos · indexed 2026-09-09 16:30 UTC
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
P0
2026-09-09 15:37 UTC
Security Journalism
The Record · indexed 2026-09-09 15:55 UTC
The first public cybersecurity strategy issued by the FBI "directs our teams, our field offices, our global presence" to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett Leatherman says.
P0
2026-09-09 15:31 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-09 15:35 UTC
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]
P15
2026-09-09 15:16 UTC
Vendor Research
Rapid7 · Conor McCormick · indexed 2026-09-09 16:10 UTC
If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer being right. The traditional answer comes from the outside: the scan engine sends traffic to a range of ports and infers each port's state from how the host responds. That…
P0
2026-09-09 14:39 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-09 15:25 UTC
"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.
P0
2026-09-09 14:33 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 14:50 UTC
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.
P0
2026-09-09 14:23 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 14:40 UTC
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
P0
2026-09-09 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Specops Software · indexed 2026-09-09 14:10 UTC
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]
P0
2026-09-09 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-11 16:45 UTC
Threat actors are exploiting GTA6 hype with fake leaked downloads spread via SEO poisoning, packed with RATs, infostealers, and wiper ransomware. Here’s what Huntress found.
P15
2026-09-09 13:47 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-09 14:50 UTC
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8). The medium-severity flaw affects V8, Google’s open source high-performance […]
P50
2026-09-09 13:07 UTC
Government
CERT-EU Security Advisories · indexed 2026-09-09 13:10 UTC
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication che…
P5
2026-09-09 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-11 16:45 UTC
See how a browser-in-the-browser phishing attack led to rogue ScreenConnect persistence and evasion tactics Huntress caught in the act.
P0
2026-09-09 13:00 UTC
Vendor Research
Tenable Blog · Mark Beblow · indexed 2026-09-09 13:10 UTC
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector.Key takeawaysThe Exchange Inspector combines Tenable’s exposure detection with OpenAI’s GPT Cyber models and with human oversight to rigorously vet submissions made to th…
P0
2026-09-09 12:32 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-09 12:50 UTC
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.
P0
2026-09-09 12:15 UTC
Security Journalism
The Record · indexed 2026-09-09 12:25 UTC
Ukraine’s prosecutor general, Ruslan Kravchenko, resigned this week over allegations that officials in his office took bribes to shield scam call centers from law enforcement.
P0
2026-09-09 12:00 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-09 13:30 UTC
Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek.
P0
2026-09-09 11:57 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 13:00 UTC
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more
P0
2026-09-09 11:17 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 11:40 UTC
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web
P0
2026-09-09 10:49 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 10:50 UTC
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek.
P10
2026-09-09 10:43 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 11:40 UTC
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through
P10
2026-09-09 10:28 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 10:30 UTC
Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek.
P25
2026-09-09 10:11 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-09 10:25 UTC
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]
P0
2026-09-09 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Rem Dudas · indexed 2026-09-09 10:10 UTC
An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42.
P0
2026-09-09 10:00 UTC
Security Journalism
Security Week · Matt Honea · indexed 2026-09-09 10:10 UTC
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek.
P0
2026-09-09 10:00 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-09 10:10 UTC
Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek.
P0
2026-09-09 09:45 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 09:50 UTC
The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek.
P25
2026-09-09 09:32 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 11:40 UTC
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to
P0
2026-09-09 09:11 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 09:30 UTC
Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to
P50
2026-09-09 09:00 UTC
Other
ESET · indexed 2026-09-10 04:40 UTC
AI scams are now hyper-realistic. But there’s one simple way to see through them.
P0