2026-10-01 07:49 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 08:55 UTC
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu,
P0
2026-10-01 07:33 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-01 07:35 UTC
On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. [...]
P0
2026-10-01 05:54 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 07:20 UTC
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched iPhones and Macs. The code causes a crash, not an execution error. Turning the memory corruption into a working
P5
2026-10-01 05:32 UTC
Community
SANS Internet Storm Center · indexed 2026-10-01 05:50 UTC
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...
P0
2026-10-01 05:21 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 05:55 UTC
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker
P25
2026-10-01 05:10 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 05:55 UTC
MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet maker said. "At this time, we have identified no immediate threat to MetaMask wallets." MetaMask
P0
2026-10-01 05:00 UTC
Other
Zero Day Initiative · indexed 2026-10-01 19:10 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-50375.
P15
2026-10-01 04:35 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 04:45 UTC
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the exploitation activity across multiple customer environments, said it identified malicious NetScaler
P0
2026-10-01 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-10-01 02:05 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-30 23:43 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-30 23:50 UTC
An FTC spokesperson confirmed the investigation but declined further comment. The post FTC is Investigating OpenAI and Anthropic Over Possible Risks to Consumers appeared first on SecurityWeek.
P0
2026-09-30 22:35 UTC
Security Journalism
The Record · indexed 2026-09-30 22:55 UTC
Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs.
P0
2026-09-30 21:25 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-30 21:40 UTC
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
P0
2026-09-30 20:51 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-30 22:10 UTC
The new White House Accord on so-called "Super Intelligence" calls on companies to implement greater controls and oversight over AI safety.
P0
2026-09-30 20:34 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-30 20:35 UTC
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]
P0
2026-09-30 20:32 UTC
Security Journalism
The Record · indexed 2026-09-30 20:40 UTC
A new study reveals fresh details about how drivers are exposed to a web of large corporations participating in the advertising ecosystem.
P0
2026-09-30 20:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-09-28 15:15 UTC
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) appeared first on Unit 42.
P50
2026-09-30 19:49 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-30 19:55 UTC
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]
P25
2026-09-30 19:35 UTC
Security Journalism
The Record · indexed 2026-09-30 19:55 UTC
An August 31 memo obtained by Recorded Future News shows that the Pentagon's assistant secretary for cyber policy made specific demands of U.S. Cyber Command leadership after reports of a cluster of suicide deaths.
P0
2026-09-30 19:31 UTC
Vendor Research
Microsoft Security Blog · Lindsay Myers · indexed 2026-09-30 21:30 UTC
This year at Microsoft Ignite, we spotlight our AI-first, end-to-end security platform designed to protect identities, devices, data, applications, clouds, infrastructure, and the AI agents now working alongside your teams. The post Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 appeared first on Microsoft Security Blog.
P0
2026-09-30 19:29 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-30 20:15 UTC
WatchGuard fixes 15 Fireware OS flaws, including a critical RCE bug that could give attackers root access to vulnerable Firebox appliances. WatchGuard has released security updates for Fireware OS that address 15 vulnerabilities, including a critical code injection flaw, tracked as CVE-2026-86131 (CVSS score of 9.2), that could allow an attacker to execute commands with […]
P20
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P20
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P0
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P10
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P0
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P15
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P0
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P0
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5