2026-09-08 19:20 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 19:30 UTC
The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities. The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek.
P45
2026-09-08 19:12 UTC
Security Journalism
The Record · indexed 2026-09-08 19:30 UTC
On August 26, the State Department labeled A/I an “extremist group” operating infrastructure for “far-left militants across the world” and announced that anyone engaging with the group financially risked exposure to sanctions.
P0
2026-09-08 18:49 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-08 19:00 UTC
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]
P5
2026-09-08 18:37 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 18:50 UTC
Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code. The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek.
P30
2026-09-08 18:18 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-08 18:20 UTC
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]
P30
2026-09-08 18:09 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-08 18:50 UTC
Researchers built a WeChat worm that spreads through incoming calls without user action. Tencent has blocked the exploit. Researchers at Calif created a WeChat worm that can take over an account through an incoming call, even if the victim never answers or touches the phone. The attack works only when the caller already appears in […]
P0
2026-09-08 18:07 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Research Special Operations · indexed 2026-09-08 18:20 UTC
104Critical860Important0Moderate0LowMicrosoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild.Microsoft patched a record 964 CVEs in its September 2026 Patch Tuesday release, with 104 rated critical and 860 rated as important.This month’s update includes patches for:.NET.NET and Visual StudioASP.NET CoreActive Directory Certificate Services (AD CS)Active Directory Domain Serv…
P65
2026-09-08 17:57 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-08 18:05 UTC
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]
P0
2026-09-08 17:25 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-08 17:35 UTC
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
P0
2026-09-08 17:21 UTC
Vendor Research
Tenable Blog · Eric Doerr · indexed 2026-09-08 17:30 UTC
Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. Tenable One Adversary View, the first innovation planned from this work, will debut in the coming weeks.Key takeawaysClaude Mythos 5 is coming to Tenable One. In addition to using Claude Mythos 5 for researc…
P0
2026-09-08 17:00 UTC
Security Journalism
The Record · indexed 2026-09-08 17:20 UTC
Public negotiations between hackers and the operators of the Liquid Network crypto platform ended with the attackers sending back most — but not all — of what they took.
P0
2026-09-08 17:00 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-08 17:15 UTC
Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions. The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek.
P0
2026-09-08 16:35 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 16:40 UTC
Alleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix. The post Hackers Return $263 Million Stolen From Liquid Network appeared first on SecurityWeek.
P0
2026-09-08 16:35 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-08 17:10 UTC
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. [...]
P0
2026-09-08 16:28 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-08 16:40 UTC
OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. [...]
P0
2026-09-08 16:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 16:50 UTC
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
P0
2026-09-08 15:22 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-08 15:40 UTC
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]
P5
2026-09-08 15:21 UTC
Security Journalism
Security Week · Mike Lennon · indexed 2026-09-08 15:25 UTC
The startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud. The post Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta appeared first on SecurityWeek.
P0
2026-09-08 14:55 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-08 15:00 UTC
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]
P5
2026-09-08 14:55 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 15:05 UTC
Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data. The post SAP Patches Critical Extended Passport Processing Vulnerability appeared first on SecurityWeek.
P0
2026-09-08 14:54 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&
P0
2026-09-08 14:40 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-08 14:45 UTC
OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities. [...]
P25
2026-09-08 14:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel
P0
2026-09-08 14:03 UTC
Security Journalism
The Record · indexed 2026-09-08 14:20 UTC
Two populous states and two large cities are among the U.S. jurisdictions where leaders have taken direct action to address criticisms of automated license plate readers (ALPRs).
P0
2026-09-08 14:00 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-09-08 14:20 UTC
A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.Key takeawaysCVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.Active exploitation of CVE-2026-75650 began on September 4, 2026, t…
P95
2026-09-08 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC
Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…
P35
2026-09-08 13:48 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI
P0
2026-09-08 13:34 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-08 13:35 UTC
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
P30
2026-09-08 13:00 UTC
Other
Check Point Research · stcpresearch · indexed 2026-09-08 13:10 UTC
Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capabilities significantly increase the practical value of LLMs, but they also change the security model: protecting user […] The post The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT appeared f…
P0
2026-09-08 13:00 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-08 13:25 UTC
The scammers purchased fleets of sports cars, flew on private jets, hired security guards and rented mansions in Miami and the Hamptons. The post Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft appeared first on SecurityWeek.
P0