2026-09-04 07:02 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-04 07:55 UTC
FBI probes suspected breach at IDScan.net after dark web service Nexus offered 153M+ US and Canadian driver’s license scans. A dark web identity theft service called Nexus appeared on September 1, 2026, offering searchable access to more than 153 million scanned driver’s licenses belonging to people in the United States and Canada. The FBI’s New […]
P0
2026-09-04 06:57 UTC
Other
Group-IB · indexed 2026-09-07 17:30 UTC
Fusion is a capability you mature into, not a team you hire. Here is the honest maturity path, the metrics that fund it, and the on-ramp that costs no headcount, startable this quarter.
P25
2026-09-04 06:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-04 08:40 UTC
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering,
P0
2026-09-04 04:00 UTC
Security Journalism
The Record · indexed 2026-09-04 18:45 UTC
Amir Yaryab is the leader of the IRGC's cyber unit and oversees hacker groups such as the CyberAv3ngers, the State Department said in posting a reward for information about him.
P0
2026-09-04 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-04 02:15 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-03 22:01 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-03 22:10 UTC
France's data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients' and their relatives' data. [...]
P0
2026-09-03 21:22 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Huntress breaks down what managed EDR is, how it differs from unmanaged, and what to look for when choosing a provider for your business.
P0
2026-09-03 21:15 UTC
Vendor Research
AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC
In Part 1 of this guide, we examined two common incident scenarios: cross-account Amazon Simple Storage Service (Amazon S3) data deletion with ransomware implications, and cryptocurrency mining deployed through AWS CloudFormation using exposed AWS Management Console credentials. We also introduced key incident response terminology and investigative frameworks for analyzing AWS CloudTrail events. In this second […]
P15
2026-09-03 21:15 UTC
Vendor Research
AWS Security Blog · Oscar Diaz · indexed 2026-09-03 21:35 UTC
AWS CloudTrail logs contain the evidence you need when investigating suspicious activity in your AWS environment, but knowing which fields matter and how to interpret them can mean the difference between surface-level analysis and uncovering the full scope of an incident. This guide walks you through real-world scenarios, showing you how to analyze CloudTrail events […]
P0
2026-09-03 21:03 UTC
Vendor Research
Cloudflare Security · Ken Sanderson · indexed 2026-09-03 21:05 UTC
Use production traffic and security signals to prioritize findings, prepare edge mitigations when safe, and propose code patches. By combining WAF data with OpenAI Daybreak models, Vulnerability Discovery and Remediation helps teams identify and patch the most critical threats first.
P0
2026-09-03 20:18 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-03 20:45 UTC
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
P0
2026-09-03 20:17 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-03 20:25 UTC
Serbian activists were targeted with zero-click Pegasus and NoviSpy spyware, exposing a major surveillance campaign ahead of elections. A member of Serbia’s student protest movement had their iPhone infected with NSO Group‘s Pegasus spyware without ever clicking a link or opening a file. The Citizen Lab confirmed the infection in collaboration with the SHARE Foundation, […]
P0
2026-09-03 20:04 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-03 20:15 UTC
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]
P0
2026-09-03 19:47 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-03 20:25 UTC
Cisco patched a critical Nexus 9000 vulnerability, CVE-2026-20212, allowing unauthenticated remote root code execution. Cisco has released patches for a critical flaw, tracked as tracked as CVE-2026-20212 (CVSS score of 9.8) in 10 Silicon One-based Nexus 9000 switches. The vulnerability could let an unauthenticated remote attacker execute code with root privileges. Cisco’s Technical Assistance Center […]
P30
2026-09-03 19:42 UTC
Security Journalism
Dark Reading · Rob Wright, Alexander Culafi · indexed 2026-09-03 20:15 UTC
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.
P0
2026-09-03 19:30 UTC
Security Journalism
The Record · indexed 2026-09-03 19:45 UTC
At least 14 Serbians have been targeted with advanced spyware since December, with victims including a member of Parliament, a local opposition politician and student protesters, according to digital forensic researchers.
P0
2026-09-03 18:28 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-03 18:35 UTC
Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. [...]
P25
2026-09-03 18:02 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 19:15 UTC
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also
P0
2026-09-03 18:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Hazel Burton · indexed 2026-09-03 18:05 UTC
From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel.
P0
2026-09-03 17:23 UTC
Security Journalism
Dark Reading · James Lyne · indexed 2026-09-04 17:45 UTC
The recent open letter is right about the "window," but it omits naming who is coming through it or, critically, who will close it.
P0
2026-09-03 16:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Noam Kochavi and Sarah Wolstencroft · indexed 2026-09-03 16:45 UTC
Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog.
P0
2026-09-03 15:52 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version. The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is
P5
2026-09-03 15:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial
P0
2026-09-03 15:22 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-03 15:35 UTC
Microsoft says a known issue that reverts mouse settings after installing the KB5120998 August 2026 preview update affects only non-English Windows 11 systems. [...]
P0
2026-09-03 15:13 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-03 15:25 UTC
ChatGPT and Codex are experiencing a major outage, with users reporting errors across nearly every major ChatGPT feature. [...]
P0
2026-09-03 15:02 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-03 15:10 UTC
Claude is experiencing an outage, with users encountering elevated errors when sending requests to multiple Anthropic AI models. [...]
P0
2026-09-03 14:52 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-03 14:55 UTC
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. [...]
P35
2026-09-03 14:39 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
P0
2026-09-03 14:38 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-03 15:00 UTC
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.
P0
2026-09-03 13:50 UTC
Security Journalism
BleepingComputer · Sponsored by Flare · indexed 2026-09-03 14:00 UTC
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]
P0