2026-09-02 10:16 UTC
Other
Check Point Research · stcpresearch · indexed 2026-09-07 17:30 UTC
Research by: Amit Yardeni Key Points Introduction Since mid-2025, Check Point Research has tracked a sustained campaign against Brazilian organizations. The tradecraft points to a Chinese-speaking cybercrime group connected to Earth Berberoka, an actor first documented targeting gambling sites across Asia. Once inside a victim, the group deploys a broad Linux toolkit: a custom downloader, several backdoors, […] The post Gaming the system: how a Chinese-speaking actor turned Brazilian government…
P0
2026-09-02 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Renzon Cruz, Nicolas Bareil, Eric Semaan and Omar Jbari · indexed 2026-09-02 10:25 UTC
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first on Unit 42.
P0
2026-09-02 09:18 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 09:40 UTC
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in versions 4.4.12 and 4.2.17 on July 8, 2026, and published the vulnerability details on August 31. GeoNetwork originated at the United Nations Food and
P15
2026-09-02 09:10 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 09:40 UTC
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in 2016 and 2017. Searzhudin Tamirlanovich Aktulaev, 40, was arrested in Cyprus in May 2025, the U.S. Attorney's Office for the Northern District of California
P0
2026-09-02 09:06 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-02 09:15 UTC
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]
P0
2026-09-02 08:00 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-02 08:15 UTC
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]
P0
2026-09-02 07:58 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-02 08:30 UTC
Hackers are exploiting a critical Langflow flaw that lets unauthenticated attackers remotely execute Python code on vulnerable systems. Hackers have started exploiting a critical vulnerability, tracked as CVE-2026-0768 (CVSS score of 9.8), in the AI-focused low-code platform Langflow. The flaw affects the code validator in Langflow’s custom component editor, it impacts all Langflow versions up […]
P15
2026-09-02 07:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 08:00 UTC
Forescout Research - Vedere Labs said it used Anthropic's Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcode on live hardware. The exploit targets CVE-2021-31886, a stack-based buffer overflow in the Nucleus FTP server's handling of the USER command
P20
2026-09-02 07:08 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 08:00 UTC
Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers to remotely execute arbitrary code as
P20
2026-09-02 06:56 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-02 08:00 UTC
The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authorities from the U.S., Bulgaria, Hungary, and Romania, in collaboration with private industry partners CrowdStrike and the Shadowserver Foundation. To that
P0
2026-09-02 06:39 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-02 06:40 UTC
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]
P40
2026-09-02 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-02 02:20 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-02 01:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-09-02 01:15 UTC
Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.
P0
2026-09-02 00:00 UTC
Government
CERT-FR Alerts · indexed 2026-09-07 17:35 UTC
Le 01 septembre 2026, SonicWall a publié un avis de sécurité concernant deux vulnérabilités affectant les Secure Mobile Access (SMA) 1000. La vulnérabilité critique CVE-2026-83548 permet une falsification de requêtes côté serveur (SSRF) de la part d'un attaquant non authentifié. La vulnérabilité...
P5
2026-09-01 22:48 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Microsoft Defender Experts and Parth Jomadkar · indexed 2026-09-01 23:55 UTC
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections, indicators of compromise, and practical mitigations to help organizations identify, block, and respond to this threat. The post Counterfeit installers to system compromise: Tracking a deceptive software download campaign appeared first on Microsoft Security B…
P0
2026-09-01 22:40 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-09-01 23:05 UTC
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) toda…
P0
2026-09-01 21:30 UTC
Community
SANS Internet Storm Center · indexed 2026-09-01 00:50 UTC
Introduction
P0
2026-09-01 21:05 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-01 21:35 UTC
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.
P15
2026-09-01 21:03 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-09-01 21:05 UTC
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
P15
2026-09-01 20:53 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-01 20:55 UTC
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
P0
2026-09-01 20:48 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-09-01 21:05 UTC
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.
P5
2026-09-01 20:35 UTC
Security Journalism
The Record · indexed 2026-09-01 20:50 UTC
A hacking operation dubbed Fire Ant "didn’t just compromise systems," according to researchers. "It compromised the trust layer those systems depend on."
P0
2026-09-01 20:13 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-01 20:50 UTC
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
P0
2026-09-01 19:28 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-01 19:30 UTC
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]
P0
2026-09-01 18:55 UTC
Vendor Research
Microsoft Security Blog · Microsoft Defender Experts Cybersecurity Incident Response · indexed 2026-09-01 20:15 UTC
Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog.
P0
2026-09-01 17:54 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-01 18:00 UTC
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]
P20
2026-09-01 17:53 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 18:15 UTC
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. "JFrog Artifactory contains an authentication weakness that, under default
P15
2026-09-01 17:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 18:15 UTC
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers." The adversary
P0
2026-09-01 17:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
New regulations, data exfiltration tactics, and shifting premiums are reshaping cyber insurance. Our 2026 report reveals what businesses need to know now.
P0
2026-09-01 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Understand the critical role of cyber insurance in safeguarding your business from cyber threats. Learn how this coverage can protect your assets.
P0