2026-09-01 15:31 UTC
Security Journalism
The Record · indexed 2026-09-01 15:50 UTC
Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.
P0
2026-09-01 15:12 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 15:40 UTC
Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025, […]
P0
2026-09-01 14:45 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-01 15:00 UTC
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
P0
2026-09-01 14:33 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 14:40 UTC
Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast Antivirus. The researcher named the exploit PrettyPrague, it triggers a privilege escalation flaw. The researcher claims to have found […]
P35
2026-09-01 14:28 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 14:30 UTC
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]
P0
2026-09-01 14:07 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 14:45 UTC
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect
P0
2026-09-01 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Spur Intelligence · indexed 2026-09-01 14:15 UTC
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. [...]
P0
2026-09-01 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-08 13:30 UTC
Healthcare organizations and banks handle highly personal information. But a new Huntress survey shows many threat actors frequently target these companies.
P0
2026-09-01 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC
Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…
P0
2026-09-01 13:56 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-01 14:50 UTC
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
P0
2026-09-01 13:50 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 14:40 UTC
Five Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty after trying to steal cash from ATMs in Kansas using the popular ATM jackpotting technique. The U.S. Department of Justice announced the case on August 31, […]
P0
2026-09-01 13:08 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 13:20 UTC
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the
P0
2026-09-01 12:38 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 12:50 UTC
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
P10
2026-09-01 12:33 UTC
Security Journalism
The Record · indexed 2026-09-01 12:50 UTC
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
P0
2026-09-01 12:28 UTC
Security Journalism
The Record · indexed 2026-09-01 12:35 UTC
Andrew Bailey, chair of the Financial Stability Board, called on financial institutions and technology providers to “prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies.”
P0
2026-09-01 12:00 UTC
Vendor Research
Google Security Blog · Eric Lynch · indexed 2026-09-01 12:15 UTC
Checking phone to see image of digital credential
P0
2026-09-01 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 11:50 UTC
The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting
P0
2026-09-01 11:08 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 11:20 UTC
Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The security firm’s investigation documents five confirmed cases in 2026 alone where DPRK-aligned workers, tracked under the name FAMOUS […]
P0
2026-09-01 09:34 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 10:20 UTC
Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Kaspersky Endpoint Security. The researcher named the exploit HardBreacher, it triggers a privilege escalation flaw. Nightmare Eclipse […]
P35
2026-09-01 09:15 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 09:25 UTC
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]
P0
2026-09-01 09:05 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 10:35 UTC
METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external actors attempted to gain unauthorized access to its systems. No sensitive information is believed to
P0
2026-09-01 08:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:55 UTC
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model's (LLM) safety mechanisms and prevent its
P0
2026-09-01 08:13 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 09:05 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578, […]
P50
2026-09-01 07:48 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 08:05 UTC
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]
P25
2026-09-01 07:22 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:00 UTC
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka
P15
2026-09-01 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Four years after the Kaseya supply chain attack, a recent incident shows how threat actors still successfully target MSPs’ downstream customers through RMM software.
P0
2026-09-01 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Exodus crypto wallet analysis by Huntress uncovered tampered installers hiding a modular RAT focused on stealing credentials, not coins.
P0
2026-09-01 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-01 02:10 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-08-31 21:08 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-08-31 21:35 UTC
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
P0
2026-08-31 21:00 UTC
Security Journalism
Huntress · indexed 2026-09-08 13:30 UTC
Bad actors are abusing Faronics Deploy in phishing campaigns to run PowerShell, deploy ScreenConnect, and evade detection by using trusted tools.
P0