2026-09-30 13:16 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-30 13:30 UTC
WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS. The post WatchGuard Patches Critical Fireware OS Code Injection Vulnerability appeared first on SecurityWeek.
P0
2026-09-30 12:48 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-30 12:50 UTC
Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772. The post Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks appeared first on SecurityWeek.
P30
2026-09-30 12:25 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-30 12:40 UTC
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]
P0
2026-09-30 12:16 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-30 12:30 UTC
Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox. The post Chrome, Firefox Updates Patch Over 100 Vulnerabilities appeared first on SecurityWeek.
P0
2026-09-30 12:00 UTC
Security Journalism
The Record · indexed 2026-09-30 12:10 UTC
The Russian state-backed hacking group Star Blizzard has expanded its phishing operations this year, using a new technique that makes it easier to infect victims with malware.
P0
2026-09-30 11:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 13:00 UTC
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in the browser. Here are the six most dangerous techniques that should be on every security team's radar in 2026. 1.
P0
2026-09-30 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 11:45 UTC
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, including customer billing records and screens of features not yet released. In most cases, they sat under developers' personal accounts
P0
2026-09-30 11:19 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-30 11:30 UTC
Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do. The post Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit appeared first on SecurityWeek.
P0
2026-09-30 11:11 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-30 11:15 UTC
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]
P25
2026-09-30 10:59 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-30 11:10 UTC
The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor. The post Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks appeared first on SecurityWeek.
P0
2026-09-30 10:45 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 11:45 UTC
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft with remote-access tool deployment, CSuite can turn a phishing incident into broader account compromise, fraud
P0
2026-09-30 10:20 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-30 10:30 UTC
In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI. The post ShinyHunters Defiant After FBI Calls on Members to Come Forward appeared first on SecurityWeek.
P0
2026-09-30 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Ashley Shen · indexed 2026-09-30 10:10 UTC
Cisco Talos uncovered a cluster of activity we track as UAT-11587 targeting government and policy organizations across Asia, including in Taiwan, India, the Philippines, and Cambodia, to deliver a previously undocumented backdoor referred to as “Antino” in developer artifacts.
P0
2026-09-30 09:14 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-30 10:10 UTC
Threat actors abused fake ChatGPT Custom GPTs and ClickFix to deliver a multi-stage RAT. ChatGPT’s Custom GPT feature is the latest legitimate surface being turned into a delivery mechanism, and Huntress researchers caught it in action across at least 40 incidents. A Custom GPT (now simply called a GPT) is essentially a version of ChatGPT […]
P0
2026-09-30 08:24 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 09:55 UTC
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) in September 2026, has targeted government, financial services, technology, education, and legal and professional
P0
2026-09-30 08:09 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 09:55 UTC
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires. The leak or crash can happen when such a resend starts while a larger handshake message is stuck part-way
P0
2026-09-30 08:04 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-30 09:10 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Apple Multiple Products flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added an Apple Multiple Products flaw, tracked as CVE-2026-86950 (CVSS score of 8.8), to its Known Exploited Vulnerabilities (KEV) catalog. This week, Apple has released security updates for iOS, iPadOS […]
P35
2026-09-30 08:00 UTC
Other
ESET · indexed 2026-10-01 11:20 UTC
Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year's worth of security patches in one go – here's how to keep pace
P0
2026-09-30 07:25 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-30 07:50 UTC
Mandiant and GTIG detail active exploitation of a Citrix NetScaler zero-day, deploying custom web shells WHIPSHOT and SLAPSHOT for root access. Mandiant and Google Threat Intelligence Group caught active exploitation of a zero-day in Citrix NetScaler ADC and Gateway appliances in late September 2026. The bug, tracked as CVE-2026-88772 (CVSS score of 9.5), has been […]
P30
2026-09-30 07:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-09-30 07:15 UTC
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.
P15
2026-09-30 06:55 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-30 07:15 UTC
Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries. The post High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL appeared first on SecurityWeek.
P0
2026-09-30 05:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 07:00 UTC
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a memory overflow bug in the Datagram Transport Layer Security (DTLS) protocol handling that's rooted in the NetScaler
P25
2026-09-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-30 21:10 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-18145.
P20
2026-09-30 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-30 21:10 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of WatchGuard FireWare OS. An attacker must first obtain the ability to write to the samld session directory on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2026-13046.
P20
2026-09-30 04:00 UTC
Security Journalism
Huntress · indexed 2026-09-30 13:10 UTC
Huntress SOC found a threat actor exploiting a file upload flaw in recreation management to breach 3 municipal servers and steal payment data.
P0
2026-09-30 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-30 02:05 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-30 01:48 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-30 02:00 UTC
The accord opened the door to future regulation but focused on four voluntary steps for the companies to take. The post Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development appeared first on SecurityWeek.
P0
2026-09-30 00:40 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-30 00:50 UTC
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. [...]
P0
2026-09-29 21:39 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Parasharan Raghavan, Deva Kanna Kannan, Sai Chakri and Microsoft Defender Experts · indexed 2026-09-29 22:40 UTC
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog.
P0
2026-09-29 21:31 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-29 21:50 UTC
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
P30