2026-09-29 21:30 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-29 21:35 UTC
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). [...]
P0
2026-09-29 21:08 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-29 21:20 UTC
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.
P0
2026-09-29 21:01 UTC
Security Journalism
The Record · indexed 2026-09-29 21:20 UTC
According to court documents, both men pleaded guilty to wire fraud, identity theft and access device fraud charges in June.
P0
2026-09-29 20:59 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-29 21:05 UTC
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]
P0
2026-09-29 20:54 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 21:50 UTC
Keio, a major Japanese railway operator, was hit by ransomware, disrupting business systems and forcing the company to shut down its network. Keio Corporation, one of Japan’s major private railway operators, was hit by a ransomware attack over the weekend, disrupting some of its business systems. The company detected a system failure early Saturday and […]
P15
2026-09-29 20:35 UTC
Security Journalism
The Record · indexed 2026-09-29 20:50 UTC
The company plans to close the deal around the end of the year at which point Paragon will begin trading on Nasdaq under the REDLattice umbrella.
P0
2026-09-29 20:14 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-29 20:30 UTC
Altman made a slew of product announcements and updates, including the company’s new agents, called Dots. The post OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference appeared first on SecurityWeek.
P0
2026-09-29 20:09 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-29 20:10 UTC
The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...]
P0
2026-09-29 19:48 UTC
Security Journalism
The Record · indexed 2026-09-29 20:05 UTC
The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches.
P0
2026-09-29 18:37 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-29 18:50 UTC
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...]
P30
2026-09-29 18:09 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-29 18:10 UTC
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]
P0
2026-09-29 17:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 18:35 UTC
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday: it worked because of weak
P0
2026-09-29 17:37 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-29 17:45 UTC
Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it. [...]
P0
2026-09-29 17:24 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-29 17:35 UTC
The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software. The post DARPA Selects Xint to Use AI in Securing Military Messaging Apps appeared first on SecurityWeek.
P0
2026-09-29 17:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 17:20 UTC
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs
P0
2026-09-29 17:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 18:35 UTC
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached
P0
2026-09-29 17:10 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-29 17:15 UTC
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. [...]
P0
2026-09-29 17:02 UTC
Security Journalism
Dark Reading · indexed 2026-09-29 17:20 UTC
Automated certificates for everyone, built for today, and hardened for the era of quantum computing.
P0
2026-09-29 17:00 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-29 17:15 UTC
Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks appeared first on SecurityWeek.
P0
2026-09-29 16:24 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how Huntress' Athena brings agentic AI to the SOC, investigating signals end-to-end while human analysts own the final call.
P0
2026-09-29 16:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Defender Experts Cybersecurity Incident Response · indexed 2026-09-29 17:10 UTC
Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure. The post Beyond source code: A path to the keys to the kingdom appeared first on Microsoft Security Blog.
P0
2026-09-29 15:39 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-29 15:50 UTC
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]
P0
2026-09-29 15:17 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-29 15:35 UTC
Bulletin ID: 2026-119-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/29/2026 08:00 AM PDT Description: GluonTS is an open source library for deep learning based time series models. We identified CVE-2026-100308 that allows arbitrary command execution upon deserialization of untrusted model artifacts. Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary opera…
P5
2026-09-29 15:12 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-29 15:30 UTC
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.
P0
2026-09-29 15:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-29 15:35 UTC
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”. The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog.
P0
2026-09-29 14:38 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-09-29 14:40 UTC
The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe. The post RemoteThreat Launches With $7 Million for Offensive Operations Platform appeared first on SecurityWeek.
P0
2026-09-29 14:19 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-09-29 15:15 UTC
The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.
P25
2026-09-29 14:13 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 15:25 UTC
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the discovery of a previously unknown critical vulnerability confined to a capability that is enabled for less than 1% of the customer base," the company
P10
2026-09-29 14:09 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 15:00 UTC
Pentagon personnel agency breach exposed data of 3 million people after attackers accessed a file-sharing server for about nine months. The U.S. Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense, is notifying people that their personal information was exposed in a data breach. According to the agency, unauthorized users […]
P0
2026-09-29 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by tenfold Software · indexed 2026-09-29 14:15 UTC
Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate suspicious activity before it escalates. [...]
P0