Cybersecurity News
Aggregated daily from 25 sources. Updated automatically every morning.
CISA
NCSC UK
SANS ISC
The Hacker News
Bleeping Computer
Krebs on Security
Dark Reading
SecurityWeek
Exploit-DB
CERT-In
Google Project Zero
PortSwigger Research
Check Point Research
Cisco Talos
CrowdStrike
Unit 42
Elastic Security Labs
SentinelOne
WithSecure Labs
Avast Threat Labs
ZDI
0days in the Wild
Lakera AI Security
Embrace the Red
Simon Willison
Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service
China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI.
The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on SecurityWeek.
Google says its new opaque redirects tackle evolving abuse, but they also prevent users from checking a result’s destination by hovering over it.
A human attacker exploited a Marimo RCE and reached an SSH bastion in eight seconds
Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control. [...]
Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims.
The post New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate appeared first on SecurityWeek.
The company unintentionally disclosed users’ information to a third party impersonating a government agency.
The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek.
As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity.
The post The Race to Control AI and Protect What Makes Us Human appeared first on SecurityWeek.
MarketsandMarkets has projected the cyber warfare market to double by 2031, amid growing demand for defensive and offensive cyber capabilities in the military
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a […]
The post 14th September – Threat Intelligence Report appeared first on Check Point Research.
Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...]
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.
CVE-2026-76461 Cisco Secure Email Gateway SQL Injection Vulnerability
This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise.
Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must
The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.
The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek.
An unauthorized party used a legitimate government email domain to fraudulently request Revolut customer data
The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.
Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm.
The post CISOs Race to Control AI Agents Without Destroying Their Value appeared first on SecurityWeek.
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.
The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.
CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0
Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.
The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek.
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. [...]
The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator.
The post Three JFrog Artifactory Flaws Exploited for Backdoor Deployment appeared first on SecurityWeek.
Researchers confirm that OpenAI agents uploaded hundreds of malicious packages to RubyGems
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]
The flaw allows attackers to send files and execute them without authorization through an active remote session.
The post ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks appeared first on SecurityWeek.
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. [...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are now exploiting a maximum-severity GitLab vulnerability in attacks. [...]
A list of topics we covered in the week of September 7 to September 13 of 2026
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Elastic Security Labs tracked this malicious browser extension across seven campaigns and 15 months, through Brazilian bank lures and the Ethereum smart contracts that hold its C2 configuration.
Uncensored refers to a lack of typical guardrails or ethical restrictions, lowering the technical barrier of entry into cybercrimeCategories: Threat ResearchTags: AI, Luciferus, underground