2026-10-09 15:15 UTC
Vendor Research
Tenable Research Advisories · Joshua Martinelle · indexed 2026-10-09 15:25 UTC
Hermes Agent - PKCE Session Takeover via Redirect-URI Parser Confusion Note: Another researcher identified the same vulnerability during the disclosure process with the Nous Researcher team.In Hermes Agent, the public GET /auth/native/authorize flow validates the redirect_uri with Python's urllib.parse.urlparse, then hands the raw, unnormalized value back to the browser after authentication.The two parsers treat backslashes differently. Python's parser and the browser's WHATWG parser therefore …
P0
2026-10-09 12:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-09 14:35 UTC
Threat actors have been observed exploiting two recently disclosed flaws in the AhsayCBS backup utility to seize control of affected devices and deploy web shells and XMRig cryptocurrency miners. Details of the flaws are below - CVE-2026-105133 (CVSS v4 score: 5.5) - An improper authentication vulnerability in the checkSysPwd() function in the "com/ahsay/obs/api/ApiStructsAction.java"
P5
2026-10-09 10:12 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-09 10:20 UTC
Microsoft says devices running unsupported versions of Windows will stop receiving security updates after next year's Windows Update certificate rotation. [...]
P5
2026-10-08 20:44 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Lora Randolph, Tahmina Ahmad and Karina Sirota Goodley · indexed 2026-10-08 21:00 UTC
Prepare for post-quantum authentication by testing certificate ecosystems now. Learn how Microsoft’s PQC TLS Pilot Program helps advance future readiness. The post Post-quantum authentication: Why organizations should start testing certificate ecosystems now appeared first on Microsoft Security Blog.
P0
2026-10-08 20:27 UTC
Security Journalism
The Record · indexed 2026-10-08 20:40 UTC
The proposed sale would include about 100 million emails, 500 million Microsoft Teams messages, employment contracts, employee and timecard records and payroll and tax information, Rep. Steven Horsford (D-NV) said in a press release.
P0
2026-10-08 13:18 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-08 13:25 UTC
A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021. [...]
P0
2026-10-08 13:00 UTC
Security Journalism
The Record · indexed 2026-10-08 13:15 UTC
"It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled," researchers at Bitdefender said about ad fraud malware found on thousands of cheap Android devices.
P0
2026-10-08 12:50 UTC
Vendor Research
Tenable Blog · Robert McSulla · indexed 2026-10-08 13:10 UTC
Community-built AI agents, skills, and MCP servers are landing in SOC workflows fast. Here’s what the Exchange Inspector tests before a listing earns its vetted tag on the CyberAgents Exchange. Three tools have already passed.Key takeawaysEvery Inspector-vetted listing clears three gates: an automated check, a frontier model assessment, and human verification. Tenable uses Tenable One AI Exposure to screen for prompt injection and exposed secrets, and OpenAI GPT Cyber models to assess the code …
P0
2026-10-08 12:08 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-08 12:20 UTC
Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings. [...]
P0
2026-10-08 07:42 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-08 08:10 UTC
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchange Server attacks known as HAFNIUM. The reward is for information leading to his identification or location, the news outlet NTD reported this week, citing a notice
P0
2026-10-07 20:51 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-10-07 21:20 UTC
Anthropic has merged Project Glasswing into a tiered access program for its advanced cyber LLMs, including Opus, Sonnet, and Mythos.
P0
2026-10-07 20:16 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-10-07 19:29 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-10-07 19:50 UTC
In Part 1 of this series, we looked at the security challenges created by fragmented, campus-by-campus environments. Higher education also faces a second pressure that makes that fragmentation harder to sustain: overlapping compliance obligations across FERPA, GLBA, HIPAA, and CMMC.Each framework brings different requirements, reporting timelines, and consequences for failure. Managing them across one institution is already complex, but across a multi-campus university system with separate tool…
P15
2026-10-07 19:27 UTC
Vendor Research
Cisco Talos Intelligence Blog · Kri Dontje · indexed 2026-10-07 20:00 UTC
Cisco Talos’ Vulnerability Discovery & Research team recently disclosed vulnerabilities in Adobe, Apple, Foxit Reader, and Microsoft.The vulnerabilities mentioned in this blog post have been patched by their respective vendors, in adherence to Cisco’s third-party vulnerability disclosure policy. For Snort coverage that can detect
P0
2026-10-07 16:00 UTC
Vendor Research
Microsoft Security Blog · Taesoo Kim · indexed 2026-10-07 16:50 UTC
Read how How Microsoft Security's FORGE Lab is scaling vulnerability research from Windows to the Linux kernel. The post 3 lessons from frontier AI vulnerability research appeared first on Microsoft Security Blog.
P0
2026-10-07 15:44 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-07 16:00 UTC
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month. [...]
P0
2026-10-07 13:06 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-10-07 13:10 UTC
Hadrian offers an agentic offensive security platform that allows defenders to operate at the same speed as attackers. The post Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform appeared first on SecurityWeek.
P0
2026-10-07 13:00 UTC
Security Journalism
Huntress · indexed 2026-10-07 13:10 UTC
A recent phishing campaign abused Microsoft Power BI links to deliver multiple rogue ScreenConnect clients.
P0
2026-10-06 16:59 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-10-06 17:35 UTC
Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.
P0
2026-10-06 16:00 UTC
Vendor Research
Microsoft Security Blog · Freddy Dezeure and Sesha Mani · indexed 2026-10-06 16:55 UTC
Learn how CISOs can mitigate cybersecurity risks and increase resilience in the age of AI-powered vulnerability management. The post CISO perspectives on managing vulnerability risks in the age of AI appeared first on Microsoft Security Blog.
P0
2026-10-06 14:09 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-06 15:20 UTC
Microsoft released emergency updates for Exchange Server to fix CVE-2026-96940, a high-severity flaw that can let attackers gain higher privileges. Microsoft has released out-of-band security updates for Exchange Server to fix a high-severity vulnerability tracked as CVE-2026-96940 (CVSS score of 8.8). The flaw is caused by weak authorization and can allow an authenticated attacker to […]
P5
2026-10-06 09:38 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-06 09:40 UTC
Hackers abused a company’s lawful access to the CPR system to steal the personal information of registered citizens. The post 8.8 Million Impacted by Data Breach at Denmark’s Central Person Register appeared first on SecurityWeek.
P0
2026-10-06 09:25 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-06 09:35 UTC
Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]
P0
2026-10-06 06:00 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 06:15 UTC
Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization ministry said on October 5. They used a private Danish company's lawful right to look up records in the Central Person Register (CPR). The ministry has told people never to
P0
2026-10-06 05:22 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-06 06:15 UTC
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.
P0
2026-10-05 21:41 UTC
Vendor Research
AWS Security Blog · Alexander Greaves-Tunnell · indexed 2026-10-05 21:50 UTC
As AI models become more capable, they uncover more security vulnerabilities and identify increasingly sophisticated paths to exploit them, raising the bar for how quickly defenders must respond. Security teams now face more potential vulnerabilities than their existing processes were designed to handle — each requiring investigation, reproduction, and a repair that must be tested […]
P0
2026-10-05 16:21 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-05 17:30 UTC
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a
P5
2026-10-05 15:21 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-10-05 15:25 UTC
Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]
P0
2026-10-05 13:33 UTC
Security Journalism
BleepingComputer · Sponsored by tenfold Software · indexed 2026-10-05 13:45 UTC
tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate suspicious identity activity. [...]
P0
2026-10-05 09:37 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-05 09:45 UTC
Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]
P0