2026-09-30 22:35 UTC
Security Journalism
The Record · indexed 2026-09-30 22:55 UTC
Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs.
P0
2026-09-30 21:25 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-30 21:40 UTC
In yet another ClickFix-style campaign, threat actors abuse legitimate domains from OpenAI and Google to fool unsuspecting users.
P0
2026-09-30 20:51 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-30 22:10 UTC
The new White House Accord on so-called "Super Intelligence" calls on companies to implement greater controls and oversight over AI safety.
P0
2026-09-30 20:34 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-30 20:35 UTC
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]
P0
2026-09-30 20:32 UTC
Security Journalism
The Record · indexed 2026-09-30 20:40 UTC
A new study reveals fresh details about how drivers are exposed to a web of large corporations participating in the advertising ecosystem.
P0
2026-09-30 20:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-09-28 15:15 UTC
Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) appeared first on Unit 42.
P50
2026-09-30 19:49 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-30 19:55 UTC
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]
P25
2026-09-30 19:35 UTC
Security Journalism
The Record · indexed 2026-09-30 19:55 UTC
An August 31 memo obtained by Recorded Future News shows that the Pentagon's assistant secretary for cyber policy made specific demands of U.S. Cyber Command leadership after reports of a cluster of suicide deaths.
P0
2026-09-30 19:31 UTC
Vendor Research
Microsoft Security Blog · Lindsay Myers · indexed 2026-09-30 21:30 UTC
This year at Microsoft Ignite, we spotlight our AI-first, end-to-end security platform designed to protect identities, devices, data, applications, clouds, infrastructure, and the AI agents now working alongside your teams. The post Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 appeared first on Microsoft Security Blog.
P0
2026-09-30 19:29 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-30 20:15 UTC
WatchGuard fixes 15 Fireware OS flaws, including a critical RCE bug that could give attackers root access to vulnerable Firebox appliances. WatchGuard has released security updates for Fireware OS that address 15 vulnerabilities, including a critical code injection flaw, tracked as CVE-2026-86131 (CVSS score of 9.2), that could allow an attacker to execute commands with […]
P20
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P15
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-30 19:00 UTC
Security Journalism
The Record · indexed 2026-09-30 19:20 UTC
Vulnerability disclosures continue to skyrocket, doubling over the course of the year to more than 10,000 each month, Google researchers warned.
P0
2026-09-30 18:56 UTC
Security Journalism
Dark Reading · indexed 2026-09-30 19:45 UTC
New Swimlane research underscores a paradox: While AI detection and response is essential to giving defenders an edge, one in four security pros say AI limits their skill development.
P0
2026-09-30 18:08 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-30 18:15 UTC
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data. [...]
P0
2026-09-30 17:30 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See how attackers like GootKit and WhisperGate abuse Windows Defender exclusions to hide malware from AV scans — and how Huntress detects it.
P0
2026-09-30 16:46 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 17:55 UTC
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol
P20
2026-09-30 16:32 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 17:55 UTC
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected
P0
2026-09-30 16:11 UTC
Other
Proofpoint Threat Insight · indexed 2026-10-09 23:30 UTC
P0
2026-09-30 15:49 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-30 15:50 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]
P25
2026-09-30 15:24 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 15:30 UTC
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manager's API as the admin user. Fixed releases are available, and there is no workaround. It carries a
P40
2026-09-30 15:09 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-30 15:25 UTC
OverviewOn September 30, 2026, Cisco published a security advisory for CVE-2026-76504, a critical API authentication bypass vulnerability affecting Cisco Catalyst SD-WAN Manager. The vulnerability has a CVSSv3.1 score of 9.8 and results from improper handling of URL encoding (CWE-177). An unauthenticated, remote attacker can send a crafted HTTP request that bypasses an authentication rule for a specific API endpoint, gaining access to the API with the privileges of the admin user.According to C…
P90
2026-09-30 15:02 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-30 15:10 UTC
The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.
P0
2026-09-30 15:00 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 15:30 UTC
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse of yet another feature in trusted artificial intelligence (AI) platforms. Prior campaigns have weaponized shared
P0
2026-09-30 14:46 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-30 15:00 UTC
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]
P50
2026-09-30 14:16 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC
Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …
P40
2026-09-30 14:05 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-30 14:10 UTC
Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution. The post Google: AI Is Changing the Pace and Profile of Vulnerability Discovery appeared first on SecurityWeek.
P15
2026-09-30 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Token Security · indexed 2026-09-30 14:20 UTC
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped permissions, and lifecycle controls. [...]
P0
2026-09-30 14:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Mahesh Mandava and Rajesh Kumar Natarajan · indexed 2026-09-30 15:00 UTC
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog.
P5
2026-09-30 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-30 14:45 UTC
Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee Introduction Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered. Key findings: Vulnerability discl…
P60