2026-09-30 01:48 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-30 02:00 UTC
The accord opened the door to future regulation but focused on four voluntary steps for the companies to take. The post Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development appeared first on SecurityWeek.
P0
2026-09-30 00:40 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-30 00:50 UTC
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. [...]
P0
2026-09-29 21:39 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Parasharan Raghavan, Deva Kanna Kannan, Sai Chakri and Microsoft Defender Experts · indexed 2026-09-29 22:40 UTC
Microsoft observed phishing campaigns that abused MSP360 RMM to deploy ScreenConnect, creating redundant remote-access channels for follow-on activity The post Phishing Abuses RMM Tools for Persistent Access appeared first on Microsoft Security Blog.
P0
2026-09-29 21:31 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-29 21:50 UTC
Attackers are exploiting CVE-2026-86950, an out-of-bounds write flaw, in an extremely sophisticated fashion, according to Apple.
P30
2026-09-29 21:30 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-29 21:35 UTC
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). [...]
P0
2026-09-29 21:08 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-29 21:20 UTC
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.
P0
2026-09-29 21:01 UTC
Security Journalism
The Record · indexed 2026-09-29 21:20 UTC
According to court documents, both men pleaded guilty to wire fraud, identity theft and access device fraud charges in June.
P0
2026-09-29 20:59 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-29 21:05 UTC
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]
P0
2026-09-29 20:54 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-29 21:50 UTC
Keio, a major Japanese railway operator, was hit by ransomware, disrupting business systems and forcing the company to shut down its network. Keio Corporation, one of Japan’s major private railway operators, was hit by a ransomware attack over the weekend, disrupting some of its business systems. The company detected a system failure early Saturday and […]
P15
2026-09-29 20:35 UTC
Security Journalism
The Record · indexed 2026-09-29 20:50 UTC
The company plans to close the deal around the end of the year at which point Paragon will begin trading on Nasdaq under the REDLattice umbrella.
P0
2026-09-29 20:14 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-29 20:30 UTC
Altman made a slew of product announcements and updates, including the company’s new agents, called Dots. The post OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference appeared first on SecurityWeek.
P0
2026-09-29 20:09 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-29 20:10 UTC
The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...]
P0
2026-09-29 19:48 UTC
Security Journalism
The Record · indexed 2026-09-29 20:05 UTC
The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches.
P0
2026-09-29 18:37 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-29 18:50 UTC
Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...]
P30
2026-09-29 18:09 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-29 18:10 UTC
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]
P0
2026-09-29 17:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 18:35 UTC
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophisticated, the agency, ANSSI, says in a report (in French) published on Tuesday: it worked because of weak
P0
2026-09-29 17:37 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-29 17:45 UTC
Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it. [...]
P0
2026-09-29 17:24 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-29 17:35 UTC
The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software. The post DARPA Selects Xint to Use AI in Securing Military Messaging Apps appeared first on SecurityWeek.
P0
2026-09-29 17:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 17:20 UTC
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across multiple CPU vendors. The new Spectre v2 variant has been codenamed Branch Target Reuse (BTR). "The key insight is that, while modern CPUs
P0
2026-09-29 17:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-29 18:35 UTC
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organizations since January, mostly in the U.S. and U.K. At least one computer was infected, but the number of breached
P0
2026-09-29 17:10 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-29 17:15 UTC
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. [...]
P0
2026-09-29 17:02 UTC
Security Journalism
Dark Reading · indexed 2026-09-29 17:20 UTC
Automated certificates for everyone, built for today, and hardened for the era of quantum computing.
P0
2026-09-29 17:00 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-29 17:15 UTC
Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks appeared first on SecurityWeek.
P0
2026-09-29 16:24 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn how Huntress' Athena brings agentic AI to the SOC, investigating signals end-to-end while human analysts own the final call.
P0
2026-09-29 16:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Defender Experts Cybersecurity Incident Response · indexed 2026-09-29 17:10 UTC
Explore how Storm-3068 turned a compromised identity into broader cloud access and the steps organizations can take to defend their identities, pipelines, and cloud infrastructure. The post Beyond source code: A path to the keys to the kingdom appeared first on Microsoft Security Blog.
P0
2026-09-29 15:39 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-29 15:50 UTC
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]
P0
2026-09-29 15:17 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-29 15:35 UTC
Bulletin ID: 2026-119-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/29/2026 08:00 AM PDT Description: GluonTS is an open source library for deep learning based time series models. We identified CVE-2026-100308 that allows arbitrary command execution upon deserialization of untrusted model artifacts. Deserialization of untrusted data in the model loading component in Amazon GluonTS before 0.17.0 might allow context-dependent attackers to execute arbitrary opera…
P5
2026-09-29 15:12 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-29 15:30 UTC
Microsoft observed a China-based actor using a previously unidentified malware framework in targeted intrusions against telcos, universities, medical, and government-related organizations.
P0
2026-09-29 15:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Threat Intelligence · indexed 2026-09-29 15:35 UTC
Since January 2026, Microsoft has observed Russian state threat actor Star Blizzard evolve their detection evasion capabilities through large-scale phishing campaigns, the use of accounts on compromised websites, and a novel malware delivery technique, tracked by Microsoft as “RedFlick”. The post Star Blizzard refines phishing and malware delivery with the RedFlick technique appeared first on Microsoft Security Blog.
P0
2026-09-29 14:38 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-09-29 14:40 UTC
The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe. The post RemoteThreat Launches With $7 Million for Offensive Operations Platform appeared first on SecurityWeek.
P0