2026-09-23 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Varonis · indexed 2026-09-23 14:15 UTC
A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [...]
P10
2026-09-23 13:56 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-23 14:20 UTC
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead […]
P25
2026-09-23 13:52 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 14:10 UTC
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions
P0
2026-09-23 13:49 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-23 14:20 UTC
Security teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it?Dynamic application security testing (DAST) helps answer those questions by testing applications as an attacker encounters them. The IDC MarketScape: Worldwide Dynamic Application Security Testing 2026 Vendor Assessment (Doc #US54119126, Septemb…
P0
2026-09-23 13:26 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall Threat Defense Virtual (FTDv) models. However, it was later found that this vulnerability affects all Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software platforms. A vulnerability in the VPN and management web servers of the Cisco Secure Firewall ASA Software a…
P5
2026-09-23 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-23 13:50 UTC
A sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.
P0
2026-09-23 12:45 UTC
Security Journalism
The Record · indexed 2026-09-23 13:00 UTC
Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims.
P0
2026-09-23 12:30 UTC
Security Journalism
The Record · indexed 2026-09-23 12:45 UTC
The United Kingdom will create a new national center "to detect, attribute and disrupt” hostile state disinformation, Prime Minister Andy Burnham announced at the United Nations General Assembly.
P0
2026-09-23 12:29 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-23 12:30 UTC
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]
P25
2026-09-23 12:17 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-23 12:30 UTC
Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature. The post Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare appeared first on SecurityWeek.
P0
2026-09-23 12:16 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 12:40 UTC
A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts. cPanel has released fixed versions for both,
P0
2026-09-23 12:00 UTC
Security Journalism
Huntress · indexed 2026-09-24 07:50 UTC
The Huntress SOC uncovered phishing attacks that trick employees into installing rogue RMM tools like ScreenConnect for persistent access. Learn how to spot it.
P0
2026-09-23 11:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 12:40 UTC
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security background then sits down and checks every claim against the target. Which findings are real,
P0
2026-09-23 11:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 12:40 UTC
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands
P0
2026-09-23 11:40 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-23 11:50 UTC
The nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek.
P10
2026-09-23 11:23 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-23 11:30 UTC
The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek.
P0
2026-09-23 11:18 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-23 11:25 UTC
Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. [...]
P5
2026-09-23 11:12 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 12:40 UTC
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst
P5
2026-09-23 11:00 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-23 11:10 UTC
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold […]
P0
2026-09-23 10:36 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-23 10:50 UTC
The browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek.
P0
2026-09-23 10:31 UTC
Vendor Research
ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC
According to fresh ANY.RUN data, phishing exposure remains above 70% in several critical industries. This doesn’t happen because organizations aren’t protected enough. Companies have been implementing email filtering, MFA, and phishing-awareness training for years. However, threats continue to evolve, and security methods that were highly effective yesterday can develop visibility gaps as attackers adapt. In […] The post Phishing Risk Across 5 Key US Industries: ANY.RUN Data & Mitigation Strate…
P0
2026-09-23 10:20 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-23 10:30 UTC
Debates over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons. The post A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk appeared first on SecurityWeek.
P0
2026-09-23 10:00 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-23 10:10 UTC
Emerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions. The post Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm appeared first on SecurityWeek.
P0
2026-09-23 08:43 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-23 09:30 UTC
OverviewOn September 22, 2026, F5 published a security advisory for CVE-2026-94127, a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic.BIG-IP APM provides identity-aware access control for applications and other corporate resources …
P50
2026-09-23 08:33 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-23 08:50 UTC
Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek.
P25
2026-09-23 08:29 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 08:45 UTC
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
P55
2026-09-23 08:29 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-23 08:45 UTC
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break
P30
2026-09-23 08:25 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-23 08:50 UTC
Attackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products using a driver that Microsoft itself had signed. That last part is the one worth […]
P0
2026-09-23 08:20 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-23 08:30 UTC
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]
P15
2026-09-23 07:36 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-23 07:50 UTC
WordPress 7.1.2 fixes an unauthenticated file inclusion bug active since version 4.7, patchable but exploitable into remote code execution. WordPress 7.1.2 shipped on September 22 address an unauthenticated local file inclusion, tracked as CVE-2026-87902 (CVSS score of 9.2), which stems of how the CMS resolves page templates, with a real path to remote code execution. […]
P20