2026-09-18 10:57 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-18 11:10 UTC
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.
P10
2026-09-18 10:40 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 11:00 UTC
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and
P0
2026-09-18 10:12 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-18 10:30 UTC
Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world. The post NightmareStresser DDoS Service Disrupted in International Operation appeared first on SecurityWeek.
P0
2026-09-18 10:04 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-18 10:50 UTC
RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve traced to China-based operators, and what makes it different isn’t the credential theft, which is […]
P0
2026-09-18 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Niv Rabin · indexed 2026-09-18 10:10 UTC
Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42.
P0
2026-09-18 09:46 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-18 09:50 UTC
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.
P0
2026-09-18 09:34 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-18 09:45 UTC
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]
P15
2026-09-18 09:18 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 09:30 UTC
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"
P0
2026-09-18 09:00 UTC
Other
ESET · indexed 2026-09-19 05:10 UTC
Whether you’re a victim, the parent of a victim, or just concerned, here’s what you can do about fake nude images
P0
2026-09-18 08:42 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-18 08:50 UTC
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek.
P40
2026-09-18 07:52 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-18 08:10 UTC
Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point addressed CVE-2026-91843 (CVSS score of 9.8), a critical vulnerability in its Security Management and Log Servers. The flaw could let an attacker with no account run code as […]
P15
2026-09-18 07:35 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-18 07:45 UTC
Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. [...]
P5
2026-09-18 07:25 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-18 07:30 UTC
The company will use the funding to accelerate platform development and expand its presence in key enterprise markets. The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek.
P0
2026-09-18 07:14 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-18 07:30 UTC
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.
P25
2026-09-18 07:00 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-18 07:10 UTC
AI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.
P0
2026-09-18 06:17 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-18 06:30 UTC
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses
P0
2026-09-18 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-18 14:35 UTC
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 4.9. The following CVEs are assigned: CVE-2026-20235.
P5
2026-09-18 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-18 14:35 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20211.
P20
2026-09-18 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-18 14:35 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-20176.
P20
2026-09-18 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-18 14:35 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-19772.
P20
2026-09-18 04:00 UTC
Security Journalism
The Record · indexed 2026-09-18 19:10 UTC
The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” — a group of cyber actors allegedly stealing cryptocurrency from job applicants by posing as AI or blockchain companies.
P0
2026-09-18 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-18 02:15 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-17 23:07 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-18 00:20 UTC
OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a formal framework for tracking, investigating, and disclosing cases of model misalignment, paired with six […]
P0
2026-09-17 22:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Sharon Maydar · indexed 2026-09-17 22:20 UTC
Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42.
P0
2026-09-17 21:50 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-17 22:00 UTC
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]
P0
2026-09-17 21:23 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-17 21:50 UTC
The move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.
P0
2026-09-17 21:19 UTC
Vendor Research
AWS Security Blog · Marta Taggart · indexed 2026-09-17 21:40 UTC
European organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can now run generative AI workloads on open weight models on Amazon Bedrock in the AWS European Sovereign Cloud. We’re excited to announce the general availability of the first open weight […]
P0
2026-09-17 21:13 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-02 16:10 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not known to be actively exploited. To assist customers in patching and streamline the disclosure process, Cisco has grouped these issues by …
P30
2026-09-17 20:36 UTC
Security Journalism
The Record · indexed 2026-09-17 20:55 UTC
The proposal, known as the EU KIDS Act, would block social media platforms from offering accounts to children younger than 13 and establish a bloc-wide minimum age of 15 for account creation.
P0
2026-09-17 20:00 UTC
Vendor Research
Google Security Blog · Maunik Shah · indexed 2026-09-17 20:25 UTC
Security State Library
P5