2026-09-17 12:29 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-17 12:30 UTC
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.
P15
2026-09-17 12:17 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-17 12:30 UTC
The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution. The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek.
P15
2026-09-17 12:15 UTC
Security Journalism
The Record · indexed 2026-09-17 12:30 UTC
An Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media personas and media outlets, researchers found.
P0
2026-09-17 11:35 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-17 12:15 UTC
The DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as easy as renting a movie. Pick a target, pay a few dollars, watch the site go dark. The Justice Department just made that a […]
P0
2026-09-17 11:33 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 11:40 UTC
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. [...]
P0
2026-09-17 10:50 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production. TL;DR Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR
P0
2026-09-17 10:05 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News
P0
2026-09-17 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Takahiro Takeda · indexed 2026-09-17 10:15 UTC
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.
P15
2026-09-17 09:53 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency. "As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the
P0
2026-09-17 09:26 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-17 10:20 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-76460 is an authentication bypass vulnerability affecting an API in Cisco Identity Services Engine (ISE). The flaw […]
P45
2026-09-17 09:00 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-17 09:15 UTC
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...]
P0
2026-09-17 08:50 UTC
Other
ESET · indexed 2026-09-18 07:30 UTC
ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
P0
2026-09-17 08:24 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 08:30 UTC
Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]
P5
2026-09-17 08:15 UTC
Vendor Research
ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC
For an MSSP, a quiet month can be a good month. No ransomware outbreak. No major account compromise. No business disruption. But it can also create an awkward conversation with the client: What exactly did we pay for this month? The problem is not that the SOC did nothing. Quite the opposite. Analysts may have […] The post How MSSPs Can Prove Their Value When “Nothing Happened” appeared first on ANY.RUN's Cybersecurity Blog.
P15
2026-09-17 08:00 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH). A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG
P0
2026-09-17 07:53 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-17 07:55 UTC
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses appeared first on SecurityWeek.
P0
2026-09-17 07:44 UTC
Vendor Research
ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC
Choosing an enterprise threat intelligence solution is about more than just data volume or integrations. The right provider should deliver relevant intelligence, fit existing workflows, and help security teams investigate threats faster. While SOCs may prioritize rapid investigation and enrichment at scale, MSSPs may focus more on multi-tenancy and customer separation. This enterprise threat intelligence […] The post Enterprise Threat Intelligence Buying Guide: How to Choose the Right Solution …
P0
2026-09-17 07:41 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-17 07:55 UTC
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.
P0
2026-09-17 07:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links. Helpfeel said
P0
2026-09-17 07:25 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-17 08:00 UTC
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services use to track down dissidents, journalists, and activists, and the […]
P0
2026-09-17 07:20 UTC
Other
Group-IB · indexed 2026-09-17 08:35 UTC
Group-IB Threat Intelligence analyzes HEAVYGRAM, a Telegram-based Windows backdoor attributed with moderate confidence to the Iran-linked threat actor Handala Hack. Active since Fall 2023, it has been used to surveil Iranian dissidents, journalists and government opponents, enabling remote command execution, data exfiltration, and persistence over Telegram command-and-control.
P0
2026-09-17 07:20 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-17 07:25 UTC
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
P50
2026-09-17 06:39 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation. The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication. "This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker
P30
2026-09-17 06:19 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-17 06:35 UTC
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.
P25
2026-09-17 05:59 UTC
Other
Group-IB · indexed 2026-09-17 08:35 UTC
Most fraud platforms only see a threat once it becomes a transaction. This guide compares the top 5 fraud prevention platforms for banks and fintechs in 2026, including Group-IB, Feedzai, Sift, DataVisor, and Kount, and what actually separates them.
P0
2026-09-17 05:13 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-17 13:45 UTC
The U.S. Department of Justice (DoJ) on Tuesday announced the court-authorized seizure of internet domains associated with a distributed denial-of-service (DDoS)-for-hire service known as NightmareStresser. The domains in question are: nightmare-stresser[.]com and nightmarestresser[.]org. Visitors to the sites are now greeted by a seizure banner that states - "This domain has been seized by
P0
2026-09-17 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-17 14:55 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Samsung rlottie. Interaction with the rlottie library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91826.
P20
2026-09-17 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-17 02:15 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-17 00:35 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-17 00:45 UTC
Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]
P0
2026-09-16 21:26 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-16 22:00 UTC
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
P0