2026-09-16 21:20 UTC
Vendor Research
AWS Security Blog · Pablo Pagani · indexed 2026-09-16 21:50 UTC
The AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AWS partition (aws-eusc), with its own control plane, AWS Identity and […]
P0
2026-09-16 21:07 UTC
Security Journalism
The Record · indexed 2026-09-16 21:30 UTC
“It's really complicated, and I wouldn't want to do something in a lame duck session to do it quickly and not get it right,” said House Energy and Commerce Chairman Brett Guthrie about the FRONTIER Act.
P0
2026-09-16 20:39 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-16 20:50 UTC
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]
P5
2026-09-16 20:24 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 20:35 UTC
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]
P0
2026-09-16 20:20 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-16 21:00 UTC
Lumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietly control infected Windows and Linux machines. Most malware connects directly to a command-and-control […]
P0
2026-09-16 20:16 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-16 20:20 UTC
Bulletin ID: 2026-113-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/16/2026 12:30 PM PDT Description: Network Policy Agent is an EKS Policy management feature. We identified CVE-2026-86831, a cross-namespace NetworkPolicy bypass in Amazon EKS Network Policy Agent (aws-network-policy-agent) before v1.4.0. Pod identifiers are constructed by concatenating the pod name and namespace with a hyphen delimiter, which is a legal character in both Kubernetes pod names a…
P5
2026-09-16 18:50 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 19:00 UTC
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]
P0
2026-09-16 18:46 UTC
Security Journalism
The Record · indexed 2026-09-16 19:05 UTC
U.S. personnel boarded an oil tanker in the Gulf of Mexico to “ensure integrity of the vessel’s operational and information technology systems," after an apparent cyberattack, the U.S. Coast Guard said.
P0
2026-09-16 18:44 UTC
Community
SANS Internet Storm Center · indexed 2026-09-16 19:00 UTC
Earlier today, I noted an odd request showing up in our "First Seen" report:
P0
2026-09-16 18:28 UTC
Security Journalism
The Record · indexed 2026-09-16 18:35 UTC
The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped to properly investigate them.
P0
2026-09-16 18:14 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-09-16 18:25 UTC
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge …
P0
2026-09-16 18:00 UTC
Security Journalism
Dark Reading · Dark Reading Editorial Team · indexed 2026-09-16 18:20 UTC
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.
P0
2026-09-16 17:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 17:45 UTC
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
P0
2026-09-16 17:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-16 17:30 UTC
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]
P0
2026-09-16 16:43 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-16 16:55 UTC
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
P0
2026-09-16 16:39 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-16 16:50 UTC
Spanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek.
P0
2026-09-16 16:07 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-09 16:30 UTC
On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these vulnerabilities, Cisco strongly recommends that customers upgrade to the fixed software that is indicated in the advisories. For more information about changes in Cisco PSIRT vulnerability disclosure, see Strengthening the Foundation: A Predictable, Customer-Focused Response to AI-Accelerated Vulnerability Discovery. Cisco Identity…
P30
2026-09-16 16:05 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. This vulnerability is due to the presence of static user credentials for a low-privileged account. An attacker could exploit this vulnerability by using the account to log in to an affected system. A successful exploit could allow the atta…
P5
2026-09-16 16:05 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to insufficient error checking when processing HTTP requests. An attacker could exploit this vulnerability by sending a crafted HTTP request to the Remot…
P5
2026-09-16 16:03 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-08-15 14:33 UTC
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to bypass authentication and execute script files on an affected device to obtain root access to the underlying operating system. This vulnerability is due to an improper system process that is created at boot time. An attacker could exploit this vulnerability by sending crafted HTTP requests to an affected device. A successful exploit could allow the at…
P15
2026-09-16 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied input. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attac…
P5
2026-09-16 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
Multiple vulnerabilities in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to modify parts of the configuration on an affected device. These vulnerabilities are due to the lack of server-side validation of Administrator permissions. An attacker could exploit these vulnerabilities by submitting a crafted HTTP request to an affected system. A successful exploit could allow …
P5
2026-09-16 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
A vulnerability in the web-based management interface of Cisco BroadWorks CommPilot Application Software could allow an authenticated, remote attacker with low privileges to alter configurations on an affected device. This vulnerability is due to missing authorization checks. An attacker could exploit this vulnerability by sending a crafted HTTP request. A successful exploit could allow the attacker to alter configurations on select pages. Cisco has released software updates that address this v…
P5
2026-09-16 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct SQL or HQL injection attacks on an affected device. These vulnerabilities are due to insufficient validation of user-supplied input to the affected APIs before it is used to build database queries. An attacker could exploit these vulnerabilities by sending a crafted request to an affected device. A successful exploit could a…
P5
2026-09-16 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow a remote attacker to conduct SQL injection attacks on an affected device. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvis…
P5
2026-09-16 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
A vulnerability in the API of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to view sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient validation of user-supplied parameters in API requests. An attacker could exploit this vulnerability by sending a crafted API request to an affected device. A successful exploit could allow the attacker …
P5
2026-09-16 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
A vulnerability in the RADIUS feature of Cisco Identity Services Engine (ISE) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper handling of certain RADIUS requests. An attacker could exploit this vulnerability by sending a crafted RADIUS request directly to an affected device. A successful exploit could allow the attacker to cause the ISE node to become unavailable. For single node deployment…
P5
2026-09-16 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
Multiple vulnerabilities in Cisco Secure Firewall Management Center (FMC) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated attacker to perform an sftunnel authentication bypass or sftunnel denial of service (DoS) attack. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This a…
P15
2026-09-16 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
A vulnerability in the TLS 1.3 implementation in Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. This vulnerability is due to improper buffer management during the TLS 1.3 connection. An attacker could exploit this vulnerability by sending a crafted TLS 1.3 packet to an affected system through a TLS 1.3-enabled listening socket. A successful e…
P5
2026-09-16 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-16 16:40 UTC
Multiple vulnerabilities in Cisco Identity Services Engine (ISE) could allow an unauthenticated, local attacker to either conduct an authentication bypass or disclose sensitive information. For more information about these vulnerabilities, see the Details section of this advisory. Cisco has released software updates that address these vulnerabilities. There are no workarounds that address these vulnerabilities. This advisory is available at the following link:https://sec.cloudapps.cisco.com/sec…
P15