2026-09-16 13:10 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-16 13:20 UTC
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek.
P40
2026-09-16 13:09 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-16 14:15 UTC
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut data exposure may be part of a much broader cyber incident involving compromised Italian government infrastructure. Revolut has confirmed that its systems were not breached. Instead, […]
P0
2026-09-16 12:45 UTC
Security Journalism
The Record · indexed 2026-09-16 13:00 UTC
Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.
P0
2026-09-16 12:16 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-16 12:30 UTC
Microsoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. [...]
P0
2026-09-16 12:11 UTC
Security Journalism
BleepingComputer · BleepingComputer · indexed 2026-09-16 12:30 UTC
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. [...]
P0
2026-09-16 12:00 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-16 12:20 UTC
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek.
P0
2026-09-16 11:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 12:45 UTC
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud
P0
2026-09-16 11:32 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-16 11:40 UTC
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek.
P15
2026-09-16 11:15 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 11:45 UTC
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database
P35
2026-09-16 11:15 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 11:45 UTC
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.
P0
2026-09-16 11:14 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-16 11:30 UTC
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]
P45
2026-09-16 11:11 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-09-16 11:20 UTC
The company will use the new capital to expand its vulnerability operations platform and support international growth. The post Hackuity Raises $19 Million for AI-Powered Vulnerability Management appeared first on SecurityWeek.
P0
2026-09-16 11:08 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 11:45 UTC
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux
P35
2026-09-16 10:47 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-16 11:00 UTC
In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information. The post 280,000 Impacted by Premier Medical Group Data Breach appeared first on SecurityWeek.
P0
2026-09-16 10:28 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-16 10:40 UTC
Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox. The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek.
P0
2026-09-16 10:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Martin Lee · indexed 2026-09-16 10:25 UTC
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensatory layer.
P0
2026-09-16 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Bradley Duncan · indexed 2026-09-16 10:20 UTC
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42.
P0
2026-09-16 09:52 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-16 10:00 UTC
CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation. The post Acronis Patches Exploited Vulnerability in cPanel Backup Plugin appeared first on SecurityWeek.
P15
2026-09-16 09:10 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-16 09:20 UTC
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. [...]
P0
2026-09-16 09:00 UTC
Other
ESET · indexed 2026-09-17 09:50 UTC
As AI adoption expands the attack surface and adds to the security workload, businesses need automation backed by experts
P0
2026-09-16 08:39 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-16 08:40 UTC
The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability appeared first on SecurityWeek.
P5
2026-09-16 08:19 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-16 08:40 UTC
CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based utility, which supplies electricity and gas to about 7 million accounts across Texas, Indiana, Minnesota and […]
P0
2026-09-16 08:06 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-16 08:20 UTC
The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws. The post Oracle Patches 800+ Vulnerabilities in September 2026 Security Update appeared first on SecurityWeek.
P5
2026-09-16 07:00 UTC
Other
Group-IB · indexed 2026-09-16 08:20 UTC
Attacks now are cheap, fast, and outsourced. The recent research shows what it changes and how organizations should strategy defense.
P0
2026-09-16 07:00 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-16 07:15 UTC
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]
P25
2026-09-16 06:40 UTC
Vendor Research
ANY.RUN Blog · ANY.RUN · indexed 2026-10-06 14:56 UTC
Speed and clarity are the ultimate advantages for modern SOC teams. The integration of ANY.RUN into SentinelOne delivers exactly that. Instant threat intelligence and interactive sandbox capabilities embedded right where your analysts already work. Let’s look at how this unified workflow eliminates context switching, accelerates incident response, and drives higher ROI by transforming alerts into […] The post ANY.RUN & SentinelOne: One Workspace, Instant Context for Rapid Response appeared firs…
P0
2026-09-16 05:48 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 06:40 UTC
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over
P15
2026-09-16 05:18 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-16 06:40 UTC
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication
P25
2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-17 00:20 UTC
This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-92183.
P20
2026-09-16 05:00 UTC
Other
Zero Day Initiative · indexed 2026-09-17 00:20 UTC
This vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of NoMachine. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.2. The following CVEs are assigned: CVE-2026-92210.
P5