2026-09-14 16:41 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-14 17:10 UTC
Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?
P0
2026-09-14 16:15 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-14 16:30 UTC
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]
P0
2026-09-14 16:15 UTC
Security Journalism
The Record · indexed 2026-09-14 16:15 UTC
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.
P0
2026-09-14 16:02 UTC
Security Journalism
The Record · indexed 2026-09-14 16:30 UTC
The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices.
P0
2026-09-14 16:00 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 17:00 UTC
WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin
P0
2026-09-14 16:00 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-14 16:20 UTC
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing. One of them is known to be actively exploited. For more information, see Cisco Secure Email Gateway SQL …
P30
2026-09-14 14:51 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-14 15:25 UTC
The managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detection and moved to a world with a convergence of exposure management and response to deliver measurable, outcome-based defenses of a larger, AI-driven attack surface.For anyone evaluating MDR right now, the Managed Detection and Response Services Landscape, Q3 2026 report by Forrester is a useful map that lays out where the market is heading…
P0
2026-09-14 14:40 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 15:35 UTC
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of
P0
2026-09-14 14:28 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-14 14:45 UTC
China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI. The post Beijing Hits Back at Anthropic CEO’s Call to Curb China’s AI Development appeared first on SecurityWeek.
P0
2026-09-14 14:08 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-14 14:25 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: Two of the above vulnerabilities affect JFrog Artifactory. CVE-2026-42016 can allow attackers to bypass authorization checks and […]
P35
2026-09-14 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Action1 · indexed 2026-09-14 14:15 UTC
Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how update rings, predefined success criteria, and human oversight can make automated patching faster without sacrificing control. [...]
P0
2026-09-14 13:31 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-14 13:45 UTC
Concerns over the potential risks of the technology are rising as new AI models become more powerful, heightening both the potential for misuse by people with criminal aims. The post New Warnings About the Risks of AI to Humanity Revive a Long-Running Debate appeared first on SecurityWeek.
P0
2026-09-14 13:03 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-14 13:10 UTC
The company unintentionally disclosed users’ information to a third party impersonating a government agency. The post Personal, Financial Info Exposed in Revolut Data Breach appeared first on SecurityWeek.
P0
2026-09-14 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-14 19:45 UTC
Attackers exploit Volume Shadow Copy for credential theft and ransomware defense evasion. See how Huntress spots the difference from routine IT activity.
P15
2026-09-14 13:00 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-14 13:10 UTC
As researchers warn that misaligned AI could threaten human survival, even beneficial systems may erode the critical thinking that defines our humanity. The post The Race to Control AI and Protect What Makes Us Human appeared first on SecurityWeek.
P0
2026-09-14 12:22 UTC
Other
Check Point Research · urias@checkpoint.com · indexed 2026-09-14 12:30 UTC
For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a […] The post 14th September – Threat Intelligence Report appeared first on Check Point Research.
P0
2026-09-14 12:15 UTC
Security Journalism
BleepingComputer · BleepingComputer · indexed 2026-09-14 12:25 UTC
Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. This webinar examines two attacks to show how these breaches unfold and which security controls can help stop them. [...]
P0
2026-09-14 12:00 UTC
Security Journalism
The Record · indexed 2026-09-14 12:20 UTC
British fintech company Revolut confirmed disclosing sensitive customer data to fraudsters who submitted emergency data requests from a legitimate government email account.
P0
2026-09-14 11:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 12:25 UTC
There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49% more than in the
P0
2026-09-14 11:51 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-14 12:10 UTC
The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek.
P0
2026-09-14 10:30 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-14 10:50 UTC
Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. The post CISOs Race to Control AI Agents Without Destroying Their Value appeared first on SecurityWeek.
P0
2026-09-14 10:02 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-14 10:50 UTC
OverviewOn September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706, a critical path traversal vulnerability (CWE-22) in the repository commits API with a CVSSv3.1 score of 10.0. According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions.On September …
P55
2026-09-14 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Osher Jacob · indexed 2026-09-14 10:10 UTC
We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries. The post Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection appeared first on Unit 42.
P0
2026-09-14 09:56 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-14 10:10 UTC
Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records. The post Telus Warns Customers of Account Breaches appeared first on SecurityWeek.
P0
2026-09-14 09:50 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-14 10:05 UTC
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. [...]
P5
2026-09-14 09:43 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-14 09:50 UTC
Two critical Check Point VPN flaws score 9.8 and could enable remote code execution. Patch now and restrict VPN access before exploitation begins. The Dutch NCSC warns that two critical vulnerabilities in Check Point VPN products, both rated CVSS score of 9.8, could soon be actively exploited. If you use Check Point VPN, you should […]
P45
2026-09-14 09:27 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-14 09:30 UTC
The vulnerabilities can allow attackers to bypass authentication and elevate their privileges to administrator. The post Three JFrog Artifactory Flaws Exploited for Backdoor Deployment appeared first on SecurityWeek.
P0
2026-09-14 08:48 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-14 08:55 UTC
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency. [...]
P0
2026-09-14 08:25 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-14 08:30 UTC
The flaw allows attackers to send files and execute them without authorization through an active remote session. The post ConnectWise Patches ScreenConnect Vulnerability Exploited in Worm-Like Attacks appeared first on SecurityWeek.
P0
2026-09-14 08:08 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-14 08:20 UTC
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. [...]
P5