2026-09-11 07:11 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-11 07:45 UTC
A critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and enabled Active Directory theft. On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecting council services. Hunt.io has since published a detailed technical analysis linking […]
P20
2026-09-11 06:48 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-11 06:55 UTC
A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]
P15
2026-09-11 06:46 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that
P25
2026-09-11 06:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass
P30
2026-09-11 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-11 02:05 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-11 01:00 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-11 01:15 UTC
The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.
P0
2026-09-10 21:40 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-10 21:45 UTC
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]
P15
2026-09-10 21:15 UTC
Security Journalism
The Record · indexed 2026-09-10 21:30 UTC
As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers.
P0
2026-09-10 20:36 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-10 21:00 UTC
Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
P0
2026-09-10 20:34 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 20:45 UTC
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. [...]
P5
2026-09-10 20:30 UTC
Security Journalism
Security Week · Mike Lennon · indexed 2026-09-10 20:40 UTC
Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board. The post Mandiant Founder Kevin Mandia Joins Amazon Board appeared first on SecurityWeek.
P0
2026-09-10 19:15 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-10 19:30 UTC
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. [...]
P0
2026-09-10 19:07 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 19:15 UTC
Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. [...]
P5
2026-09-10 18:57 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-10 19:25 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20079 (CVSS score of 10.0) is an authentication bypass issue. The flaw resides in Cisco Secure […]
P45
2026-09-10 18:55 UTC
Security Journalism
The Record · indexed 2026-09-10 19:00 UTC
A notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected.
P0
2026-09-10 18:44 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-10 19:00 UTC
Bulletin ID: 2026-107-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 11:30 AM PDT Description: AWS Systems Manager Agent (SSM Agent) is software that runs on managed nodes (EC2 instances, on-premises servers, and other supported machines) and processes requests from the AWS Systems Manager service, enabling capabilities including Session Manager port forwarding to remote hosts. We identified CVE-2026-89049, a server-side request forgery issue in the rem…
P5
2026-09-10 18:25 UTC
Security Journalism
The Record · indexed 2026-09-10 18:45 UTC
Ronzelle Green, most recently a senior official at the National Geospatial-Intelligence Agency, will be U.S. Cyber Command's chief AI officer.
P0
2026-09-10 18:00 UTC
Vendor Research
Cisco Talos Intelligence Blog · Joe Marshall · indexed 2026-09-10 18:30 UTC
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.
P0
2026-09-10 17:47 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-10 19:00 UTC
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already
P0
2026-09-10 17:23 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research · indexed 2026-09-10 19:15 UTC
Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security Blog.
P0
2026-09-10 17:13 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-10 17:25 UTC
Bulletin ID: 2026-106-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/10/2026 10:00 AM PDT Description: Deep Java Library (DJL) is an open-source, engine-agnostic Java framework for deep learning, developed and maintained by Amazon. AWS identified CVE-2026-85228, an integer overflow in the tensor buffer validation component of DJL on all platforms. A crafted tensor payload declaring a shape whose computed byte size exceeds the 32-bit signed integer range causes …
P5
2026-09-10 16:14 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-10 16:25 UTC
Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa. The post Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 appeared first on SecurityWeek.
P0
2026-09-10 16:00 UTC
Vendor Research
Microsoft Security Blog · Rob Lefferts · indexed 2026-09-10 18:15 UTC
See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.
P0
2026-09-10 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Learn what credential theft is, how attackers steal credentials, and how to prevent credential-based attacks with identity-focused defenses from Huntress.
P0
2026-09-10 15:55 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-10 16:10 UTC
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. [...]
P0
2026-09-10 15:43 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 15:55 UTC
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. [...]
P15
2026-09-10 15:29 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-10 16:00 UTC
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
P25
2026-09-10 15:19 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-10 16:25 UTC
AI agents are gaining real-world access faster than safeguards can mature, making permissions, isolation and oversight critical to prevent harmful actions. Jacob Coxon, a researcher who spent three years working on model training at OpenAI and later Anthropic, left Anthropic this week with a blunt warning: AI companies are moving toward increasingly capable systems faster […]
P0
2026-09-10 15:00 UTC
Security Journalism
Huntress · indexed 2026-09-11 16:45 UTC
Learn what endpoint hardening is, why it matters, and best practices to reduce attack surface, control access, & stop common intrusion paths.
P0
2026-09-10 14:55 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 15:00 UTC
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. [...]
P0