2026-09-09 21:02 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-09 21:05 UTC
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]
P0
2026-09-09 19:54 UTC
Security Journalism
The Record · indexed 2026-09-09 20:05 UTC
The U.S. government also carried out a seizure of $52.8 million from 52 wallets connected to the platform.
P0
2026-09-09 19:47 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-09 20:05 UTC
US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.
P0
2026-09-09 19:09 UTC
Vendor Research
AWS Security Blog · Anshumali Shrivastava · indexed 2026-09-09 19:30 UTC
Security teams are starting to actively use AI for security work, including vulnerability triage, penetration testing, threat modeling, incident response, and code review. The promise is speed, but a security tool that moves fast and raises too many false alarms doesn’t save time. Engineers spend time on false alarms, on-call is noisier, and teams distrust […]
P0
2026-09-09 18:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 19:50 UTC
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime
P0
2026-09-09 18:20 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-09 18:50 UTC
US agencies accuse six Chinese AI firms of extracting billions of tokens from US AI models to accelerate development and copy advanced capabilities. NSA, CISA, and the FBI jointly published an advisory accusing six Chinese AI companies, DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, of running industrial-scale extraction campaigns against US frontier models since […]
P0
2026-09-09 18:11 UTC
Security Journalism
The Record · indexed 2026-09-09 18:20 UTC
The settlement concludes a legal fight that dates to April 2024, when UK users sued for the alleged violations of their country’s privacy laws.
P0
2026-09-09 17:46 UTC
Community
SANS Internet Storm Center · indexed 2026-09-09 18:00 UTC
About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.
P0
2026-09-09 17:41 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Krithika Ramakrishnan, Bharat Vaghela, Vaibhav Deshmukh, Subhajit Ghosh, Anusha Chakraborty, Akash Chaudhuri, Victor Chingtham and Ivan Macalintal · indexed 2026-09-09 18:45 UTC
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. The post Passkey-themed social engineering leads to identity and cloud compromise appeared first on Microsoft Security Blog.
P0
2026-09-09 17:23 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 17:30 UTC
The company will increase its US market presence and will expand its engineering and go-to-market teams. The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek.
P0
2026-09-09 17:03 UTC
Security Journalism
The Record · indexed 2026-09-09 17:20 UTC
Veradigm said access was limited to a specific interface, and did not impact the company’s broader environment such as its networks, servers or databases. The incident did not result in operational disruptions, the company added.
P0
2026-09-09 16:56 UTC
Security Journalism
Security Week · Kevin Townsend · indexed 2026-09-09 17:10 UTC
Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG. The post AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns appeared first on SecurityWeek.
P0
2026-09-09 16:48 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-09 16:50 UTC
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]
P0
2026-09-09 16:34 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 19:50 UTC
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
P0
2026-09-09 16:30 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 16:50 UTC
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components. The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek.
P15
2026-09-09 16:30 UTC
Security Journalism
The Record · indexed 2026-09-09 16:50 UTC
A Google Chrome bug identified in August was exploited by at least four China-linked cyber-espionage groups, according to researchers.
P25
2026-09-09 16:22 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 16:30 UTC
Major chipmakers announced patches for vulnerabilities recently discovered in their products. The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek.
P0
2026-09-09 16:08 UTC
Vendor Research
Cisco Talos Intelligence Blog · Cisco Talos · indexed 2026-09-09 16:30 UTC
Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software.
P0
2026-09-09 15:37 UTC
Security Journalism
The Record · indexed 2026-09-09 15:55 UTC
The first public cybersecurity strategy issued by the FBI "directs our teams, our field offices, our global presence" to align their efforts on countering malicious hackers and cybercrime groups, senior official Brett Leatherman says.
P0
2026-09-09 15:31 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-09 15:35 UTC
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]
P15
2026-09-09 15:16 UTC
Vendor Research
Rapid7 · Conor McCormick · indexed 2026-09-09 16:10 UTC
If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them.Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer being right. The traditional answer comes from the outside: the scan engine sends traffic to a range of ports and infers each port's state from how the host responds. That…
P0
2026-09-09 14:39 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-09 15:25 UTC
"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.
P0
2026-09-09 14:33 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-09 14:50 UTC
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.
P0
2026-09-09 14:23 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-09 14:40 UTC
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
P0
2026-09-09 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Specops Software · indexed 2026-09-09 14:10 UTC
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]
P0
2026-09-09 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-11 16:45 UTC
Threat actors are exploiting GTA6 hype with fake leaked downloads spread via SEO poisoning, packed with RATs, infostealers, and wiper ransomware. Here’s what Huntress found.
P15
2026-09-09 13:47 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-09 14:50 UTC
Google patched 230 Chrome flaws, including an actively exploited V8 bug that could let attackers run arbitrary code through a crafted HTML page. Google released a Chrome update fixing 230 security vulnerabilities, including one already exploited in the wild tracked as CVE-2026-87491 (CVSS score of 8.8). The medium-severity flaw affects V8, Google’s open source high-performance […]
P50
2026-09-09 13:07 UTC
Government
CERT-EU Security Advisories · indexed 2026-09-09 13:10 UTC
On 8 September 2026, as part of its September Security Patch Day, SAP released Security Notes addressing two critical vulnerabilities affecting a broad range of SAP products[3]. The most severe, CVE-2026-44756 (CVSS 10.0), is a memory corruption vulnerability in SAP Extended Passport (EPP) processing, nicknamed "OVERPASS" by the Onapsis Research Labs (ORL), which discovered and responsibly disclosed it[3]. The second, CVE-2026-58240 (CVSS 9.8), nicknamed "S4GET", is a missing authentication che…
P5
2026-09-09 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-11 16:45 UTC
See how a browser-in-the-browser phishing attack led to rogue ScreenConnect persistence and evasion tactics Huntress caught in the act.
P0
2026-09-09 13:00 UTC
Vendor Research
Tenable Blog · Mark Beblow · indexed 2026-09-09 13:10 UTC
Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector.Key takeawaysThe Exchange Inspector combines Tenable’s exposure detection with OpenAI’s GPT Cyber models and with human oversight to rigorously vet submissions made to th…
P0