2026-09-08 16:35 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-08 17:10 UTC
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. [...]
P0
2026-09-08 16:28 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-08 16:40 UTC
OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. [...]
P0
2026-09-08 16:20 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 16:50 UTC
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
P0
2026-09-08 15:22 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-08 15:40 UTC
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]
P5
2026-09-08 15:21 UTC
Security Journalism
Security Week · Mike Lennon · indexed 2026-09-08 15:25 UTC
The startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud. The post Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta appeared first on SecurityWeek.
P0
2026-09-08 14:55 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-08 15:00 UTC
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]
P5
2026-09-08 14:55 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 15:05 UTC
Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data. The post SAP Patches Critical Extended Passport Processing Vulnerability appeared first on SecurityWeek.
P0
2026-09-08 14:54 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&
P0
2026-09-08 14:40 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-08 14:45 UTC
OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities. [...]
P25
2026-09-08 14:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel
P0
2026-09-08 14:03 UTC
Security Journalism
The Record · indexed 2026-09-08 14:20 UTC
Two populous states and two large cities are among the U.S. jurisdictions where leaders have taken direct action to address criticisms of automated license plate readers (ALPRs).
P0
2026-09-08 14:00 UTC
Vendor Research
Tenable Cyber Exposure Alerts · Satnam Narang · indexed 2026-09-08 14:20 UTC
A critical unauthenticated remote code execution (RCE) zero-day in Adobe Commerce and Magento Open Source, dubbed StyleSmuggler, has been actively exploited since September 4 with attacks observed three days before a vendor patch became available.Key takeawaysCVE-2026-75650 is a critical remote code execution vulnerability in Adobe Commerce, Adobe Commerce B2B and Magento Open Source that can be triggered without authentication.Active exploitation of CVE-2026-75650 began on September 4, 2026, t…
P95
2026-09-08 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-08 13:45 UTC
Executive Summary Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. In these operations, human-in-the-loop latency is dramatically reduced, compressing the traditional window for defenders to respond. In Q2 2026, GTIG observed threat actors compromise a cloud resource, then plan, b…
P35
2026-09-08 13:48 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 15:20 UTC
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI
P0
2026-09-08 13:34 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-08 13:35 UTC
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
P30
2026-09-08 13:00 UTC
Other
Check Point Research · stcpresearch · indexed 2026-09-08 13:10 UTC
Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capabilities significantly increase the practical value of LLMs, but they also change the security model: protecting user […] The post The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT appeared f…
P0
2026-09-08 13:00 UTC
Security Journalism
Security Week · Associated Press · indexed 2026-09-08 13:25 UTC
The scammers purchased fleets of sports cars, flew on private jets, hired security guards and rented mansions in Miami and the Hamptons. The post Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft appeared first on SecurityWeek.
P0
2026-09-08 12:40 UTC
Security Journalism
BleepingComputer · BleepingComputer · indexed 2026-09-08 13:20 UTC
Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. [...]
P0
2026-09-08 12:30 UTC
Security Journalism
The Record · indexed 2026-09-08 12:50 UTC
French authorities detained an 18-year-old suspected member of the ZeroBytes hacking group over cyberattacks against the country's tax authority and other organizations.
P0
2026-09-08 12:03 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-08 12:10 UTC
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]
P0
2026-09-08 12:00 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-09-09 12:10 UTC
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
P0
2026-09-08 12:00 UTC
Security Journalism
The Record · indexed 2026-09-08 12:20 UTC
A municipal utility in Bavaria is recovering from a cyberattack that encrypted its internal IT systems but did not affect water and electricity services.
P0
2026-09-08 11:57 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-08 12:00 UTC
Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. [...]
P0
2026-09-08 11:54 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 13:20 UTC
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since
P0
2026-09-08 11:49 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 13:20 UTC
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally
P0
2026-09-08 11:22 UTC
Vendor Research
Cisco Security Advisories · indexed 2026-09-02 16:10 UTC
Multiple vulnerabilities in the Secure/Multipurpose Internet Mail Extensions (S/MIME) decryption functionality of Cisco Secure Email could allow an unauthenticated, remote attacker to recover plain text from encrypted email messages. These vulnerabilities are due to insufficient validation of message integrity. An attacker could exploit these vulnerabilities by using a machine-in-the-middle technique to intercept and modify traffic between email gateways. A successful exploit could allow the at…
P5
2026-09-08 11:22 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-08 11:45 UTC
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The
P0
2026-09-08 11:15 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-08 11:30 UTC
Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices. The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek.
P10
2026-09-08 11:01 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-08 11:30 UTC
An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017 to April 2026. The data includes sensitive details such as passport numbers, identities and flight information, potentially affecting […]
P0
2026-09-08 11:01 UTC
Vendor Research
Rapid7 · Stephen Fewer · indexed 2026-09-08 12:25 UTC
OverviewWhile conducting research into a recent N-able N-central authentication bypass vulnerability (CVE-2026-18577), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server.CVE IDDescriptionCWECVSSv4CVE-2026-86206Semicolon/Forwarded access-control bypassCWE-791…
P15