2026-09-01 22:40 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-09-01 23:05 UTC
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) toda…
P0
2026-09-01 21:30 UTC
Community
SANS Internet Storm Center · indexed 2026-09-01 00:50 UTC
Introduction
P0
2026-09-01 21:05 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-01 21:35 UTC
CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.
P15
2026-09-01 21:03 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-09-01 21:05 UTC
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
P15
2026-09-01 20:53 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-01 20:55 UTC
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
P0
2026-09-01 20:48 UTC
Security Journalism
Dark Reading · Rob Wright · indexed 2026-09-01 21:05 UTC
The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.
P5
2026-09-01 20:35 UTC
Security Journalism
The Record · indexed 2026-09-01 20:50 UTC
A hacking operation dubbed Fire Ant "didn’t just compromise systems," according to researchers. "It compromised the trust layer those systems depend on."
P0
2026-09-01 20:13 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-01 20:50 UTC
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
P0
2026-09-01 19:28 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-01 19:30 UTC
Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...]
P0
2026-09-01 18:55 UTC
Vendor Research
Microsoft Security Blog · Microsoft Defender Experts Cybersecurity Incident Response · indexed 2026-09-01 20:15 UTC
Cyber resilience starts before a crisis. Gain practical insights from DART to strengthen readiness and response. The post Cybersecurity IR Workshop: The workshop you shouldn’t miss appeared first on Microsoft Security Blog.
P0
2026-09-01 17:54 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-01 18:00 UTC
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]
P20
2026-09-01 17:53 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 18:15 UTC
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. "JFrog Artifactory contains an authentication weakness that, under default
P15
2026-09-01 17:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 18:15 UTC
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers." The adversary
P0
2026-09-01 17:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
New regulations, data exfiltration tactics, and shifting premiums are reshaping cyber insurance. Our 2026 report reveals what businesses need to know now.
P0
2026-09-01 16:00 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
Understand the critical role of cyber insurance in safeguarding your business from cyber threats. Learn how this coverage can protect your assets.
P0
2026-09-01 15:31 UTC
Security Journalism
The Record · indexed 2026-09-01 15:50 UTC
Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.
P0
2026-09-01 15:12 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 15:40 UTC
Aesto Health suffered a breach exposing personal and health data of more than 9.5 million people after attackers accessed its AWS infrastructure. Aesto Health, a U.S. healthcare technology company, disclosed a data breach that exposed personal and health information belonging to more than 9.5 million people. The company discovered the incident on December 18, 2025, […]
P0
2026-09-01 14:45 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-01 15:00 UTC
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
P0
2026-09-01 14:33 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 14:40 UTC
Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast Antivirus. The researcher named the exploit PrettyPrague, it triggers a privilege escalation flaw. The researcher claims to have found […]
P35
2026-09-01 14:28 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 14:30 UTC
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]
P0
2026-09-01 14:07 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 14:45 UTC
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect
P0
2026-09-01 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Spur Intelligence · indexed 2026-09-01 14:15 UTC
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. [...]
P0
2026-09-01 14:00 UTC
Security Journalism
Huntress · indexed 2026-09-08 13:30 UTC
Healthcare organizations and banks handle highly personal information. But a new Huntress survey shows many threat actors frequently target these companies.
P0
2026-09-01 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC
Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…
P0
2026-09-01 13:56 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-01 14:50 UTC
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
P0
2026-09-01 13:50 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 14:40 UTC
Five Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty after trying to steal cash from ATMs in Kansas using the popular ATM jackpotting technique. The U.S. Department of Justice announced the case on August 31, […]
P0
2026-09-01 13:08 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 13:20 UTC
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the
P0
2026-09-01 12:38 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 12:50 UTC
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
P10
2026-09-01 12:33 UTC
Security Journalism
The Record · indexed 2026-09-01 12:50 UTC
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
P0
2026-09-01 12:28 UTC
Security Journalism
The Record · indexed 2026-09-01 12:35 UTC
Andrew Bailey, chair of the Financial Stability Board, called on financial institutions and technology providers to “prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies.”
P0