- CISA: Critical VMware RCE flaw now exploited by ransomware gangsby Sergiu Gatlan on September 15, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a […]
- Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Secondsby info@thehackernews.com (The Hacker News) on September 15, 2026
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new […]
- Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Pointby info@thehackernews.com (The Hacker News) on September 15, 2026
Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail […]
- Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Serversby info@thehackernews.com (The Hacker News) on September 15, 2026
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an […]
- Suspected Black Axe gang leaders face cybercrime charges in the USby Sergiu Gatlan on September 15, 2026
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to […]
- Microsoft confirms KB5002914 Excel update breaks copy and pasteby Sergiu Gatlan on September 15, 2026
Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update. [...]
- Cisco patches Secure Email Gateway zero-day exploited in attacksby Sergiu Gatlan on September 15, 2026
Cisco warned customers to patch a critical Secure Email Gateway zero-day security flaw that threat actors have been exploiting in attacks. [...]
- LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Serverby info@thehackernews.com (The Hacker News) on September 15, 2026
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned […]
- Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Executionby info@thehackernews.com (The Hacker News) on September 15, 2026
Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. […]
- China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGEby info@thehackernews.com (The Hacker News) on September 15, 2026
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to […]
- Microsoft releases emergency Windows updates to fix RDS failuresby Lawrence Abrams on September 14, 2026
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with […]
- Japan's Digital Agency says VPN flaw exposed 246,000 personnel recordsby Bill Toulas on September 14, 2026
Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. […]
- Homebrew 7.0.0 gets built-in GUI, better security controlsby Bill Toulas on September 14, 2026
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native […]
- Twitch extension with 30K installs exposes users’ OAuth tokensby Bill Toulas on September 14, 2026
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a […]
- Hackers hijack HBO Max Reddit account to push malware in ClickFix adsby Lawrence Abrams on September 14, 2026
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with […]
- New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computingby info@thehackernews.com (The Hacker News) on September 14, 2026
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping […]
- 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentialsby info@thehackernews.com (The Hacker News) on September 14, 2026
An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a […]
- Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exportsby info@thehackernews.com (The Hacker News) on September 14, 2026
A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in […]
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countriesby info@thehackernews.com (The Hacker News) on September 14, 2026
A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to […]
- Hackers target exposed Vite dev servers to steal AWS, Azure secretsby Bill Toulas on September 14, 2026
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure […]
- WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distributionby info@thehackernews.com (The Hacker News) on September 14, 2026
WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API […]
- ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkitsby info@thehackernews.com (The Hacker News) on September 14, 2026
AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also […]
- Why Patch Automation Needs Brakes, Not Just an Acceleratorby Sponsored by Action1 on September 14, 2026
Patch automation can help IT teams keep pace with growing update volumes, but deploying faster also means bad updates can spread faster. Action1 explains how […]
- Conti Ransomware Member Sentenced to 4 Years in Jailby Steve Alder on September 14, 2026
A Ukrainian national who deployed Conti ransomware on the networks of at least 12 organizations in the United States and The post Conti Ransomware Member […]
- Webinar: How malicious OAuth apps can lead to Google Workspace breachesby BleepingComputer on September 14, 2026
Attackers can combine social engineering with malicious OAuth applications to gain access to Google Workspace data without relying solely on stolen passwords. […]
- AI Changed the Exposure Problem. Validation Needs to Change With It.by info@thehackernews.com (The Hacker News) on September 14, 2026
There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery […]
- Microsoft: September updates cause RDS failures on Windows Serverby Sergiu Gatlan on September 14, 2026
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. [...]
- Revolut discloses data breach exposing financial info, passportsby Sergiu Gatlan on September 14, 2026
Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government […]
- Microsoft: September updates break audio on some Windows PCsby Sergiu Gatlan on September 14, 2026
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. […]
- Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Usersby info@thehackernews.com (The Hacker News) on September 14, 2026
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial […]
- Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Databy info@thehackernews.com (The Hacker News) on September 13, 2026
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam […]
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEVby info@thehackernews.com (The Hacker News) on September 12, 2026
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and […]
- When the Whole Company Adopts AI: What It Does to Your SOCby info@thehackernews.com (The Hacker News) on September 12, 2026
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts […]
- OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Serversby info@thehackernews.com (The Hacker News) on September 12, 2026
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers […]
- GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosureby info@thehackernews.com (The Hacker News) on September 11, 2026
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours […]
- Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacksby info@thehackernews.com (The Hacker News) on September 11, 2026
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including […]
- Claude Used to Automate Exploitation and Data Theft Across Multiple Victimsby info@thehackernews.com (The Hacker News) on September 11, 2026
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass […]
- Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detectionby info@thehackernews.com (The Hacker News) on September 11, 2026
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted […]
- Orthanc DICOM Server Vulnerability Can Lead to Denial of Serviceby Steve Alder on September 11, 2026
A high-severity vulnerability has been identified in Orthanc DICOM Server that could be exploited by an authenticated remote attacker to The post Orthanc […]
- Your Critical Vulnerabilities Might Not Be Your Biggest Riskby info@thehackernews.com (The Hacker News) on September 11, 2026
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining […]
- Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoorsby info@thehackernews.com (The Hacker News) on September 11, 2026
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted […]
- China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoorby info@thehackernews.com (The Hacker News) on September 11, 2026
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a […]
- PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flawsby info@thehackernews.com (The Hacker News) on September 11, 2026
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two […]
- Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomwareby info@thehackernews.com (The Hacker News) on September 11, 2026
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure […]
- The Future of Payment Integrity: How Leading Plans Move from Recovering Dollars to Preventing Leakageby mcottam on September 10, 2026
The Future of Payment Integrity: How Leading Plans Move from Recovering Dollars to Preventing Leakage Explore how Medicaid plans can move beyond […]
- ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Storiesby info@thehackernews.com (The Hacker News) on September 10, 2026
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes […]
- High Severity Vulnerabilities Identified in NextGen Healthcare Mirth Connectby Steve Alder on September 10, 2026
Three high-severity vulnerabilities have been identified in NextGen Healthcare Mirth Connect (Mirth Connect), a cross-platform healthcare integration engine […]
- Google Play Early Access Abused to Push Thousands of Deceptive Android Appsby info@thehackernews.com (The Hacker News) on September 10, 2026
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. […]
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCEby info@thehackernews.com (The Hacker News) on September 10, 2026
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow […]
- PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instancesby info@thehackernews.com (The Hacker News) on September 10, 2026
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair […]































