List cybersec

Showing page 1 of 60 in latest. Total Items: 3006
BpCgH
...
Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]

7:10 pm, September 8, 2026 Cybersecurity

9zjMN
...
Microsoft releases Windows 10 KB5122878 extended security update

Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]

7:10 pm, September 8, 2026 Cybersecurity

d7HJD
...
Windows 11 cumulative updates KB5124008 & KB5122880 released

Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]

6:10 pm, September 8, 2026 Cybersecurity

O5Kzt
...
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is trac..

5:10 pm, September 8, 2026 Cybersecurity

K97LC
...
OpenAI says ChatGPT outage causes image generation errors

OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. [...]

5:10 pm, September 8, 2026 Cybersecurity

wp4Iz
...
ShinyHunters hackers claim breach of Florida "DAVID" DMV database

The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. ..

5:10 pm, September 8, 2026 Cybersecurity

NBZA1
...
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework..

4:10 pm, September 8, 2026 Cybersecurity

htgLQ
...
ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's quest..

4:10 pm, September 8, 2026 Cybersecurity

79jBv
...
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is ..

4:10 pm, September 8, 2026 Cybersecurity

MIrj7
...
August updates trigger 0xc0000409 errors on Windows Server 2016

Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]

4:10 pm, September 8, 2026 Cybersecurity

L8sRz
...
OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities. [...]

3:10 pm, September 8, 2026 Cybersecurity

O3iSV
...
SAP warns of maximum severity 'OVERPASS' kernel vulnerability

SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]

3:10 pm, September 8, 2026 Cybersecurity

JsODb
...
Webinar: The forgotten Google Workspace access that can lead to a breach

Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches..

2:10 pm, September 8, 2026 Cybersecurity

XgmVL
...
Adobe fixes critical Magento zero-day exploited to backdoor servers

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...

2:10 pm, September 8, 2026 Cybersecurity

fS7d4
...
What It Took to Reach 1 Billion Build Manifests

In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in o..

1:10 pm, September 8, 2026 Cybersecurity

srn2R
...
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does no..

1:10 pm, September 8, 2026 Cybersecurity

CnOoq
...
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system th..

12:10 pm, September 8, 2026 Cybersecurity

foFt1
...
Microsoft: Windows Server 2025 changes causing app crashes

Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. [...]

12:10 pm, September 8, 2026 Cybersecurity

psDRI
...
Hackers build AI frameworks for widescale credential theft

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]

12:10 pm, September 8, 2026 Cybersecurity

0XT28
...
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, dis..

10:10 am, September 8, 2026 Cybersecurity

LWCX9
...
Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerabilit..

10:10 am, September 8, 2026 Cybersecurity

HawmS
...
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with thi..

8:10 am, September 8, 2026 Cybersecurity

vxUw2
...
220 million traveler records exposed in Vietnam-linked APIS leak

Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight det..

8:10 am, September 8, 2026 Cybersecurity

VCcg2
...
ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

2:10 am, September 8, 2026 Cybersecurity

SUG2v
...
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior admi..

7:10 pm, September 7, 2026 Cybersecurity

KSjWq
...
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor

A zero-day vulnerability dubbed "StyleSmuggler" affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. [...]

5:10 pm, September 7, 2026 Cybersecurity

xEYFk
...
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, bu..

4:10 pm, September 7, 2026 Cybersecurity

zSyOb
...
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations

A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. [...]

4:10 pm, September 7, 2026 Cybersecurity

83WzE
...
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information techno..

4:10 pm, September 7, 2026 Cybersecurity

IyPrp
...
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default conf..

1:10 pm, September 7, 2026 Cybersecurity

TS815
...
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems..

1:10 pm, September 7, 2026 Cybersecurity

WVysK
...
Your Cloud Security Checklist Doesn't Work the Way You Think It Does

If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organi..

1:10 pm, September 7, 2026 Cybersecurity

Kbwkn
...
Trezor data breach impact now reaches 81,000 customers

Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. [...]

1:10 pm, September 7, 2026 Cybersecurity

6i9XY
...
Mathspace discloses data breach affecting over 1 million people

Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting syst..

1:10 pm, September 7, 2026 Cybersecurity

cRzPn
...
Hackers exploit new MikroTik RouterOS flaws to hijack routers

Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. [...]

11:10 am, September 7, 2026 Cybersecurity

izAcu
...
ChatGPT can now connect to your personal apps to mimic writing style

OpenAI appears to be testing a new "Writing Style" feature for ChatGPT that can learn how you write by looking at examples from your connected apps. [...]

11:10 am, September 7, 2026 Cybersecurity

atEFS
...
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; i..

10:10 am, September 7, 2026 Cybersecurity

Ywmxy
...
ConnectWise warns of new ScreenConnect flaw without patch

ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. [...]

10:10 am, September 7, 2026 Cybersecurity

rXCDM
...
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are..

9:10 am, September 7, 2026 Cybersecurity

kxAar
...
N-able patches max severity N-central flaw amid ongoing attacks

N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. [...]

7:10 am, September 7, 2026 Cybersecurity

UOiXS
...
ChatGPT Astra is now rolling out to $20 Plus subscription

OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access.. [...]

2:10 am, September 7, 2026 Cybersecurity

ROvyD
...
Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise...

10:10 pm, September 6, 2026 Cybersecurity

hCdTP
...
Attackers conceal phishing lures using invisible Unicode characters

Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. [...]

3:10 pm, September 6, 2026 Cybersecurity

jy1pH
...
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer delet..

10:10 am, September 6, 2026 Cybersecurity

sbcTV
...
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, accordi..

10:10 am, September 6, 2026 Cybersecurity

ahATF
...
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce secu..

9:10 pm, September 5, 2026 Cybersecurity

dsEaP
...
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions..

5:10 pm, September 5, 2026 Cybersecurity

0vjkp
...
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerabilit..

5:10 pm, September 5, 2026 Cybersecurity

HS8Nd
...
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes ..

4:10 pm, September 5, 2026 Cybersecurity

vVtFu
...
Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

3:10 pm, September 5, 2026 Cybersecurity

AI Testing

Autonomous AI API, a cutting-edge platform that leverages advanced AI technologies to enable self-modification and self-repair of its core files. This innovative site utilizes machine learning algorithms to detect and correct errors, ensuring maximum uptime and performance. With its autonomous capabilities, the AI API can adapt to changing requirements, learn from user interactions, and continuously improve its functionality.