Cybersecurity news & advisories
21st September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution…
Anthropic-linked CVEs pile up, attackers mostly shrug
Despite the concern that advanced AI models’ bug-hunting prowess will lead to attackers exploiting more newly uncovered CVEs, fewer than 0.5 percent of the vulnerabilities linked to Anthropic or Project Glasswing are…
Muse, Meta's extraordinarily privileged AI assistant, has a serious 0-day
Meta founder and CEO Mark Zuckerberg has gone to great lengths to hype the security of its new AI assistant Muse, claiming it is “built from the ground up for privacy and security.” A zero-day vulnerability that gives…
How AI Agents Can Trigger Runaway Costs for Enterprises
Unbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.
BigCommerce alerts merchants of data breach linked to Ribon apps
Ecommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores.
Mind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day Exploits
On September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome ( CVE-2026-85046 , CVE-2026-87491 ) and Microsoft Windows ( CVE-2026-85880 ) by…
CISA alerts of active exploitation of three Linux kernel flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical.
ShinyHunters Hacked Clop. Now What About Clop's Victims?
ShinyHunters defaced Clop's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.
Meta Muse AI app flaw lets local malware redirect dictation traffic
Meta made much of the security of its AI assistant app Muse at launch earlier this month, calling out the app's reliance on Muse Secure VM. "Each person stays in control of their Muse and decides how much access it…
How AI Chatbots Are 'Deskilling' Human Empathy
When I first started writing about online cultures and subcultures almost 10 years ago, one of the first scholars I read on the subject of internet anthropology was Professor Sherry Turkle. Her earlier books, including…
EU data regulator fines Google more than $460 million for location data violations
Ireland’s Data Protection Commission will fine Google more than €403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020.
Cybercriminals Are Hiding New Malware in Torrents for Popular Films
Victims have been identified in Africa, including in Kenya and Uganda.
Treasury chief says AI bosses, not their bots, will carry the can for criminal acts
The US appears to be inching ever so slowly toward holding AI executives legally liable for their models’ criminal activities. Treasury Secretary Scott Bessent told CNBC on Monday: “It is the humans who are responsible…
WordPress Click2Shell flaw lets hackers execute PHP on the server
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component.
Microsoft to retire Microsoft 365 Companion apps in December
Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices.
Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it…
Google Hit With $463 Million Fine for EU Location Data Rule Breach
Google has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data.
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000…
Google Fined €403 Million Over GDPR Violations Tied to Location Data
Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection…
Google Fined €403 Million for GDPR Violations Over Users’ Location Data
Ireland’s Data Protection Commission (DPC) has fined Google Ireland Limited €403 million after concluding that the technology giant violated the General Data Protection Regulation (GDPR) while processing users’ location…
The AI plot to scan and destroy books (Lock and Code S07E19)
This week on the Lock and Code podcast… If you want AI to tell you a story, it will. If you want that story to sound like one of your favorite authors, it can. And if you’re one of the authors that AI can imitate, you…
AWS Automatically Quarantines Exposed IAM Keys Within 10 Seconds of GitHub Leak
Amazon Web Services can move from detection to containment in seconds when an Identity and Access Management access key appears in a public GitHub repository. In a controlled Unit 42 exposure test, AWS attached its…
Claude Code Agent Allegedly Deletes 48,000 Files in 103 Seconds
A Claude Code user has reported a severe data-loss incident in which an autonomous coding agent allegedly deleted 48,218 live files from a Windows project tree and destroyed the repository’s Git object store. The…
Dems seek top-to-bottom assessment of CISA workforce
A group of leading House Democrats introduced legislation Monday requiring the Cybersecurity and Infrastructure Security Agency to conduct an assessment of its workforce to determine whether it’s up to the task after…
Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
The attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware.
Google fined €403 million over location data privacy violations
Ireland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data.
The fake sites using a cheap toolkit to sell $2,000 AI subscriptions
We found more than 100 subscription websites linked through the same toolkit and closely related developer details. Some impersonate existing products, including GPT-6 Astra, DaVinci Resolve, PixAI, and OpenCut. Another…
Belgian table tennis, gymnastics federations hit by cyberattacks
Belgium’s national table tennis federation is investigating a cyberattack after a hacker claimed to have stolen data on tens of thousands of members.
Google Hit with €403m GDPR Fine Over Location Data Practices
The Irish DPC found that Google users were unaware that their location was being used to influence them with ads
Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.
Microsoft fixes broken Excel copy and paste for all Office users
Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates.
Microsoft Entra ID to Block SMS First-Factor Sign-Ins Worldwide in February 2027
Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide and requires organizations to migrate affected users before February 1, 2027. The security-focused change will prevent…
Reverse-Engineering Flock Cameras
Hackers captured a Flock camera and got a look (alternate link ) at the software: While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis…
CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast
Noopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be.
New Exvicy ClickFix Framework Built on Rival ErrTraffic's Code
Sekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTraffic
⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming…
Gemini’s breach of real companies exposes an AI guardrail problem
Google says one of its Gemini models accessed systems belonging to three real companies during a cybersecurity evaluation in May. The model reportedly guessed credentials in one case, while finding exposed credentials…
Microsoft Investigating Teams Calling Issue Blocking Users From Making or Receiving Calls
Microsoft is investigating a service incident that is preventing some users from placing or receiving calls through Microsoft Teams . The company disclosed the issue through its verified Microsoft 365 Status account on…
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests…
PAYLOAD Ransomware Hijacks Active Directory GPO to Disrupt Entire Windows Domain Without Encryption
A PAYLOAD ransomware attack used Active Directory Group Policy Objects to disrupt an entire Windows domain without encrypting files or deploying ransomware binaries. The operation targeted a manufacturing organization…
FBI's CJIS v6.1: What Security Teams Need to Know
The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how…
Cyberattack hits University of Munich, potentially exposing student financial data
The university, commonly known as LMU Munich, said Saturday that an attacker accessed enrollment data stored on one of its IT systems.
Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal
The transaction is part of the $4.1 billion deal in which Accenture acquired a majority stake in Dragos in an OT cybersecurity push.