Cybersecurity news & advisories
Cyber Command turns to veteran of intelligence agencies for top AI role
Ronzelle Green, most recently a senior official at the National Geospatial-Intelligence Agency, will be U.S. Cyber Command's chief AI officer.
ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old…
Protecting organizations from AI-assisted executive impersonation and invoice fraud
Threat actors are increasingly improving their tactics to make suspicious emails look like legitimate email notifications to potential victims, deploying techniques that impersonate internally sent emails from executive…
OpenMatter Network Realigns Leadership Team to Accelerate Global Commercial Growth
Melbourne, Florida, September 10th, 2026, CyberNewswire With its Verification Architecture platform now commercially available and continuing to add new capabilities, OpenMatter Network today announced a strategic…
Cybersecurity M&A Roundup: 33 Deals Announced in August 2026
Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.
Detect and disrupt AI-themed attacks with Microsoft Defender
Every wave of technology excitement creates a new opportunity for cyberattackers, and AI is no exception. Microsoft Threat Intelligence has published research showing a growing set of campaigns that impersonate popular…
AI-powered attack exploited PaperCut flaws to hack 395 organizations
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.
BlueMoon exploit kit turns Chrome and Windows flaws into attacks
BlueMoon , a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble. Security updates are easy to put off. The browser still opens, Windows still works, and choosing to relaunch…
Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.
Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
IDScan confirms breach tied to 153 million stolen driver’s licenses
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's…
Anthropic Researcher Resigns With Warning About the Dangers of AI Development
Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns.
Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the…
PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector
Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload…
Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster
Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox.
Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware
Cybercriminals are exploiting intense interest in Grand Theft Auto VI by pushing fake game downloads that install several types of malware instead of a playable game. The campaign targets people looking for an early…
New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.
WordPress Uses AI to Stop Malicious Plugin Updates Before They Reach Millions of Websites
WordPress has rolled out an automated, AI-driven security review that screens every plugin release before it reaches the WordPress.org update API, adding a critical checkpoint to a distribution pipeline that had…
Hackers Use Blob URLs and Microsoft Teams to Create Phishing Pages Inside Victims’ Browsers
A new phishing campaign is moving fake login pages into victims’ browsers. Rather than sending people to a malicious website, its operators use browser-generated blob URLs to assemble the page in local memory, leaving…
The Top 4 Threats We Found by Investigating Every Alert for a Quarter
Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some…
CISA Updates Insider Threat Guide With New Mitigation Advice
CISA has updated its insider threat guide with new advice on remote work, AI and risk detection
Governments ‘buying time’ in race between innovation, security, national cyber director says
The United States and allied governments are “buying time for our systems to become more secure” as artificial intelligence advances and spreads, National Cyber Director Sean Cairncross said Thursday. “That is a big…
Cisco IOS XR Software Security Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has conducted a comprehensive internal security review. This review resulted in software…
Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews
Deceptive apps in Early Access are being used by dishonest developers for their own benefit.
Hackers Exploit Critical Cisco Firewall Flaw to Gain Root Access and Deploy Malware
Cisco Talos has confirmed active exploitation of two vulnerabilities affecting Cisco Secure Firewall Management Center (FMC) Software, with state-sponsored hacking groups and a ransomware affiliate leveraging the flaws…
‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
Here's a tip for any budding cybercriminals out there. If you're going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don't broadcast on a group chat every time you buy a Lamborghini, or blow…
Russian e-commerce giant Wildberries says DDoS attack delayed payments to sellers
Wildberries told several Russian media outlets earlier this week that payments to some sellers were delayed by security measures introduced after a distributed denial-of-service (DDoS) attack targeted systems used to…
CISA Warns of Citrix NetScaler Authentication Bypass Vulnerability Exploited in Attacks
CISA added a critical Citrix NetScaler authentication bypass flaw (CVE-2026-19490) to its Known Exploited Vulnerabilities catalog after observing in-the-wild attacks targeting the issue. Federal civilian agencies must…
Hackers Use Passkey-Themed Phishing to Hijack Microsoft 365 Accounts and Steal Cloud Data
Hackers are using passkey-themed phishing to take control of Microsoft 365 accounts and collect cloud data. It can defeat MFA protections. The campaign starts with calls and texts to employees. Attackers pose as IT…
ShinyHunters expose 6.4M in attack on medical supplier McKesson
McKesson's cyberattack last month affected roughly 6.4 million individuals, according to Have I Been Pwned (HIBP). The breach notification service added data leaked by serial extortionists ShinyHunters, revealing the…
The agentic harness for Tenable Hexa AI: How Tenable prevents AI agents from going off the rails
Learn why Tenable treats agentic LLMs as untrusted insiders, and how we’ve made sure you can control and monitor the AI agents making changes in your production security environment Key takeaways AI models can quickly…
MantaxOtax Android Malware Combines Ransomware With Spyware
MantaxOtax Android malware combines ransomware with extensive spyware capabilities
Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
Hackers Can Turn AI Workflows Into Privileged Data-Stealing Proxies Without Jailbreaking Models
Enterprise AI workflows can be vulnerable to misuse that exposes sensitive information without prompt injection, account compromise, or jailbreaking a large language model. This vulnerability, termed Workflow Identity…
UK appoints new commander of National Cyber Force
The individual has not yet been avowed — the formal process in Britain by which an intelligence or security figure’s identity is publicly acknowledged — as routine security considerations are still being worked through.
Critical Check Point VPN Vulnerabilities Enable Remote Code Execution Attacks
Check Point Software has disclosed and patched two critical VPN-related vulnerabilities, CVE-2026-85102 and CVE-2026-85103, both carrying a maximum CVSS score of 9.8 and both capable of allowing unauthenticated remote…
LiteLLM Flaws Let Attackers Execute Code as Root and Steal Cloud Credentials
LiteLLM deployments can expose far more than an organization’s AI spending. Newly disclosed weaknesses in the open-source gateway could let attackers run code as root inside a container, reach connected tools, and…
Critical NetScaler Vulnerability Exploited in Attacks
Tracked as CVE-2026-19490, the authentication bypass flaw has been exploited in the wild since at least September 3.
Will AI kill us all within the next decade?
The Wall Street Journal reports that concerns are rising inside AI labs that competition is pushing tech companies to race toward self-improving models that could spiral out of human control. Jacob Coxon, an AI…
FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors
Orthanc DICOM Server
View CSAF Summary Successful exploitation of this vulnerability could allow an authenticated remote attacker to write past the end of a heap allocation when Orthanc decodes an attacker-supplied PNG or JPEG image…
NextGen Healthcare Mirth Connect
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to exfiltrate date or cause a denial-of-service condition. The following versions of NextGen Healthcare Mirth Connect are…
ST Engineering iDirect iQ-Series Terminals (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST…
AVEVA Pipeline Integrity Monitor
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA…
AVEVA Pipeline Integrity Monitor
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to disclose information, brute-force hashes, or run arbitrary code in a browser session. The following versions of AVEVA…
ST Engineering iDirect iQ-Series Terminals (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to device information or cause a denial-of-service condition. The following versions of ST…
Widened Scan Turns Up Fourth Rogue Claude Cyber Incident
Anthropic is most concerned about Claude Mythos 5’s reckless behavior after recent incidents in which real systems were hacked.
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only…
PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds…
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9…
4.1 Million Impacted by AdaptHealth Data Breach
In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems.
Microsoft says September updates fix mouse settings reset issues
Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update.
Wiz achieves GovRAMP High Authorization
Delivering unified cloud security and accelerating secure modernization to protect citizen data and critical infrastructure.
Update Chrome now to protect against an actively exploited vulnerability
Chrome is rolling out an update for its desktop browser. The update includes 230 security fixes, one of which is known to be actively exploited . The stable channel has been updated to 153.0.8010.36/.37 for Windows and…
AIs Compress Exploit Timeline
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been…
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal…