Cybersecurity news & advisories
Rogue external MFA providers can steal passwords during logins
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts.
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people.
Windows CLOSEDQUORUM malware uses AI models to autonomously select post-compromise actions
A new Windows malware called CLOSEDQUORUM can query up to four LLM providers - Google Gemini, DeepSeek, Qwen, and Mistral - to autonomously select from predefined post-compromise actions, including stealing users’…
After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program
A House Democrat tapped to lead his party’s efforts on artificial intelligence has introduced legislation that would establish a test program within the Cybersecurity and Infrastructure Security Agency to give critical…
Relays Are Masking Chinese Access to Frontier AI Models in the US
More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases.
Microsoft Disrupts EvilTokens Device Code Phishing Service
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
Canadian regulator opens probe of IDScan for allegedly violating data privacy laws
The investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release.
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants.
The Truth about GET and HTTP Standards, (Tue, Sep 22nd)
On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow "GET" requests that include a body. The main reason for this was that GET requests typically do not contain…
Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects
Volexity researchers spotted another state-aligned Chinese threat group exploiting a triple-link chain of zero-day vulnerabilities across multiple campaigns, the company said in a blog post Monday. The threat group it…
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the…
New ClosedQuorum Windows malware uses AI for attack decisions
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack.
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to…
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily…
BigCommerce Data Stolen via Ribon Apps Hack
The attackers used a compromised BigCommerce application key held by Ribon to access customer data.
Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.
ShinyHunters claims FBI hack: 'This is NOT financially motivated'
ShinyHunters claims it hacked the FBI and stole more than 2 TB of employee data - and this time it’s personal. The gang wants the Feds to correct the record on how it operates. “This is NOT financially motivated,” a…
Reducing shadow IT visibility gaps with Wazuh
Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and…
Check Point Management Server 0-Day Vulnerability Actively Exploited in Attacks
Check Point has warned customers that attackers are exploiting a critical zero-day vulnerability in its Security Management infrastructure. Tracked as CVE-2026-93616 , the flaw carries a CVSS score of 9.8 and enables an…
Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization…
Aembit Launches Support for Okta Cross App Access, Extending Enterprise Identity Controls to AI Agents
Silver Spring, Maryland, USA, September 22nd, 2026, CyberNewswire Aembit , the identity and access management (IAM) company for AI agents, today announced support for Cross App Access (XAA), an open protocol introduced…
‘We Hacked the FBI:’ Hackers Say They Have Data on All FBI Employees
A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data…
Scaling SOC Capabilities: How Threat Intelligence Cuts Triage Time and Burnout
A suspicious IP, unfamiliar domain, or file hash can trigger an investigation in seconds. Understanding what that indicator means can take much longer. An IOC rarely tells the full story. Analysts may need to determine…
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP…
NightmareEclipse's latest zero-day leaves Microsoft Defender stuck in the past
Serial Microsoft zero-day leaker NightmareEclipse has found another way to mess with Windows Defender, this time by stopping the antivirus from updating itself. The security researcher, also known as Abdelhamid Naceri…
Meta Tests Muse AI Agent Calls That Are Actually Made By Humans in a Call Center
Last week, Meta executives announced that its much-hyped AI agent, Muse, had a new feature: It could call businesses for you to do things like make a restaurant reservation or a haircut appointment. But in reality, Meta…
Check Point warns of Management Server zero-day exploited in attacks
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts.
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster…
Z.ai says sorry for slurping up your code, open sources ZCode
Chinese AI giant Z.ai has apologized after developers caught it pulling a Grok, packaging up and uploading user workspaces to cloud storage. In a case that’s highly reminiscent of the issues over which Elon Musk’s xAI…
Autonomous AI Agents Hack Retailers for $25 and Steal 600,000 Credit Cards
A financially motivated operator has been running three open-source AI tools against many online retailers, mostly without supervision. The results are shocking: over 600,000 credit card records have been stolen…
Two arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminals
Available on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached…
CAIRN – A New Tool to Track AI Malware That Operates Without Human Control
Cisco Talos has released CAIRN, an open-source toolkit designed to hunt, classify, and track AI-integrated malware by examining the digital markers developers leave behind. The Cognitive Artifact Intelligence Research…
Citing China, President Trump doubles down on hands-off approach to AI regulation
President Donald Trump continued to defend his administration’s hands-off approach to AI regulation in the wake of hacks carried out by U.S. commercial frontier models that have rattled policymakers and industry…
Some cheap smart glasses are a security disaster
Apart from the privacy concerns around smart glasses , researchers have found that some cheap brands come with barely any security at all. ABC Australia reports that researchers from NSB Cyber and Abstract Shield tested…
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU).
Unmasking EvilTokens: Getting to the root of device code phishing
Following its emergence in February 2026, EvilTokens quickly became one of the most widely used phishing-as-a-service (PhaaS) platforms, providing cybercriminals with AI capabilities for tailoring phishing lures and…
Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud
Microsoft, along with a group of industry partners, disrupted EvilTokens, a short-lived but highly consequential cybercrime platform that investigators linked to more than 12,000 compromised Microsoft customer email…
UK cops arrest 2 EvilTokens suspects, Microsoft seizes 50 phishing kit websites
A coalition of law enforcement and private-sector tech companies led by Microsoft have disrupted the EvilTokens phishing service, arresting suspected website admins, taking down more than 50 websites, and notifying…
Who signed off on that AI agent? Nobody? Thought so
If you were in any doubt that AI agents are capable of complex autonomous work, that skepticism should have faded this summer. In July, news emerged that an autonomous swarm of OpenAI agents running in a sandbox broke…
Cyera Raises $400 Million at $12+ Billion Valuation
The data security company received the new investment from Goldman Sachs Alternatives, extending its Series G funding round.
North Korean Attackers Hit 30,000 Devices and Steal $10.7m
WaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto wallets
LOW - Now Available
After 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in…
Microsoft SharePoint Flaw Lets Attackers Execute Code Remotely With Low Privileges
Microsoft has confirmed a high-severity remote code execution vulnerability in on-premises SharePoint Server that lets an authenticated, low-privileged attacker run arbitrary code over a network without user…
New TASK#STOMP Backdoor Uses PowerShell to Steal Documents and Wi-Fi Passwords
TASK#STOMP is a newly analyzed Windows backdoor that turns ordinary built-in tools into a durable spying operation. It uses a Visual Basic Script installer, hidden PowerShell, scheduled tasks, and runtime code…
Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-89775, could let attackers escape an ARM64 virtual machine and access the underlying host system. The issue affects KVM/arm64 environments where nested…
Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Abdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse.