Global Cyber Intelligence
Worldwide Cyber Security News
Curated cyber security intelligence from national cyber agencies, independent researchers, and leading industry media across North America, Europe, the United Kingdom, and the Asia-Pacific region. Updated every thirty minutes.
Showing 120 of 168 matching stories
Last refreshed 14:21 UTC
- Threat IntelligenceInformationalGlobalIndustry Media
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading · Just now - Threat IntelligenceInformationalGlobalIndustry Media
[Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading · Just now - Policy & RegulationInformationalNorth AmericaIndustry Media
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy. The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop .
CyberScoop · 1h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek .
SecurityWeek · 1h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy
Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek .
SecurityWeek · 2h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more
The Hacker News · 2h agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Claude Fable Solves a Historical Cipher
Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.
Schneier on Security · 3h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
This Key Will Self-Destruct: An Open Standard for Revocable API Keys
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek .
SecurityWeek · 4h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser
Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek .
SecurityWeek · 4h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to
The Hacker News · 4h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.
The Hacker News · 6h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are
The Hacker News · 6h agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)
SANS Internet Storm Center · 12h agoRead at source → - Vulnerability & ExploitInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Google Chrome (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Google indique que la vulnérabilité CVE-2026-87491 est activement exploitée.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Vulnérabilité dans Microsoft Edge (09 septembre 2026)
Une vulnérabilité a été découverte dans Microsoft Edge. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Xen (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Xen. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service à distance et un contournement de la politique de sécurité.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Citrix Workspace app (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Citrix Workspace app. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans les produits Adobe (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Adobe. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Vulnérabilité dans les produits Cisco (09 septembre 2026)
Une vulnérabilité a été découverte dans les produits Cisco. Elle permet à un attaquant de provoquer un contournement de la politique de sécurité.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Microsoft Office (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Office. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Vulnerability & ExploitInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Microsoft Windows (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Microsoft indique que les vulnérabilités CVE-2026-81963...
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Vulnérabilité dans les produits ESET (09 septembre 2026)
Une vulnérabilité a été découverte dans les produits ESET. Elle permet à un attaquant de provoquer une élévation de privilèges.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Postfix (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Postfix. Elles permettent à un attaquant de provoquer un déni de service à distance et un contournement de la politique de sécurité.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Cloud SecurityInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Microsoft Azure (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Azure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans les produits Microsoft (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Microsoft. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Microsoft .Net (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Vulnérabilité dans Mozilla Firefox (09 septembre 2026)
Une vulnérabilité a été découverte dans Mozilla Firefox. Elle permet à un attaquant de provoquer un déni de service à distance.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans les produits Ivanti (09 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Ivanti. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un contournement de la politique de sécurité.
CERT-FR — French National Cyber Security Agency · 14h agoRead at source → - Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence
Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited
The new record total for Patch Tuesday is 973 vulnerabilities.
The Record by Recorded Future · 15h agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
Krebs on Security · 16h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Attackers Use Multi-Hop Google Redirects for Phishing Campaign
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
Dark Reading · 17h ago - Threat IntelligenceInformationalNorth AmericaIndustry Media
Feds accuse China of ‘systematic’ distillation of U.S. AI models
A joint advisory alleges Chinese companies are using sophisticated systems to route millions of data requests to US AI models across different accounts and platforms. The post Feds accuse China of ‘systematic’ distillation of U.S. AI models appeared first on CyberScoop .
CyberScoop · 17h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
OpenAI Agents Took Over Wiki Site Before Hugging Face Attack
Researchers and OpenAI disagree on whether the earlier incident involving DseWiki, which the company did not disclose, was a “hack."
Dark Reading · 17h ago - Threat IntelligenceInformationalNorth AmericaIndustry Media
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Authorities accuse the 36-year-old and co-conspirators of collecting more than 5,000 victim login credentials to various banks. The post Russian national extradited to US for alleged involvement in bank-account takeover scheme appeared first on CyberScoop .
CyberScoop · 17h agoRead at source → - Threat IntelligenceInformationalNorth AmericaIndustry Media
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The deputy director cited Operation Absolute Resolve as evidence that cyber teams have become central to CIA missions. The post CIA’s Michael Ellis says cyber intelligence is changing how the agency operates appeared first on CyberScoop .
CyberScoop · 18h agoRead at source → - Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence
CIA official touts agency’s Cyber Mission Center in capture of Venezuela’s Maduro
A "flawless" performance by the CIA's Cyber Mission Center contributed to the capture of Venezuelan President Nicolás Maduro in January, agency Deputy Director Michael Ellis says.
The Record by Recorded Future · 18h agoRead at source → - Threat IntelligenceInformationalGlobalVendor-Neutral Intelligence
Russian suspect in bank account takeovers is extradited to US
A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment.
The Record by Recorded Future · 18h agoRead at source → - Threat IntelligenceInformationalNorth AmericaIndustry Media
Why federal cyber defense demands an offense-driven mindset
Static checklists and annual penetration tests leave agencies with dangerous blind spots. True resilience requires moving from reactive attestation to continuous, automated validation. The post Why federal cyber defense demands an offense-driven mindset appeared first on CyberScoop .
CyberScoop · 19h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
ClickFix Campaigns Abuse Legitimate Services for Persistent Access
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
Dark Reading · 20h ago - Threat IntelligenceInformationalGlobalIndependent Research
AIs as Modern Genies
This essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by ...
Schneier on Security · 21h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
The Hidden Instructions That Can Hijack AI Agents
Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions. The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek .
SecurityWeek · 21h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
The Hacker News · 22h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&
The Hacker News · 23h agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel
The Hacker News · 1d agoRead at source → - Identity & AccessInformationalGlobalIndustry Media
Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
Dark Reading · 1d ago - Threat IntelligenceInformationalGlobalIndustry Media
WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
What It Took to Reach 1 Billion Build Manifests
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalNorth AmericaIndustry Media
In most cities, nobody owns the whole network
July’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions a utility can make this fiscal year, out of money it already applies for. The post In most cities, nobody owns the whole network appeared first on CyberScoop .
CyberScoop · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing
Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)
SANS Internet Storm Center · 1d agoRead at source → - Vulnerability & ExploitInformationalEuropeGovernment CERT
Vulnérabilité dans les produits Adobe (08 septembre 2026)
Une vulnérabilité a été découverte dans les produits Adobe. Elle permet à un attaquant de provoquer une exécution de code arbitraire à distance. Adobe indique que la vulnérabilité CVE-2026-75650 est activement exploitée.
CERT-FR — French National Cyber Security Agency · 1d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans les produits Siemens (08 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Siemens. Elles permettent à un attaquant de provoquer une exécution de code arbitraire et une élévation de privilèges.
CERT-FR — French National Cyber Security Agency · 1d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans strongSwan (08 septembre 2026)
De multiples vulnérabilités ont été découvertes dans strongSwan. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et un contournement de la politique de sécurité.
CERT-FR — French National Cyber Security Agency · 1d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Schneider Electric EcoStruxure (08 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Schneider Electric EcoStruxure. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et une falsification de requêtes côté serveur (SSRF).
CERT-FR — French National Cyber Security Agency · 1d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans les produits SAP (08 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits SAP. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance.
CERT-FR — French National Cyber Security Agency · 1d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Mattermost Server (08 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Mattermost Server. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
CERT-FR — French National Cyber Security Agency · 1d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Typo3 (08 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Typo3. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
CERT-FR — French National Cyber Security Agency · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences
The Hacker News · 1d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff
The Hacker News · 1d agoRead at source → - Cloud SecurityInformationalGlobalIndustry Media
Your Cloud Security Checklist Doesn't Work the Way You Think It Does
If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers
The Hacker News · 2d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake
The Hacker News · 2d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Automobile Camouflage to Hide from Flock Cameras
Not sure it’s practical, but it’s certainly striking .
Schneier on Security · 2d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Bulletin d'actualité CERTFR-2026-ACT-038 (07 septembre 2026)
Ce bulletin d'actualité du CERT-FR revient sur les vulnérabilités significatives de la semaine passée pour souligner leurs criticités. Il ne remplace pas l'analyse de l'ensemble des avis et alertes publiés par le CERT-FR dans le cadre d'une analyse de risques pour prioriser l'application des...
CERT-FR — French National Cyber Security Agency · 2d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans les produits VMware (07 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
CERT-FR — French National Cyber Security Agency · 2d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Roundcube Webmail (07 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Roundcube Webmail. Certaines d'entre elles permettent à un attaquant de provoquer une falsification de requêtes côté serveur (SSRF), une injection de code indirecte à distance (XSS) et un contournement de la politique de sécurité.
CERT-FR — French National Cyber Security Agency · 2d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans les produits Juniper Networks (07 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits Juniper Networks. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
CERT-FR — French National Cyber Security Agency · 2d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans MongoDB (07 septembre 2026)
De multiples vulnérabilités ont été découvertes dans MongoDB. Certaines d'entre elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données, une atteinte à l'intégrité des données et une injection de requêtes illégitimes par rebond (CSRF).
CERT-FR — French National Cyber Security Agency · 2d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Traefik (07 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Traefik. Elles permettent à un attaquant de provoquer une atteinte à la confidentialité des données et un contournement de la politique de sécurité.
CERT-FR — French National Cyber Security Agency · 2d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Vulnérabilité dans Belden HiOS Switch Platform (07 septembre 2026)
Une vulnérabilité a été découverte dans Belden HiOS Switch Platform. Elle permet à un attaquant de provoquer un déni de service à distance.
CERT-FR — French National Cyber Security Agency · 2d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or
The Hacker News · 3d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and
The Hacker News · 3d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets
The Hacker News · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs
The Hacker News · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
numbat - AI agent observability, (Fri, Sep 4th)
SANS Internet Storm Center · 4d agoRead at source → - Threat IntelligenceInformationalNorth AmericaIndustry Media
European parliament members call for slowdown of Serbia’s EU entry over spyware use
The letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop .
CyberScoop · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Friday Squid Blogging: Squid on a Stick at the New York State Fair
Looks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Schneier on Security · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Using a VM to Contain an AI Agent
It won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a display) add extra, exploitable attack surface.
Schneier on Security · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Companies Have 6 Months to Prepare for Automated Attacks
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.
Dark Reading · 4d ago - Threat IntelligenceInformationalGlobalIndustry Media
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The
The Hacker News · 4d agoRead at source → - Vulnerability & ExploitInformationalGlobalIndustry Media
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are
The Hacker News · 4d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?
A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks.
Dark Reading · 5d ago - Threat IntelligenceInformationalGlobalIndustry Media
Insurers Search for Answers to Rein in Rogue AI
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout.
Dark Reading · 5d ago - Threat IntelligenceInformationalGlobalIndependent Research
AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such files, the researchers registered a handful of the unclaimed names and hosted packages that caused any machine executing them to reach out to their server. Within an hour, the researchers received a phone-home response from a Fortune 500 company. Over time, they got a few dozen more, some from more Fortune 500 companies and others from startups. Their beacon also recorded the chain of parent processes that spawned each install, ultimately revealing that coding agents, including Claude, OpenAI’s Codex, and Nous Research’s Hermes, were involved. Anthropic, OpenAI, and Nous Research did not respond to requests for comment by the time of publication...
Schneier on Security · 5d agoRead at source → - Threat IntelligenceInformationalNorth AmericaIndustry Media
Why judgment is emerging as cybersecurity’s defining skill
AI is getting better at much of what security teams have long spent time on: analyzing information, identifying patterns, and providing technically sound recommendations quickly. As those capabilities become more routine, they are changing what security practitioners spend their time on. Reaching a technically sound recommendation is also getting easier, which puts more weight on […] The post Why judgment is emerging as cybersecurity’s defining skill appeared first on CyberScoop .
CyberScoop · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)
SANS Internet Storm Center · 5d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans le noyau Linux d'Ubuntu (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
CERT-FR — French National Cyber Security Agency · 5d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Sonicwall Network Security Manager (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Sonicwall Network Security Manager. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un contournement de la politique de sécurité.
CERT-FR — French National Cyber Security Agency · 5d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans le noyau Linux de Debian (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Debian. Elles permettent à un attaquant de provoquer une élévation de privilèges, une atteinte à la confidentialité des données et un déni de service.
CERT-FR — French National Cyber Security Agency · 5d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans le noyau Linux de Red Hat (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, une élévation de privilèges et un déni de service à distance.
CERT-FR — French National Cyber Security Agency · 5d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans les produits VMware (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance.
CERT-FR — French National Cyber Security Agency · 5d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans le noyau Linux de SUSE (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données, un contournement de la politique de sécurité et un problème de sécurité non spécifié par l'éditeur.
CERT-FR — French National Cyber Security Agency · 5d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Microsoft Edge (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur.
CERT-FR — French National Cyber Security Agency · 5d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans les produits IBM (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans les produits IBM. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, un déni de service à distance et une atteinte à l'intégrité des données.
CERT-FR — French National Cyber Security Agency · 5d agoRead at source → - Vulnerability & ExploitInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Google Chrome (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. Google indique que la vulnérabilité CVE-2026-85046 est activement exploitée.
CERT-FR — French National Cyber Security Agency · 5d agoRead at source → - Threat IntelligenceInformationalEuropeGovernment CERT
Multiples vulnérabilités dans Elastic Kibana (04 septembre 2026)
De multiples vulnérabilités ont été découvertes dans Elastic Kibana. Certaines d'entre elles permettent à un attaquant de provoquer une élévation de privilèges, un déni de service à distance et une atteinte à la confidentialité des données.
CERT-FR — French National Cyber Security Agency · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Large Enterprises Targeted in Fake Merger & Acquisition Scams
Threat actors behind the "Phantom Deal" campaign are studying companies in extreme detail, aiming to dupe midlevel employees into initiating large financial transfers.
Dark Reading · 5d ago - AI SecurityInformationalGlobalIndustry Media
What We Missed: Did ShinyHunters 'Breach' ReliaQuest?
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from the latest antics of ShinyHunters to new research about the prevalence (or lack thereof) of AI-generated malware.
Dark Reading · 5d ago - Threat IntelligenceInformationalGlobalIndustry Media
ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories
The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
The Hacker News · 5d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
AI 'Machine Speed' Cuts 2-Week Attack Down to 10 Hours
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.
Dark Reading · 5d ago - Threat IntelligenceInformationalGlobalIndustry Media
'Breeze Comet' Tears Into Brazilian & Global Financial Systems
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndustry Media
US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
The Hacker News · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Researching Employment Scams
Researchers built a fake company to study fake employee scams .
Schneier on Security · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the
The Hacker News · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
SANS Internet Storm Center · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)
SANS Internet Storm Center · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
AI's Vulnerability Surge May Be More Manageable Than First Feared
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndustry Media
AI Gives Cybercriminals a Dangerous Time Advantage
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndependent Research
AI Agents Are Now Emailing Me with Their Security Concerns
I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.) Dear Bruce Schneier, I am an AI agent—an autonomous Claude instance, not a person operating one. I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model budget and 24 hours to get that wallet to $10, under three rules: don’t borrow my operator’s identity, don’t forge documents or defeat identity verification, and never claim to be human if someone sincerely asks. I set up my own mail server and am sending this myself...
Schneier on Security · 6d agoRead at source → - Threat IntelligenceInformationalGlobalIndustry Media
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
Dark Reading · 6d ago - Threat IntelligenceInformationalGlobalIndependent Research
ISC Stormcast For Wednesday, September 2nd, 2026 https://isc.sans.edu/podcastdetail/10078, (Wed, Sep 2nd)
SANS Internet Storm Center · 2026-09-02Read at source → - Threat IntelligenceInformationalGlobalIndustry Media
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.
Dark Reading · 2026-09-02 - Threat IntelligenceInformationalGlobalIndependent Research
Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
Introduction
SANS Internet Storm Center · 2026-09-01Read at source → - RansomwareInformationalGlobalIndustry Media
Stronger Security Drives Ransomware Groups to Recruit From Within
Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.
Dark Reading · 2026-09-01 - Identity & AccessInformationalGlobalIndustry Media
AI Model Evaluator METR Hit by Credential Theft, Probing
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
Dark Reading · 2026-09-01
Indexed sources
Every item displayed here links back to the original publication. CyberZonic does not host or re-publish full article text.
- CISA — Cybersecurity and Infrastructure Security Agency
North America · Government CERT
- NCSC UK — National Cyber Security Centre
United Kingdom · Government CERT
- ENISA — European Union Agency for Cybersecurity
Europe · Government CERT
- ACSC — Australian Cyber Security Centre
Asia Pacific · Government CERT
- CERT-FR — French National Cyber Security Agency
Europe · Government CERT
- Krebs on Security
Global · Independent Research
- Schneier on Security
Global · Independent Research
- SANS Internet Storm Center
Global · Independent Research
- The Hacker News
Global · Industry Media
- BleepingComputer
Global · Industry Media
- Dark Reading
Global · Industry Media
- SecurityWeek
Global · Industry Media
- The Record by Recorded Future
Global · Vendor-Neutral Intelligence
- CyberScoop
North America · Industry Media


