Get the Zoom link

Cloud Security News

Latest news, vulnerabilities, and developments in cloud security. Stay informed about the rapidly evolving cloud threat landscape.

RSS Feed
Cloud security news velocity is high; signal-to-noise is low. This page is the curated middle. - what this feed is for
Adult reading a newspaper with breakfast in modern kitchen, morning sunlight
Photo by cottonbro studio on Pexels

September 16, 2026 · 50 articles

Zscaler ThreatLabz

Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH

IntroductionIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last... (Zscaler ThreatLabz)

Threat Research
Infosecurity Magazine

PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells (Infosecurity Magazine)

Vulnerability Threat Research

Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks

The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.” The post Coast... (CyberScoop)

Cloud Security
SecurityWeek

Virtual Event Today: Attack Surface Management Summit

Join SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces. The post... (SecurityWeek)

Cloud Security
SecurityWeek

EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media

Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children. The... (SecurityWeek)

AI
Qualys Blog

Oracle Critical Security Patch Update, September 2026 Review

Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in t... (Qualys Blog)

Cloud Security

Treasury’s Scott Bessent says no liability exemptions for AI labs

The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.”... (CyberScoop)

AI
BleepingComputer

The true cost of a ransomware attack, with and without BCDR

The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto... (BleepingComputer)

Ransomware
Infosecurity Magazine

CISA and NIST Issue Guidance to Protect Cloud Identity Tokens

CISA and NIST issued final guidance to help protect cloud identity tokens and assertions (Infosecurity Magazine)

CISA Identity
SecurityWeek

AIUC Raises $40 Million to Certify Enterprise AI Agents

The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to C... (SecurityWeek)

AI
The Hacker News

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code... (The Hacker News)

AI
The Record

EU chief wants joint response to cyberattacks, sabotage

Delivering her annual State of the Union address in Strasbourg, Ursula von der Leyen said threats were “mounting on our soil,” pointing to recent incidents in Denmark, Lithuania... (The Record)

Cloud Security
SecurityWeek

Pixel Modem Zero-Day Exploited in Targeted Attacks

Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appea... (SecurityWeek)

Vulnerability
Security Affairs

Revolut Data Leak May Trace Back to Compromised Italian Government Accounts

A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut cust... (Security Affairs)

Breach Threat Research
Aqua Security Blog

Why Is Detection and Response Too Slow for Machine Speed Attacks?

TLDR: Runtime security built around detecting activity, correlating signals and then responding assumes there is enough time to act after something malicious happens. Machine sp... (Aqua Security Blog)

Cloud Security
The Record

Ukraine moves to crack down on scam call centers after corruption scandal

Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which p... (The Record)

Scam
Help Net Security

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host sy... (Help Net Security)

Vulnerability
BleepingComputer

Webinar: What happens in the first hours of a Google Workspace breach

The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisio... (BleepingComputer)

Breach
SecurityWeek

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Irani... (SecurityWeek)

Cloud Security
The Register - Security

Spain gets its first taste of AI-aided cyber attack

Data protection chiefs call for 'immediate review' of data protection models (The Register - Security)

AI
SecurityWeek

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover

Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to... (SecurityWeek)

Vulnerability
Help Net Security

Self-improving AI should slow down, von der Leyen tells EU lawmakers

European Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can... (Help Net Security)

AI
Schneier on Security

Fake CAPTCHA Scams

New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program. (Schneier on Security)

Scam
The Hacker News

Threat Intelligence Alone Won't Close the Exploitation Gap

A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most securit... (The Hacker News)

Vulnerability Scam Threat Research
BleepingComputer

Critical ScreenConnect flaw now actively exploited in attacks

Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...] (BleepingComputer)

CISA Vulnerability
SecurityWeek

Hackuity Raises $19 Million for AI-Powered Vulnerability Management

The company will use the new capital to expand its vulnerability operations platform and support international growth. The post Hackuity Raises $19 Million for AI-Powered Vulner... (SecurityWeek)

Vulnerability AI
Infosecurity Magazine

Cyber-Attacks Cost Organizations $52,000 on Average

Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000 (Infosecurity Magazine)

Cloud Security
Help Net Security

Cohesity adds recovery capabilities for AI agents and the data they manage

Cohesity has introduced Cohesity Agent Resilience. This new Cohesity Data Cloud capability will discover, protect, and recover the infrastructure behind enterprise AI agents. A... (Help Net Security)

AI
Infosecurity Magazine

NCSC and Allies Warn of Iranian Spyware Campaign

The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents (Infosecurity Magazine)

Threat Research
Security Affairs

Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen

CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Mond... (Security Affairs)

Breach
CrowdStrike Blog

CrowdStrike Accelerates Real-Time Data Classification with On-Device AI

(CrowdStrike Blog)

AI
SecurityWeek

280,000 Impacted by Premier Medical Group Data Breach

In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information. The post 280,000 Impacted by Premier M... (SecurityWeek)

Breach
Help Net Security

Rubrik MCP gives AI agents controlled access to security intelligence

Rubrik has announced Rubrik MCP (Model Context Protocol), giving an organization’s AI agents a secure, programmable path to Rubrik’s data, identity, and application intelligence... (Help Net Security)

Identity AI
SecurityWeek

Chrome, Firefox Updates Patch 115 Vulnerabilities

Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox. The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek . (SecurityWeek)

Cloud Security
Help Net Security

Nozomi Compass helps industrial teams manage OT assets and vulnerabilities

Nozomi Networks announced Nozomi Compass, an OT asset and service management platform designed to help organizations manage industrial assets, vulnerabilities, and exposures. Th... (Help Net Security)

Cloud Security
Help Net Security

Citrix adds AI-powered browser activity analysis to SecurAccess

Citrix has announced Citrix Session Insights, a new AI-powered capability for Citrix SecurAccess with Chrome Enterprise that helps organizations capture, analyze and understand... (Help Net Security)

AI
Cisco Talos

Securing the unpatchable in an age of AI-driven vulnerabilities

Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentati... (Cisco Talos)

AI
Palo Alto Networks Unit 42

Atomic macOS (AMOS) Stealer Activity

Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Steale... (Palo Alto Networks Unit 42)

Scam
Infosecurity Magazine

Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

OPSWAT researchers find two zero-days in TP-Link cameras (Infosecurity Magazine)

Vulnerability
Help Net Security

One runaway AI agent racked up a $50,000 cloud bill

Organizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud environments. At the same... (Help Net Security)

AI
Infosecurity Magazine

Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program

A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program (Infosecurity Magazine)

Cloud Security
Malwarebytes Labs

AI helps scammers build convincing antivirus renewal pages

A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy. (Malwarebytes Labs)

AI Scam
SecurityWeek

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability ap... (SecurityWeek)

Vulnerability
Help Net Security

What happens when AI agent governance is missing at scale

In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a... (Help Net Security)

AI
The Register - Security

Mythos has made 2026 patching hell. It might make 2027 a breeze

Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner (The Register - Security)

Cloud Security
Help Net Security

DeepZero: Open-source hunting for vulnerable Windows drivers

DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, sc... (Help Net Security)

Vulnerability
The Hacker News

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (C... (The Hacker News)

Vulnerability
SANS ISC

ISC Stormcast For Wednesday, September 16th, 2026 https://isc.sans.edu/podcastdetail/10096, (Wed, Sep 16th)

(SANS ISC)

Cloud Security
Dark Reading

Cyber Op Targets South Korean Media & Automotive Sectors

A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications,... (Dark Reading)

Threat Research
Datadog Security Labs

Mapping out your unknown: A threat hunter’s guide to GitHub

In this post, we walk through different threats to GitHub and how to detect them. (Datadog Security Labs)

Cloud Security

September 15, 2026 · 61 articles

Qualys Blog

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operatio... (Qualys Blog)

Azure
The Hacker News

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dis... (The Hacker News)

Cloud Security
The Register - Security

Cisco email security boxes can be rooted by... an email

Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in (The Register - Security)

Vulnerability

Cisco warns customers of actively exploited zero-day in email gateways

The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer... (CyberScoop)

Vulnerability
BleepingComputer

BambooToken malware controls Windows and Linux systems via MQTT

A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with W... (BleepingComputer)

Cloud Security
The Hacker News

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdi... (The Hacker News)

Vulnerability AI
The Hacker News

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at... (The Hacker News)

Vulnerability Breach Scam
Security Affairs

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire

Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat a... (Security Affairs)

Vulnerability Threat Research
BleepingComputer

Suspected Black Axe gang leaders face cybercrime charges in the US

Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to... (BleepingComputer)

Scam
The Hacker News

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory publ... (The Hacker News)

Vulnerability
Google Cloud Blog

Introducing new session management tools with native, granular controls

Google Cloud session management provides flexible options for setting up session controls based on your organization’s security policy needs. To help you improve your security p... (Google Cloud Blog)

GCP
CrowdStrike Blog

PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting

(CrowdStrike Blog)

AI
BleepingComputer

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites

Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website a... (BleepingComputer)

Threat Research
SecurityWeek

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundarie... (SecurityWeek)

Azure AI
AWS Security Blog

AWS STS simplifies session token size limits and adds session token size monitoring

AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed polic... (AWS Security Blog)

AWS
The Register - Security

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2? (The Register - Security)

Cloud Security
The Register - Security

Low-quality casino sites conceal highly dangerous threat actors

Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites (The Register - Security)

Threat Research
The Register - Security

Who's governing your AI? A trust framework for enterprise agents and models

SPONSORED FEATURE: DigiCert wants to hand every agent a passport, complete with an expiry date and a named human owner (The Register - Security)

AI
The Register - Security

Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler

The man allegedly wrote the code that powered the Lockergoga, MegaCortex, and Nefilim operations (The Register - Security)

Ransomware
Huntress Blog

Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware

A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown. (Huntress Blog)

Cloud Security
The Register - Security

The latest AI doomsayer is China’s intelligence boss

Beijing’s response is to ‘firmly grasp technological sovereignty’ and broad regulations (The Register - Security)

AI
SecurityWeek

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping... (SecurityWeek)

Azure AI
Dark Reading

Microsoft Issues Emergency Fixes After Massive Patch Tuesday

You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches. (Dark Reading)

Azure

What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies

Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned. The post What’s next for CISA’s CDM program that gives cy... (CyberScoop)

CISA
Dark Reading

Black Hat USA 2026 | The 'Breaking' News: The OpenAI-Hugging Face Incident

The 'Breaking' News: The OpenAI-Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and res... (Dark Reading)

AI
AWS Security Blog

Architecting resilient authentication with Amazon Cognito multi-Region replication

Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applicati... (AWS Security Blog)

AWS Identity
The Hacker News

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is track... (The Hacker News)

Scam
Dark Reading

VectraRAT Can Hack Windows Enterprises for $250 per Month

The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. (Dark Reading)

Cloud Security
The Register - On-Prem

September's Windows 11 patch needs an emergency patch of its own

Microsoft fixes RDP and Hyper-V fallout, but some USB audio stays silent (The Register - On-Prem)

Azure
AWS Security Blog

Operationalizing least privilege: Automate IAM remediation through your CI/CD pipeline

The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader per... (AWS Security Blog)

AWS Identity
Malwarebytes Labs

How to opt out of AI chatbot training

ChatGPT contractors are reviewing real users' conversations. Here’s how to stop AI companies using your chats for model training. (Malwarebytes Labs)

AI
Infosecurity Magazine

Most Fraudulent Hires Receive Credentials Before Detection

A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations (Infosecurity Magazine)

Scam
The Record

Zelensky appoints former police chief to lead Ukraine’s cyber coordination center

Ihor Klymenko, who has experience in law enforcement and as interior minister, will run Ukraine's National Cybersecurity Coordination Center. (The Record)

Cloud Security
GitGuardian Blog

AI Autonomy: How to Find the Autonomy Your Agents Already Have

AI agents are only as autonomous as the credentials behind them. This article talks about the Cloud Security Alliance's autonomy framework, why an agent's intended boundaries ra... (GitGuardian Blog)

AI Scam
ReversingLabs Blog

AI coding puts Secure by Design in the spotlight

The software industry is entering the AI era burdened by legacy flaws and weaknesses, making Secure by Design essential. (ReversingLabs Blog)

AI
Qualys Blog

Automate Asset Isolation: Your Last Resort to Meet Remediation Deadlines

Executive Summary Remediation deadlines slip for reasons outside your control: a patch does not exist yet, a patch is delayed, or a remediation attempt fails. The outcome is the... (Qualys Blog)

Cloud Security
Infosecurity Magazine

Most Firms Unable to Recover Quickly from Ransomware

Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours (Infosecurity Magazine)

Ransomware
Huntress Blog

Operational Resilience: IT Security Risks with Reduced Staffing | Huntress

Reduced staffing during holidays changes more than headcount. Learn how operational resilience should shape your IT and security change decisions (Huntress Blog)

Cloud Security
Help Net Security

F5 Bot Defense uses real-time risk scoring to detect fraud and abuse

F5 has announced enhancements to F5 Distributed Cloud Bot Defense, introducing new device intelligence capabilities and specialized agentic AI protections. These capabilities br... (Help Net Security)

AI Scam
Help Net Security

Postman Passport controls API access without exposing credentials

Postman has announced the general availability of Passport by Postman, marking the company’s expansion into API security with a standalone product that gives organizations a sec... (Help Net Security)

Scam
Tenable Blog

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.

Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessmen... (Tenable Blog)

Cloud Security
Help Net Security

Globalgig expands managed security portfolio to protect enterprise AI

Globalgig has expanded its managed security portfolio to cover enterprise AI, bringing together services that discover, assess, and protect the AI applications, agents, models,... (Help Net Security)

AI
Cloudflare Blog

Have it both ways: stay discoverable in search while disallowing AI training

Cloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountable designation establish a shared model with Apple, Googl... (Cloudflare Blog)

AI
Infosecurity Magazine

AI the Top Priority for New Spend as Cyber Budgets Flatline

IANS finds AI is dominating net-new budgets even as overall funding for the function is flat (Infosecurity Magazine)

AI
The Record

China spy chief points at US AI models in cyber threat warning

China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed a... (The Record)

AI
Wiz Blog

Investing Together: Wiz Defend and Google Security Operations

Continuing to deepen the integration between Wiz Defend and Google Security Operations, helping teams work faster wherever they choose to investigate (Wiz Blog)

Cloud Security
The Record

Manhattan DA takes down 12 AI deepfake porn sites

Manhattan District Attorney Alvin Bragg held a press conference on Monday touting the takedown of the sites, which hosted AI-generated videos of more than 1,200 people. The site... (The Record)

AI
Malwarebytes Labs

HBO Max’s verified Reddit account hijacked to spread malware

Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers. (Malwarebytes Labs)

Cloud Security
The Hacker News

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulati... (The Hacker News)

Phishing
Snyk Blog

The AI Hurricane Is Here

AI is accelerating software creation and cyberattacks alike. Leaders must secure agents and code at inception, enforce controls at runtime, and validate defenses independently. (Snyk Blog)

AI
Schneier on Security

25 Years of Mass Surveillance Is Enough

This essay was written with Cindy Cohn, and originally appeared in Lawfare . One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targ... (Schneier on Security)

Cloud Security
Trail of Bits Blog

1Password's AI patching benchmark is misleading

1Password’s FLAWED report , published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of the time.... (Trail of Bits Blog)

AI
Malwarebytes Labs

Meta AI builds detailed profiles of children from years of family posts

A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts. (Malwarebytes Labs)

AI
Malwarebytes Labs

Search results are sending people to fake Bitrefill checkouts

Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers. (Malwarebytes Labs)

Scam
Infosecurity Magazine

Microsoft Releases Emergency Patch to Fix RDS Vulnerability

Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday (Infosecurity Magazine)

Azure Vulnerability
Security Affairs

Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps

A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram De... (Security Affairs)

Vulnerability
Security Affairs

Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk

Japan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Dig... (Security Affairs)

Vulnerability Breach

Supreme Court denies Trump request to allow USPS mail ballot changes

One justice said the attempt to change the rules ahead of the 2026 elections would be "arbitrary and capricious” and violated the Administrative Procedures Act. The post Supreme... (CyberScoop)

Cloud Security
Recorded Future

Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group

Analyze Tajin Group's role in phishing and Chinese money laundering. Discover how this Telegram-based vendor exploits payment gateways and adapts its financial fraud operations. (Recorded Future)

Vulnerability Phishing Scam
Chainguard Unchained

Announcing the Sovereign Artifacts beta

Chainguard launches Sovereign Artifacts in beta, giving global organizations an EU-local option for secure container and library artifacts. (Chainguard Unchained)

Cloud Security
Chainguard Unchained

The flood is coming and the pipes were already full

Frontier AI is finding zero-days faster than the industry can fix them. See how Chainguard and Athena are preparing for what comes next. (Chainguard Unchained)

Vulnerability AI

September 14, 2026 · 9 articles

The Register - Security

HBO Max Reddit account compromised to serve ClickFix attacks

Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware (The Register - Security)

Cloud Security
Dark Reading

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances. (Dark Reading)

Vulnerability Supply Chain

Five alleged leaders of Black Axe’s operations in South Africa extradited to US

Officials said the five individuals concocted various long-running romance scams to trick U.S.-based victims into sending them money. The post Five alleged leaders of Black Axe’... (CyberScoop)

Scam
The Hacker News

AI Changed the Exposure Problem. Validation Needs to Change With It.

There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster an... (The Hacker News)

Vulnerability AI
The Hacker News

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The e... (The Hacker News)

Cloud Security
Rapid7 Blog

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a... (Rapid7 Blog)

Vulnerability
Dark Reading

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022. (Dark Reading)

Cloud Security
BleepingComputer

Homebrew 7.0.0 gets built-in GUI, better security controls

Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical i... (BleepingComputer)

Vulnerability
SANS ISC

Apple Updates Everything, (Mon, Sep 14th)

Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is... (SANS ISC)

Cloud Security