September 16, 2026 · 50 articles

Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
September 16, 2026
IntroductionIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last... (Zscaler ThreatLabz)

PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
September 16, 2026
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells (Infosecurity Magazine)
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
September 16, 2026
The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.” The post Coast... (CyberScoop)

Virtual Event Today: Attack Surface Management Summit
September 16, 2026
Join SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces. The post... (SecurityWeek)

EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media
September 16, 2026
Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children. The... (SecurityWeek)

Oracle Critical Security Patch Update, September 2026 Review
September 16, 2026
Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in t... (Qualys Blog)
Treasury’s Scott Bessent says no liability exemptions for AI labs
September 16, 2026
The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.”... (CyberScoop)

The true cost of a ransomware attack, with and without BCDR
September 16, 2026
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto... (BleepingComputer)

CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
September 16, 2026
CISA and NIST issued final guidance to help protect cloud identity tokens and assertions (Infosecurity Magazine)

AIUC Raises $40 Million to Certify Enterprise AI Agents
September 16, 2026
The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to C... (SecurityWeek)

Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
September 16, 2026
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code... (The Hacker News)

EU chief wants joint response to cyberattacks, sabotage
September 16, 2026
Delivering her annual State of the Union address in Strasbourg, Ursula von der Leyen said threats were “mounting on our soil,” pointing to recent incidents in Denmark, Lithuania... (The Record)

Pixel Modem Zero-Day Exploited in Targeted Attacks
September 16, 2026
Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appea... (SecurityWeek)

Revolut Data Leak May Trace Back to Compromised Italian Government Accounts
September 16, 2026
A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut cust... (Security Affairs)

Why Is Detection and Response Too Slow for Machine Speed Attacks?
September 16, 2026
TLDR: Runtime security built around detecting activity, correlating signals and then responding assumes there is enough time to act after something malicious happens. Machine sp... (Aqua Security Blog)

Ukraine moves to crack down on scam call centers after corruption scandal
September 16, 2026
Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which p... (The Record)

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)
September 16, 2026
A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host sy... (Help Net Security)

Webinar: What happens in the first hours of a Google Workspace breach
September 16, 2026
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisio... (BleepingComputer)

US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
September 16, 2026
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Irani... (SecurityWeek)

Spain gets its first taste of AI-aided cyber attack
September 16, 2026
Data protection chiefs call for 'immediate review' of data protection models (The Register - Security)

Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
September 16, 2026
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to... (SecurityWeek)

Self-improving AI should slow down, von der Leyen tells EU lawmakers
September 16, 2026
European Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can... (Help Net Security)

Fake CAPTCHA Scams
September 16, 2026
New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program. (Schneier on Security)

Threat Intelligence Alone Won't Close the Exploitation Gap
September 16, 2026
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most securit... (The Hacker News)

Critical ScreenConnect flaw now actively exploited in attacks
September 16, 2026
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...] (BleepingComputer)

Hackuity Raises $19 Million for AI-Powered Vulnerability Management
September 16, 2026
The company will use the new capital to expand its vulnerability operations platform and support international growth. The post Hackuity Raises $19 Million for AI-Powered Vulner... (SecurityWeek)

Cyber-Attacks Cost Organizations $52,000 on Average
September 16, 2026
Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000 (Infosecurity Magazine)

Cohesity adds recovery capabilities for AI agents and the data they manage
September 16, 2026
Cohesity has introduced Cohesity Agent Resilience. This new Cohesity Data Cloud capability will discover, protect, and recover the infrastructure behind enterprise AI agents. A... (Help Net Security)

NCSC and Allies Warn of Iranian Spyware Campaign
September 16, 2026
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents (Infosecurity Magazine)

Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen
September 16, 2026
CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Mond... (Security Affairs)

CrowdStrike Accelerates Real-Time Data Classification with On-Device AI
September 16, 2026
(CrowdStrike Blog)

280,000 Impacted by Premier Medical Group Data Breach
September 16, 2026
In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information. The post 280,000 Impacted by Premier M... (SecurityWeek)

Rubrik MCP gives AI agents controlled access to security intelligence
September 16, 2026
Rubrik has announced Rubrik MCP (Model Context Protocol), giving an organization’s AI agents a secure, programmable path to Rubrik’s data, identity, and application intelligence... (Help Net Security)

Chrome, Firefox Updates Patch 115 Vulnerabilities
September 16, 2026
Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox. The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek . (SecurityWeek)

Nozomi Compass helps industrial teams manage OT assets and vulnerabilities
September 16, 2026
Nozomi Networks announced Nozomi Compass, an OT asset and service management platform designed to help organizations manage industrial assets, vulnerabilities, and exposures. Th... (Help Net Security)

Citrix adds AI-powered browser activity analysis to SecurAccess
September 16, 2026
Citrix has announced Citrix Session Insights, a new AI-powered capability for Citrix SecurAccess with Chrome Enterprise that helps organizations capture, analyze and understand... (Help Net Security)

Securing the unpatchable in an age of AI-driven vulnerabilities
September 16, 2026
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentati... (Cisco Talos)

Atomic macOS (AMOS) Stealer Activity
September 16, 2026
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Steale... (Palo Alto Networks Unit 42)

Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
September 16, 2026
OPSWAT researchers find two zero-days in TP-Link cameras (Infosecurity Magazine)

One runaway AI agent racked up a $50,000 cloud bill
September 16, 2026
Organizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud environments. At the same... (Help Net Security)

Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program
September 16, 2026
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program (Infosecurity Magazine)

AI helps scammers build convincing antivirus renewal pages
September 16, 2026
A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy. (Malwarebytes Labs)

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability
September 16, 2026
The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability ap... (SecurityWeek)

What happens when AI agent governance is missing at scale
September 16, 2026
In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a... (Help Net Security)

Mythos has made 2026 patching hell. It might make 2027 a breeze
September 16, 2026
Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner (The Register - Security)

DeepZero: Open-source hunting for vulnerable Windows drivers
September 16, 2026
DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, sc... (Help Net Security)

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
September 16, 2026
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (C... (The Hacker News)

ISC Stormcast For Wednesday, September 16th, 2026 https://isc.sans.edu/podcastdetail/10096, (Wed, Sep 16th)
September 16, 2026
(SANS ISC)

Cyber Op Targets South Korean Media & Automotive Sectors
September 16, 2026
A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications,... (Dark Reading)

Mapping out your unknown: A threat hunter’s guide to GitHub
September 16, 2026
In this post, we walk through different threats to GitHub and how to detect them. (Datadog Security Labs)
September 15, 2026 · 61 articles

Before You Patch. Why Patch Reliability Matters for Confident Deployment
September 15, 2026
Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operatio... (Qualys Blog)

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
September 15, 2026
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dis... (The Hacker News)

Cisco email security boxes can be rooted by... an email
September 15, 2026
Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in (The Register - Security)
Cisco warns customers of actively exploited zero-day in email gateways
September 15, 2026
The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer... (CyberScoop)

BambooToken malware controls Windows and Linux systems via MQTT
September 15, 2026
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with W... (BleepingComputer)

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
September 15, 2026
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdi... (The Hacker News)

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
September 15, 2026
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at... (The Hacker News)

One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire
September 15, 2026
Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat a... (Security Affairs)

Suspected Black Axe gang leaders face cybercrime charges in the US
September 15, 2026
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to... (BleepingComputer)

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
September 15, 2026
A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory publ... (The Hacker News)

Introducing new session management tools with native, granular controls
September 15, 2026
Google Cloud session management provides flexible options for setting up session controls based on your organization’s security policy needs. To help you improve your security p... (Google Cloud Blog)

PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting
September 15, 2026
(CrowdStrike Blog)

Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
September 15, 2026
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website a... (BleepingComputer)

Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints
September 15, 2026
The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundarie... (SecurityWeek)

AWS STS simplifies session token size limits and adds session token size monitoring
September 15, 2026
AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed polic... (AWS Security Blog)

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches
September 15, 2026
September Patch Tuesday part 2? (The Register - Security)

Low-quality casino sites conceal highly dangerous threat actors
September 15, 2026
Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites (The Register - Security)

Who's governing your AI? A trust framework for enterprise agents and models
September 15, 2026
SPONSORED FEATURE: DigiCert wants to hand every agent a passport, complete with an expiry date and a named human owner (The Register - Security)

Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler
September 15, 2026
The man allegedly wrote the code that powered the Lockergoga, MegaCortex, and Nefilim operations (The Register - Security)

Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware
September 15, 2026
A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown. (Huntress Blog)

The latest AI doomsayer is China’s intelligence boss
September 15, 2026
Beijing’s response is to ‘firmly grasp technological sovereignty’ and broad regulations (The Register - Security)

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
September 15, 2026
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping... (SecurityWeek)

Microsoft Issues Emergency Fixes After Massive Patch Tuesday
September 15, 2026
You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches. (Dark Reading)
What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies
September 15, 2026
Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned. The post What’s next for CISA’s CDM program that gives cy... (CyberScoop)

Black Hat USA 2026 | The 'Breaking' News: The OpenAI-Hugging Face Incident
September 15, 2026
The 'Breaking' News: The OpenAI-Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and res... (Dark Reading)

Architecting resilient authentication with Amazon Cognito multi-Region replication
September 15, 2026
Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applicati... (AWS Security Blog)

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
September 15, 2026
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is track... (The Hacker News)

VectraRAT Can Hack Windows Enterprises for $250 per Month
September 15, 2026
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access. (Dark Reading)

September's Windows 11 patch needs an emergency patch of its own
September 15, 2026
Microsoft fixes RDP and Hyper-V fallout, but some USB audio stays silent (The Register - On-Prem)

Operationalizing least privilege: Automate IAM remediation through your CI/CD pipeline
September 15, 2026
The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader per... (AWS Security Blog)

How to opt out of AI chatbot training
September 15, 2026
ChatGPT contractors are reviewing real users' conversations. Here’s how to stop AI companies using your chats for model training. (Malwarebytes Labs)

Most Fraudulent Hires Receive Credentials Before Detection
September 15, 2026
A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations (Infosecurity Magazine)

Zelensky appoints former police chief to lead Ukraine’s cyber coordination center
September 15, 2026
Ihor Klymenko, who has experience in law enforcement and as interior minister, will run Ukraine's National Cybersecurity Coordination Center. (The Record)

AI Autonomy: How to Find the Autonomy Your Agents Already Have
September 15, 2026
AI agents are only as autonomous as the credentials behind them. This article talks about the Cloud Security Alliance's autonomy framework, why an agent's intended boundaries ra... (GitGuardian Blog)

AI coding puts Secure by Design in the spotlight
September 15, 2026
The software industry is entering the AI era burdened by legacy flaws and weaknesses, making Secure by Design essential. (ReversingLabs Blog)

Automate Asset Isolation: Your Last Resort to Meet Remediation Deadlines
September 15, 2026
Executive Summary Remediation deadlines slip for reasons outside your control: a patch does not exist yet, a patch is delayed, or a remediation attempt fails. The outcome is the... (Qualys Blog)

Most Firms Unable to Recover Quickly from Ransomware
September 15, 2026
Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours (Infosecurity Magazine)

Operational Resilience: IT Security Risks with Reduced Staffing | Huntress
September 15, 2026
Reduced staffing during holidays changes more than headcount. Learn how operational resilience should shape your IT and security change decisions (Huntress Blog)

F5 Bot Defense uses real-time risk scoring to detect fraud and abuse
September 15, 2026
F5 has announced enhancements to F5 Distributed Cloud Bot Defense, introducing new device intelligence capabilities and specialized agentic AI protections. These capabilities br... (Help Net Security)

Postman Passport controls API access without exposing credentials
September 15, 2026
Postman has announced the general availability of Passport by Postman, marking the company’s expansion into API security with a standalone product that gives organizations a sec... (Help Net Security)

Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.
September 15, 2026
Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessmen... (Tenable Blog)

Globalgig expands managed security portfolio to protect enterprise AI
September 15, 2026
Globalgig has expanded its managed security portfolio to cover enterprise AI, bringing together services that discover, assess, and protect the AI applications, agents, models,... (Help Net Security)

Have it both ways: stay discoverable in search while disallowing AI training
September 15, 2026
Cloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountable designation establish a shared model with Apple, Googl... (Cloudflare Blog)

AI the Top Priority for New Spend as Cyber Budgets Flatline
September 15, 2026
IANS finds AI is dominating net-new budgets even as overall funding for the function is flat (Infosecurity Magazine)

China spy chief points at US AI models in cyber threat warning
September 15, 2026
China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed a... (The Record)

Investing Together: Wiz Defend and Google Security Operations
September 15, 2026
Continuing to deepen the integration between Wiz Defend and Google Security Operations, helping teams work faster wherever they choose to investigate (Wiz Blog)

Manhattan DA takes down 12 AI deepfake porn sites
September 15, 2026
Manhattan District Attorney Alvin Bragg held a press conference on Monday touting the takedown of the sites, which hosted AI-generated videos of more than 1,200 people. The site... (The Record)

HBO Max’s verified Reddit account hijacked to spread malware
September 15, 2026
Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers. (Malwarebytes Labs)

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
September 15, 2026
Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulati... (The Hacker News)

The AI Hurricane Is Here
September 15, 2026
AI is accelerating software creation and cyberattacks alike. Leaders must secure agents and code at inception, enforce controls at runtime, and validate defenses independently. (Snyk Blog)

25 Years of Mass Surveillance Is Enough
September 15, 2026
This essay was written with Cindy Cohn, and originally appeared in Lawfare . One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targ... (Schneier on Security)

1Password's AI patching benchmark is misleading
September 15, 2026
1Password’s FLAWED report , published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of the time.... (Trail of Bits Blog)

Meta AI builds detailed profiles of children from years of family posts
September 15, 2026
A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts. (Malwarebytes Labs)

Search results are sending people to fake Bitrefill checkouts
September 15, 2026
Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers. (Malwarebytes Labs)

Microsoft Releases Emergency Patch to Fix RDS Vulnerability
September 15, 2026
Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday (Infosecurity Magazine)

Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps
September 15, 2026
A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram De... (Security Affairs)

Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk
September 15, 2026
Japan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Dig... (Security Affairs)
Supreme Court denies Trump request to allow USPS mail ballot changes
September 15, 2026
One justice said the attempt to change the rules ahead of the 2026 elections would be "arbitrary and capricious” and violated the Administrative Procedures Act. The post Supreme... (CyberScoop)

Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group
September 15, 2026
Analyze Tajin Group's role in phishing and Chinese money laundering. Discover how this Telegram-based vendor exploits payment gateways and adapts its financial fraud operations. (Recorded Future)

Announcing the Sovereign Artifacts beta
September 15, 2026
Chainguard launches Sovereign Artifacts in beta, giving global organizations an EU-local option for secure container and library artifacts. (Chainguard Unchained)

The flood is coming and the pipes were already full
September 15, 2026
Frontier AI is finding zero-days faster than the industry can fix them. See how Chainguard and Athena are preparing for what comes next. (Chainguard Unchained)
September 14, 2026 · 9 articles

HBO Max Reddit account compromised to serve ClickFix attacks
September 14, 2026
Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware (The Register - Security)

Maximum Severity GitLab Flaw Puts Supply Chains at Risk
September 14, 2026
CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances. (Dark Reading)
Five alleged leaders of Black Axe’s operations in South Africa extradited to US
September 14, 2026
Officials said the five individuals concocted various long-running romance scams to trick U.S.-based victims into sending them money. The post Five alleged leaders of Black Axe’... (CyberScoop)

AI Changed the Exposure Problem. Validation Needs to Change With It.
September 14, 2026
There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster an... (The Hacker News)

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
September 14, 2026
A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The e... (The Hacker News)

CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild
September 14, 2026
Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a... (Rapid7 Blog)

'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink
September 14, 2026
The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022. (Dark Reading)

Homebrew 7.0.0 gets built-in GUI, better security controls
September 14, 2026
Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical i... (BleepingComputer)

Apple Updates Everything, (Mon, Sep 14th)
September 14, 2026
Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is... (SANS ISC)