MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Service Espionage Alert" issued on Sept
03-10-2026 20:08

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, obse
03-10-2026 20:06

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and internet-facing infrastructure, secu
03-10-2026 16:30

doxx.net Raises $38 Million to Prevent AI Agent-on-the-Internet Misadventures
doxx.net’s new ADN platform prevents agentic misadventure while the agent is operating under the user’s authority. The post appeared first on .
03-10-2026 11:45

Fortra Patches Critical Vulnerabilities in BoKS
The bugs could lead to authentication bypass, shell command execution, and memory corruption. The post appeared first on .
03-10-2026 11:34

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI mode
02-10-2026 23:03

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakist
02-10-2026 23:03

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVS
02-10-2026 22:32

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing an
02-10-2026 17:53

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone e
02-10-2026 17:00

In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post appeared first on .
02-10-2026 14:30

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API servin
02-10-2026 13:31

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor
The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post appeared first on .
02-10-2026 13:15

Crypto Scammers Hijack Microsoft’s Official X Account
Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post appeared first on .
02-10-2026 11:46

Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability,
02-10-2026 11:19

In Rare Move, Alleged Iranian State Hacker Extradited to US
Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post appeared first on .
02-10-2026 11:14

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post appeared first on .
02-10-2026 09:34

FTC Probes OpenAI, Anthropic as AI Agent Safety Risks Draw Scrutiny
The FTC is investigating OpenAI, Anthropic and other AI firms over potential consumer harms, safety claims and risks tied to increasingly autonomous AI systems. The post appeared first on .
02-10-2026 08:50

AI Agents Aimed SQL Injection at US and Canadian Government Sites
The attacks targeted the US Department of Education and Library and Archives Canada, and researchers linked some agents to OpenAI. The post appeared first on .
02-10-2026 08:38

Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action
CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post appeared first on .
02-10-2026 08:07

Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was o
01-10-2026 22:25

ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A publi
01-10-2026 22:15

WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has been codenamed
01-10-2026 20:07

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right. The post appeared first on .
01-10-2026 18:00

Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains
Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures. The post appeared first on .
01-10-2026 17:16

How Financial Services Companies Can Modernize Their Software Supply Chain
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices ou
01-10-2026 17:15

OpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI Associates
OpenAI on Wednesday said it identified and disrupted a coordinated distillation campaign that was designed to illicitly extract protected reasoning from its artificial intelligence (AI) models. A "core cluster of the activity," going back to the first w
01-10-2026 16:12

CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The
01-10-2026 16:03

Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says
PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures. The post appeared first on .
01-10-2026 14:30

Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says. The post appeared first on .
01-10-2026 14:30

Police Shut Down KillSec Ransomware, Identify Alleged Teen Leader
Police took control of KillSec’s leak site and secured at least 110 terabytes of data stolen from victims. The post appeared first on .
01-10-2026 14:17

Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflo
01-10-2026 13:19

AI Has Changed Attack Speed, Not Security Fundamentals
As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals. The post appeared first on .
01-10-2026 13:15

Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure
Under certain conditions, CVE-2026-73570 can be exploited via specially crafted emails without user interaction. The post appeared first on .
01-10-2026 12:55

Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch. The post appeared first on .
01-10-2026 11:40

Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded f
01-10-2026 11:24

Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme. The post appeared first on .
01-10-2026 10:51

Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified mali
01-10-2026 10:51

Zammad Zero-Days Exploited in AI-Powered DIVD Hack
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root. The post appeared first on .
01-10-2026 10:42

MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are actively addressing and remediating the issue internally, in coordination with external partners and security
01-10-2026 10:40

Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations &
01-10-2026 10:05

500,000 Active Credentials Left Exposed on GitHub
Roughly 200,000 of the credentials were exposed after GitHub enabled push protections by default. The post appeared first on .
01-10-2026 09:43

Cisco Patches Exploited Catalyst SD-WAN Zero-Day Vulnerability
The flaw could allow remote, unauthenticated attackers to access vulnerable appliances with administrative privileges. The post appeared first on .
01-10-2026 08:26

Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders
The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide. The post appeared first on .
01-10-2026 07:52

FTC is Investigating OpenAI and Anthropic Over Possible risks to Consumers
An FTC spokesperson confirmed the investigation but declined further comment. The post appeared first on .
30-09-2026 23:43

Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score:
30-09-2026 22:16

Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content.
30-09-2026 22:02

Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote a
30-09-2026 20:54

Meta AI Shares Seller’s Address: Facebook Marketplace Buyer Shows Up at His Home
Meta’s Muse AI shared a Facebook Marketplace seller’s pickup address and arranged a deal that ended with a buyer showing up unexpectedly. The post appeared first on .
30-09-2026 20:31

Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026
30-09-2026 20:30

Know Your Enemy: Browser-Based Attack Techniques in 2026
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfi
30-09-2026 17:28

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub
AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organiz
30-09-2026 17:00

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By comb
30-09-2026 16:15

iPhone Security Warning: Apple Says iOS 26 Flaw May Have Been Exploited
Apple patched an iPhone flaw that may have been exploited in targeted attacks. Here’s what iOS 26 users need to know and how to update. The post appeared first on .
30-09-2026 15:49

Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution. The post appeared first on .
30-09-2026 14:05

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Thre
30-09-2026 13:54

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no rep
30-09-2026 13:39

WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS. The post appeared first on .
30-09-2026 13:16

Government, Finance Orgs Targeted in Weeks-Long NetScaler Zero-Day Attacks
Several security firms have confirmed seeing exploitation of the NetScaler vulnerabilities CVE-2026-88771 and CVE-2026-88772. The post appeared first on .
30-09-2026 12:48

Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox. The post appeared first on .
30-09-2026 12:16

Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit
Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do. The post appeared first on .
30-09-2026 11:19

Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.
30-09-2026 11:00

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor. The post appeared first on .
30-09-2026 10:59

ShinyHunters Defiant After FBI Calls on Members to Come Forward
In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI. The post appeared first on .
30-09-2026 10:20

This month in security with Tony Anscombe – September 2026 edition
Autonomous AI agents go on a hacking spree, and Microsoft ships what used to be a year's worth of security patches in one go – here's how to keep pace
30-09-2026 08:00

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries.  The post appeared first on .
30-09-2026 06:55

Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development
The accord opened the door to future regulation but focused on four voluntary steps for the companies to take. The post appeared first on .
30-09-2026 01:48

French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leav
29-09-2026 23:17

New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system kernel, across m
29-09-2026 22:50

Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, hav
29-09-2026 22:50

OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference
Altman made a slew of product announcements and updates, including the company’s new agents, called Dots. The post appeared first on .
29-09-2026 20:14

Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity led to the discov
29-09-2026 19:43

101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project to add the vic
29-09-2026 19:15

DARPA Selects Xint to Use AI in Securing Military Messaging Apps
The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software. The post appeared first on .
29-09-2026 17:24

New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel The post appeared first on .
29-09-2026 17:00

RemoteThreat Launches With $7 Million for Offensive Operations Platform
The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe. The post appeared first on .
29-09-2026 14:38

iOS 27.0.1 Is Here: 3 iPhone Problems Apple Just Fixed
Apple’s iOS 27.0.1 fixes three iPhone problems involving Face ID restarts, camera artifacts, and an unresponsive touchscreen. The post appeared first on .
29-09-2026 14:32

Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunt
29-09-2026 14:05

Reco Raises $55 Million for Agentic Security
The company will use the funds to expand its sales, partnerships, channels, and customer support teams. The post appeared first on .
29-09-2026 13:20

Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands. The post appeared first on .
29-09-2026 13:03

Pentagon Personnel Agency Data Breach Impacts 3 Million People
The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense. The post appeared first on .
29-09-2026 12:25

Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks
Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents The post appeared first on .
29-09-2026 12:00

Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the c
29-09-2026 11:38

Four Cyber Threats Harboring Big Plans for the Future
- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. The post appeared first on .
29-09-2026 11:30

OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training
The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations.  The post appeared first on .
29-09-2026 11:15

Dutch Police Arrest Convicted Hacker in ShinyHunters Investigation
Pepijn van der Stap was convicted in 2023 for hacking multiple organizations, stealing their data, and extorting them. The post appeared first on .
29-09-2026 11:01

OpenAI Shelves GPT-6.1 Astra After Tests Find Deception and Unauthorized Actions
OpenAI on Monday shelved plans to release GPT-6.1 Astra, a next-generation artificial intelligence (AI) model that was planned for an October launch, after it failed internal safety and alignment audits. The development was first reported by The Wall St
29-09-2026 10:42

OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent
29-09-2026 10:15

Private 5G Moves Into Banking at Hana Financial’s 16-Floor Headquarters
Hana Financial’s new headquarters runs private 5G across 16 floors, giving roughly 3,000 employees secure wireless access to internal systems. The post appeared first on .
29-09-2026 10:04

Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
The malware framework uses a modular architecture and a custom executable file format for long-term persistence. The post appeared first on .
29-09-2026 09:46

Timeshare exit scams: From fake buyers to recovery fraud
Con artists are targeting timeshare owners who want out – and some victims are hit twice
29-09-2026 09:00

Apple Patches Zero-Day Linked to ‘Extremely Sophisticated Attack’ 
Apple released iOS and macOS updates to patch a zero-day vulnerability (CVE-2026-86950) reported by Meta’s product security team. The post appeared first on .
29-09-2026 06:18

Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting
29-09-2026 00:48

Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunicatio
29-09-2026 00:05

IAM for AI agents: A Practical Enterprise Framework
What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of conventional p
28-09-2026 23:50

Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level inte
28-09-2026 23:12

RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a
28-09-2026 23:08

⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, we
28-09-2026 19:30

Modulate Raises $25 Million to Advance Deepfake Detection
The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention.  The post appeared first on .
28-09-2026 17:30

Webinar: How to Govern AI Agents, Reduce Excessive Access, and Control Shadow AI
AI agents are moving into production faster than security teams can govern them. They are connecting to apps, handling data, calling APIs, and acting across business systems—often without the same controls applied to human users. According to Okta’s Glo
28-09-2026 17:28

source : hackernews, securityweek, techrepublicsecurity, welivesecurity