Krebs on Security
The Hacker News
- WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage [50m]
- Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer [2h]
- RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall [5h]
- Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root [17h]
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories [17h]
- Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files [19h]
- Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords [21h]
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone [23h]
- Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar [23h]
- CISO's Expert Guide to Agentic Pentesting for Websites [1d]
BleepingComputer
- New Check Point flaw lets hackers execute code with root privileges [1h]
- Microsoft fixes broken copy and paste for Excel 2016 users [3h]
- New RatHat Android malware uses AI to automate device control [13h]
- OpenAI details more cases of AI agents taking unauthorized actions [16h]
- Brevo supply-chain attack injected ClickFix scripts on customer sites [18h]
- What Recent AI-Powered Attacks Mean for Your Identity Security [21h]
- Windows 11 24H2 Home and Pro reach end of support in October [22h]
- US takes down NightmareStresser DDoS-for-hire platform [23h]
- Chinese hackers use SparroWocky malware in govt espionage attacks [1d]
- Microsoft shares workaround for Windows domain login issues [1d]
- Cisco warns of max severity ISE zero-day exploited in attacks [1d]
- Anthropic wants Claude to analyze your bank account and financial data [1d]
- Windows 11 KB5124008 update breaks domain trust for some users [1d]
- Iranian hackers use CHOSEN BRICK Windows malware to spy on targets [1d]
- Malware bypasses browser checks to force install Chrome, Edge extensions [1d]
- Spain reports first alleged AI-powered data theft attack [1d]
- Spain's data agency gets first report of AI-powered data breach [1d]
- The true cost of a ransomware attack, with and without BCDR [1d]
- Microsoft says Copilot buttons still missing in classic Outlook [1d]
- Webinar: What happens in the first hours of a Google Workspace breach [1d]
- Critical ScreenConnect flaw now actively exploited in attacks [2d]
- Windows Server 2022 reaches end of mainstream support next month [2d]
- Google fixes actively exploited Android zero-day on Pixel devices [2d]
- Acronis warns of actively exploited flaw in its cPanel backup plugin [2d]
- Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites [2d]
Dark Reading
- [Virtual Event] Cybersecurity Outlook 2027 [now]
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI [now]
- [Virtual Event] Building a Secure AI Strategy for the Enterprise [now]
- AI Agent Breaches Spanish Organization, Modifies Personal Data [4h]
- CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus [14h]
- China's FamousSparrow APT Spies on US Politics in Latin America [16h]
- AI Security Spending Jumps as Fear Outpaces Proof of Value [1d]
- Fighting Your Dragons Through Tough Tech Times [1d]
- BragJack Attack Can Turn a Browser's Agentic AI Against It [1d]
- Cyber Op Targets South Korean Media & Automotive Sectors [2d]
- Microsoft Issues Emergency Fixes After Massive Patch Tuesday [2d]
- Black Hat USA 2026 | OpenAI's Deep Dive Into Hugging Face Incident [2d]
- VectraRAT Can Hack Windows Enterprises for $250 per Month [2d]
The Record
- European Commission set to push social media restrictions, safety requirements into law [14h]
- China’s FamousSparrow hackers target Latin America with new backdoor [19h]
- Hackers claim breach of Russian election systems days before parliamentary vote [21h]
- Congress eyes new support for Cyber Command after recent suicide deaths [21h]
- Israeli contractor BlackCore trained Angolan officials in online influence operations [23h]
- Key lawmaker suggests action on AI safety legislation will wait until 2027 [1d]
- Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’ [1d]
- House passes bill to equip local law enforcement with scam-fighting tools [1d]
- International Meteor Organization says cyberattack dealt ‘critical blow’ to website [1d]
- Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts [1d]
- Flock camera use by internal affairs unit puts DC police at odds with officers’ union [1d]
- EU chief wants joint response to cyberattacks, sabotage [1d]
- Ukraine moves to crack down on scam call centers after corruption scandal [1d]
- Norway announces investigations into telecom Telenor’s work with Myanmar junta [2d]
- Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’ [2d]
- Zelensky appoints former police chief to lead Ukraine’s cyber coordination center [2d]
- Electric and gas utility CenterPoint Energy warns of data breach after dark web post [2d]
- China spy chief points at US AI models in cyber threat warning [2d]
- Manhattan DA takes down 12 AI deepfake porn sites [2d]
CyberScoop
- Cisco alerts customers to second actively exploited zero-day in as many days [14h]
- The AI hacking apocalypse is not inevitable [16h]
- Authorities seize popular, long-running DDoS-for-hire service domains [21h]
- America’s cyber strategy overlooks the infrastructure that actually keeps the military moving [1d]
- CISA promotes a fresh way to deter cyberattackers: Lie to them [1d]
- Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks [1d]
- Treasury’s Scott Bessent says no liability exemptions for AI labs [1d]
- What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies [2d]
- Cisco warns customers of actively exploited zero-day in email gateways [2d]
SANS ISC
- HTTP QUERY Method: The Grey Zone Between GET And POST. [5h]
- ISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100 [9h]
- LausivLoader analysis, or how to pass data between malware stages [20h]
- ISC Stormcast For Thursday, September 17th, 2026 https://isc.sans.edu/podcastdetail/10098 [1d]
- Scans Targeting Hospitality Applications [1d]
- ISC Stormcast For Wednesday, September 16th, 2026 https://isc.sans.edu/podcastdetail/10096 [2d]
- MacOS 27 - First Boot [2d]
Schneier on Security
Rapid7 Blog
Malwarebytes Labs
- Fake parcel delivery messages steal your card and bank details [3h]
- Flock cameras are tracking people as well as cars [16h]
- Revolut phishing texts appear days after data breach [21h]
- 12 celebrity deepfake websites seized by Manhattan DA [1d]
- T-Mobile rewards points expiry texts are a phishing scam [1d]
- Google Pixel owners urged to patch actively exploited modem flaw [2d]
- AI helps scammers build convincing antivirus renewal pages [2d]
- How to opt out of AI chatbot training [2d]
- HBO Max’s verified Reddit account hijacked to spread malware [2d]
Graham Cluley
WeLiveSecurity (ESET)
Unit 42 (Palo Alto)
CISA Advisories
- Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) [23h]
- Mitsubishi Electric GX Works3 and Motion Control Settings [23h]
- Hitachi Energy FACTS Control Platform (FCP) [23h]
- Bransys ELD [23h]
- Schneider Electric NetBotz 5 750/755 [23h]
- Schneider Electric Modicon M340 Controller and Communication Modules [23h]
- Schneider Electric PowerChute Serial Shutdown [23h]
- ABB Ability Edgenius [23h]
- CISA Adds One Known Exploited Vulnerability to Catalog [1d]
- Using Cyber Decoys to Strengthen Detection and Response [1d]
- CISA Adds Two Known Exploited Vulnerabilities to Catalog [1d]
- Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers [2d]
- Digital Watchdog VMAX DVR and NVR Product Lineups [2d]
- mySCADA myPRO Manager [2d]
- Schneider Electric SCADAPack x70 Products [2d]
- Siemens Teamcenter [2d]
- Siemens Mendix SAML [2d]
- Wärtsilä FOS-Onboard [2d]
- Siemens Reyrolle 7SR5 [2d]
- CareCam CM2507 [2d]
Zero Day Initiative
- ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability [1d]
- ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability [2d]
- ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability [2d]
- ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability [2d]
- ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability [2d]
- ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability [2d]
- ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability [2d]
- ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability [2d]