Krebs on Security
The Hacker News
- Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone [11h]
- Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar [11h]
- CISO's Expert Guide to Agentic Pentesting for Websites [12h]
- China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America [13h]
- OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads [13h]
- BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS [15h]
- Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records [16h]
- Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks [16h]
- U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks [18h]
- Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution [1d]
BleepingComputer
- New RatHat Android malware uses AI to automate device control [1h]
- OpenAI details more cases of AI agents taking unauthorized actions [4h]
- Brevo supply-chain attack injected ClickFix scripts on customer sites [6h]
- What Recent AI-Powered Attacks Mean for Your Identity Security [9h]
- Windows 11 24H2 Home and Pro reach end of support in October [10h]
- US takes down NightmareStresser DDoS-for-hire platform [11h]
- Chinese hackers use SparroWocky malware in govt espionage attacks [14h]
- Microsoft shares workaround for Windows domain login issues [15h]
- Cisco warns of max severity ISE zero-day exploited in attacks [16h]
- Anthropic wants Claude to analyze your bank account and financial data [22h]
- Windows 11 KB5124008 update breaks domain trust for some users [1d]
- Iranian hackers use CHOSEN BRICK Windows malware to spy on targets [1d]
- Malware bypasses browser checks to force install Chrome, Edge extensions [1d]
- Spain reports first alleged AI-powered data theft attack [1d]
- Spain's data agency gets first report of AI-powered data breach [1d]
- The true cost of a ransomware attack, with and without BCDR [1d]
- Microsoft says Copilot buttons still missing in classic Outlook [1d]
- Webinar: What happens in the first hours of a Google Workspace breach [1d]
- Critical ScreenConnect flaw now actively exploited in attacks [1d]
- Windows Server 2022 reaches end of mainstream support next month [1d]
- Google fixes actively exploited Android zero-day on Pixel devices [1d]
- Acronis warns of actively exploited flaw in its cPanel backup plugin [2d]
- Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites [2d]
- CenterPoint Energy confirms customer data stolen in cyberattack [2d]
- BambooToken malware controls Windows and Linux systems via MQTT [2d]
Dark Reading
- [Virtual Event] Cybersecurity Outlook 2027 [now]
- [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI [now]
- [Virtual Event] Building a Secure AI Strategy for the Enterprise [now]
- CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus [2h]
- China's FamousSparrow APT Spies on US Politics in Latin America [4h]
- AI Security Spending Jumps as Fear Outpaces Proof of Value [1d]
- Fighting Your Dragons Through Tough Tech Times [1d]
- BragJack Attack Can Turn a Browser's Agentic AI Against It [1d]
- Cyber Op Targets South Korean Media & Automotive Sectors [1d]
- Microsoft Issues Emergency Fixes After Massive Patch Tuesday [2d]
- Black Hat USA 2026 | OpenAI's Deep Dive Into Hugging Face Incident [2d]
- VectraRAT Can Hack Windows Enterprises for $250 per Month [2d]
The Record
- European Commission set to push social media restrictions, safety requirements into law [2h]
- China’s FamousSparrow hackers target Latin America with new backdoor [7h]
- Hackers claim breach of Russian election systems days before parliamentary vote [9h]
- Congress eyes new support for Cyber Command after recent suicide deaths [9h]
- Israeli contractor BlackCore trained Angolan officials in online influence operations [11h]
- Key lawmaker suggests action on AI safety legislation will wait until 2027 [1d]
- Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’ [1d]
- House passes bill to equip local law enforcement with scam-fighting tools [1d]
- International Meteor Organization says cyberattack dealt ‘critical blow’ to website [1d]
- Three Ukrainians to face charges for alleged hack of 610,000 Roblox accounts [1d]
- Flock camera use by internal affairs unit puts DC police at odds with officers’ union [1d]
- EU chief wants joint response to cyberattacks, sabotage [1d]
- Ukraine moves to crack down on scam call centers after corruption scandal [1d]
- Norway announces investigations into telecom Telenor’s work with Myanmar junta [2d]
- Iranian cyber spies used fake MRI scan results to hack ‘enemy of regime’ [2d]
- Zelensky appoints former police chief to lead Ukraine’s cyber coordination center [2d]
- Electric and gas utility CenterPoint Energy warns of data breach after dark web post [2d]
- China spy chief points at US AI models in cyber threat warning [2d]
- Manhattan DA takes down 12 AI deepfake porn sites [2d]
CyberScoop
- Cisco alerts customers to second actively exploited zero-day in as many days [2h]
- The AI hacking apocalypse is not inevitable [4h]
- Authorities seize popular, long-running DDoS-for-hire service domains [9h]
- America’s cyber strategy overlooks the infrastructure that actually keeps the military moving [13h]
- CISA promotes a fresh way to deter cyberattackers: Lie to them [1d]
- Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks [1d]
- Treasury’s Scott Bessent says no liability exemptions for AI labs [1d]
- What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies [2d]
- Cisco warns customers of actively exploited zero-day in email gateways [2d]
- Supreme Court denies Trump request to allow USPS mail ballot changes [2d]
SANS ISC
- LausivLoader analysis, or how to pass data between malware stages [8h]
- ISC Stormcast For Thursday, September 17th, 2026 https://isc.sans.edu/podcastdetail/10098 [21h]
- Scans Targeting Hospitality Applications [1d]
- ISC Stormcast For Wednesday, September 16th, 2026 https://isc.sans.edu/podcastdetail/10096 [1d]
- MacOS 27 - First Boot [2d]
- ISC Stormcast For Tuesday, September 15th, 2026 https://isc.sans.edu/podcastdetail/10094 [2d]
Schneier on Security
Rapid7 Blog
Malwarebytes Labs
- Flock cameras are tracking people as well as cars [4h]
- Revolut phishing texts appear days after data breach [9h]
- 12 celebrity deepfake websites seized by Manhattan DA [12h]
- T-Mobile rewards points expiry texts are a phishing scam [12h]
- Google Pixel owners urged to patch actively exploited modem flaw [1d]
- AI helps scammers build convincing antivirus renewal pages [1d]
- How to opt out of AI chatbot training [2d]
- HBO Max’s verified Reddit account hijacked to spread malware [2d]
- Meta AI builds detailed profiles of children from years of family posts [2d]
- Search results are sending people to fake Bitrefill checkouts [2d]
Graham Cluley
WeLiveSecurity (ESET)
Unit 42 (Palo Alto)
CISA Advisories
- Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) [11h]
- Mitsubishi Electric GX Works3 and Motion Control Settings [11h]
- Hitachi Energy FACTS Control Platform (FCP) [11h]
- Bransys ELD [11h]
- Schneider Electric NetBotz 5 750/755 [11h]
- Schneider Electric Modicon M340 Controller and Communication Modules [11h]
- Schneider Electric PowerChute Serial Shutdown [11h]
- ABB Ability Edgenius [11h]
- CISA Adds One Known Exploited Vulnerability to Catalog [1d]
- Using Cyber Decoys to Strengthen Detection and Response [1d]
- CISA Adds Two Known Exploited Vulnerabilities to Catalog [1d]
- Protecting Tokens and Assertions from Forgery, Theft, and Misuse: Implementation Recommendations for Agencies and Cloud Service Providers [2d]
- Digital Watchdog VMAX DVR and NVR Product Lineups [2d]
- mySCADA myPRO Manager [2d]
- Schneider Electric SCADAPack x70 Products [2d]
- Siemens Teamcenter [2d]
- Siemens Mendix SAML [2d]
- Wärtsilä FOS-Onboard [2d]
- Siemens Reyrolle 7SR5 [2d]
- CareCam CM2507 [2d]
Zero Day Initiative
- ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability [18h]
- ZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation Vulnerability [1d]
- ZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution Vulnerability [1d]
- ZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution Vulnerability [1d]
- ZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation Vulnerability [1d]
- ZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability [1d]
- ZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure Vulnerability [1d]
- ZDI-26-713: GIMP APNG File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability [1d]