BLOG 2026 SEPTEMBER 2026 2025 2024 2023
AI blog APT blog Attack blog BigBrother blog BotNet blog Cyber blog Cryptocurrency blog Exploit blog Hacking blog ICS blog Incident blog IoT blog Malware blog OS Blog Phishing blog Ransom blog Safety blog Security blog Social blog Spam blog Vulnerebility blog
2026 January(89) February(123) March(106) April(119) May(126) June(97) July(101) August(348) September(194) October(0) November(0) December(0)
DATE |
NAME |
Info |
CATEG. |
WEB |
|
12.9.26 |
LLMs Just Made Your IP Easier to Steal: Here’s the Fix | Large Language Models (LLMs) have fundamentally altered the economics of reverse engineering, meaning that any organization still relying on traditional obfuscation as its primary defense is protecting against an attacker who no longer exists. | AI blog | JSCRAMBLER |
|
12.9.26 |
When Detection Arrives After the Damage: Ransomware as a Patient-Safety Emergency | Healthcare ransomware is a patient-safety emergency, not just a data-privacy incident: when ransomware encrypts hospital systems, it disrupts the technology clinicians use to diagnose, treat, and stabilize patients — diverting ambulances, delaying procedures, and forcing a return to paper at the moment care is most time-sensitive. | Ransom blog | MORPHISEC |
|
12.9.26 |
Expanding the Attack Surface: Analyzing Nightmare-Eclipse's Latest PoCs | In our previous blog, we explored a series of disclosures from the leak persona Nightmare-Eclipse that focused heavily on Microsoft's ecosystem, including Windows Defender, Cloud Files, and core operating system functionality. | Hacking blog | SPIDERLABS |
|
12.9.26 |
Malicious Chrome and Firefox Extensions Steal Crypto Traders’ Session and Wallet Data | Malicious Chrome and Firefox extensions target Axiom Trade and Padre users, stealing session tokens and wallet data. | Cryptocurrency blog | SOCKET.DEV |
|
12.9.26 |
Anthropic Identifies Biased Reasoning and Recklessness as Drivers of Claude’s PyPI Attack | Anthropic found biased reasoning and recklessness drove Claude Mythos 5 to publish malware on PyPI and compromise a security vendor. | AI blog | SOCKET.DEV |
|
12.9.26 |
Shai-Hulud in the Wild: What Security and Incident Response Teams Need to Know | Learn how Shai-Hulud compromises trusted software workflows, exposes credentials across CI/CD environments, and creates attack paths into cloud, production, and downstream systems, and how security teams can contain and recover from the compromise. | Hacking blog | SYGNIA |
|
12.9.26 |
Introducing automatic remediation policies with Cloudflare CASB | Today, we’re making Cloudflare CASB more powerful than ever by introducing automatic remediation policies. This means security teams can now design event-driven logic to revoke risky file shares and dispatch custom webhooks, without manual intervention. | Security blog | CLOUDFLARE |
|
12.9.26 |
1.1.1.1 now supports post-quantum DNSSEC, all 2,420 bytes of it | 1.1.1.1 now validates DNSSEC signatures made with ML-DSA-44, a post-quantum signature algorithm standardized by the National Institute of Standards and Technology (NIST). This is a first step toward preparing DNSSEC for a future in which today’s signature algorithms are no longer secure. | Security blog | CLOUDFLARE |
|
12.9.26 |
How we rebuilt Cloudflare Workers’ module registry for Node.js compatibility | We’ve rewritten the module registry in workerd, the core open-source component of the Workers runtime, to be faster, more standards-compliant, and more closely aligned with Node.js' module registry. | Security blog | CLOUDFLARE |
|
12.9.26 |
Automatic Key Exchange: faster, post-quantum secure origin handshakes for 45 billion daily connections (and counting) | Every time Cloudflare opens a new TLS 1.3 connection to an origin server, we have to make a guess: the protocol requires us to commit to a key agreement algorithm in the very first packet we send, before the origin has told us anything about itself or what it can support. If we guess right, the handshake completes in one round trip. Guess wrong, and the origin replies with a HelloRetryRequest, we start over, and the connection costs two round trips. | Security blog | CLOUDFLARE |
|
12.9.26 |
Reduce AI Token Waste by Getting Decisions Right Earlier | AI coding assistants are changing the economics of software development. They can interpret tasks, inspect codebases, select dependencies, make changes, call tools, run tests, and prepare pull requests. | AI blog | SONATYPE |
|
12.9.26 |
DefCon 2026: The Sandbox Is a Suggestion: Breaking Claude Code, Gemini CLI, and Codex Sandboxes | How we broke the default sandboxes in Claude Code, Gemini CLI, and Codex — leaking credentials from all three, including a CVSS 10.0 chain. DefCon 2026 research. | Cyber blog | NOVEE |
|
12.9.26 |
DefCon 2026: No Prompt Required: Pre-Task RCE in Google Gemini CLI | How a CVSS 10.0 pre-task RCE in Google Gemini CLI ran attacker code before the sandbox started. No prompt injection required. Full DefCon 2026 research. | Cyber blog | NOVEE |
|
12.9.26 |
CRA Reporting Goes Live September 11: What Manufacturers Must Have in Place When the Clock Starts | Product security continues to stand as a forefront of risk for manufacturers and developers worldwide. Consumers are consistently seeking new ways to protect themselves, their environments and their own systems. While some of this responsibility may fall on user’LAUDs, many look to the product engineers behind their solutions as a first line of defense. | Cyber blog | GUIDESECURITY |
|
12.9.26 |
Agentic AI Security: Key Findings from New IDC Research on the Identity Control Plane | A new IDC whitepaper, commissioned by GuidePoint Security, explores why identity is the foundational control plane for securing agentic AI and what organizations should prioritize as adoption accelerates. | AI blog | GUIDESECURITY |
|
12.9.26 |
URL Laundering by Rogue Agents: Newly Discovered Messages and Sandbox Circumvention by AI Swarms | We found a thousand new messages and additional sandbox circumvention methods used by the collusion.wiki Rogue AI agent swarms | AI blog | ZENITY |
|
12.9.26 |
ShieldCrash PoC: Microsoft Defender Fix Bypass | Microsoft recently fixed CVE-2026-69414 (ShieldBreak), a High-severity elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine. | Vulnerebility blog | SOCRADAR |
|
12.9.26 |
Cisco FMC CVE-2026-20079 Actively Exploited | Cisco has confirmed active exploitation of CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC) with a maximum CVSS score of 10.0. | Vulnerebility blog | SOCRADAR |
|
12.9.26 |
Vibe-Terrorism: Inside the Yemen Cell That Used Claude to Build Guided Weapons | In Anthropic’s September 2026 threat intelligence report, one case stands apart from the rest. A small cell based in northern Yemen used Claude Code to develop guidance, navigation, and control (GNC) software for missiles. They ran three weapons programs simultaneously, conducted a live test-fire and when the rocket failed, they came back to Claude within hours to figure out why. | AI blog | SOCRADAR |
|
12.9.26 |
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs (CVE-2026-81963, CVE-2026-85880) | Microsoft addresses 964 CVEs, smashing July’s release as the largest Patch Tuesday release. This month’s updates include patches for two zero-days that were exploited in the wild | Vulnerebility blog | TENABLE |
|
12.9.26 |
Introducing the CyberAgents Exchange AI Inspector: Rigorous review for community-built AI | Open-source registries for AI agents are only effective when they include a rigorous, transparent security review process for community submissions. That’s why for its new CyberAgents Exchange registry, Tenable paired its exposure management expertise with OpenAI GPT Cyber models to create the CyberAgents Exchange AI Inspector. | AI blog | TENABLE |
|
12.9.26 |
FileRun: Four More Ways to Run Your Files | Today VulnCheck is disclosing four vulnerabilities in FileRun, the self-hosted file manager and sharing platform. They are being disclosed in accordance with VulnCheck's coordinated vulnerability disclosure policy, and all four were allocated through the VulnCheck CNA. Each one ends in remote code execution as the web-server user: | Vulnerebility blog | VULNCHECK |
|
12.9.26 |
The Anthropic Glasswing Receipts Are Starting to Trickle In | Anthropic’s Project Glasswing is approaching 5 months old, and Anthropic published its Vulnerability Disclosure Ledger on May 22nd. It hadn't received an update until this past week, when it backfilled the ledger with additional findings and updates, so naturally I thought it would be worthwhile to take a look at the receipts. | AI blog | VULNCHECK |
|
12.9.26 |
New on the Map — August 2026: 14 Protocol Scanners | Most organizations don’t have a complete picture of what’s reachable from the Internet. A router, a camera system, a data warehouse, a building access controller — any one of these could be answering requests from anywhere in the world right now, and your security team might not know. However, attackers scan for these services systematically, every day. | Security blog | CENSYS |
|
12.9.26 |
CVE-2026-82533: DeepSeek Harness Vulnerability Lets AI Agents Escape Their Own Sandbox | OX Research found and disclosed a critical vulnerability in DeepSeek Harness, DeepSeek’s open-source AI coding-agent harness, that allowed a sandboxed AI agent to disable its own confinement with a single shell command – on shipped defaults, with no network exposure and no credentials. | Vulnerebility blog | OX SECURITY |
|
12.9.26 |
Finding and Notifying a ShinyHunters Claims Impersonation Campaign Before It Activated: 61 Domains, 48 Brands | ReliaQuest Threat Research published a short public advisory about a ShinyHunters campaign on August 17, 2026. This campaign was built on domains following a company[.]claims pattern, and reported that the group had added legal team impersonation to its established help desk and IT pretexts. The advisory had no domains, and described a shape that left the reader to find the instances. | CyberCrime blog | FLARE.IO |
|
12.9.26 |
I just trusted the security certificate prompt… Beware of the LegionLoader malware being distributed via the ClickFix method | The AhnLab SEcurity intelligence Center (ASEC) recently identified the LegionLoader malware, which is currently being distributed via the ClickFix method. There are two main distribution methods identified so far; both involve tricking users into visiting a malicious URL and then prompting them to directly execute malicious PowerShell commands through a fake Cloudflare CAPTCHA screen. | Malware blog | Zscaler |
|
12.9.26 |
Casbaneiro: A Banking Trojan with Distributed Data-Receiving Servers | In August 2026, FortiGuard Labs observed a Casbaneiro attack campaign targeting users in Latin America, using phishing emails and PDF files themed around fake invoices and legal notices as the initial stage. | Malware blog | FORTNITE |
|
12.9.26 |
ShadowPane: Inside a Frostedwrist-Linked BITB Campaign Targeting Real Estate and Escrow Firms | ZeroBEC uncovered a phishing campaign we track as ShadowPane that uses browser-in-the-browser deception to make malicious RMM installations appear to originate from Adobe. | Phishing blog | ZEROBEC |
|
12.9.26 |
Imperva Customers Protected Against StyleSmuggler (CVE-2026-75650) in Adobe Commerce and Magento Open Source | TL;DR: CVE-2026-75650, dubbed StyleSmuggler, is a critical vulnerability affecting Adobe Commerce and Magento Open Source. The vulnerability allows an unauthenticated attacker to inject malicious PHP code into Magento’s template system and achieve remote code execution. | Vulnerebility blog | IMPERVA |
|
12.9.26 |
ANY.RUN Secures Leader Status in G2’s Malware Analysis Rankings | In G2’s Fall 2026 awards, we earned both Momentum Leader and Grid Leader recognition, highlighting our continued growth and strong position in the market. Most importantly, these achievements reflect the trust security professionals place in ANY.RUN every day to support their threat investigations. | Malware blog | ANYRUN BLOG |
|
12.9.26 |
15 Minutes Saved Per Alert: How a Lean German Manufacturer Protects 10,000 Endpoints with ANY.RUN | To get an insider’s view on how teams navigate these industry demands, we sat down with Philipp Z., Security Lead at a leading German manufacturer. He shared how replacing complex manual analysis with ANY.RUN’s Interactive Sandbox helped his team accelerate incident response by 15 minutes per case, eliminate tedious routines, and strengthen their overall security posture. | Cyber blog | ANYRUN BLOG |
|
12.9.26 |
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence | Huntress recently analyzed two attacks that started with a phishing message and then redirected victims to a browser-in-the-browser (BiTB) page (both using the same template and lure) that prompted them to download an "updated Adobe Reader" version to view files. | Phishing blog | Huntress |
|
12.9.26 |
Grand Theft Auto VI Hype Leads to Malware | Threat actors are taking advantage of overeager gamers searching for a leaked version of the upcoming Grand Theft Auto VI (GTA6), using fake game downloads as an initial access lure. | Malware blog | Huntress |
|
12.9.26 |
UK Council Attack Linked to SonicWall SMA 1000 Campaign | Disclosure note: Hunt.io notified the UK National Cyber Security Centre (NCSC) and other relevant national CERTs ahead of publication, so that affected organisations identified during the research could be contacted. | Vulnerebility blog | HUNT.IO |
|
12.9.26 |
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities. Proofpoint is tracking the exploit kit used in this activity as BlueMoon. | Vulnerebility blog | PROOFPOINT |
|
12.9.26 |
Beyond the Alert: Bringing Context to Insider Risk and AI Investigations | Proofpoint is announcing two expansions to its communications intelligence capabilities today. Proofpoint Prism Investigator now connects directly to Microsoft 365, and Proofpoint Human Communications Intelligence (HCI) now brings AI communications governance signals into insider risk investigations. | AI blog | PROOFPOINT |
|
12.9.26 |
SloppyRAT: A New Tool For Ransomware Attacks | In June 2026, Zscaler ThreatLabz identified a new malware family, tracked as SloppyRAT, that is likely leveraged by a ransomware-related threat actor. ThreatLabz observed SloppyRAT being delivered through a multi-stage ClickFix infection chain. | Malware blog | Zscaler |
|
12.9.26 |
This SonicWall bug is 2 years old. Akira ransomware is still exploiting it. | The Akira ransomware gang is still breaking into networks through a firewall bug SonicWall fixed two years ago. The critical vulnerability, CVE-2024-40766, carries a CVSS score of 9.3 out of 10. | Vulnerebility blog | THREATDOWN |
|
12.9.26 |
Dissecting a PHP web server rootkit | Sophos X-Ops takes a deep dive into an insidious piece of malware | Malware blog | SOPHOS |
|
12.9.26 |
MacSync: The Evasive macOS Stealer Exploiting ClickFix Lures | Executive Summary MacSync Stealer is a family of macOS information stealers and remote-access stagers designed to evade detection and sold commercially under a malware-as-a-service (MaaS) model. In the attack chain, MacSync binaries are native stagers and multi-part exfiltration engines.... | Malware blog | SEQRITE |
|
12.9.26 |
Cyble Introduces Major Upgrade to its Executive Monitoring Module | Cyble has rolled out a significant upgrade to Executive Monitoring inside Cyble Vision, bringing unified findings, AI-driven scoring, and expanded alerting together in a single protection suite. | Cyber blog | Cyble |
|
12.9.26 |
From Infostealer Log to Marketplace Listing: A Technical Walkthrough of the Credential Theft Pipeline | Infostealer malware turns a single infection into a marketplace listing. A technical look at harvesting, stealer logs, enrichment, and resale. | Malware blog | Cyble |
|
12.9.26 |
Qatar’s Digital Boom Has a Blind Spot: What the 2025-26 Threat Data Is Telling Us | Qatar is racing toward a knowledge-based, fully digital economy. But that pace of transformation makes Qatar an attractive target in the cyber realm. | Cyber blog | Cyble |
|
12.9.26 |
AI-Driven Threat Intelligence for Gulf Enterprises: Why Detection Speed Is Now a Regulatory Requirement | AI-powered threat intelligence helps GCC enterprises detect breaches faster, close compliance gaps, and meet strict cyber incident reporting deadlines. | AI blog | Cyble |
|
12.9.26 |
Gray Rabbits and the Tale of a One-Click Backdoor | One click. Three critical failures. One backdoor. | Malware blog | GENDIGITAL |
|
12.9.26 |
Infostealers Have Found a New Target: Your AI Agent | Malware operators are expanding beyond browser passwords and crypto wallets to collect access tokens, MCP configurations, prompt histories and project data stored by AI tools. | AI blog | GENDIGITAL |
|
12.9.26 |
Protecting organizations from AI-assisted executive impersonation and invoice fraud | Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. | AI blog | Microsoft blog |
|
12.9.26 |
Passkey-themed social engineering leads to identity and cloud compromise | Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. | Security blog | Microsoft blog |
|
12.9.26 |
Microsoft Security Bulletin Coverage for September 2026 | Microsoft’s September 2026 Patch Tuesday is the largest on record, addressing 971 vulnerabilities, including 438 Elevation of Privilege vulnerabilities. The SonicWall Capture Labs Threat Research team analyzed Microsoft’s security advisories for September 2026 and developed coverage for 42 of the reported vulnerabilities. | OS Blog | SonicWall |
|
12.9.26 |
Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure | A recent Unit 42 investigation into seemingly low-priority enterprise infections demonstrates how the most effective camouflage in cybercrime is not necessarily in the use of sophisticated techniques, but in how unremarkable the threat appears. The activities that we investigated would typically not require escalation or further inquiry. But upon closer inspection, we discovered a massive cybercrime campaign largely targeting young gamers. | CyberCrime blog | Palo Alto |
|
12.9.26 |
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America | We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities. | AI blog | Palo Alto |
|
12.9.26 |
The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE | This research demonstrates post-exploitation techniques that could allow an attacker with root access on a compromised Kubernetes node to misuse an open standard and reference implementation for machine identity known as SPIFFE/SPIRE to impersonate co-located workloads and harvest SPIFFE Verifiable Identity Documents (SVIDs). | Exploit blog | Palo Alto |
|
12.9.26 |
PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector | In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. | AI blog | CHECKPOINT |
|
12.9.26 |
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT | Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. | AI blog | CHECKPOINT |
|
12.9.26 |
ClickFix moves into the browser: Cryptocurrency theft with Google-hosted C2 | Cisco Talos is tracking a cryptocurrency-stealing campaign that abuses the Google Visualization API for command and control (C2), retrieving obfuscated JavaScript from a publicly published Google Sheets document and injecting it into the victim's browser session. | Cryptocurrency blog | CISCO TALOS |
|
12.9.26 |
We've got one word for it, and it's usually the wrong one | In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it. | Cyber blog | CISCO TALOS |
|
12.9.26 |
Active exploitation of Cisco Secure Firewall Management Center vulnerabilities | Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software. | Exploit blog | CISCO TALOS |
|
12.9.26 |
ClearFake WebDAV infection chain delivers Amatera stealer, ZigCryptoStealer, and NetSupport Manager | We assess with moderate confidence that the attacks are not targeted at a particular organization, but are a part of a cryptocurrency and credentials-stealing operation using the Amatera stealer as the primary payload. | Malware blog | CISCO TALOS |
|
12.9.26 |
Microsoft Patch Tuesday for September 2026 — Snort rules and prominent vulnerabilities | Microsoft has released its monthly security update for September 2026, which includes 973 vulnerabilities affecting a range of products, including 113 that Microsoft marked as "critical." | Vulnerebility blog | CISCO TALOS |
|
12.9.26 |
GuardBreaker: Derailing AI-assisted malware analysis with a code comment | AI blog | Eset | |
|
12.9.26 |
Safe word: What is it and why do you need one? | AI scams are now hyper-realistic. But there’s one simple way to see through them. | Security blog | Eset |
|
12.9.26 |
Testing race conditions with memory access tracing and stack-based delay injection | Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: | Hacking blog | PROJECT ZERO |
|
12.9.26 |
Trellix SecondSight Threat Hunting Report: How AI and Human Intelligence Expose 2026 Cyber Threats | As adversaries adopt new technologies, techniques, and increasingly AI-enabled ways of operating, defenders have access to more telemetry, intelligence, and automation than ever before. The challenge is knowing where to look, what matters, and when a weak signal deserves a closer look. This is focus of the September 2026 Trellix SecondSight Threat Hunting Report. | AI blog | TRELLIX |
|
11.9.26 |
Mantax Otax: Indonesian Mobile Ransomware with Spyware Integration | The zLabs research team has discovered a sophisticated and highly aggressive mobile malware strain linked to Indonesian threat actors, that marks a dangerous tactical evolution by seamlessly integrating comprehensive spyware capabilities with traditional ransomware functionality into a single attack vector. | Ransom blog | ZIMPERIUM |
|
11.9.26 |
DCOM Service PsmServiceExtHost LPE - SSD Secure Disclosure | Threre is a heap buffer overflow vulnerability in a DCOM service that can be leveraged to achieve LPE from a Medium IL standard user to System IL. | Vulnerebility blog | SSD-DISCLOSURE |
|
11.9.26 |
Wiz achieves GovRAMP High Authorization | Delivering unified cloud security and accelerating secure modernization to protect citizen data and critical infrastructure. | Security blog | Wiz Blog |
|
11.9.26 |
What Is Agentic Cyber Defense Engineering? | Attackers can now find weaknesses faster, adapt tactics in minutes and scale campaigns without requiring extensive expertise or large networks of threat actors. Meanwhile, many security teams still rely on manual processes to execute and coordinate critical activities. The result is a widening gap between the speed of AI-powered threats and the ability of security teams to respond. | AI blog | CYMULATE |
|
11.9.26 |
New Ruxie AI power-up: Precedent engine turns repetitive alerts into faster decisions | A large portion of the daily security alert queue is made up of alerts that look almost exactly like cases our analysts have already investigated and closed. | AI blog | Expel |
|
11.9.26 |
How to build a continuous penetration testing program | Headcount is the wrong lever. More security hiring, or more bought pentest days, feeds the one stream that can't scale, so coverage barely moves even when the budget clears. | Security blog | ESCAPE.TECH |
|
11.9.26 |
How Amp got its Soc 2 Type II pentest evidence in hours | Amp is the AI hiring team for high-volume frontline employers. Restaurants, retailers, logistics operators, hospitality groups, healthcare staffing firms. Amp screens candidates against the criteria you set, books interviews on your managers' calendars, runs candidate comms, and closes offers you approve. | AI blog | ESCAPE.TECH |
|
11.9.26 |
How a Fraudulent Hire Clears Your Verification Process | The controls most companies trust to vet a candidate were built to catch mistakes and embellishments. They were not built for a well-funded adversary using a real person's identity, and sometimes a real person. | CyberCrime blog | ABNORMAL |
|
10.9.26 |
Attack Cases in Korea Involving the Installation of Radmin and UltraVNC | The AhnLab SEcurity intelligence Center (ASEC) recently identified attack cases that exploited Radmin and UltraVNC. Although the Initial Intrusion method remains unknown, the attackers installed Radmin—a remote control tool—and then installed UltraVNC. | APT blog | Zscaler |
|
10.9.26 |
2026 State of the Internet: The Exposure Notification Gap in ICS Devices | New Censys data reveals a major blind spot in Internet-exposed industrial control systems. | ICS blog | Censys |
|
10.9.26 |
The Anthropic Glasswing Receipts Are Starting to Trickle In | Anthropic’s Project Glasswing is approaching 5 months old, and Anthropic published its Vulnerability Disclosure Ledger on May 22nd. It hadn't received an update until this past week, when it backfilled the ledger with additional findings and updates, so naturally I thought it would be worthwhile to take a look at the receipts. | AI blog | VULNCHECK |
|
10.9.26 |
Coming to Tenable One: Claude Mythos 5 and “Adversary View” | Tenable is bringing Anthropic’s Claude Mythos 5 into our enterprise security offerings. Adding frontier adversarial reasoning to the Tenable One Exposure Management Platform will help customers better anticipate how attackers could breach their environments and stay ahead of AI-fueled risk. | AI blog | TENABLE |
|
10.9.26 |
Signing in without actually signing in | Session tokens are the skeleton keys used to hijack | Hacking blog | OKTA |
|
10.9.26 |
September 2026 Patch Tuesday: 974 Flaws, 2 Zero-Days | Microsoft’s September 2026 Patch Tuesday release addresses 974 vulnerabilities, including two actively exploited zero-days. Both zero-days are Windows elevation of privilege flaws, and both were added to CISA’s Known Exploited Vulnerabilities (KEV) catalog. | Vulnerebility blog | SOCRADAR |
|
10.9.26 |
E-Commerce Access, Vedicline Data, Langflow RCE, ASUS Claim, and Energy Shell Access | SOCRadar Dark Web Team identified several new underground posts, including an alleged Bangladeshi e-commerce customer database sale, an alleged Vedicline customer database sale, and a claimed Langflow 1.12.0 zero-day RCE exploit. Other posts advertised an alleged ASUS database and shell access to an Indian energy sector organization. | Vulnerebility blog | SOCRADAR |
|
10.9.26 |
SOCRadar MCP Server for ChatGPT: Setup and Use Cases | The SOCRadar Threat Intelligence MCP app connects ChatGPT to the SOCRadar MCP server over OAuth, exposing your licensed intelligence modules as callable tools. Analysts enrich indicators, check CVE exploitation, and query Dark Web exposure without leaving the conversation. | AI blog | SOCRADAR |
|
10.9.26 |
StyleSmuggler: Unpatched Magento and Adobe Commerce Zero-Day Exploited | Attackers are actively exploiting an unpatched zero-day vulnerability in Magento Open Source and Adobe Commerce that allows unauthenticated remote code execution and persistent backdoor installation. | Exploit blog | SOCRADAR |
|
10.9.26 |
FBI Investigates Nexus Claim of 153M+ ID Records | A Dark Web service called Nexus has claimed to offer access to more than 153 million driver’s license records from the United States and Canada, along with millions of other identity documents. The FBI has reportedly opened an investigation into the exposure. | CyberCrime blog | SOCRADAR |
|
10.9.26 |
CVE-2025-25249 Exploitation Delivers PivotC2, a FortiGate Post-Exploitation RAT | One of the most common entry points for attackers is the exploitation of public-facing edge devices (such as VPNs, routers, and firewalls). Over the years, FortiGate firewalls have remained a consistent target, as evidenced by the recent widespread FortiBleed campaign conducted jointly by the INC and Lynx ransomware groups. | Vulnerebility blog | SOCRADAR |
|
10.9.26 |
Dark Web Market: Anubis Market | Anubis Market is a multi-category Dark Web marketplace operating as a Tor hidden service, with escrow-backed trading in Bitcoin (BTC) and Monero (XMR). Its visible category strip displays more than 11,000 listings, and while narcotics account for the largest share of physical goods, its Digital section is the single biggest category on the market. | CyberCrime blog | SOCRADAR |
|
10.9.26 |
Browser-based phishing hides pages inside victims’ browsers | How attackers chain trusted business platforms together to make credential theft look like routine work | Phishing blog | BARRACUDA |
|
10.9.26 |
Browser-in-the-browser phishing campaign chains DocuSign, Adobe and Microsoft trust | How attackers abuse Microsoft OAuth redirects, Teams domains, blob URLs, and service workers to deliver phishing pages without a traditional phishing site. | Phishing blog | BARRACUDA |
|
10.9.26 |
NSA Best Practices for Cyber Hygiene recommends allowlisting, Zero Trust controls | On September 3, 2026, the NSA released new cyber hygiene best practices focused on defending against AI-enhanced threats. With cybercriminals increasingly using AI tools to boost attacks, the NSA highlighted weak authentication, unpatched systems, and misconfigurations as persistent issues attackers take advantage of. | Cyber blog | THREATLOCKER |
|
9.9.26 |
Vwork: Weaponized Open-source Software as an Addon for Gigabud | How the Gigabud Android banking trojan abuses Shelter, an open-source app cloner, and what that means for banks, users, and defenders. | Malware blog | GROUP-IB |
|
9.9.26 |
Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days | Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities. Proofpoint is tracking the exploit kit used in this activity as BlueMoon. | Vulnerebility blog | PROOFPOINT |
|
9.9.26 |
Redis Cryptomining Botnet Compromised 3,562 Servers, Exposed by the Operator's Own Files | Note on withheld data: Individual victim IPs are aggregated by network block, not listed. Sensitive data incidentally exposed on unrelated third-party sites has been removed from this report and, where possible, reported to the relevant providers. This report documents attacker infrastructure and tradecraft; it is not a disclosure against any named organization. | Cryptocurrency blog | HUNT.IO |
|
9.9.26 |
Beyond Lazarus: How North Korea Organizes Its Cyber Operations | Get the full overview of North Korea's cyber operations, from state institutions and APT clusters to IT workers units, and enablers. | APT blog | SEKOIA |
|
9.9.26 |
Phishing Attacks Serve Browser-in-the-Browser Pages, Rogue RMM Persistence | Huntress recently analyzed two attacks that started with a phishing message and then redirected victims to a browser-in-the-browser (BiTB) page (both using the same template and lure) that prompted them to download an "updated Adobe Reader" version to view files. | Phishing blog | Huntress |
|
9.9.26 |
German Manufacturer Saves 15 Minutes Per Alert | To get an insider’s view on how teams navigate these industry demands, we sat down with Philipp Z., Security Lead at a leading German manufacturer. He shared how replacing complex manual analysis with ANY.RUN’s Interactive Sandbox helped his team accelerate incident response by 15 minutes per case, eliminate tedious routines, and strengthen their overall security posture. | Security blog | ANYRUN BLOG |
|
9.9.26 |
GTIG AI Threat Tracker: From Prompting to Autonomy – The Evolution of Adversarial AI | Since the release of our May 2026 report detailing adversarial misuse of artificial intelligence (AI), Google Threat Intelligence Group (GTIG) has observed forward leaning adversaries transition from basic prompting to agentic AI workflows and AI-enabled automation. | AI blog | GTI |
|
9.9.26 |
The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT | Check Point Research discovered a covert cross-account command channel through which an attacker could use a victim’s ChatGPT session to execute hidden tasks with the tools, data, and connected apps available to that session. The victim could receive a normal answer to their visible request while the attacker’s task was processed separately and its result returned across accounts. In our proof of concept, ChatGPT retrieved email data from the victim’s connected Gmail account and relayed it to the attacker. | AI blog | CHECKPOINT |
|
8.9.26 |
AI Agent 'opencode'로 미끼를 만든 김수키, GitHub PAT 기반 LNK 공격 진화 | Kimsuky Uses the AI Agent 'opencode' to Create Decoys as Its GitHub PAT-Based LNK Attacks Evolve | AI blog | GENIANS |
|
8.9.26 |
Tracking BigBear 2.0 Evilginx2 Phishing Campaign | CloudSEK researchers uncovered BigBear 2.0, a global Microsoft 365 phishing-as-a-service operation targeting hundreds of organizations across 40+ countries. | Phishing blog | CloudSEK |
|
8.9.26 |
Beyond Lazarus: How North Korea Organizes Its Cyber Operations | Get the full overview of North Korea's cyber operations, from state institutions and APT clusters to IT workers units, and enablers. | APT blog | SEKOIA |
|
8.9.26 |
HVNC Backdoor Targets LATAM Organizations with Fake Tax Lures | Fake tax documents are being used to target organizations across LATAM, delivering a custom HVNC backdoor built for stealthy, persistent access. Once installed, the malware can give attackers hidden remote control, steal browser data, monitor keystrokes, and survive system reboots. | Malware blog | ANYRUN BLOG |
|
8.9.26 |
Detection and Removal of the Syslogk Rootkit in a Linux Environment | The AhnLab SEcurity intelligence Center (ASEC) continuously monitors various threats targeting Linux environments. Techniques that modify the Linux kernel to conceal malware and signs of compromise have been used for a long time, and Syslogk is one such rootkit that operates in this manner. | Malware blog | Zscaler |
|
7.9.26 |
N-able N-central HF4 Patches Critical Pre-Auth RCE | N-able has released N-central 2026.3 Hotfix 4 (build 2026.3.1.14) to fix CVE-2026-86218, a critical pre-authentication remote code execution vulnerability in its remote monitoring and management platform. The update supersedes three hotfixes issued between August 2 and September 5 and is the current security baseline for the 2026.3 branch. | Vulnerebility blog | SOCRADAR |
|
7.9.26 |
CVE-2026-73749: HPE ArubaOS-CX RCE | HPE patched CVE-2026-73749, a critical unauthenticated Remote Code Execution (RCE) vulnerability in HPE Aruba Networking AOS-CX, also known as ArubaOS-CX. | Vulnerebility blog | SOCRADAR |
|
7.9.26 |
CVE-2026-20212: Cisco Nexus 9000 RCE Flaw | Cisco has disclosed a critical vulnerability, CVE-2026-20212, in the Silicon One integration used by certain Nexus 9000 switches. The flaw allows an unauthenticated remote attacker who can access the affected service to execute code with root privileges. | Vulnerebility blog | SOCRADAR |
|
7.9.26 |
Elementor Pro RCE Flaw Under Active Attack | A critical vulnerability in Elementor Pro, a widely used WordPress page builder plugin, allowed unauthenticated attackers to upload files through the plugin’s Forms module. Tracked as CVE-2026-32475, the flaw could lead to remote code execution on affected sites. Wordfence reported blocked exploitation attempts beginning August 19, 2026, the same day Elementor released a fix. | Vulnerebility blog | SOCRADAR |
|
7.9.26 |
Neither Malware nor Harmless: Tracking the NPS Proxy Across the Internet | NPS is an open-source tunneling tool, popular with the Chinese-speaking security community. | Malware blog | Censys |
|
7.9.26 |
Attacking and Defending SCOM: Management Server Relay and Obtaining Run As Credentials | For organizations managing hundreds or thousands of servers, System Center Operations Manager (SCOM) provides a single pane of glass into system health, performance and availability. It is deeply integrated, broadly deployed and trusted with the access it needs to do its job. | Security blog | GUIDESECURITY |
|
5.9.26 |
Introducing More Granular Controls for AI Bot Traffic | We’ve updated our Akamai Bot Directory to split the single AI Bots category into three distinct types: AI training crawlers, AI search crawlers, and AI fetchers and agents. | BotNet blog | AKAMAI |
|
5.9.26 |
CTEM vs BAS: The Difference and Why the Comparison Misses the Point | "CTEM vs BAS" is the wrong question. CTEM is a workflow. BAS is a product category that fits inside one stage of that workflow. The comparison peoWhat is CTEM (continuous threat exposure management)?ple actually need is BAS vs adversarial exposure validation (AEV), both of which sit inside CTEM's Validation stage. | Security blog | ETHIACK |
|
5.9.26 |
Microsoft Teams Notifications Are Now Available in Socket | Socket can now send alerts and supply chain attack notifications to Microsoft Teams, with filters that route the right updates to each channel. | OS Blog | SOCKET.DEV |
|
5.9.26 |
Beyond Point-in-Time: Continuous Offensive Security with the Cobalt API | For enterprise security programs, the challenge was never running offensive security testing against your applications and networks. It's whether the process and results were manageable at scale and could actually drive faster remediation across every business unit and engineering team in the organization. | APT blog | COBALT |
|
5.9.26 |
Attackers exploit a Chrome flaw, update your browser now | Google has shipped a new Chrome desktop release that closes 12 security holes, and one of them was already being used in attacks before the fix arrived. Hong Kong's HKCERT, relaying Google's advisory, rates the release "Extremely High Risk" on the strength of that single bug. | Exploit blog | INTELFUSIONS |
|
5.9.26 |
Hackers quietly turn Korean PCs into proxies and VPNs | A PowerShell process on a Korean machine pulls down a zip file and unpacks a batch script that installs Radmin, a perfectly legitimate remote desktop product, into C:\Intel\RServer. Nothing in that sequence looks like malware. That is the point. | Hacking blog | INTELFUSIONS |
|
5.9.26 |
Video encoders can be rooted and no patch is coming | Taking over a QVidium Opera11 video encoder takes one web request, and there is nobody left to ship a fix. The company that built the devices has gone out of business. | Vulnerebility blog | INTELFUSIONS |
|
5.9.26 |
ServiceNow flaws let strangers run code on an instance | ServiceNow has fixed four security flaws in the platform many large organizations use to run their IT service desks, and its own security team scored every one of them at the top of the scale: CVSS 10.0. Three of the four can be reached by someone with no account and no password at all. | Vulnerebility blog | INTELFUSIONS |
|
5.9.26 |
How we could save petabytes of cache storage with Zstandard and Pingora | Memory costs are increasing dramatically. Both RAM and hard disk drive prices have exploded over the past year. At Cloudflare, we run several massively distributed storage products (including our famous CDN) that rely on making efficient use of the memory we have deployed so we can continue to serve all of our customers. | Security blog | CLOUDFLARE |
|
5.9.26 |
Introducing context-aware vulnerability discovery and remediation with Cloudflare Managed Defense and OpenAI Daybreak models | Your scanner just flagged 4,000 new vulnerabilities, 78 of them critical. Which one do you fix first? | Vulnerebility blog | CLOUDFLARE |
|
5.9.26 |
Your ATS Is Now Part of Your Attack Surface | The attack that should worry your security team most this quarter didn't start with a phishing email. It started with a job application. | Security blog | ABNORMAL |
|
5.9.26 |
How Abnormal and OpenAI are Detecting and Responding to Rogue AI in the Cloud | Abnormal AI is extending its behavioral AI engine to the cloud, using OpenAI models to detect, investigate, and respond to risky or malicious AI-agent behavior. | AI blog | ABNORMAL |
|
5.9.26 |
How Turbopack chunks your JavaScript | Open the network tab of this page and you’ll see a list of JavaScript files with seemingly random names: | Malware blog | NEXT.JS |
|
5.9.26 |
TrendAI™ Brings OpenAI's GPT Cyber Models Into the Race to Shrink Exposure Time to Zero | OpenAI’s GPT cyber models help TrendAI™ close the exposure window, from vulnerability to fix, faster than ever. | AI blog | Trend Micro |
|
5.9.26 |
Introducing Agentic Code Scanning: The Holistic Cycode System Around Any Model | TL;DR: Agentic Code Scanning is the fourth dimension of Cycode’s code scanning spectrum, not a separate product bolted on. Deterministic SAST, AI SAST, SAST + AI Exploitability, and Agentic Code Scanning run as one single system that decides what runs where, so you stop trading precision vs. cost vs. model. It caught both authorization CVEs in our benchmark that no rule engine can express, and all on an affordable open-weights model. | Security blog | CYCODE |
|
5.9.26 |
Contagious Interview steps outside the developer workflow | Jamf Threat Labs uncovers fake macOS installers tied to the same infrastructure behind past Git hook and VS Code task file attacks. | Vulnerebility blog | JAMF |
|
5.9.26 |
7 Best AI Penetration Testing Tools of 2026 | Compare the 7 best AI penetration testing tools of 2026. See which platforms prove exploits, reason like attackers, and run continuous testing at scale. | AI blog | NOVEE |
|
5.9.26 |
Recent Update to FAQ Regarding SAQ Eligibility Criteria Could Affect Your PCI DSS Compliance | The PCI Security Standards Council (PCI SSC) updated FAQ 1331 on its website. This FAQ governs the use of Self-Assessment Questionnaire (SAQ) eligibility criteria as a guide for determining applicability of PCI DSS requirements for Report on Compliance (ROC) assessments. | Security blog | GUIDESECURITY |
|
5.9.26 |
Attacking and Defending SCOM: Management Server Relay and Obtaining Run As Credentials | For organizations managing hundreds or thousands of servers, System Center Operations Manager (SCOM) provides a single pane of glass into system health, performance and availability. It is deeply integrated, broadly deployed and trusted with the access it needs to do its job. | Security blog | GUIDESECURITY |
|
5.9.26 |
DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors | A new Linux toolkit, identified by Rapid7 Labs, has been targeting organizations across South Korea’s automotive and media industries with minimal detection. The campaign made use of a HAProxy instance named “ted backdoor”, alongside trojanized versions of crond, agetty, atd, sshd, and polkitd. | APT blog | RAPID7 |
|
5.9.26 |
Varonis Achieves Snowflake Premier Partner Tier and Is Now Available on Snowflake Marketplace | Building a closer partnership to make it easier to secure the data and AI that customers build, run, and analyze with Snowflake. | Malware blog | VARONIS |
|
5.9.26 |
How attackers abuse PowerShell, WMI, and LOLBins | Windows environments already contain powerful tools capable of executing commands, changing configurations, communicating across networks, and managing operating systems. For administrators, these capabilities are essential, but they also provide attackers with a clear route to breach an environment. | Security blog | THREATLOCKER |
|
5.9.26 |
PEEP: A Browser RAT Posing as a Chrome Extension | The Threat Research Unit (STRU) at SOCRadar’s Extended Threat Intelligence (XTI) platform identified and analyzed PEEP, a Chromium-based emerging post-exploitation toolkit disguised as “Smart Bookmarks.” Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences integrity values. | Malware blog | SOCRADAR |
|
5.9.26 |
SonicWall CVE-2026-83548 Leads to CISA Alert | SonicWall disclosed two actively exploited vulnerabilities in SMA1000 Series appliances: CVE-2026-83548, a pre-authentication server-side request forgery flaw, and CVE-2026-83549, a post-authentication OS command injection flaw. | Vulnerebility blog | SOCRADAR |
|
5.9.26 |
JFrog Artifactory CVE-2026-82329 Exploited | A critical authentication bypass vulnerability in JFrog Artifactory, tracked as CVE-2026-82329, is under active exploitation, posing an immediate threat to self-managed software supply chains worldwide. Under default configurations, unauthenticated network attackers can gain full administrative control over exposed instances. | Vulnerebility blog | SOCRADAR |
|
5.9.26 |
FalconFlank: CrowdStrike Falcon 0-Day PoC | FalconFlank is an alleged privilege escalation zero-day vulnerability in CrowdStrike Falcon Sensor for Windows, published with working Proof-of-Concept (PoC) code by researcher Chaotic Eclipse. The concern: a security product running with elevated privileges may be tricked, through its own malicious-macro remediation workflow, into acting on an attacker’s behalf. | Vulnerebility blog | SOCRADAR |
|
5.9.26 |
427 or 4 Devices?: Measuring Internet-Exposed Industrial Infrastructure in the UK | On August 22, 2026, The Telegraph reported that a small UK power generator had been shut down for four days in July following a cyberattack by hackers linked to Iran. | ICS blog | FLARE.IO |
|
5.9.26 |
Someone Else Is Using Your AI | FortiCNAPP analyzes an AWS LLMjacking incident involving a leaked administrator key and unauthorized access to Amazon Bedrock. | AI blog | FORTNITE |
|
5.9.26 |
One Blank Field Bypasses Direct Send Control | This is external threat intelligence from the ReliaQuest Threat Research team. The findings describe threats, vulnerabilities, and attacker activity affecting third parties and the broader threat landscape—not ReliaQuest’s own environment. Nothing in this report should be read as a vulnerability in ReliaQuest’s systems or data. | Vulnerebility blog | RELIAQUEST |
|
5.9.26 |
H1 2026 Malware Vulnerability Trends | H1 2026 activity showed a continued adversary preference for abusing legitimate tools, trusted platforms, and routine workflows already present in enterprise and consumer environments. Threat actors used exposed software, developer tools, remote access utilities, payment workflows, and third-party services to gain access, steal credentials, move laterally, and monetize intrusions while blending into expected activity. | Malware blog | Recorded Futures |
|
5.9.26 |
How to correlate Kubernetes audit logs with container runtime data | Two fields join the Kubernetes API to what ran inside the pod, and one turns up a container escape your process events never recorded. | Security blog | ELASTIC |
|
5.9.26 |
Data access: the hidden cost of security vendor lock-in | Getting data into a security platform is always easy; getting it back out is where vendors add cost, extra tooling, and latency, and it is the part of the evaluation most teams overlook. | Security blog | ELASTIC |
|
5.9.26 |
Chinese-Speaking Operator Uses AI Agents to Target Government and Education Systems | Disclosure note: Hunt.io disclosed these findings under TLP:AMBER to the relevant national CERTs for the affected jurisdictions and, following responsible disclosure, held publication until September 3, 2026. | APT blog | HUNT.IO |
|
5.9.26 |
eSentire Wins 2026 Global AI Award for AI in Cybersecurity | We're proud to announce that eSentire has won a 2026 Global AI Award in the AI in Cybersecurity category, recognizing the Atlas Platform and the Controlled Autonomy SecOps operating model behind it. | AI blog | ESENTIRE |
|
5.9.26 |
Compliance at the Speed of Regulation | For years, compliance teams built their programs around a manageable, well-known set of frameworks: PCI-DSS for payment data, HIPAA for healthcare, SOC 2 for service organizations, ISO 27001 for information security management. These frameworks were stable. Auditors knew them. Tooling was built around them. And most importantly, the list didn't change very often. | Cyber blog | PROOFPOINT |
|
5.9.26 |
Why Proofpoint Is Signing On to Collective Cyber Defense with Frontier Labs | Last week, OpenAI published an open letter calling for a global surge in cyber defense. Proofpoint is proud to stand alongside frontier labs, fellow security vendors, and global enterprises in signing it. | Cyber blog | PROOFPOINT |
|
5.9.26 |
Proofpoint Introduces SOC Analyst Agent, Powered by OpenAI Daybreak Models Through Daybreak Defense Network | Security teams don’t have a data problem. They have a prioritization problem. Alerts arrive faster than any team can review them, spread across a growing set of products, each with its own console and its own version of the truth. | Cyber blog | PROOFPOINT |
|
5.9.26 |
Microsoft Exchange Vulnerability CVE-2026-62911: What Administrators Should Do and How Zscaler Can Help | Microsoft's August 2026 Patch Tuesday included a fix for CVE-2026-62911, a high-severity authentication bypass vulnerability affecting Exchange Server 2016, 2019, and Subscription Edition. The severity has a CVSS score of 8.0 from Microsoft. | Vulnerebility blog | Zscaler |
|
5.9.26 |
AI threat so great that security “takes precedence over everything except critical business operations” | OpenAI just published an open letter, co-signed by Anthropic, Google, and more than 120 other organizations, warning that the window to prepare for AI-enabled attacks is closing rapidly. | AI blog | THREATDOWN |
|
5.9.26 |
CrowdStrike Delivers the Next Evolution of the Agentic SOC | The agentic SOC provides a foundation that agents can reason over, teams of expert agents that learn each environment, and one workspace to build and govern it all, delivered on the Falcon platform. | Security blog | CROWDSTRIKE |
|
5.9.26 |
CrowdStrike Announces Agentic Identity Provider | CrowdStrike gives every AI agent a trusted identity and continuously controls their access based on real-time context, and expands modern privileged access to where work happens. | AI blog | CROWDSTRIKE |
|
5.9.26 |
Peer Pressure: Inside the Sality Botnet Disruption Operation | CrowdStrike collaborated with international law enforcement and industry partners to execute a coordinated disruption of the Sality peer-to-peer botnet. | BotNet blog | CROWDSTRIKE |
|
5.9.26 |
CrowdStrike Falcon Guardian Defines the Next Generation of AI Security | CrowdStrike’s new flagship AI detection and response solution delivers runtime protection for AI agents, introduces a new AI gateway, and extends expert-led defense. | AI blog | CROWDSTRIKE |
|
5.9.26 |
Ungentlemanly behavior: Insights into a ransomware operation | Analysis of 15 intrusions revealed tradecraft used by GOLD SHERWOOD affiliates | Ransom blog | SOPHOS |
|
5.9.26 |
Google Threat Intelligence Group (GTIG) is tracking three distinct suspected Russian cyber espionage threat clusters abusing legitimate authentication flows to target individuals working in academia, aerospace and defense, governments and think tanks across Europe, as well as academia and think tanks within the United States. | APT blog | GTI | |
|
5.9.26 |
Supply Chain Attacks in 2026: Why Threat Intelligence Is the Only Early Warning System That Works | Supply chain attacks in 2026 are a major breach vector, exposing vendor dependencies and software risks that traditional security tools often miss. | Hacking blog | Cyble |
|
5.9.26 |
The NDA Was the Payload: Inside Phantom Deal, a Fake Acquisition Fraud Campaign | Attackers posed as executives, moved conversations to WhatsApp and personal email, and forged acquisition documents to set up international wire transfers. When they targeted Gen, researchers played along, exposing a wider M&A scam. | CyberCrime blog | GENDIGITAL |
|
5.9.26 |
ASCII smuggling crosses over from AI prompt injection to phishing evasion | Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. | Phishing blog | Microsoft blog |
|
5.9.26 |
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access | Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node. | Cyber blog | Microsoft blog |
|
5.9.26 |
Counterfeit installers to system compromise: Tracking a deceptive software download campaign | An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. | Cyber blog | Microsoft blog |
|
5.9.26 |
Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America | We have analyzed two ongoing, multi-stage network intrusion and data-exfiltration campaigns targeting organizations in Latin America. Corroborating recent findings from the broader threat intelligence community, we observed attackers leveraging artificial intelligence (AI) to enhance their capabilities. | AI blog | Palo Alto |
|
5.9.26 |
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation | Unit 42 responded to an incident where a human attacker used frontier AI to breach an enterprise network autonomously as part of a ransom attack. The agents breached the company's security layers in a methodical manner, each targeting a different layer of defense to achieve a shared goal. | AI blog | Palo Alto |
|
5.9.26 |
Oracle HTTP & WebLogic Servers Proxy Plug-in Authentication Bypass | The SonicWall Capture Labs threat research team became aware of an unauthenticated authentication bypass vulnerability in Oracle HTTP & WebLogic Servers, assessed its impact and developed mitigation measures. | Vulnerebility blog | SonicWall |
|
5.9.26 |
Orova: A New Linux Ransomware Targeting ESXi Hypervisors | This week, the SonicWall Capture Labs Threat Research Team identified and analyzed an emerging ransomware family known as Orova. The sample is an ELF 64-bit binary targeting Linux servers and VMware ESXi hypervisors. This target has drawn growing attention from ransomware operators due to the concentrated value of virtual machine datastores. | Ransom blog | SonicWall |
|
5.9.26 |
The story behind the intelligence | From engaging with cybercriminals to surviving a live Flamin’ Hot Cheetos taste test, Hazel reflects on the latest Beers with Talos with Azim, where they cover the full spectrum of what it takes to gather threat intel. | Cyber blog | CISCO TALOS |
|
5.9.26 |
I’ve been deepfaked: What do I do? | Don’t panic if you spot an illegally created image or video of you online – there are ways to request its removal | Cyber blog | Eset |
|
5.9.26 |
This month in security with Tony Anscombe – August 2026 edition | Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news | Cyber blog | Eset |
|
5.9.26 |
The Bug Report – August 2026 Edition | This blog will walk through the complete kill chain: an attacker enumerates domain-wide SPNs, identifies a vulnerable user account, and silently requests a Kerberos Ticket Granting Service (TGS) ticket encrypted with the weak RC4-HMAC algorithm. | Vulnerebility blog | TRELLIX |
|
3.9.26 |
Mini Shai-Hulud's Latest Wave: 280 New Places | A new Mini Shai-Hulud wave hit keyv and 800+ npm packages. The malware now scans 469 secret locations, including AI agents, crypto wallets, and CI/CD tools. | Cryptocurrency blog | GITGUARDIAN |
|
3.9.26 |
Pegasus Spyware Infection of Serbian Pro-Democracy Student Activist | In collaboration with the SHARE Foundation, the Citizen Lab confirmed that the iPhone of a member of Serbia’s student protest movement was infected with Pegasus spyware. | BigBrother blog | CITIZENLAB |
|
3.9.26 |
Docker OIDC connections for GitHub Actions available for Docker Orgs | TL;DR: Docker now supports OpenID Connect (OIDC) for GitHub Actions. Your workflows can authenticate with short-lived, per-run tokens instead of stored PATs or OATs. No secrets to rotate, no credentials to leak. | Security blog | DOCKER |
|
3.9.26 |
Node.js: Old Technique Makes a Comeback | The trusted JavaScript runtime has featured in multiple attacks since February 2026, some linked to ransomware. In one case, attackers installed it from its official site to run an implant commanded via the Ethereum blockchain. | Hacking blog | SECURITY.COM |
|
3.9.26 |
EtherHiding: Blockchain Technology as a Cyber Weapon | In the cybercrime world, a strange cat and mouse game is continuously taking place. Cybersecurity researchers tirelessly hunt attackers' infrastructures. As soon as some of their components are discovered and brougth to light, they quickly become obsolete because of their addition on IOC's lists that strengthen cybersecurity equipments. This is why attackers must be able to constantly adapt themselves. | Hacking blog | STORMSHIELD |
|
3.9.26 |
EtherHiding Exposed: What Security Leaders Need to Know | Attackers have compromised the websites of at least 31 legitimate businesses, including e-commerce, professional services and retail logistics organizations. Visitors arriving to the compromised sites via search engine encounter a fake “Verify you’re human”. | Hacking blog | GUIDESECURITY |
|
3.9.26 |
FBI Investigates Nexus Claim of 153M+ ID Records | A Dark Web service called Nexus has claimed to offer access to more than 153 million driver’s license records from the United States and Canada, along with millions of other identity documents. The FBI has reportedly opened an investigation into the exposure. | Incident blog | SOCRADAR |
|
3.9.26 |
Kali365 phishing kit abuses Microsoft authentication | The Kali365 phishing kit epitomizes a major shift in phishing, from stealing passwords to abusing legitimate authentication processes. | Phishing blog | BARRACUDA |
|
3.9.26 |
The Outsider Phishing Kit: A Resilient Threat in the Face of Law Enforcement Action | This blog provides a deep-dive into the phishing kit created by Chenlun known as the Outsider Phishing Kit. It is a well established kit in the Chinese community with over 267 ready-made phishing templates targeting over 54 countries worldwide. | Phishing blog | GROUP-IB |
|
3.9.26 |
eSentire Wins 5 G2 Badges in the Fall 2026 Grid® Report | We are thrilled to share that eSentire has once again been recognized with multiple badges by G2 as part of their Fall 2026 Grid® Reports! The quarterly G2 Grid® Reports provide a high-level overview of the top leaders in any given product category, based on peer-to-peer feedback from real customers and market presence (based on market share, seller size, and social impact). | Security blog | ESENTIRE |
|
3.9.26 |
REVSTEALER ramps up: analysis of up-and-coming infostealer | REVSTEALER's credential harvesting reaches 225 browser extensions and 51 crypto wallets, its gaming session theft needs no password, and its backup C2 address sits on the Polygon blockchain waiting for the primary server to fail. | Malware blog | ELASTIC |
|
3.9.26 |
Linux Detection Engineering - Fileless Execution | We reproduced five Linux fileless execution patterns with FENIX, including memfd_create staging, interpreter one-liners, deleted binaries, and in-memory kernel module loads, then mapped each to the Elastic Defend rules that catch it. | OS Blog | ELASTIC |
|
3.9.26 |
Rogue ScreenConnect Installations Across Unrelated Hosts Suggest Worm-Like Activity | Huntress is observing the same anomalous pattern across unrelated endpoints in various organizations: rogue ScreenConnect clients repeatedly spawning wscript.exe to execute 1.vbs, 2.vbs, 3.vbs, and 4.vbs. | Malware blog | Huntress |
|
3.9.26 |
Release Notes: Faster TI Investigations & 650+ Threat Updates | Security teams need threat intelligence that helps them move quickly from a suspicious indicator to the context, evidence, and next action. ANY.RUN’s August updates focus on making that process faster and more practical, while expanding detection coverage across host, file, and network activity. | Security blog | ANYRUN BLOG |
|
3.9.26 |
Counterfeit installers to system compromise: Tracking a deceptive software download campaign | Microsoft Defender Experts is tracking an active malware campaign that uses counterfeit software-download websites to impersonate trusted vendors and distribute malicious installers. | Cyber blog | Microsoft blog |
|
3.9.26 |
Clop Never Left: Inside the PTC Windchill Data Theft Campaign | Patch CVE-2026-12569, but do not confuse patching with scoping. Hunt back to early June for hex-named JSP files in the Windchill codebase login directory, for flst.txt, and for the X-windchill-req header if you happen to log headers. | Cyber blog | SUCERONIX |
|
3.9.26 |
Langflow and Rails Exploitation Raises Credential Risks | Attackers are exploiting two separate critical vulnerabilities affecting Langflow and Ruby on Rails. CVE-2026-0768 allows unauthenticated attackers to execute Python code on affected Langflow deployments, while CVE-2026-66066 can expose files and application secrets through Rails Active Storage. | Vulnerebility blog | SOCRADAR |
|
3.9.26 |
Kim Sooki again? This time, it was disguised as a request for seafood ingredients | A request to review the purchase of seafood ingredients arrived. When the file is opened, a normal hwp document appears, but while the user is reviewing the contents, a malicious script runs in the background and even registers a scheduled task. | Hacking blog | AHNLAB |
|
3.9.26 |
“Evasive” Malware Attack Tactics: Hiding, Bypassing, and Reappearing | People who initially seem fine but tend to subtly avoid others as the relationship deepens or when conflicts arise—and who disappear when pressured—are commonly referred to as “avoidant types.” By repeatedly pulling away only to reappear, they drain the other person’s emotions and energy, ultimately undermining the relationship. | Malware blog | AHNLAB |
|
3.9.26 |
BlueKit PhaaS in the Wild: BitM, Geofencing, and ScreenConnect Post-Exploitation | The campaign did not stop at credential or session theft. After a BlueKit browser-in-the-middle flow, selected victims were moved into a fake document-viewer workflow that delivered a legitimate ScreenConnect client configured for an attacker-used ScreenConnect cloud instance. | Phishing blog | ZEROBEC BLOG |
|
2.9.26 |
Your Security Vendor May Not Be Telling You the Truth About Your MTTD – Here's Why | That would be inaccurate. The robbery did not start when the security guard called 911. It started when the attacker entered the building. Those first 45 minutes matter. They are the difference between understanding the full incident and reporting only the moment it becomes visible. | Security blog | RELIAQUEST |
|
2.9.26 |
Triage & Response Bottlenecks Eating into MSSP Margins: How to Remove the Friction | That gap shows up in triage and response first. Teams spend too much time checking IOCs, switching between tools, rebuilding context, and escalating cases that could have been closed earlier. Across thousands of investigations, those extra minutes turn into slower response, more pressure on Tier 2, and higher delivery costs. | Security blog | ANYRUN BLOG |
|
2.9.26 |
Major Cyber Attacks in August 2026: US and EU Businesses Hit by Session Hijacking, Remote Access, and Insider Risk | August’s attacks showed how quickly trusted business activity can turn into risk. Across the US and Europe, attackers abused Microsoft 365 sessions, legitimate remote-management tools, business-themed files, and even hiring processes to reach corporate systems. | Hacking blog | ANYRUN BLOG |
|
2.9.26 |
The Crypto Wallet That Never Opened: Tampered Exodus Installer Hides a Modular RAT | Between late July and mid August 2026, multiple Huntress-protected organizations were hit by the same modular RAT, three of which were hit within an 85-minute window. Victims were tricked into downloading a JavaScript file that quietly pulled down an installer for a real, working Exodus crypto wallet, with the RAT hidden inside. | Cryptocurrency blog | Huntress |
|
2.9.26 |
Daisy-Chaining Trust: Investigating Faronics Deploy Abuse | Threat actors are abusing Faronics Deploy, a legitimate endpoint management platform, to execute attacker-controlled PowerShell after phishing victims install the software. | Hacking blog | Huntress |
|
2.9.26 |
Proofpoint Sponsors the Insider Threat Matrix: Building a Common Language for Insider Risk | Today, Proofpoint is proud to sponsor the Insider Threat MatrixTM, an open, community-driven framework designed to help organizations better understand, detect, and investigate insider risk—both human and synthetic. | Cyber blog | PROOFPOINT |
|
2.9.26 |
Beyond Device Code Phishing: Preparing for the Next Wave of AI-Powered Attacks | Cybercriminals have always embraced new technologies to improve their effectiveness. Today, artificial intelligence has become another tool that can help threat actors operate faster and at greater scale. | Phishing blog | PROOFPOINT |
|
2.9.26 |
Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weapon | A Chinese-speaking actor is now targeting Brazil. Check Point Research has uncovered a sustained campaign against Brazilian organizations, primarily government and educational institutions since mid-2025. | APT blog | CHECKPOINT |
|
2.9.26 |
Uncovering StreamRat: From Meta Ads to Full Device Takeover | ThreatFabric researchers have uncovered StreamRat, a new Android banking trojan promoted to Spanish-speaking users through Meta and TikTok advertisements impersonating a free TV-streaming service, with the campaign reaching approximately 570,000 potential victims. | Malware blog | THREATFABRIC |
|
2.9.26 |
Can AI Create PLC Attacks? Yes, But It’s Not That Easy Yet | We used AI assistance to successfully port a remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) model to another. | ICS blog | FORESCOUT |