What's happening in security
Breaches, credential dumps, actively exploited bugs and AI incidents — pulled from 2,897 items across public feeds, Have I Been Pwned and CISA KEV.
Biggest this week
- Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) — Help Net Security, 1h ago
- Google fixes actively exploited Android zero-day on Pixel devices — BleepingComputer, 1d ago
- Cisco warns customers of actively exploited zero-day in email gateways — CyberScoop, 1d ago
- Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) — Help Net Security, 2d ago
- Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day — SecurityWeek, 5h ago
-
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
-
[Virtual Event] Building a Secure AI Strategy for the Enterprise
-
FBI takes down one of the longest-running DDoS-for-hire services
The FBI has seized the domains behind NightmareStresser, a DDoS-for-hire service officials call one of the longest running booter operations in existence. The domain seizure notice (Source: US Department of Justice) Booter service…
-
US takes down NightmareStresser DDoS-for-hire platform
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. [...]
-
How Candidates Could Use AI for Good
This essay was written with Nathan E. Sanders, and originally appeared in The Guardian . There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI s impacts …
-
Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)
Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE)…
-
Scammers leave AI fingerprints all over fake antivirus renewal page
AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page impersonating Avast, aimed at users in Belgium, that wa…
-
Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use
Ransomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital …
-
America’s cyber strategy overlooks the infrastructure that actually keeps the military moving
Ports, railroads, and utilities keep the military operational. They're all vulnerable to Iranian cyberattacks. The post America s cyber strategy overlooks the infrastructure that actually keeps the military moving appeared first o…
-
Hackers reveal how Flock cameras really track cars and people
One hacked camera captured 1.6 million images and could detect people as well as cars.
-
Chinese hackers use SparroWocky malware in govt espionage attacks
The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...]
-
Flock Once Touted Its Cameras as ‘Made in the USA.’ Now It’s Not So Clear
Flock reveals little about where its license plate readers are assembled, but the answer could have geopolitical and cybersecurity implications.
-
The Karavshin roller coaster: a kilometer up, a kilometer down.
Our rambling along the Karavshin route in Kyrgyzstan continues… Next up for us was a three-day out-and-back leg toward some seriously contemplative views in the gorge that goes by the same name – Karavshin – plus the Asan-Usen gla…
-
Spain reports first data breach involving autonomous AI agent
Spain s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a company s network, found a way to alter personal records, and pulled in…
-
Microsoft shares workaround for Windows domain login issues
Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]
-
Fake AI trading agent steals crypto wallet passwords
Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign…
-
CISA Releases Guidance on Deploying Cyber Decoys
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Guidance on Deploying Cyber Decoys appeared first on SecurityWeek .
-
AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared f…
-
Cisco warns of max severity ISE zero-day exploited in attacks
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
-
Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek .
-
Riverbed NPM 360 uses AI to predict and prevent network disruptions
Riverbed has announced new Riverbed intelligent network observability solutions that combine 360-degree network visibility with agentic AI to help network operations teams accelerate troubleshooting, identify root causes, predict …
-
Tuskira Vector brings autonomous red teaming to attack surface validation
Tuskira has announced Vector, its autonomous red teaming agentic capability, which identifies an organization s exploitable attack surface by simulating what an attacker can do from outside it. Tuskira validates every external fin…
-
The AI security question leaders should be asking instead
In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and wh…
-
A flat cybersecurity budget doesn’t have to mean weaker coverage
Cheri Hotman, Managing Partner of Hotman Group, works as a vCISO and vGRC leader. In this Help Net Security video, she talks about holding coverage steady when the CFO asks for a flat budget or a 12% cut. Her advice is to stop tri…
-
AWS’s new sign-up gives accounts spend caps, email invites, and agent-set permissions
New AWS customers can now sign up with a Google, GitHub, or Apple login, start with $100 in Free Tier credits, and build inside a project where AWS and coding agents set up permissions automatically. Paid projects get a monthly sp…
-
GNOME 51 adds passkey logins, offline maps and drawn PDF signatures
GNOME 51, the new version of the Linux desktop, came out on September 16 under the codename A Coruña. The release adds offline maps and live transit information to Maps, new login options at the login screen, hand-drawn signatures…
-
AI is adding to the review load on open-source projects, many of them thinly funded
AI coding tools are making open source software harder to maintain and secure, according to six authors writing for the Association for Computing Machinery s Technology Policy Council, among them Simson Garfinkel and Josiah Dykstr…
-
The world must establish red lines for autonomous AI weapons
AI is transforming warfare and international conflict. Autonomous weapon systems pose a genuine threat to civilians. The war in Ukraine has become a proving ground for weapons that can navigate, identify targets, resist electronic…
-
Anthropic wants Claude to analyze your bank account and financial data
Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]
-
Whoa. I explored the site a bit more. They’re trying to sell licenses to this AI slop. Whaaaaat
Whoa. I explored the site a bit more. They’re trying to sell licenses to this AI slop. Whaaaaat
-
datasette 1.0a40
Release: datasette 1.0a40 Same security fix as 0.65.5 , plus some neat new features and bug fixes: Plugins can now launch and manage background tasks using the new datasette.add_background_task() method. Thanks, Alex Garcia . I've…
-
datasette 0.65.5
Release: datasette 0.65.5 Security fix for an issue where a trailing newline in a requested table name could bypass table permissions and expose private rows, reported by dpfkdlemtp in GHSA-h547-rmjf-5m2m . Tags: security , datase…
-
A Fortinet flaw that entered the exploited catalog on September 9 had carried its identifier since February 20…
A Fortinet flaw that entered the exploited catalog on September 9 had carried its identifier since February 2025. A ha! A Fortinet flaw! We’re talking about vulnerabilities! Finally, a shred of context. The Fortinet vulnerability …
-
OKAY. Next paragraph. SC-2026-006 · Exploitation Precedes Defender Awareness: rating under review after the cr…
OKAY. Next paragraph. SC-2026-006 · Exploitation Precedes Defender Awareness: rating under review after the criterion supporting this cycle's scheduled upgrade failed construct validation. The upgrade action is voided. Prior state…
-
Let’s break down this first paragraph. CHQ maintains ratings on a standing set of structural security conditio…
Let’s break down this first paragraph. CHQ maintains ratings on a standing set of structural security conditions. CHQ is the website. Okay. What is a standing set of structural security conditions? I have no idea. Why does the set…
-
I’m not sure how I ended up on the mailing list, but this is a shining jewel in my collection of “reasons why …
I’m not sure how I ended up on the mailing list, but this is a shining jewel in my collection of “reasons why you should not let AI do your writing”. It is breathtakingly unreadable. Even the title is unintelligible. https:// disp…
-
Smashing Security podcast #485: These researchers got drunk to hack an LG TV
Researchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, …
-
Victory! Appeals Court Rejects Expansive New Copyright Claim
The U.S. Court of Appeals for the Ninth Circuit handed internet users and programmers a big win today, by rejecting an attempt to stretch a narrow provision of the Digital Millennium Copyright Act (DMCA) into a new source of copyr…
-
AI Security Spending Jumps as Fear Outpaces Proof of Value
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?
-
Nonprofit that tracks meteors taken down by "critical blow" from a cyberattack
Group plans to be largely out of commission for several weeks.
-
Key lawmaker suggests action on AI safety legislation will wait until 2027
“It's really complicated, and I wouldn't want to do something in a lame duck session to do it quickly and not get it right,” said House Energy and Commerce Chairman Brett Guthrie about the FRONTIER Act.
-
Windows 11 KB5124008 update breaks domain trust for some users
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]
-
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]
-
Booz Allen is the latest to get into AI cybersecurity benchmarks. I checked them out and share my thoughts. Sa…
Booz Allen is the latest to get into AI cybersecurity benchmarks. I checked them out and share my thoughts. Sanity check: benchmarks != real world capabilities, but they do give us a data point we can use to measure AI model chang…
-
CISA promotes a fresh way to deter cyberattackers: Lie to them
It’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries. The post CISA promotes a fresh way to deter cyberattackers: Lie to them app…
-
Friend and repeat BSides Knoxville speaker Chris Craig delighted me with his presentation, titled Stacking the…
Friend and repeat BSides Knoxville speaker Chris Craig delighted me with his presentation, titled Stacking the Deck . It was not only chock full of useful, actionable information on how to use AI for offensive security and how he …
-
My friend and mentor, @ wendynather , keynoted the event and also sat front row for my talk - always lovely to…
My friend and mentor, @ wendynather , keynoted the event and also sat front row for my talk - always lovely to have support in the front row! Her keynote, Brother can you spare a token explores how AI affects the security poverty …
-
Malware bypasses browser checks to force install Chrome, Edge extensions
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]
-
Coast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’
U.S. personnel boarded an oil tanker in the Gulf of Mexico to “ensure integrity of the vessel’s operational and information technology systems," after an apparent cyberattack, the U.S. Coast Guard said.
-
House passes bill to equip local law enforcement with scam-fighting tools
The Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal inves…
Last fetch 18m ago · 2 new · 2 source error(s)