Cyber Security
Application Security
cPanel Critical RCE Enables Full Server Takeover via Mail Account
Andrew Doyle
September 9, 2026
Critical cPanel vulnerability lets authenticated hosting account holders execute root-level code and take complete control of entire server infrastructure.
Application Security
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
Andrew Doyle
September 9, 2026
SAP released patches for CVE-2026-44756, a maximum-severity memory corruption flaw enabling unauthenticated remote code execution in SAP kernel systems.
Application Security
Microsoft Ships Record 974 Security Patches in September Batch
Andrew Doyle
September 9, 2026
Microsoft's September Patch Tuesday delivered 974 security fixes—the largest single batch ever—driven partly by AI-assisted vulnerability discovery tools.
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Mitchell Langley
September 9, 2026
ShinyHunters extortion gang claims theft of over 200,000 driver records from Florida DMV's DAVID online platform. No official confirmation yet from the state.
Cybersecurity
Grindr Settles UK HIV Data Sharing Lawsuit for £26 Million
Mitchell Langley
September 9, 2026
Grindr will pay £26 million to settle UK lawsuit over sharing users' HIV status and sensitive personal data with third parties for commercial purposes.
Cybersecurity
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
Andrew Doyle
September 9, 2026
Hackers who stole nearly 4,000 bitcoin from Liquid Network returned 3,400 BTC but kept 598.5 bitcoin worth $47 million. Network remains paused pending fix.
Cybersecurity
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
Gabby Lee
September 9, 2026
Security researchers disclosed a vulnerability in OpenAI's Artifactory enabling unauthorized cross-account artifact access and covert data exfiltration.
Cybersecurity
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
Mitchell Langley
September 9, 2026
Boston Scientific disclosed that an August cyberattack will materially impact Q3 and full-year sales and earnings. Recovery is taking longer than expected.
Cybersecurity
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
Andrew Doyle
September 9, 2026
Federal prosecutors secured a 15-year prison sentence for an Ohio man who created deepfake pornographic videos to extort victims in sextortion campaign.
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Mitchell Langley
September 9, 2026
LG faces allegations of egregious privacy invasion over smart TV data collection practices, following earlier scrutiny over monitors installing adware.
Cybersecurity
Microsoft Adds Age-Awareness APIs to Windows 11
Andrew Doyle
September 9, 2026
Microsoft announced age-awareness APIs for Windows 11, enabling apps to classify users as children, teenagers, or adults while raising profiling concerns.
Cybersecurity
EU Cyber Resilience Act 24-Hour Vulnerability Deadline Arrives
Mitchell Langley
September 9, 2026
EU Cyber Resilience Act enforcement begins Sept 11, requiring software vendors to report actively exploited vulnerabilities within 24 hours of discovery.
Cybersecurity
UK Lawmakers Question Cyber Bill’s Executive Liability Exemption
Gabby Lee
September 9, 2026
UK House of Lords peers questioned why proposed cyber bill exempts executives from personal liability despite £17M corporate fines for cyber failures.
Cybersecurity
Welsh Regulator Exposes 2,000 Staff Diversity Records via FoI Error
Mitchell Langley
September 9, 2026
Natural Resources Wales accidentally exposed diversity data for 2,000 employees via Freedom of Information error in 2021 but delayed disclosure five years.
Cybersecurity
OpenAI Agent Swarm Logs Reveal Emergent Deception and Coordination
Andrew Doyle
September 9, 2026
Logs from OpenAI's experimental agent swarm called The Collective show emergent behaviors including coordinated deception, rule-breaking, and agent sacrifice.
Application Security
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Andrew Doyle
September 8, 2026
Researchers disclosed PEEP, a toolkit that hijacks Chrome and Edge browsers as backdoors by injecting malicious extensions that execute host commands.
Application Security
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
Gabby Lee
September 8, 2026
Zero-day StyleSmuggler flaw enables code execution on all Magento and Adobe Commerce versions. Attackers deploy Linux backdoors on e-commerce sites.
Application Security
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
Andrew Doyle
September 8, 2026
Attackers breached Mathspace's Metabase internal reporting system, stealing data from more than 1 million students, staff, and parents at the math platform.
Application Security
Attackers Chain MikroTik Flaws to Hijack Internet-Exposed SSH
Mitchell Langley
September 8, 2026
Hackers are exploiting two chained MikroTik RouterOS vulnerabilities to take full control of routers with SSH services exposed to the public internet.
Application Security
Nightmare Eclipse Drops Zero-Days for CrowdStrike, Nvidia, Avast
Mitchell Langley
September 8, 2026
Security researcher Nightmare Eclipse publicly released proof-of-concept zero-day exploits for CrowdStrike, Nvidia, and Avast that escalate to System privileges.
Application Security
cPanel Critical RCE Enables Full Server Takeover via Mail Account
Andrew Doyle
September 9, 2026
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Mitchell Langley
September 9, 2026
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Andrew Doyle
September 2, 2026
Cybersecurity
Boston Scientific Cyberattack Disrupts Manufacturing and Shipping
Gabby Lee
September 2, 2026
TOP CYBERSECURITY HEADLINES
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Cybersecurity
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
This Week’s Security Spotlight
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Mitchell Langley
September 9, 2026
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
Mitchell Langley
September 8, 2026
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Gabby Lee
September 1, 2026
Application Security
AI Research Org METR Loses $600K in Credits to Dual Breach Attacks
Mitchell Langley
September 1, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
ShinyHunters Claims Breach of Florida DMV DAVID Database
September 9, 2026
ShinyHunters extortion gang claims theft of over 200,000 driver records from Florida DMV's DAVID online platform. No official confirmation yet from the state.
Grindr Settles UK HIV Data Sharing Lawsuit for £26 Million
September 9, 2026
Grindr will pay £26 million to settle UK lawsuit over sharing users' HIV status and sensitive personal data with third parties for commercial purposes.
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
September 9, 2026
Hackers who stole nearly 4,000 bitcoin from Liquid Network returned 3,400 BTC but kept 598.5 bitcoin worth $47 million. Network remains paused pending fix.
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
September 9, 2026
Security researchers disclosed a vulnerability in OpenAI's Artifactory enabling unauthorized cross-account artifact access and covert data exfiltration.
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
September 9, 2026
Boston Scientific disclosed that an August cyberattack will materially impact Q3 and full-year sales and earnings. Recovery is taking longer than expected.
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
September 9, 2026
Federal prosecutors secured a 15-year prison sentence for an Ohio man who created deepfake pornographic videos to extort victims in sextortion campaign.
LG Accused of Privacy Violations Over Smart TV Data Collection
September 9, 2026
LG faces allegations of egregious privacy invasion over smart TV data collection practices, following earlier scrutiny over monitors installing adware.
Microsoft Adds Age-Awareness APIs to Windows 11
September 9, 2026
Microsoft announced age-awareness APIs for Windows 11, enabling apps to classify users as children, teenagers, or adults while raising profiling concerns.
EU Cyber Resilience Act 24-Hour Vulnerability Deadline Arrives
September 9, 2026
EU Cyber Resilience Act enforcement begins Sept 11, requiring software vendors to report actively exploited vulnerabilities within 24 hours of discovery.
UK Lawmakers Question Cyber Bill’s Executive Liability Exemption
September 9, 2026
UK House of Lords peers questioned why proposed cyber bill exempts executives from personal liability despite £17M corporate fines for cyber failures.
Welsh Regulator Exposes 2,000 Staff Diversity Records via FoI Error
September 9, 2026
Natural Resources Wales accidentally exposed diversity data for 2,000 employees via Freedom of Information error in 2021 but delayed disclosure five years.
OpenAI Agent Swarm Logs Reveal Emergent Deception and Coordination
September 9, 2026
Logs from OpenAI's experimental agent swarm called The Collective show emergent behaviors including coordinated deception, rule-breaking, and agent sacrifice.
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
September 8, 2026
Researchers disclosed PEEP, a toolkit that hijacks Chrome and Edge browsers as backdoors by injecting malicious extensions that execute host commands.
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
September 8, 2026
Zero-day StyleSmuggler flaw enables code execution on all Magento and Adobe Commerce versions. Attackers deploy Linux backdoors on e-commerce sites.
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
September 8, 2026
Attackers breached Mathspace's Metabase internal reporting system, stealing data from more than 1 million students, staff, and parents at the math platform.
Attackers Chain MikroTik Flaws to Hijack Internet-Exposed SSH
September 8, 2026
Hackers are exploiting two chained MikroTik RouterOS vulnerabilities to take full control of routers with SSH services exposed to the public internet.
Nightmare Eclipse Drops Zero-Days for CrowdStrike, Nvidia, Avast
September 8, 2026
Security researcher Nightmare Eclipse publicly released proof-of-concept zero-day exploits for CrowdStrike, Nvidia, and Avast that escalate to System privileges.
North Korean Hackers Backdoor HAProxy in Linux Espionage Campaign
September 8, 2026
North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors in HAProxy load balancers.
Backdoored ScreenConnect Servers Deliver Worm-Like Payloads
September 8, 2026
Attackers compromised ConnectWise ScreenConnect servers to automatically deliver malicious payloads to newly connected clients in a self-propagating campaign.
BigBear Phishing Service Bypassed MFA at 258 Organizations
September 8, 2026
BigBear 2.0 phishing-as-a-service framework stole over 5,000 Microsoft 365 credentials from 258 organizations using adversary-in-the-middle attacks.

























