Cyber Security
Malicious npm Packages Bypass Install-Script Detection
Researchers Escape OpenAI Codex Sandbox, Compromise Staff Accounts
Single Browser Extension Hijacks AI Assistants Across Five Browsers
North Korean WaterPlum Stole $10.7M After Infecting 30,000 Devices
ShinyHunters Breaches Clop Ransomware Leak Site, Threatens Gang
Viral AI Actress Service Face-Scans Callers, Tracks Emotions
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
Thousands of Scam Apps Exploit Google Play Early Access Program
Four Nation-State Groups Deploy BlueMoon Kit Within 12 Days
NSA, CISA, FBI Accuse Six Chinese AI Firms of Model Distillation
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
Attackers Use BYOD Weaknesses to Access M365 via Graph API
Surfshark VPN Breach Exposes Internal Testing and Proxy Servers
Citrix NetScaler CVE-2026-19490 Exploited Since September 3
CISA Sets September 12 Deadline for Cisco, Citrix, Fortinet Flaws
Infostealer Logs Expose Replayable AI Tokens That Bypass MFA
Google Patches Seventh Chrome Zero-Day of 2026, CVE-2026-87491
PoisonedRefresh Rootkit Injects PHP Web Shells into F5 BIG-IP Memory
September Windows Server Updates Break Remote Desktop Services
Microsoft Excel KB5002914 Update Breaks Copy and Paste Functions
cPanel Critical RCE Enables Full Server Takeover via Mail Account
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
Microsoft Ships Record 974 Security Patches in September Batch
ShinyHunters Claims Breach of Florida DMV DAVID Database
Grindr Settles UK HIV Data Sharing Lawsuit for £26 Million
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
Application Security
Google Patches Seventh Chrome Zero-Day of 2026, CVE-2026-87491
Google released Chrome security update on September 9 patching CVE-2026-87491, an out-of-bounds write in V8 engine — the seventh actively exploited Chrome zero-day of 2026.
Application Security
PoisonedRefresh Rootkit Injects PHP Web Shells into F5 BIG-IP Memory
SophosLabs published analysis of PoisonedRefresh, a fileless Linux rootkit that injects PHP web shells directly into F5 BIG-IP APM Apache server memory, leaving no disk ...
Application Security
September Windows Server Updates Break Remote Desktop Services
Microsoft's September security updates cause Remote Desktop Services failures on Windows Server 2019, 2022, and 2025, with some systems requiring hard reset reported September 10.
Application Security
Microsoft Excel KB5002914 Update Breaks Copy and Paste Functions
Microsoft's KB5002914 Office security update breaks copy-and-paste operations and formula dragging in Excel, with affected users removing the update to restore functionality reported September 10.
Application Security
cPanel Critical RCE Enables Full Server Takeover via Mail Account
Critical cPanel vulnerability lets authenticated hosting account holders execute root-level code and take complete control of entire server infrastructure.
Application Security
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
SAP released patches for CVE-2026-44756, a maximum-severity memory corruption flaw enabling unauthenticated remote code execution in SAP kernel systems.
Application Security
Microsoft Ships Record 974 Security Patches in September Batch
Microsoft's September Patch Tuesday delivered 974 security fixes—the largest single batch ever—driven partly by AI-assisted vulnerability discovery tools.
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
ShinyHunters extortion gang claims theft of over 200,000 driver records from Florida DMV's DAVID online platform. No official confirmation yet from the state.
Cybersecurity
Grindr Settles UK HIV Data Sharing Lawsuit for £26 Million
Grindr will pay £26 million to settle UK lawsuit over sharing users' HIV status and sensitive personal data with third parties for commercial purposes.
Cybersecurity
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
Hackers who stole nearly 4,000 bitcoin from Liquid Network returned 3,400 BTC but kept 598.5 bitcoin worth $47 million. Network remains paused pending fix.
Cybersecurity
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
Security researchers disclosed a vulnerability in OpenAI's Artifactory enabling unauthorized cross-account artifact access and covert data exfiltration.
Cybersecurity
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
Boston Scientific disclosed that an August cyberattack will materially impact Q3 and full-year sales and earnings. Recovery is taking longer than expected.
Cybersecurity
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
Federal prosecutors secured a 15-year prison sentence for an Ohio man who created deepfake pornographic videos to extort victims in sextortion campaign.
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
LG faces allegations of egregious privacy invasion over smart TV data collection practices, following earlier scrutiny over monitors installing adware.
Cybersecurity
Microsoft Adds Age-Awareness APIs to Windows 11
Microsoft announced age-awareness APIs for Windows 11, enabling apps to classify users as children, teenagers, or adults while raising profiling concerns.
Cybersecurity
EU Cyber Resilience Act 24-Hour Vulnerability Deadline Arrives
EU Cyber Resilience Act enforcement begins Sept 11, requiring software vendors to report actively exploited vulnerabilities within 24 hours of discovery.
Cybersecurity
UK Lawmakers Question Cyber Bill’s Executive Liability Exemption
UK House of Lords peers questioned why proposed cyber bill exempts executives from personal liability despite £17M corporate fines for cyber failures.
Cybersecurity
Welsh Regulator Exposes 2,000 Staff Diversity Records via FoI Error
Natural Resources Wales accidentally exposed diversity data for 2,000 employees via Freedom of Information error in 2021 but delayed disclosure five years.
Cybersecurity
OpenAI Agent Swarm Logs Reveal Emergent Deception and Coordination
Logs from OpenAI's experimental agent swarm called The Collective show emergent behaviors including coordinated deception, rule-breaking, and agent sacrifice.
Application Security
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Researchers disclosed PEEP, a toolkit that hijacks Chrome and Edge browsers as backdoors by injecting malicious extensions that execute host commands.
Issabel Framework Flaw Enables Unauthenticated OS Command Execution
CVE Vulnerability Alerts
Issabel Framework Flaw Enables Unauthenticated OS Command Execution
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
Cybersecurity
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
Application Security
GoldFactory and Mantax Otax Target Indonesian Android Bank Users

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
Viral AI Actress Service Face-Scans Callers, Tracks Emotions
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Microsoft Excel KB5002914 Update Breaks Copy and Paste Functions
Microsoft's KB5002914 Office security update breaks copy-and-paste operations and formula dragging in Excel, with affected users removing the update to restore functionality reported September 10.
cPanel Critical RCE Enables Full Server Takeover via Mail Account
Critical cPanel vulnerability lets authenticated hosting account holders execute root-level code and take complete control of entire server infrastructure.
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
SAP released patches for CVE-2026-44756, a maximum-severity memory corruption flaw enabling unauthenticated remote code execution in SAP kernel systems.
Microsoft Ships Record 974 Security Patches in September Batch
Microsoft's September Patch Tuesday delivered 974 security fixes—the largest single batch ever—driven partly by AI-assisted vulnerability discovery tools.
ShinyHunters Claims Breach of Florida DMV DAVID Database
ShinyHunters extortion gang claims theft of over 200,000 driver records from Florida DMV's DAVID online platform. No official confirmation yet from the state.
Grindr Settles UK HIV Data Sharing Lawsuit for £26 Million
Grindr will pay £26 million to settle UK lawsuit over sharing users' HIV status and sensitive personal data with third parties for commercial purposes.
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
Hackers who stole nearly 4,000 bitcoin from Liquid Network returned 3,400 BTC but kept 598.5 bitcoin worth $47 million. Network remains paused pending fix.
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
Security researchers disclosed a vulnerability in OpenAI's Artifactory enabling unauthorized cross-account artifact access and covert data exfiltration.
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
Boston Scientific disclosed that an August cyberattack will materially impact Q3 and full-year sales and earnings. Recovery is taking longer than expected.
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
Federal prosecutors secured a 15-year prison sentence for an Ohio man who created deepfake pornographic videos to extort victims in sextortion campaign.
LG Accused of Privacy Violations Over Smart TV Data Collection
LG faces allegations of egregious privacy invasion over smart TV data collection practices, following earlier scrutiny over monitors installing adware.
Microsoft Adds Age-Awareness APIs to Windows 11
Microsoft announced age-awareness APIs for Windows 11, enabling apps to classify users as children, teenagers, or adults while raising profiling concerns.
EU Cyber Resilience Act 24-Hour Vulnerability Deadline Arrives
EU Cyber Resilience Act enforcement begins Sept 11, requiring software vendors to report actively exploited vulnerabilities within 24 hours of discovery.
UK Lawmakers Question Cyber Bill’s Executive Liability Exemption
UK House of Lords peers questioned why proposed cyber bill exempts executives from personal liability despite £17M corporate fines for cyber failures.
Welsh Regulator Exposes 2,000 Staff Diversity Records via FoI Error
Natural Resources Wales accidentally exposed diversity data for 2,000 employees via Freedom of Information error in 2021 but delayed disclosure five years.
OpenAI Agent Swarm Logs Reveal Emergent Deception and Coordination
Logs from OpenAI's experimental agent swarm called The Collective show emergent behaviors including coordinated deception, rule-breaking, and agent sacrifice.
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Researchers disclosed PEEP, a toolkit that hijacks Chrome and Edge browsers as backdoors by injecting malicious extensions that execute host commands.
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
Zero-day StyleSmuggler flaw enables code execution on all Magento and Adobe Commerce versions. Attackers deploy Linux backdoors on e-commerce sites.
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
Attackers breached Mathspace's Metabase internal reporting system, stealing data from more than 1 million students, staff, and parents at the math platform.
Attackers Chain MikroTik Flaws to Hijack Internet-Exposed SSH
Hackers are exploiting two chained MikroTik RouterOS vulnerabilities to take full control of routers with SSH services exposed to the public internet.