Cyber Security
Application Security
Microsoft Ships Record 974 Security Patches in September Batch
Andrew Doyle
September 9, 2026
Microsoft's September Patch Tuesday delivered 974 security fixes—the largest single batch ever—driven partly by AI-assisted vulnerability discovery tools.
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Mitchell Langley
September 9, 2026
ShinyHunters extortion gang claims theft of over 200,000 driver records from Florida DMV's DAVID online platform. No official confirmation yet from the state.
Cybersecurity
Grindr Settles UK HIV Data Sharing Lawsuit for £26 Million
Mitchell Langley
September 9, 2026
Grindr will pay £26 million to settle UK lawsuit over sharing users' HIV status and sensitive personal data with third parties for commercial purposes.
Cybersecurity
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
Andrew Doyle
September 9, 2026
Hackers who stole nearly 4,000 bitcoin from Liquid Network returned 3,400 BTC but kept 598.5 bitcoin worth $47 million. Network remains paused pending fix.
Cybersecurity
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
Gabby Lee
September 9, 2026
Security researchers disclosed a vulnerability in OpenAI's Artifactory enabling unauthorized cross-account artifact access and covert data exfiltration.
Cybersecurity
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
Mitchell Langley
September 9, 2026
Boston Scientific disclosed that an August cyberattack will materially impact Q3 and full-year sales and earnings. Recovery is taking longer than expected.
Cybersecurity
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
Andrew Doyle
September 9, 2026
Federal prosecutors secured a 15-year prison sentence for an Ohio man who created deepfake pornographic videos to extort victims in sextortion campaign.
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Mitchell Langley
September 9, 2026
LG faces allegations of egregious privacy invasion over smart TV data collection practices, following earlier scrutiny over monitors installing adware.
Cybersecurity
Microsoft Adds Age-Awareness APIs to Windows 11
Andrew Doyle
September 9, 2026
Microsoft announced age-awareness APIs for Windows 11, enabling apps to classify users as children, teenagers, or adults while raising profiling concerns.
Cybersecurity
EU Cyber Resilience Act 24-Hour Vulnerability Deadline Arrives
Mitchell Langley
September 9, 2026
EU Cyber Resilience Act enforcement begins Sept 11, requiring software vendors to report actively exploited vulnerabilities within 24 hours of discovery.
Cybersecurity
UK Lawmakers Question Cyber Bill’s Executive Liability Exemption
Gabby Lee
September 9, 2026
UK House of Lords peers questioned why proposed cyber bill exempts executives from personal liability despite £17M corporate fines for cyber failures.
Cybersecurity
Welsh Regulator Exposes 2,000 Staff Diversity Records via FoI Error
Mitchell Langley
September 9, 2026
Natural Resources Wales accidentally exposed diversity data for 2,000 employees via Freedom of Information error in 2021 but delayed disclosure five years.
Cybersecurity
OpenAI Agent Swarm Logs Reveal Emergent Deception and Coordination
Andrew Doyle
September 9, 2026
Logs from OpenAI's experimental agent swarm called The Collective show emergent behaviors including coordinated deception, rule-breaking, and agent sacrifice.
Application Security
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Andrew Doyle
September 8, 2026
Researchers disclosed PEEP, a toolkit that hijacks Chrome and Edge browsers as backdoors by injecting malicious extensions that execute host commands.
Application Security
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
Gabby Lee
September 8, 2026
Zero-day StyleSmuggler flaw enables code execution on all Magento and Adobe Commerce versions. Attackers deploy Linux backdoors on e-commerce sites.
Application Security
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
Andrew Doyle
September 8, 2026
Attackers breached Mathspace's Metabase internal reporting system, stealing data from more than 1 million students, staff, and parents at the math platform.
Application Security
Attackers Chain MikroTik Flaws to Hijack Internet-Exposed SSH
Mitchell Langley
September 8, 2026
Hackers are exploiting two chained MikroTik RouterOS vulnerabilities to take full control of routers with SSH services exposed to the public internet.
Application Security
Nightmare Eclipse Drops Zero-Days for CrowdStrike, Nvidia, Avast
Mitchell Langley
September 8, 2026
Security researcher Nightmare Eclipse publicly released proof-of-concept zero-day exploits for CrowdStrike, Nvidia, and Avast that escalate to System privileges.
Application Security
North Korean Hackers Backdoor HAProxy in Linux Espionage Campaign
Gabby Lee
September 8, 2026
North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors in HAProxy load balancers.
Application Security
Backdoored ScreenConnect Servers Deliver Worm-Like Payloads
Mitchell Langley
September 8, 2026
Attackers compromised ConnectWise ScreenConnect servers to automatically deliver malicious payloads to newly connected clients in a self-propagating campaign.
Application Security
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
Mitchell Langley
September 23, 2026
Application Security
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
Mitchell Langley
September 23, 2026
Application Security
Malicious npm Package indexed-btree Hides Payload in Runtime Code
Gabby Lee
September 23, 2026
Cybersecurity
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
Gabby Lee
September 21, 2026
TOP CYBERSECURITY HEADLINES
Application Security
Microsoft Seizes 50 EvilTokens Phishing Sites, UK Arrests 2
Application Security
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
Application Security
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Application Security
Arista VeloCloud CVSS 10.0 Flaw Under Active Exploitation
This Week’s Security Spotlight
Application Security
Fake LastPass Authenticator Uses Signed Driver to Disable EDR
Gabby Lee
September 23, 2026
Cybersecurity
Viral AI Actress Service Face-Scans Callers, Tracks Emotions
Gabby Lee
September 21, 2026
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Andrew Doyle
September 11, 2026
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Mitchell Langley
September 9, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
September 9, 2026
Hackers who stole nearly 4,000 bitcoin from Liquid Network returned 3,400 BTC but kept 598.5 bitcoin worth $47 million. Network remains paused pending fix.
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
September 9, 2026
Security researchers disclosed a vulnerability in OpenAI's Artifactory enabling unauthorized cross-account artifact access and covert data exfiltration.
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
September 9, 2026
Boston Scientific disclosed that an August cyberattack will materially impact Q3 and full-year sales and earnings. Recovery is taking longer than expected.
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
September 9, 2026
Federal prosecutors secured a 15-year prison sentence for an Ohio man who created deepfake pornographic videos to extort victims in sextortion campaign.
LG Accused of Privacy Violations Over Smart TV Data Collection
September 9, 2026
LG faces allegations of egregious privacy invasion over smart TV data collection practices, following earlier scrutiny over monitors installing adware.
Microsoft Adds Age-Awareness APIs to Windows 11
September 9, 2026
Microsoft announced age-awareness APIs for Windows 11, enabling apps to classify users as children, teenagers, or adults while raising profiling concerns.
EU Cyber Resilience Act 24-Hour Vulnerability Deadline Arrives
September 9, 2026
EU Cyber Resilience Act enforcement begins Sept 11, requiring software vendors to report actively exploited vulnerabilities within 24 hours of discovery.
UK Lawmakers Question Cyber Bill’s Executive Liability Exemption
September 9, 2026
UK House of Lords peers questioned why proposed cyber bill exempts executives from personal liability despite £17M corporate fines for cyber failures.
Welsh Regulator Exposes 2,000 Staff Diversity Records via FoI Error
September 9, 2026
Natural Resources Wales accidentally exposed diversity data for 2,000 employees via Freedom of Information error in 2021 but delayed disclosure five years.
OpenAI Agent Swarm Logs Reveal Emergent Deception and Coordination
September 9, 2026
Logs from OpenAI's experimental agent swarm called The Collective show emergent behaviors including coordinated deception, rule-breaking, and agent sacrifice.
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
September 8, 2026
Researchers disclosed PEEP, a toolkit that hijacks Chrome and Edge browsers as backdoors by injecting malicious extensions that execute host commands.
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
September 8, 2026
Zero-day StyleSmuggler flaw enables code execution on all Magento and Adobe Commerce versions. Attackers deploy Linux backdoors on e-commerce sites.
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
September 8, 2026
Attackers breached Mathspace's Metabase internal reporting system, stealing data from more than 1 million students, staff, and parents at the math platform.
Attackers Chain MikroTik Flaws to Hijack Internet-Exposed SSH
September 8, 2026
Hackers are exploiting two chained MikroTik RouterOS vulnerabilities to take full control of routers with SSH services exposed to the public internet.
Nightmare Eclipse Drops Zero-Days for CrowdStrike, Nvidia, Avast
September 8, 2026
Security researcher Nightmare Eclipse publicly released proof-of-concept zero-day exploits for CrowdStrike, Nvidia, and Avast that escalate to System privileges.
North Korean Hackers Backdoor HAProxy in Linux Espionage Campaign
September 8, 2026
North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors in HAProxy load balancers.
Backdoored ScreenConnect Servers Deliver Worm-Like Payloads
September 8, 2026
Attackers compromised ConnectWise ScreenConnect servers to automatically deliver malicious payloads to newly connected clients in a self-propagating campaign.
BigBear Phishing Service Bypassed MFA at 258 Organizations
September 8, 2026
BigBear 2.0 phishing-as-a-service framework stole over 5,000 Microsoft 365 credentials from 258 organizations using adversary-in-the-middle attacks.
ConnectWise Discloses Unpatched ScreenConnect Flaw
September 8, 2026
ConnectWise disclosed a new ScreenConnect vulnerability with no patch available. The vendor shared temporary mitigations and plans a fix this week.
JSCeal Malware Bypasses Google Auth with Stolen Session Cookies
September 8, 2026
Check Point Research discovered JSCeal malware that harvests credentials and bypasses Google authentication using stolen session cookies on Windows.


































