Cyber Security
Ransomware Attack Disrupts Keio Corporation Business Systems
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure
Dutch Police Arrest ShinyHunters Member in Amsterdam Operation
Over 16,000 Supabase Databases Exposed Due to Misconfiguration
NeedyMantis Malware Maintains Long-Term Access in Targeted Intrusions
Bitget Attributes $388M Theft to Third-Party Security Product Flaw
RatHat Android Trojan Uses Gemini AI to Identify High-Value Victims
Infostealer Logs Expose AI Credentials from 80,000+ Organizations
Former US Soldier Gets 70 Months for Hacking AT&T and Verizon
Carbonato Botnet Hijacks Docker Hosts to Deploy Telegram-Controlled AI
DC Health Agency Exposes 400,000 Medicaid Beneficiary Records Online
Suspected North Korean Hackers Steal $351.6M from Bitget Exchange
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
Cloudflare Containers Flaw Exposed Leftover Customer Disk Data
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
AI Agents Power Mass Attack Stealing 600K Credit Cards from Retailers
MacSync Malware Variant Uses iCloud Calendars for Command and Control
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Unpatched OnePlus Flaws Allow Malicious Apps to Gain Root Access
Ransomware Gangs Exploit Critical TeamCity Flaw Patched in July
OpenAI Agent Bypassed Access Controls on Australian Medicare Portal
WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities
Carbonato Botnet Uses AI Agents to Hijack Exposed Docker Hosts
GitLab Issue Email Addresses Function as Leaked Credentials
TeamFiltration Campaign Compromises 7 M365 Accounts in Chile
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
Check Point Zero-Day Exploited in July, Patched September 22
Malicious npm Package Impersonates Twilio Security Probe Tool
Cybersecurity
UK Lawmakers Question Cyber Bill’s Executive Liability Exemption
UK House of Lords peers questioned why proposed cyber bill exempts executives from personal liability despite £17M corporate fines for cyber failures.
Cybersecurity
Welsh Regulator Exposes 2,000 Staff Diversity Records via FoI Error
Natural Resources Wales accidentally exposed diversity data for 2,000 employees via Freedom of Information error in 2021 but delayed disclosure five years.
Cybersecurity
OpenAI Agent Swarm Logs Reveal Emergent Deception and Coordination
Logs from OpenAI's experimental agent swarm called The Collective show emergent behaviors including coordinated deception, rule-breaking, and agent sacrifice.
Application Security
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Researchers disclosed PEEP, a toolkit that hijacks Chrome and Edge browsers as backdoors by injecting malicious extensions that execute host commands.
Application Security
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
Zero-day StyleSmuggler flaw enables code execution on all Magento and Adobe Commerce versions. Attackers deploy Linux backdoors on e-commerce sites.
Application Security
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
Attackers breached Mathspace's Metabase internal reporting system, stealing data from more than 1 million students, staff, and parents at the math platform.
Application Security
Attackers Chain MikroTik Flaws to Hijack Internet-Exposed SSH
Hackers are exploiting two chained MikroTik RouterOS vulnerabilities to take full control of routers with SSH services exposed to the public internet.
Application Security
Nightmare Eclipse Drops Zero-Days for CrowdStrike, Nvidia, Avast
Security researcher Nightmare Eclipse publicly released proof-of-concept zero-day exploits for CrowdStrike, Nvidia, and Avast that escalate to System privileges.
Application Security
North Korean Hackers Backdoor HAProxy in Linux Espionage Campaign
North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors in HAProxy load balancers.
Application Security
Backdoored ScreenConnect Servers Deliver Worm-Like Payloads
Attackers compromised ConnectWise ScreenConnect servers to automatically deliver malicious payloads to newly connected clients in a self-propagating campaign.
Application Security
BigBear Phishing Service Bypassed MFA at 258 Organizations
BigBear 2.0 phishing-as-a-service framework stole over 5,000 Microsoft 365 credentials from 258 organizations using adversary-in-the-middle attacks.
Application Security
ConnectWise Discloses Unpatched ScreenConnect Flaw
ConnectWise disclosed a new ScreenConnect vulnerability with no patch available. The vendor shared temporary mitigations and plans a fix this week.
Application Security
JSCeal Malware Bypasses Google Auth with Stolen Session Cookies
Check Point Research discovered JSCeal malware that harvests credentials and bypasses Google authentication using stolen session cookies on Windows.
Application Security
Trezor Data Breach Impact Reaches 81,000 Customers
Trezor updated breach impact to 81,000 total customers after a third-party logistics provider ShipMonk was compromised in August 2026.
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
OpenAI agents made 15,000 to 18,000 autonomous edits to a German wiki over three months, evading moderation controls in unauthorized AI activity.
Application Security
Fake IT Help Desk Calls Target Microsoft 365 Executives
Vishing campaign targets directors and VPs with fake IT help desk calls, using adversary-in-the-middle token theft and residential proxies.
Application Security
Telerik UI Padding Oracle Chained to Unauthenticated RCE
TantoSec released a PoC exploit chaining Telerik UI padding oracle to unauthenticated RCE two months after Progress Software shipped a patch.
Application Security
REVSTEALER Modules Disable Windows Defender to Deploy Miner
Elastic Security Labs found four REVSTEALER persistence modules that remain after the stealer deletes itself, disabling Defender to run a crypto miner.
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Russian-speaking Aurora ransomware group leveraged Cursor AI coding assistant to conduct hands-on exploitation against 10 targets between April and May 2026.
Application Security
Five Critical WordPress Flaws Enable Site Takeover and RCE
Five critical vulnerabilities in WPMU DEV Dashboard, Avada Theme, TranslatePress, Pods, and GiveWP allow authentication bypass, privilege escalation, and RCE.
Application Security
Apple Patches CoreGraphics Zero-Day Used in Targeted Attacks
Application Security
MCP Python SDK Flaw Exposes OAuth Credentials to Malicious Servers
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Cybersecurity
JadePuffer Deploys AI Agents to Destroy Azure Cloud Infrastructure

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
OpenAI Shelves GPT-6.1 Astra After Safety Failures and Rogue Actions
Cybersecurity
Times Car Breach Exposes 6.6 Million Japanese Car-Sharing Accounts
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Cybersecurity
GitLab Issue Email Addresses Function as Leaked Credentials
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Researchers disclosed PEEP, a toolkit that hijacks Chrome and Edge browsers as backdoors by injecting malicious extensions that execute host commands.
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
Zero-day StyleSmuggler flaw enables code execution on all Magento and Adobe Commerce versions. Attackers deploy Linux backdoors on e-commerce sites.
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
Attackers breached Mathspace's Metabase internal reporting system, stealing data from more than 1 million students, staff, and parents at the math platform.
Attackers Chain MikroTik Flaws to Hijack Internet-Exposed SSH
Hackers are exploiting two chained MikroTik RouterOS vulnerabilities to take full control of routers with SSH services exposed to the public internet.
Nightmare Eclipse Drops Zero-Days for CrowdStrike, Nvidia, Avast
Security researcher Nightmare Eclipse publicly released proof-of-concept zero-day exploits for CrowdStrike, Nvidia, and Avast that escalate to System privileges.
North Korean Hackers Backdoor HAProxy in Linux Espionage Campaign
North Korean threat actors deployed a new Linux espionage toolkit targeting South Korean automotive and media firms by embedding backdoors in HAProxy load balancers.
Backdoored ScreenConnect Servers Deliver Worm-Like Payloads
Attackers compromised ConnectWise ScreenConnect servers to automatically deliver malicious payloads to newly connected clients in a self-propagating campaign.
BigBear Phishing Service Bypassed MFA at 258 Organizations
BigBear 2.0 phishing-as-a-service framework stole over 5,000 Microsoft 365 credentials from 258 organizations using adversary-in-the-middle attacks.
ConnectWise Discloses Unpatched ScreenConnect Flaw
ConnectWise disclosed a new ScreenConnect vulnerability with no patch available. The vendor shared temporary mitigations and plans a fix this week.
JSCeal Malware Bypasses Google Auth with Stolen Session Cookies
Check Point Research discovered JSCeal malware that harvests credentials and bypasses Google authentication using stolen session cookies on Windows.
Trezor Data Breach Impact Reaches 81,000 Customers
Trezor updated breach impact to 81,000 total customers after a third-party logistics provider ShipMonk was compromised in August 2026.
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
OpenAI agents made 15,000 to 18,000 autonomous edits to a German wiki over three months, evading moderation controls in unauthorized AI activity.
Fake IT Help Desk Calls Target Microsoft 365 Executives
Vishing campaign targets directors and VPs with fake IT help desk calls, using adversary-in-the-middle token theft and residential proxies.
Telerik UI Padding Oracle Chained to Unauthenticated RCE
TantoSec released a PoC exploit chaining Telerik UI padding oracle to unauthenticated RCE two months after Progress Software shipped a patch.
REVSTEALER Modules Disable Windows Defender to Deploy Miner
Elastic Security Labs found four REVSTEALER persistence modules that remain after the stealer deletes itself, disabling Defender to run a crypto miner.
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks
Russian-speaking Aurora ransomware group leveraged Cursor AI coding assistant to conduct hands-on exploitation against 10 targets between April and May 2026.
Five Critical WordPress Flaws Enable Site Takeover and RCE
Five critical vulnerabilities in WPMU DEV Dashboard, Avada Theme, TranslatePress, Pods, and GiveWP allow authentication bypass, privilege escalation, and RCE.
Anthropic Warns Infostealer Malware Hijacking Claude Sessions
Anthropic warns Vidar, Lumma, StealC, RedLine, and AMOS malware are stealing Claude session tokens, enabling attackers to drain user credits fraudulently.
Boston Scientific Cyberattack Disrupts Manufacturing and Shipping
August 25 cyberattack hit Boston Scientific's on-premises IT, disrupting manufacturing, order processing, and some cardiac monitor remote activations.
FulcrumSec Claims 86GB Manchester Airports Data Breach
FulcrumSec claims theft of 86 gigabytes from Manchester Airports Group, exposing booking data for 8.7 million customers from a third-party database breach.