access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
Thorough reorganization at NSA will create five ‘mission centers,’ including cyber and AI
The largest electronic spy agency in the world is reorganizing. And fast. First seen on therecord.media Jump to article: therecord.media/nsa-reorganization-five-mission-centers also interesting: âš¡ THN Recap: Top Cybersecurity Threats, Tools and Tips (Dec 2 – 8) DeepSeek Accused of Over-Collecting Personal Data, Says South Korea’s Spy Agency Beware of Fake ChatGPT Apps That Spy on Users…
-
Toronto’s CISOs to Watch: Leaders Across Industry
Toronto anchors Canada’s financial, retail, and technology sectors, with a cybersecurity leadership community shaped by the demands of banking regulation, critical infrastructure protection, and large-scale digital transformation. The CISOs below bring experience spanning transit systems, national retail, enterprise software, professional… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/torontos-cisos-to-watch-leaders-across-industry/ also interesting: 25 on 2025: APAC security…
-
SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 114
Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter REVSTEALER ramps up Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode GuardBreaker: Derailing AI-assisted malware analysis with a code comment DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive…
-
Why isn’t my process terminating on Windows on ARM?
Tags: windowsA hung process, a live kernel dump and a Windows on ARM emulation bug that only some of our binaries seem to hit.This is the first post in a series from MIND’s R&D team in Tel Aviv, where we write… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/why-isnt-my-process-terminating-on-windows-on-arm/ also interesting: Crowdstrike und Windows: Wie große…
-
Hackers exploit Tencent app flaw to deploy GrayRabbit malware
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent’s Sogou Input Method for Windows to deploy the GrayRabbit backdoor. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/hackers-exploit-tencent-app-flaw-to-deploy-grayrabbit-malware/ also interesting: The 2024 cyberwar playbook: Tricks used by nation-state actors F5 Security Incident Advisory Top 10 Cybersecurity Predictions for 2026…
-
East Coast CISOs to Watch: Leaders Across Industry
The East Coast is home to a diverse range of organizations spanning healthcare, manufacturing, technology, and standards bodies, each with distinct security challenges and regulatory demands. The CISOs below are helping shape security strategy across industries that form a significant… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/east-coast-cisos-to-watch-leaders-across-industry/ also interesting: How organizations can secure their…
-
Security Affairs newsletter Round 594 by Pierluigi Paganini INTERNATIONAL EDITION
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open…
-
BlueMoon: Neues Exploit-Kit nutzt Patch-Lücken für gezielte Angriffe
Sicherheitsforscher von Proofpoint haben eine gezielte Spearphishing-Kampagne entdeckt, bei der mehrere staatlich unterstützte Spionagegruppen ein neues Exploit-Kit namens BlueMoon einsetzen. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/bluemoon-exploit-kit-patch-luecken also interesting: Exploits gesichtet – Schwachstellen in VMware vCenter ermöglichen Malware-Angriffe Critical Mitel, Oracle flaws find active exploitation, CISA urges patching 25 on 2025: APAC security thought…
-
CISOs to Watch in New York’s Fintech Industry
New York’s fintech sector spans digital banking platforms, trading infrastructure, financial technology providers, and payments companies operating at the intersection of financial services and rapid technological innovation. CISOs in this space must protect complex digital ecosystems while navigating stringent regulatory… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cisos-to-watch-in-new-yorks-fintech-industry/ also interesting: Quantum supremacy: Cybersecurity’s ultimate arms…
-
Daily OT Security News: September 13, 2026
Today’s OT-security briefing collects reported developments that affect operational technology, network infrastructure, supply chains, and incident response posture across multiple industrial and critical”‘infrastructure sectors. The summaries below focus on factual takeaways relevant to operators, security teams, and resilience planners without… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-13-2026/ also interesting: Purdue 2.0? : Rising to…
-
Risks of hard-coded secrets in software
Risks of hard-coded secrets in software For many UK SMEs, software is now part of day-to-day business operations, whether it supports sales, customer service, finance, or operations. That makes the way software is built and maintained a business issue, not… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/risks-of-hard-coded-secrets-in-software/ also interesting: 10 top XDR tools and…
-
OpenAI boss and Elon Musk back calls to put brakes on ‘reckless’ AI development
Rare show of unity from rival developers after safety warnings from Anthropic boss and AI researchers<ul><li><a href=”https://www.theguardian.com/commentisfree/2026/sep/11/the-guardian-view-on-controlling-ai-humanity-cannot-outsource-its-survival”>The Guardian view on controlling AI: humanity cannot outsource its survival</li></ul>Sam Altman and Elon Musk have backed a <a href=”https://www.theguardian.com/technology/2026/sep/12/we-must-slow-the-pace-ceo-of-anthropic-calls-for-an-ai-slowdown”>call from the head of Anthropic, Dario Amodei, to “slow the pace” of AI development after he warned that an…
-
GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read Exploited Within 24 Hours
CVE-2026-85706, a CVSS 10.0 GitLab path traversal, was under active exploitation within 24 hours of disclosure. GitLab disclosed CVE-2026-85706 (CVSS score of 10.0) on September 10, 2026, a path traversal vulnerability in its repository commits API. CVE-2026-85706 affects GitLab’s repository commits API and can let attackers access files they should not see. A crafted request…
-
VLC-Sicherheitslücken: Manipulierte Streams können Speicherinhalte auslesen
Tags: unclassifiedVLC-Sicherheitslücken gefährden Nutzer: Manipulierte PNGs können Codeausführung ermöglichen, RTSP-Antworten Speicherinhalte preisgeben. First seen on tarnkappe.info Jump to article: tarnkappe.info/artikel/it-sicherheit/vlc-sicherheitsluecken-manipulierte-streams-333426.html also interesting: Nook Simple Touch Hacked to Emulate PlayStation: The Nook Simple Touch by Barnes and Noble is famously easy to r… E-skimming campaign uses Unicode obfuscation to hide the Mongolian Skimmer Schadsoftware bei einem Krankenhaus…
-
Purple-team validation of detections against MITRE ATTCK
Purple-team validation is the practical bridge between a threat model and a detection that actually works in production. For UK SMEs, it is one of the most useful ways to answer a simple question: if an attacker uses a known… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/purple-team-validation-of-detections-against-mitre-attck/ also interesting: Threat-informed defense for operational technology:…
-
Conti Hacker Who Built Malware and Attacked Victims Gets Four-Year Sentence
Ukrainian lawyer and Conti malware developer Oleksii Lytvynenko was sentenced to four years in U.S. prison for ransomware attacks. Oleksii Oleksiyovych Lytvynenko had, by most accounts, a fairly ordinary legal career in Ukraine before he switched to writing malware. A US federal court sentenced the 44-year-old to four years in prison this week for conspiracy…
-
Week in review: Linux rootkit deployed on F5 BIG-IP APM devices, Cisco FMC bugs exploited
Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: Zero trust AI agents demand a different kind of security In this interview, … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/13/week-in-review-linux-rootkit-deployed-on-f5-big-ip-apm-devices-cisco-fmc-bugs-exploited/ also interesting: Week in review: Exploited zero-day in Cisco email security appliances, Kali Linux 2025.4 released 10 promising…
-
‘Cheap iPhone deal’: warning over scam sites selling latest Apple mobiles
Criminals exploit demand for iPhone 18 Pro and foldable Duo to trick people eager to get their hands on oneApple has just launched a range of new iPhones, including a foldable handset, just as you decide it is time to replace your own ageing mobile. But you balk at the £1,199 price tag for the…
-
Tesco alerts police as supermarket becomes latest victim of scam ‘endorsement’ ads
Exclusive: Supermarket joins line of firms and sports stars including Bellingham and Haaland to have their image hijacked via adsTesco has alerted City of London police after it became the latest in a string of companies and sports stars, including Barclays bank and Lewis Hamilton, to have its image hijacked in a “scam” by unlicensed…
-
Digitale Manipulation erkennen Methoden, Risiken und moderne Gegenstrategien
Deepfakes, synthetische Stimmen und manipulierte Kontexte erhöhen den Prüfaufwand für Unternehmen, Behörden und Redaktionen. Entscheidend ist nicht der eine Detektor, sondern ein belastbarer Verifikationsprozess, der technische Analyse, Quellenprüfung, Provenienznachweise und klare Verantwortlichkeiten verbindet. Management Summary Manipulation ist multimedial: Bild, Video, Audio, Text, Metadaten und Kontext müssen gemeinsam bewertet werden. Einzelne KI-Detektoren reichen nicht: Ihre Ergebnisse……
-
KI-Agenten sicher steuern: Kontrolle beginnt bei Identitäten und Berechtigungen
Tags: aiKI-Agenten entwickeln sich vom Analysewerkzeug zum operativen Akteur. Sobald sie Daten abrufen, Anwendungen steuern oder Prozesse auslösen, werden Identitäten, Berechtigungen und Abschaltmechanismen zur Managementaufgabe. Unternehmen brauchen deshalb klare Leitplanken, eindeutige Verantwortlichkeiten und technische Kontrollen, bevor KI in geschäftskritische Abläufe einzieht. Management Summary KI-Agenten sind digitale Identitäten: Wer Systeme und Daten eigenständig nutzt, benötigt ein… First…
-
Kein Flickenteppich beim Kinderschutz Deutschland muss auf europäische Lösung setzen
Tags: germanyMindestalter und Altersverifikation weltweit: eco Infomap zeigt, wie zahlreiche nationale Ansätze und Diskussionen den regulatorischen Flickenteppich beim Schutz Minderjähriger prägen. Am 11. September findet die Abschlusskonferenz der Expertenkommission »Kinder- und Jugendschutz in der digitalen Welt« statt. Zu den zentralen Themen gehört auch die Frage nach Altersgrenzen bzw. einem Mindestalter. eco Verband der Internetwirtschaft… First seen…
-
152.000 Zugriffe auf gefälschte Medienartikel geblockt
Innerhalb von nur drei Tagen registrierte Avast eine Betrugskampagne, die gefälschte Medienberichte für KI-Investment-Scams nutzte. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/gefaelschte-medienartikel also interesting: Charm Security Emerges From Stealth With $8 Million in Funding The Wild West of AI-Driven Fraud Memcyco Gets $37M to Fight AI-Powered Impersonation Attacks Researchers Trick Perplexity’s Comet AI Browser…
-
CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.Details of the vulnerabilities are as follows – CVE-2026-42016 (CVSS score: 8.1) – An incorrect authorization First seen on thehackernews.com…
-
Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons
AI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks. Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becoming part of the operational machinery itself. That is the main message emerging from…
-
Google-Play-Frühzugang wird für Betrug missbraucht
Bitdefender warnt: Betrüger nutzen Googles Early-Access-Programm, um Warnungen anderer Nutzer zu verhindern. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/google-play-betrug also interesting: Cybersecurity Snapshot: CISA Hands Down Cloud Security Directive, While Threat from North Korean IT Workers Gets the Spotlight Cybersecurity Snapshot: AI Security Skills Drive Up Cyber Salaries, as Cyber Teams Grow Arsenal of…
-
Managing endlife software risks
End-of-life software is not just an IT housekeeping issue. For a small business, it can become a cost problem, a reliability problem, and a reputation problem all at once. Once software reaches the point where the supplier no longer provides… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/managing-end-of-life-software-risks/ also interesting: Exploring the Pros and Cons…
-
Saturday Security: AI Industrializes Phishing
This week’s Saturday Security Story shows how AI is industrializing an old scam, and doing it at a scale that should get everyone’s attention. Microsoft spotted a campaign that blasted more than 1 million fraudulent emails across a three-day… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/saturday-security-ai-industrializes-phishing/ also interesting: Privacy Roundup: Week 3 of Year…
-
Anthropic stoppt russische Cyberspionage mit Claude
Die russische Gruppe Midnight Blizzard nutzte Claude, um Schadsoftware automatisiert vor Sicherheitsprodukten zu verstecken. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/anthropic-cyberspionage also interesting: Void Blizzard: New Russian Cyberespionage Group Targets NATO and Ukraine Void Blizzard nimmt NATO-Organisationen ins Visier Russische APT-Gruppe greift westliche KRITIS-Betreiber an Hacker linked to Void Blizzard faces charges over cyberespionage…
-
KI: Anthropic entlarvt Claude-Missbrauch für russische Drohnenschwärme
Russische Entwickler hatten mit Claude einen autonomen Kamikaze-Drohnenschwarm zum Einsatz gegen die Ukraine gebaut. First seen on golem.de Jump to article: www.golem.de/news/ki-anthropic-entlarvt-claude-missbrauch-fuer-russische-drohnenschwaerme-2609-212949.html also interesting: What security pros can learn about AI from the Russia-Ukraine war Ukraine sees surge in AI-Powered cyberattacks by Russia-linked Threat Actors Cyberkriminalität: Europas KMU im Visier Ukraine says Russia is deploying…
-
Six Nigerians extradited to US over $6M online romance scam
Alleged members of Black Axe criminal network that swindled US women out of $6m flown from South AfricaSix Nigerian nationals linked to an organized criminal network that allegedly swindled American women out of more than $6m through <a href=”https://apnews.com/article/scams-online-scams-ai-internet-safety-phishing-fraud-takeaways-b1350fd421cce73ac585a649b07332d5″>online romance scams were extradited to the United States on Friday.<a href=”https://www.theguardian.com/world/southafrica”>South African police confirmed they were…
-
Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent
The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/dutch-ncsc-critical-check-point-vpn-flaws-exploitation-is-imminent/ also interesting: Top 12 ways hackers broke into your systems in 2024 WatchGuard patches ‘critical’ VPN flaw in firewalls that could lead…
-
Revolut confirms customer data breach through fake government requests
Revolut said it notified affected customers and alerted the relevant government agency, law enforcement, and financial regulators. First seen on techcrunch.com Jump to article: techcrunch.com/2026/09/12/revolut-confirms-customer-data-breach-through-fake-government-requests/ also interesting: How defenders use the dark web 13 cybersecurity myths organizations need to stop believing TDL 007 – Cyber Warriors Digital Shadows: Insights from Canada’s Cybersecurity Leader Rogues gallery:…
-
Daily OT Security News: September 12, 2026
Today’s briefing covers five OT/IoT developments: maritime operational-technology monitoring challenges, expanded U.S. critical-infrastructure support, the start of EU Cyber Resilience Act vulnerability reporting for actively exploited flaws, a U.S. Department of Energy request for input on bulk-power system risks, and… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/daily-ot-security-news-september-12-2026/ also interesting: What to Know About CyberAv3ngers:…
-
Cisco bestätigt Angriffe auf kritische FMC-Sicherheitslücke
Die Schwachstelle CVE-2026-20079 im Cisco Secure FMC hat den Höchstwert 10.0 und wird laut Cisco bereits aktiv ausgenutzt. First seen on it-daily.net Jump to article: www.it-daily.net/it-sicherheit/cybercrime/cisco-sicherheitsluecke also interesting: Altgeräte bedrohen Sicherheit in Unternehmen Cisco confirms cyberattacks on Smart Licensing Utility flaw Ungepatchte Lücken ermöglichen Übernahme von GitLab-Konten Hacker nutzen gravierende Schwachstelle bei SAP S/4HANA aus
-
When the Whole Company Adopts AI: What It Does to Your SOC
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and…
-
From Hacks to Bioweapons, Claude Misuse Is Now Everywhere
Plus: The US disrupts the internet’s biggest black market, a Conti ransomware hacker gets prison time, Meta fails to stop AI-generated videos of child abuse. First seen on wired.com Jump to article: www.wired.com/story/security-news-this-week-from-hacks-to-bioweapons-claude-misuse-is-now-everywhere/ also interesting: Cybersecurity Snapshot: Study Raises Open Source Security Red Flags, as Cyber Agencies Offer Prevention Tips Against Telecom Spying Attacks Top…
-
Detecting commandcontrol traffic at the network layer
Command-and-control traffic, often shortened to C2, is the communication path an attacker uses to control a compromised system after initial access. Once malware or a hands-on operator has a foothold, C2 is how they issue commands, move data, stage tools,… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/detecting-command-and-control-traffic-at-the-network-layer/ also interesting: The state of ransomware: Fragmented…
-
OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber…
-
(g+) Sidecar-Angriffsfläche: Die Dienste, die kein Portscan sieht
Tags: unclassifiedEin Postgresql-Helfer riss Splunk auf. Solche Dienste laufen überall mit, ungezählt. Worauf Admins achten müssen. First seen on golem.de Jump to article: www.golem.de/news/sidecar-angriffsflaeche-die-dienste-die-kein-portscan-sieht-2609-212900.html also interesting: 10 Holiday Gifts for Stressed-Out Security Pros Fünf Schritte zur Cyberresilienz – So schützen Unternehmen sich vor millionenschweren Schäden The Future of eCommerce: How Custom Apps Help You Get Ahead…
-
China-Linked Hackers Chain Chrome Zero-Day With Windows Kernel Flaw in Attacks
China-linked threat actors UTA0560 and JungleBamboo chained a Google Chrome zero-day with a Windows kernel privilege-escalation flaw in phishing campaigns targeting NGOs and other victims. Volexity documented the operations, detected on September 1, 2026, as using identical browser-to-kernel exploit components but ultimately installing separate espionage payloads: the GRIMWEDGE JScript backdoor and the LONGTALE credential-stealing Chrome…
-
Threat Actors Use Claude AI Agents to Automate Cyberattacks and Steal Sensitive Data
Threat actors are increasingly using Claude-based AI workflows to automate cyberattacks, accelerate data theft, and reduce the technical expertise needed to run complex intrusions. Anthropic’s report details cyber espionage, financially motivated extortion, supply-chain compromise, and hacktivist activity disrupted between December 2025 and August 2026. Rather than using an AI chatbot only for occasional coding assistance,…
-
OpenAI Agents Flood RubyGems With 2,000 Packages and Exploit Build System for RCE
A swarm of AI agents believed to be operated internally by OpenAI uploaded more than 2,000 malicious packages to RubyGems in May 2026, abusing the ecosystem’s documentation build process to execute code remotely and attempting to steal user API keys through a then-undisclosed server-side flaw. Researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx said…
-
New Phishing Campaign Abuses Windows Mshta.exe to Steal Credentials and Secrets
A newly identified phishing campaign is abusing the legitimate Windows utility mshta.exe to execute malicious HTML Application (HTA) files, conduct system reconnaissance, and potentially deploy payloads designed to steal credentials and local secrets. Fortra’s Intelligence and Research Experts (FIRE) said the activity began in June and remains active, with operators regularly recompiling malware samples to…
-
Cybersecurity May Be AI’s Next Compute Market
Jensen Huang recently described cybersecurity as one of NVIDIA’s next major AI growth opportunities. The obvious interpretation is that NVIDIA sees another large enterprise market for AI. But I think there is a more interesting idea underneath it: cybersecurity may… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cybersecurity-may-be-ais-next-compute-market/ also interesting: DeepSeek hit by cyberattack and…
-
CISA Warns of Critical GitLab Vulnerability Exploited in Attacks
Tags: attack, cisa, cve, cyber, cybersecurity, exploit, flaw, gitlab, infrastructure, Internet, kev, mitigation, vulnerabilityThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a critical GitLab flaw, tracked as CVE-2026-85706, to its Known Exploited Vulnerabilities catalog after confirming it was exploited in attacks. The issue affects both GitLab Community Edition and Enterprise Edition and requires urgent mitigation, particularly for internet-accessible GitLab instances. CVE-2026-85706 is a path traversal vulnerability…
-
Trotz Meldepflichten: Nur 3 % der deutschen Industrieunternehmen sind vollständig auf EU Cyber Resilience Act vorbereitet
PwC-Studie: Bewusstsein für CRA-Anforderungen ist hoch, operative Umsetzung bleibt weit dahinter zurück. Jedes zweite Unternehmen hat noch nicht mit der CRA-Umsetzung begonnen. Mittelständische Unternehmen liegen in nahezu allen Bereichen hinter größeren Unternehmen. Die Meldepflichten des EU Cyber Resilience Act (CRA) gelten seit dem 11. September 2026. Doch die deutsche Industrie ist auf die neue… First…

