access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
Nightmare Stresser: DDoS-Portal mit über 500.000 Nutzern vom Netz genommen
Das FBI hat eine Plattform zerschlagen, die für Hunderttausende DDoS-Angriffe auf weltweit verteilte Ziele genutzt worden sein soll. First seen on golem.de Jump to article: www.golem.de/news/nightmare-stresser-ddos-portal-mit-ueber-500-000-nutzern-vom-netz-genommen-2609-213180.html also interesting: DDoS-Angriff auf die Website einer Stadtverwaltung in Italien News alert: Link11’s research shows DDoS attacks are more targeted, and doubled, year-over-year DDoS-Angriff auf ein Medienunternehmen in Mexiko…
-
AI Agent Breaches Spanish Organization, Modifies Personal Data
AI-driven cyberattacks used to be exotic. Soon, it’ll be odd if threat actors aren’t using agents to do all of their bidding. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ai-agent-breaches-spanish-organization-personal-data also interesting: Time of Reckoning Reviewing My 2024 Cybersecurity Predictions Agents, Robotics, and Auth Oh My! – Impart Security Your Network Is Showing Time to…
-
Scammers Tell T-Mobile Users Their Rewards Are Expiring to Trick Them Into Clicking Phishing Links
A large-scale SMS phishing campaign is impersonating T-Mobile and warning recipients that their “rewards points” are about to expire, using fabricated balances, urgent deadlines, and lookalike redemption links to steal sensitive information. Security researchers have tracked the operation since early May 2026 and continue to observe new message variants despite a decline from its peak…
-
Trustmarque Ultima ushers in TMU brand
Tags: businessBusiness unveils fresh look as it continues to integrate businesses that came together in a merger 10 months ago First seen on computerweekly.com Jump to article: www.computerweekly.com/microscope/news/366650190/Trustmarque-Ultima-ushers-in-TMU-brand also interesting: 8 Cyber Predictions for 2025: A CSO’s Perspective Scattered Spider Launches Supply Chain Attacks on UK Retail Organizations 7 Top Security Execs On How The AI…
-
Home Office challenged on ‘farcical’ secrecy over Apple ‘backdoor’ order
UK government argues that national security would be damaged if it departs from ‘neither confirm nor deny policy’ on Apple ‘backdoor’ notice First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650612/Home-Office-challenged-on-farcical-secrecy-over-Apple-backdoor-order also interesting: Privacy Roundup: Week 9 of Year 2025 Apple withdraws encrypted iCloud storage from UK after government demands ‘backdoor’ access UK Cybersecurity Weekly News…
-
AI Malware Keeps Changing Its Code to Break Traditional Signature-Based Detection
AI-powered malware is beginning to erode one of endpoint security’s oldest assumptions: that malicious code will remain stable long enough to identify, fingerprint, and block. A new class of threats uses large language models during execution to rewrite scripts, generate commands, and alter obfuscation on demand producing variants that can evade static hashes and traditional…
-
Neue Cyberattacken: FamousSparrow nimmt Lateinamerika ins Visier
Die mutmaßlich China-verbundene Hackergruppe FamousSparrow konzentriert ihre Spionageaktivitäten auf Regierungsstellen in Lateinamerika. Dafür setzt sie eine neue Schadsoftware ein, die sich tief im Windows-System versteckt und Überwachungsmaßnahmen gezielt umgehen kann. First seen on welivesecurity.com Jump to article: www.welivesecurity.com/de/uber-eset-research/neue-cyberattacken-famoussparrow-nimmt-lateinamerika-ins-visier/ also interesting: 8 biggest cybersecurity threats manufacturers face Japanese Police claim China ran five-year cyberattack campaign Hacker…
-
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices.”Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses First seen on thehackernews.com Jump to…
-
Hardcoded MCP credentials found in public GitHub files
Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/hush-security-mcp-credential-exposure-report/ also interesting: AI programming copilots are worsening code security and leaking more secrets APT Attacks Target Indian Government Using…
-
Abandoned IoT apps keep sending sensitive data to broken servers
Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/abandoned-iot-apps-data-security-risks/ also interesting: Cybersecurity Snapshot: Tenable Highlights Risks of AI Use in the Cloud, as UK’s NCSC Offers Tips for…
-
Zahlungssicherheit im Zeitalter von KI-gestützten Deepfakes – Deutsche Unternehmen zögern beim Schutz vor KI-Zahlungsbetrug
First seen on security-insider.de Jump to article: www.security-insider.de/ki-zahlungsbetrug-b2b-deutschland-2026-a-f633586bc71baf4d1e678fb080f0a9a7/ also interesting: Startup can identify deepfake video in real time KI-gestützte Cybersicherheit 10 Prognosen für das Jahr 2025 Deepfakes are rewriting the rules of geopolitics Deepfakes are rewriting the rules of geopolitics
-
MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2
A newly identified Windows malware framework dubbed MovieReaper is being distributed through pirated movie torrents after threat actors compromised a public torrent-file repository used by multiple tracker sites. The campaign combines a multi-stage infection chain, anti-analysis techniques, UAC bypass, file-management capabilities, and Solana blockchain-based command-and-control (C2) discovery to make disruption more difficult. Kaspersky researchers identified…
-
Most WordPress pros still lack a breach recovery plan
Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/wordpress-security-survey-recovery-plan/ also interesting: Swarms of Fake WordPress Plug-ins Infect Sites With Infostealers 390,000+ WordPress Credentials Stolen via Malicious GitHub Repository Hosting…
-
OpenAI Reveals AI Models Concealing Mistakes, Using Exposed API Keys and Sharing Files
OpenAI has introduced a new framework for reporting model misalignment after discovering instances where its AI systems concealed mistakes, accessed exposed API keys, fabricated data, uploaded files without authorization, and communicated through unintended channels. The company released six initial reports detailing behaviors observed during model training and evaluation. They argue that AI developers need more…
-
FBI Seizes NightmareStresser DDoSHire Domains Used in Hundreds of Thousands of Attacks
The FBI has seized internet domains linked to NightmareStresser, a long-standing distributed denial-of-service (DDoS)-for-hire platform allegedly used to launch hundreds of thousands of attacks or attempted attacks worldwide since 2022. The U.S. Attorney’s Office for the District of Alaska announced the action, which targets the infrastructure that allowed paying customers to overwhelm victims’ networks and…
-
Cybersecurity und Datenschutz im iGaming-Sektor
www.pexels.com/de-de/foto/laptop-tippen-computer-kommunikation-5475752/ Wenige Online-Branchen verarbeiten so dichte Datenbestände wie das regulierte Glücksspiel. Ein Spielerkonto vereint Ausweisdaten, Bankverbindungen, Transaktionshistorien und detaillierte Verhaltensprofile in einem einzigen Datensatz. Entsprechend hoch sind die Anforderungen an IT-Sicherheit und Datenschutz, die Betreiber im deutschsprachigen Markt erfüllen müssen. Hinzu kommt die schiere Frequenz: Große Anbieter verzeichnen täglich hunderttausende Logins, Einzahlungen und Auszahlungsanträge…. First…
-
Konfigurationen prüfen – Samba-Schwachstellen ermöglichen Remote Code Execution
First seen on security-insider.de Jump to article: www.security-insider.de/samba-kritische-rce-luecken-updates-a-fd876cee91ffe494cffac65c82a8e097/ also interesting: Critical Veeam Vulnerabilities Allow Remote Code Execution Update Now How threat actors breached a U.S. federal civilian agency by exploiting a GeoServer flaw vLLM Flaw Allows Remote Code Execution Through Malicious Payloads Oracle OIM zero”‘day: Pre”‘auth RCE forces rapid patching across enterprises
-
Konfigurationen prüfen – Samba-Schwachstellen ermöglichen Remote Code Execution
First seen on security-insider.de Jump to article: www.security-insider.de/samba-kritische-rce-luecken-updates-a-fd876cee91ffe494cffac65c82a8e097/ also interesting: Critical Veeam Vulnerabilities Allow Remote Code Execution Update Now How threat actors breached a U.S. federal civilian agency by exploiting a GeoServer flaw vLLM Flaw Allows Remote Code Execution Through Malicious Payloads Oracle OIM zero”‘day: Pre”‘auth RCE forces rapid patching across enterprises
-
Konfigurationen prüfen – Samba-Schwachstellen ermöglichen Remote Code Execution
First seen on security-insider.de Jump to article: www.security-insider.de/samba-kritische-rce-luecken-updates-a-fd876cee91ffe494cffac65c82a8e097/ also interesting: Critical Veeam Vulnerabilities Allow Remote Code Execution Update Now How threat actors breached a U.S. federal civilian agency by exploiting a GeoServer flaw vLLM Flaw Allows Remote Code Execution Through Malicious Payloads Oracle OIM zero”‘day: Pre”‘auth RCE forces rapid patching across enterprises
-
Konfigurationen prüfen – Samba-Schwachstellen ermöglichen Remote Code Execution
First seen on security-insider.de Jump to article: www.security-insider.de/samba-kritische-rce-luecken-updates-a-fd876cee91ffe494cffac65c82a8e097/ also interesting: Critical Veeam Vulnerabilities Allow Remote Code Execution Update Now How threat actors breached a U.S. federal civilian agency by exploiting a GeoServer flaw vLLM Flaw Allows Remote Code Execution Through Malicious Payloads Oracle OIM zero”‘day: Pre”‘auth RCE forces rapid patching across enterprises
-
Physische KI bis 2030: Wie Roboter, autonome Systeme und resiliente IoT-Infrastrukturen die operative Arbeit verändern
Physische KI wird bis 2030 zu einem strategischen Hebel für Produktivität, Resilienz und Arbeitssicherheit. Unternehmen müssen jetzt klären, welche operativen Prozesse sich durch intelligente Maschinen, autonome Systeme und vernetzte Sensorik neu gestalten lassen und welche Governance dafür nötig ist. Physische KI wird operativ: KI-Systeme verlassen die reine Daten- und Textverarbeitung und greifen über Roboter,… First…
-
Steam Windows Vulnerability Lets Users Escalate Privileges to NT AUTHORITYSYSTEM
A newly published proof of concept called >>BrokenPipe<< has revealed a local privilege escalation vulnerability in the Steam Client Service on Windows systems. According to the project's GitHub repository, this flaw could allow a standard, non-administrative Windows user to make the Steam Client Service launch an executable with NT AUTHORITY\SYSTEM privileges. The proof of concept…
-
98% of fraudulent hires have company credentials by the time they’re caught
A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/hypr-hiring-fraud-detection-report/ also interesting: AI disinformation didn’t upend 2024 elections, but the threat is very real 9 things CISOs need know about…
-
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.”HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading, First seen on thehackernews.com Jump to article:…
-
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15.The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179,…
-
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough.So the…
-
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network.The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says…
-
How Pentest Companies Adapt In The Era of AI
Every penetration testing firm is facing the same pressure right now. AI tools are faster, cheaper, andincreasingly capable, and testers are using them whether the company has a policy on it or not. There’s ahigh change AI has already entered your workflow the question is whether it has entered on your terms oryour employee’s personal…
-
New infosec products of the week: September 18, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr uses … First seen on helpnetsecurity.com Jump to article: www.helpnetsecurity.com/2026/09/18/new-infosec-products-of-the-week-september-18-2026/ also interesting: New infosec products of the week: September 20, 2024 New infosec products of the week: February 14, 2025 Developers…
-
States Expand Cyber Support Beyond Their Own Networks
Local Control and Funding Gaps Complicate Critical Infrastructure Protection. States are extending cyber support to local utilities and other essential services they do not control. Closing the gap will require more than grants and tools. Local operators need sustained monitoring, OT expertise and stronger, consistent vendor controls. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/states-expand-cyber-support-beyond-their-own-networks-a-32858…
-
States Expand Cyber Support Beyond Their Own Networks
Local Control and Funding Gaps Complicate Critical Infrastructure Protection. States are extending cyber support to local utilities and other essential services they do not control. Closing the gap will require more than grants and tools. Local operators need sustained monitoring, OT expertise and stronger, consistent vendor controls. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/states-expand-cyber-support-beyond-their-own-networks-a-32858…
-
States Expand Cyber Support Beyond Their Own Networks
Local Control and Funding Gaps Complicate Critical Infrastructure Protection. States are extending cyber support to local utilities and other essential services they do not control. Closing the gap will require more than grants and tools. Local operators need sustained monitoring, OT expertise and stronger, consistent vendor controls. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/states-expand-cyber-support-beyond-their-own-networks-a-32858…
-
Mind Raises $72M to Rebuild DLP Around AI Agents
AI Agents Could Help Analysts Separate Meaningful Data Events From Routine Activity. Mind raised $72 million to expand a DLP platform that pairs endpoint enforcement with AI agents designed to analyze data lineage, surface evidence of sensitive data movement and guide employees through policy violations. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/mind-raises-72m-to-rebuild-dlp-around-ai-agents-a-32860 also interesting:…
-
OpenAI admits its models lie to cover their own mistakes
OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a formal framework for tracking, investigating, and disclosing cases of model misalignment, paired with six…
-
CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus
The move is consistent with the agency’s advice on the need for organizations to prioritize the vulnerabilities that actually matter. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/cisa-ditches-weekly-vuln-roundups-risk-based-focus also interesting: CISA Releases Nine Security Advisories on ICS Vulnerabilities and Exploits Frequently Asked Questions About the MITRE CVE Program Expiration and Renewal Cybersecurity Snapshot: AI Will…
-
Korean AI Benchmark Exposes Gaps in Multilingual Safety
Scale AI Finds Model Guardrails Shift With Language and Cultural Context. AI infrastructure company Scale AI partnered with the Korean AI Safety Institute to develop a benchmark called ROK-Fortress. They found that many AI models adhere to safety guidelines more often when prompted in Korean, rather than English. First seen on govinfosecurity.com Jump to article:…
-
New RatHat Android malware uses AI to automate device control
A new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. First seen on bleepingcomputer.com Jump to article: www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/ also interesting: Cybersecurity Snapshot: AI Will Take Center Stage in Cyber in 2026, Google Says, as MITRE Revamps ATTCK Framework Cybersecurity Snapshot: Global Agencies Target…
-
Breach Roundup: China Calls for Stronger AI Oversight
Also, Spain’s First AI Agent-Linked Data Breach, NightmareStresser Domains Seized. This week: a call for stronger AI oversight in China, an AI agent-linked breach in Spain, Cisco active exploits, Check Point patched flaws. NightmareStresser seized – again! South Korea data breach fines, AI made BEC attacks worse. An Android Trojan, an exploited Pixel flaw and…
-
Cisco alerts customers to second actively exploited zero-day in as many days
The latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025. First seen on cyberscoop.com Jump to article: cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/ also interesting: Cisco Firewall and VPN Zero Day Attacks: CVE-2025-20333 and CVE-2025-20362 Active Exploitation of Cisco and Citrix 0-Day Vulnerabilities Allows Webshell Deployment…
-
European Commission set to push social media restrictions, safety requirements into law
Tags: lawThe proposal, known as the EU KIDS Act, would block social media platforms from offering accounts to children younger than 13 and establish a bloc-wide minimum age of 15 for account creation. First seen on therecord.media Jump to article: therecord.media/european-commission-set-to-push-social-media-kids-restrictions-into-law also interesting: Europol Dismantles Kidflix With 72,000 CSAM Videos Seized in Major Operation TRM Launches…
-
China’s FamousSparrow APT Spies on US Politics in Latin America
Amid the US and China’s fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-spies-latin-america also interesting: Earth Alux Hackers Use VARGIET Malware to Target Organizations Pandas Galore: Chinese Hackers Boost Attacks in Latin America Chinese APT Exploits Microsoft Exchange to Breach Energy Sector…
-
Cloudflare trennt Websuche und KI-Training Website-Betreiber erhalten mehr Kontrolle über ihre Inhalte
Cloudflare trennt Suche, KI-Training und KI-Agenten: Website-Betreiber können KI-Training blockieren, ohne ihre Sichtbarkeit in Suchmaschinen zu verlieren. First seen on infopoint-security.de Jump to article: www.infopoint-security.de/cloudflare-trennt-websuche-und-ki-training-website-betreiber-erhalten-mehr-kontrolle-ueber-ihre-inhalte/a46422/ also interesting: Frequently Asked Questions About Model Context Protocol (MCP) and Integrating with AI for Agentic Applications ‘Eine Krisensituation erfordert klare Entscheidungen” Preventing training data leakage in AI systems Entwickler…
-
Warum gute digitale Gewohnheiten weiterhin wichtig sind
Die Zahl digitaler Konten wächst kontinuierlich. E-Mail-Dienste, Cloud-Anwendungen, Online-Shops, Unternehmensplattformen und zahlreiche weitere Anwendungen erfordern jeweils eigene Zugangsdaten. Gleichzeitig entwickeln sich auch die Methoden weiter, mit denen Cyberkriminelle versuchen, sich Zugriff auf diese Daten zu verschaffen. Für Unternehmen und Privatanwender wird es deshalb zunehmend wichtiger, IT-Sicherheit nicht als isolierte Einzelmaßnahme zu betrachten, sondern als festen…
-
The AI hacking apocalypse is not inevitable
While large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices. First seen on cyberscoop.com Jump to article: cyberscoop.com/ai-agent-hacking-apocalypse-cybersecurity/ also interesting: 25 on 2025: APAC security thought leaders share their predictions and aspirations Cybersecurity Snapshot: NIST Aligns Its Privacy and Cyber Frameworks,…
-
LLMs respond differently to harmful prompts when AI watermarking is used
SynthID can cause models to follow harmful instructions they would otherwise refuse. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/ai-text-watermarking-can-make-models-more-vulnerable-to-adversarial-prompts/ also interesting: The 7 most in-demand cybersecurity skills today IT-Trends 2025 Video-Statements von Experten der Netzpalaver-Community Key questions CISOs must ask before adopting AI-enabled cyber solutions AI agents can bypass guardrails and put credentials at…
-
China’s Answer to AI Safety: More Controls, Not Slower Development
China is emphasizing technical controls for AI agents as U.S. leaders debate slowing frontier AI, raising new questions for businesses deploying autonomous systems. The post China’s Answer to AI Safety: More Controls, Not Slower Development appeared first on TechRepublic. First seen on techrepublic.com Jump to article: www.techrepublic.com/article/news-china-ai-control-agents-safety-standards-apac/ also interesting: Top 12 ways hackers broke into…
-
Canadian PM Floats Tech Sovereignty Alliance With Europe
‘No One’ Should Control Open Markets or ‘Impair Our Sovereignty,’ Says Mark Carney. Canada and Europe should pool their compute resources and collaborate on artificial intelligence rules as part of a wide-ranging alliance that would provide a counterweight to the United States and China, Canadian Prime Minister Mark Carney has proposed. First seen on govinfosecurity.com…

