On Friday, the US and China agreed to discuss various AI safety risks during a planned September meeting. These will be the first official bilateral talks between the two countries since the second Trump administration began, and the talks will be led by US Treasury Secretary Sco
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. The VPN service provider said the incident did not affect its customers and did not extend to other parts of its infrastructure, but it exposed servi
MantaxOtax Android malware has combined file encryption with extensive surveillance, letting attackers steal messages, credentials and device data while restricting access to infected phones. In a technical write up published on September 9, Zimperium's zLabs team linked the malw
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, targeting users with ph
With the release of Apple Watch Series 12, Apple has decided that it's ok to capture people's conversations without their consent. The latest Apple Watch comes with Audio Intelligence, a set of AI audio processing capabilities tuned for the company's S11 chip. Its features includ
The FBI has published its first ever Cyber Strategy, providing guidance on how the agency investigates and disrupts cyber threat actors. The new document, published on September 9, highlights the need for strategic response to escalating cyber-attacks perpetrated by financially-m
SolarView Compact provided by Contec Co., Ltd. contains multiple vulnerabilities. The affected products include SolarView Compact, SV-CPT-MC310 versions prior to 9.00, and SV-CPT-MC310F versions prior to 9.00.
The U.S. Department of Justice (DOJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and depl
Recently, ANY.RUN researchers uncovered N0va, a new phishkit targeting organizations across North America and the EU, including government, technology, consulting, and healthcare. What makes N0va especially relevant for SOC leaders is how it spreads the attack across different la
Proofpoint identified four espionage-motivated threat actors employing a new exploit kit that chains multiple Chrome browser and Microsoft Windows vulnerabilities. Proofpoint is tracking the exploit kit used in this activity as BlueMoon. The first observed cluster using the BlueM
CVE-2026-15460 details a missing channel-state validation in the Zephyr Bluetooth Classic L2CAP receive path. The Bluetooth Classic (BR/EDR) L2CAP receive handler bt_l2cap_br_recv() in subsys/bluetooth/host/classic/l2cap_br.c dispatched inbound data PDUs based only on the destina
CVE-2026-88002: Open WebUI: Any authenticated user can hang the server via a cyclic chat message history. Open WebUI is an extensible, feature-rich, and user-friendly self-hosted AI platform. This vulnerability affects versions from 0.5.0 until 0.11.1. The core issue involves the
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. DAVID is the "Driver and Vehicle Information Database" platform operated by the
An exposed Vietnam-linked APIS database contained 220.8 million passenger and crew records, including passport and flight data. Researchers found an exposed Advance Passenger Information System (APIS) database containing 220.8 million passenger and crew records from January 2017
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. The malware shows signs of being a second-stage payload that was likely deployed
Grindr has agreed to pay £26m ($35.2m) to settle a UK group action over allegations that it unlawfully processed users' personal data and misused private information before 2020. The settlement was reached on September 2 and disclosed to investors two days later in a filing with
Last year, someone submitted a vulnerability report to a security address for a free software project I help to review. It contained 95 vulnerabilities, purportedly. Two or three of the 95 turned out to be real. Then came the second email: pay $100,000, or the report would go pub
Answering six weeks of research into Active Directory Rights Management Services (AD RMS) produced a compiled tool, four independent key-extraction paths, a 255-year non-rotatable private key sitting in a file on my desktop, and a plaintext copy of a document I had encrypted, ope
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. In a Saturday blog post, Mathspace CTO Alvin Savoy said that unknown attacke
Natural Resources Wales (NRW) says diversity data belonging to around 2,000 current and former employees who worked at the environmental regulator between April 2013 and March 2018 was exposed in a classic Freedom of Information (FoI) blunder. The Welsh government-sponsored body
JSCeal hides crypto-stealing malware in V8 bytecode, but researchers built a tool to decompile it and expose its advanced theft capabilities. JSCeal is a cryptocurrency stealer that Check Point Research has tracked since early 2025. JSCeal uses a clever trick. Instead of deliveri
Hackers have drained roughly $320 million in Bitcoin from the federation wallet backing the Liquid Network, while claiming to be the good guys. Liquid, a Bitcoin sidechain developed by Blockstream and used by exchanges and other financial institutions, said in a post on X on Sund
Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family's phones, laptops, printers, and smart-home devices. Now, a new investigation by Gamers Nexus, carried out with Level1Techs and i
Abuse of Node.js has undergone a revival. The Symantec Threat Hunter Team has observed the technique being used by multiple actors since February 2026, with victims including government departments, technology companies, and hotels. The technique's appeal is that node.exe (the bi
Recently, Huntress observed a strange pattern across unrelated endpoints within several different organizations that we protect. In late August, our Security Operations Center (SOC) sent out three critical incident reports for what looked like malicious ScreenConnect installation
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called **BraZetsu** that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive ma
Huntress is tracking a worm-like attack campaign that's installing rogue ScreenConnect clients on unrelated endpoints at various organizations. The attacks begin with social engineering, but the payload can then spread itself within an organization. The reserachers explain, "This
The SamlConsumer.getAuthenticatedUserFromSamlResponse() method was where the authentication decision happened. This method processed SAMLResponse values. The signature verification call was gated behind a null check on the certificate data. If an administrator configured SAML aut
A member of Serbia's student protest movement has been infected with NSO Group's Pegasus spyware through an iMessage zero-click exploit, according to a forensic investigation by the Citizen Lab and the SHARE Foundation. The Citizen Lab said it found high-confidence indicators of
JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications. Its campaign activity dates back to March 2024. Unlike ordinary JavaScript malware, JSCeal reaches the analyst after two transformations
The Virtualizor platform, for those unfamiliar, is a VPS management platform used by many hosting providers to deploy and manage virtual servers on KVM, Xen, LXC, OpenVZ, Proxmox and other virtualization platforms. It is not some tiny admin panel either. Virtualizor publicly list
Microsoft on Friday reported that a glitch is causing Windows to tell users that Microsoft Defender Antivirus is turned off when it is in fact fully functional, a bug that the vendor says it is working to fix. The glitch, which Microsoft says it working to fix, creates an attacke
Microsoft is investigating a widespread service issue causing authentication issues, connection problems, email delays and failures, and various other issues for Microsoft 365 customers. It first acknowledged this incident (tracked under EX1464935 in the admin center) at 5:30 PM
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. According to current information, the threat actor artificially inflated the price of Tectonic's
Bishop Fox staff identified one vulnerability in Traefik, an open-source reverse proxy and ingress controller widely deployed in container and Kubernetes environments. This vulnerability, described as "Request Read Timeout Not Applied to HTTP/3" and tracked as GHSA-7ghq-v6jf-g56c
An exposed open directory revealed months of activity from belonging to a Russian speaking Aurora ransomware affiliate, active against more than twenty organisations between April and July 2026. The directory included the operator's own toolkit and shell history alongside the Aur
Three major UK airports have been hit by a "cyber security incident" in which criminal hackers accessed the data of almost nine million people and demanded a ransom. Manchester Airports Group (MAG), which owns Manchester, East Midlands and London Stansted airports, said customers
The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) said it's responding to a "major" cybersecurity incident shortly after the Qilin ransomware gang posted the US federal law enforcement agency on its leak site. An ATF spokesperson told The Register the intruders access
We open a JavaScript artifact hoping for code, and instead get string arrays, strangely named functions, encoded URLs, runtime decoders, and eval statements. Obfuscated JavaScript is still code, but it is code with the useful context stripped out, the names ruined, the strings hi
But even something that seems to be "run-of-the-mill" at first glance can sometimes turn out to be quite interesting. One such message led to a URL which, instead of displaying a phishing page, caused the browser to remain effectively stuck for about 30 seconds, while utilization
As threat actors increasingly target Version Control Systems (VCS) to execute both targeted attacks and broad supply chain compromises (such as the campaigns attributed to TeamPCP), it is essential to understand available telemetry, recommended configurations, and available audit
Our story comes courtesy of Mia Morin, Editor & AI Quality Analyst at Intimeros, a site that rates, reviews, and evaluates AI companions. The trouble started during a redesign when one of Morin's colleagues was working on a test version of the site. The test site was supposed to
JVN#18593874 reports a vulnerability where the installer for Rakuten Kobo Desktop Application (Windows version) may insecurely load Dynamic Link Libraries. Specifically, the installer for Rakuten Kobo Desktop Application (Windows version) provided by Rakuten Kobo Inc. may insecur
From several independent reports, we've seen evidence of scammers using fake Android "interview" apps to target job seekers on the Indeed platform. Indeed is one of the world's largest employment websites, giving scammers access to a huge pool of potential victims, especially in
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. In a paper published by the University of Toronto, researchers say that GPUThor achieves far
Less expected is that an expired Visa card, too, could serve as an errant key into their bank account if it's left unattended or discarded intact, discovered by a fraudster, and "zombified" using a new technique researchers recently revealed. At the Usenix Cybersecurity Conferenc
Kubernetes 1.37 has just been released, bringing 67 enhancements. In terms of security, we've identified 19 changes with security implications spanning new security features to mount volumes, improvements on snapshots, authentication by default on webhooks, and more.
Eval injection in the Kenwood ITM file format driver of CHIRP, an open-source application for programming amateur radios, allows an attacker who can persuade a user to open a crafted radio file to execute arbitrary Python code with the privileges of that user. The affected path i
A critical vulnerability enabling half-click unauthenticated remote code execution (RCE) on Horde Groupware IMP has been detailed, stemming from a stored Cross-Site Scripting (XSS) flaw. The blog focuses on this stored XSS, which is chainable with other vulnerabilities. Researche
CVE-2026-58073 (CVSS 9.5) and CVE-2026-58072 (CVSS 9.0) are critical vulnerabilities in Veeam Service Provider Console, the multi-tenant console that managed service providers use to run backups across all of their customers. The first lets an unauthenticated network peer claim a