Latest news
-
Threat Intel via The Record
Nations take action on North Korean IT workers after UN report
A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in…
-
Vulnerabilities via SecurityWeek
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug…
-
AI Security via Malwarebytes Labs
Did an AI really try to break free from human control?
Amid discussions about slowing down AI development, the Telegraph ran the headline: “OpenAI sounds alarm after bot tries to break free from human control.” That headline…
-
Vulnerabilities via Canadian Centre for Cyber Security
[Control systems] Advantech security advisory (AV26-937)
Serial number: AV26-937 Date: September 18, 2026 As of September 4, 2026, Advantech is affected by vulnerabilities in the following products: EKI-1242EIMS Prior to or…
-
AI Security via TechCrunch
Researchers used Anthropic’s Claude to hack into OpenAI
Security researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an internal code…
-
via BleepingComputer
Secure enterprise sharing with access reviews for Microsoft 365
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still…
-
Vulnerabilities via Microsoft Security Response Center
CVE-2026-88097 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability
Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.
-
via BleepingComputer
Microsoft Teams will let admins block custom file extensions
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements.
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability
A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure…
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure…
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability
A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense…
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability
A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA)…
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities
Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software…
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability
A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD)…
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability
A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software…
-
Vulnerabilities via Canadian Centre for Cyber Security
Grafana security advisory (AV26-936)
Serial number: AV26-936 Date: September 18, 2026 As of September 17, 2026, Grafana is affected by vulnerabilities in the following product: Grafana OSS Version 12.3.0 to…
-
AI Security via Ars Technica
Researchers used Claude to hack OpenAI
Cyber researchers broke into OpenAI using its key rival Anthropic’s software, highlighting vulnerabilities in the ChatGPT maker’s security as leading AI companies face…
-
Ransomware via Infosecurity Magazine
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks
-
Threat Intel via The Record
Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.
-
via BleepingComputer
Webinar: Which Google Workspace security controls actually matter?
Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world…
