Latest news

  1. Threat Intel via The Record

    Nations take action on North Korean IT workers after UN report

    A report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in…

  2. Vulnerabilities via SecurityWeek

    In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

    Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug…

  3. AI Security via Malwarebytes Labs

    Did an AI really try to break free from human control?

    Amid discussions about slowing down AI development, the Telegraph ran the headline: “OpenAI sounds alarm after bot tries to break free from human control.” That headline…

  4. Vulnerabilities via Canadian Centre for Cyber Security

    [Control systems] Advantech security advisory (AV26-937)

    Serial number: AV26-937 Date: September 18, 2026 As of September 4, 2026, Advantech is affected by vulnerabilities in the following products: EKI-1242EIMS Prior to or…

  5. AI Security via TechCrunch

    Researchers used Anthropic’s Claude to hack into OpenAI

    Security researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an internal code…

  6. via BleepingComputer

    Secure enterprise sharing with access reviews for Microsoft 365

    Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still…

  7. Vulnerabilities via Microsoft Security Response Center

    CVE-2026-88097 Microsoft Edge (Chromium-based) Elevation of Privilege Vulnerability

    Use after free in Microsoft Edge (Chromium-based) allows an unauthorized attacker to elevate privileges locally.

  8. via BleepingComputer

    Microsoft Teams will let admins block custom file extensions

    Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements.

  9. Vulnerabilities via Cisco PSIRT

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Logging Denial of Service Vulnerability

    A vulnerability in the system rate-limiting process for syslog message 419002 of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure…

  10. Vulnerabilities via Cisco PSIRT

    Cisco Secure Firewall Adaptive Security Appliance, Secure Firewall Threat Defense, and Secure Firewall Management Center Software Hardening Release: September 2026

    As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Firewall Adaptive Security Appliance (ASA) Software, Cisco Secure…

  11. Vulnerabilities via Cisco PSIRT

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software for Secure Firewall 3100 and 4200 Series DTLS Denial of Service Vulnerability

    A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense…

  12. Vulnerabilities via Cisco PSIRT

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software IKEv2 Certificate Authentication Denial of Service Vulnerability

    A vulnerability in the certification authentication feature of Internet Key Exchange version 2 (IKEv2) for Cisco Secure Firewall Adaptive Security Appliance (ASA)…

  13. Vulnerabilities via Cisco PSIRT

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Object Group Access Control List Bypass Vulnerabilities

    Multiple vulnerabilities in the access control list (ACL) Object Group Search (OGS) implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software…

  14. Vulnerabilities via Cisco PSIRT

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software TCP DNS Denial of Service Vulnerability

    A vulnerability in the DNS over TCP implementation of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD)…

  15. Vulnerabilities via Cisco PSIRT

    Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software EIGRP Denial of Service Vulnerability

    A vulnerability in the EIGRP implementation in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software…

  16. Vulnerabilities via Canadian Centre for Cyber Security

    Grafana security advisory (AV26-936)

    Serial number: AV26-936 Date: September 18, 2026 As of September 17, 2026, Grafana is affected by vulnerabilities in the following product: Grafana OSS Version 12.3.0 to…

  17. AI Security via Ars Technica

    Researchers used Claude to hack OpenAI

    Cyber researchers broke into OpenAI using its key rival Anthropic’s software, highlighting vulnerabilities in the ChatGPT maker’s security as leading AI companies face…

  18. Ransomware via Infosecurity Magazine

    New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing

    Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks

  19. Threat Intel via The Record

    Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia

    Over the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.

  20. via BleepingComputer

    Webinar: Which Google Workspace security controls actually matter?

    Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world…