Latest news
-
Vulnerabilities via Canadian Centre for Cyber Security
Google security advisory (AV26-926)
Serial number: AV26-926 Date: September 16, 2026 As of September 15, 2026, Google is affected by vulnerabilities in the following product: Chrome Prior to 153.0.8010.48…
-
Vulnerabilities via CERT/CC
VU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization control
Overview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the…
-
Vulnerabilities via Canadian Centre for Cyber Security
Android security advisory – September 2026 monthly rollup (AV26-920) – Update 1
Serial Number: AV26-920 Date: September 14, 2026 Updated: September 16, 2026 As of September 8, 2026, Android published a security bulletin to address vulnerabilities…
-
Vulnerabilities via Chrome Releases
Chrome Beta for Desktop Update
The Chrome team is excited to announce the promotion of Chrome 155 to the Beta channel for Windows, Mac and Linux. Chrome 155.0.8059.5 contains our usual under-the-hood…
-
Breaches via HIPAA Journal
House Subcommittee on Health Examines Healthcare Cybersecurity Proposals
On September 15, 2026, the United States House Energy and Commerce Committee Subcommittee on Health held a legislative hearing on proposals to improve healthcare…
-
Threat Intel via Eclypsium
BTS #82 - Firmware Analysis, Linux Malware, Future of AI
Below the Surface episode 82 was recorded on September 10, 2026, with host Paul Asadoorian joined by Vlad Babkin and Chase Snyder. The conversation moves across several…
-
AI Security via Dark Reading
BragJack Attack Can Turn a Browser's Agentic AI Against It
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
-
Vulnerabilities via Chrome Releases
Chrome Beta for iOS Update
Hi everyone! We've just released Chrome Beta 155 (155.0.8059.2) for iOS; it'll become available on App Store in the next few days. You can see a partial list of the…
-
AI Security via Simon Willison
Quoting Mustafa Suleyman
We should not treat models as though they have feelings, preferences, rights, or any entitlement to our welfare. Consciousness is the foundation of our ethical, legal…
-
Threat Intel via SpecterOps
Ghostwriter v7.3.0: A Fresh New Look
TL;DR: The upcoming Ghostwriter v7.3.0 release brings a major UI refresh to nearly every part of the application. The new design is easier on the eyes, more accessible…
-
Vulnerabilities via CERT/CC
VU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environment
Overview A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation…
-
Threat Intel via Zscaler ThreatLabz
Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH
IntroductionIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since…
-
Threat Intel via Infosecurity Magazine
PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells
-
Breaches via CyberScoop
Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks
The Coast Guard and FBI boarded two foreign vessels coming to the United States last month to investigate potential cyberattacks on the ships, according to a joint…
-
Vulnerabilities via TechCrunch
Google says some Pixel phone owners were hacked in zero-day attacks
The Pixel phone maker said there are indications that a bug in the phone's modem "may be under limited, targeted exploitation."
-
Vulnerabilities via Qualys
Oracle Critical Security Patch Update, September 2026 Review
Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities…
-
Vulnerabilities via Cisco PSIRT
Cisco Advance Notification for Publication of September 16, 2026, Security Advisories
On September 16, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the advisories that are listed in the following tables. To remediate these…
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software SSL VPN Denial of Service Vulnerability
Update for September 16, 2026: The original 1.0 version of this advisory was specific to the Cisco Adaptive Security Virtual Appliance (ASAv) and Cisco Secure Firewall…
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Firewall Management Center Software Static Credential Vulnerability
A vulnerability in the web interface of Cisco Secure Firewall Management Center (FMC) Software could allow an unauthenticated, remote attacker to log in to an affected…
-
Vulnerabilities via Cisco PSIRT
Cisco Secure Firewall Adaptive Security Appliance and Secure Firewall Threat Defense Software Remote Access SSL VPN Denial of Service Vulnerability
A vulnerability in the Remote Access SSL VPN service for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD)…
