Latest news

  1. Threat Intel via Malwarebytes Labs

    Fake parcel delivery messages steal your card and bank details

    Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a…

  2. Vulnerabilities via BleepingComputer

    Microsoft fixes broken copy and paste for Excel 2016 users

    Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update.

  3. AI Security via SecurityWeek

    MIND Secures $72 Million for AI-Powered DLP

    The company will use the funding to accelerate platform development and expand its presence in key enterprise markets.

  4. Vulnerabilities via SecurityWeek

    Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

    Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.

  5. Breaches via HIPAA Journal

    Ambry Genetics Pays $700,000 Penalty to Settle HIPAA Violations

    The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) and the Aliso Viejo, California-based genetic testing and clinical genomics company…

  6. AI Security via Dark Reading

    AI Agent Breaches Spanish Organization, Modifies Personal Data

    AI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.

  7. Threat Intel via The Hacker News

    RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

    Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial…

  8. Breaches via HIPAA Journal

    McKesson Cyberattack: Stolen Data Includes 6.4 Million Unique Email Addresses

    McKesson, a major U.S. wholesale medical supplies & equipment, pharmaceutical distribution, and healthcare technology solutions company, continues to investigate a…

  9. Vulnerabilities via Help Net Security

    Abandoned IoT apps keep sending sensitive data to broken servers

    Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving…

  10. AI Security via Help Net Security

    Hardcoded MCP credentials found in public GitHub files

    Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to…

  11. Breaches via Help Net Security

    98% of fraudulent hires have company credentials by the time they’re caught

    A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report…

  12. Vulnerabilities via Zero Day Initiative

    ZDI-26-718: Cisco Identity Services Engine MnTRESTLivelogService XML External Entity Processing Information Disclosure Vulnerability

    This vulnerability allows remote attackers to disclose sensitive information on affected installations of Cisco Identity Services Engine. Authentication is required to…

  13. Vulnerabilities via Zero Day Initiative

    ZDI-26-717: Cisco Identity Services Engine AlarmMessageDiskQueue Deserialization of Untrusted Data Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit…

  14. Vulnerabilities via Zero Day Initiative

    ZDI-26-716: Cisco Identity Services Engine createDBLink Command Injection Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Cisco Identity Services Engine. Authentication is required to exploit…

  15. Vulnerabilities via Zero Day Initiative

    ZDI-26-715: Linux Mint Xreader PDF File Parsing Type Confusion Remote Code Execution Vulnerability

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of Linux Mint Xreader. User interaction is required to exploit this…

  16. Vulnerabilities via Zero Day Initiative

    ZDI-CAN-31049: RARLAB

    A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by 'Landon Peng (Lunbun LLC)' was reported to the affected vendor on: 2026-09-18…

  17. Breaches via Help Net Security

    Most WordPress pros still lack a breach recovery plan

    Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The…

  18. AI Security via Help Net Security

    New infosec products of the week: September 18, 2026

    Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr…

  19. Threat Intel via The Record

    North Korean hackers infect thousands of devices across 100 countries as part of ‘WaterPlum’ campaign

    The FBI and Defense Department partnered with Japan’s National Police Agency and law enforcement agencies in Australia and Germany on a new advisory about “WaterPlum” —…

  20. AI Security via The Register

    USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech

    Think tank the Australian Strategic Policy Institute (ASPI) has warned that Venezuela is poised to adopt Chinese AI systems to enhance surveillance systems that already…