On-site only · nothing emailed

What's happening in security.

The latest breaches, malware, and privacy stories from BleepingComputer, The Hacker News, Krebs on Security, and Malwarebytes Labs — short excerpts, always linking back to the original source. Last refreshed 23 Sep 2026 · 15:55.

BleepingComputer

InfraTrust report warns network management systems under attack

Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]

23 Sep 2026 · 14:35
The Hacker News

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwo...

23 Sep 2026 · 14:17
BleepingComputer

How One Kubernetes YAML Can Hand Over a GCP Organization

A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem c...

23 Sep 2026 · 14:01
The Hacker News

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and mac...

23 Sep 2026 · 13:52
Malwarebytes Labs

Fake Claude Max giveaway hides a Google account phishing trap

A convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.

23 Sep 2026 · 12:45
BleepingComputer

Arista patches actively exploited VeloCloud Orchestrator zero-day

Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]

23 Sep 2026 · 12:29
The Hacker News

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and...

23 Sep 2026 · 12:16
Malwarebytes Labs

ShinyHunters claims FBI breach was revenge for “false” report

The extortion group says it stole sensitive data on FBI agents and job applicants, and wants the bureau to retract a warning about its tactics.

23 Sep 2026 · 12:03
The Hacker News

545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent

Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, an...

23 Sep 2026 · 11:47
The Hacker News

Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests

Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step u...

23 Sep 2026 · 11:47
BleepingComputer

Microsoft: September Windows updates break Always On VPN connections

Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. [...]

23 Sep 2026 · 11:18
The Hacker News

Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS scor...

23 Sep 2026 · 11:12
The Hacker News

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth auth...

23 Sep 2026 · 08:29
The Hacker News

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the...

23 Sep 2026 · 08:29
BleepingComputer

Ryuk ransomware member sentenced to 24 months in prison

An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]

23 Sep 2026 · 08:20
BleepingComputer

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. [...]

23 Sep 2026 · 07:17
The Hacker News

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an atta...

23 Sep 2026 · 07:04
The Hacker News

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold ve...

23 Sep 2026 · 05:30
BleepingComputer

Rogue external MFA providers can steal passwords during logins

Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]

22 Sep 2026 · 21:45
BleepingComputer

Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]

22 Sep 2026 · 21:40
BleepingComputer

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]

22 Sep 2026 · 20:35
BleepingComputer

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]

22 Sep 2026 · 19:13
The Hacker News

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service...

22 Sep 2026 · 18:29
BleepingComputer

New ClosedQuorum Windows malware uses AI for attack decisions

A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [...]

22 Sep 2026 · 18:04
The Hacker News

WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code....

22 Sep 2026 · 18:03
The Hacker News

Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harv...

22 Sep 2026 · 17:58
BleepingComputer

Reducing shadow IT visibility gaps with Wazuh

Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can h...

22 Sep 2026 · 17:17
The Hacker News

Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. Distr...

22 Sep 2026 · 17:03
The Hacker News

Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, t...

22 Sep 2026 · 16:41
BleepingComputer

Check Point warns of Management Server zero-day exploited in attacks

Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. [...]

22 Sep 2026 · 16:32
The Hacker News

Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no C...

22 Sep 2026 · 16:14
Malwarebytes Labs

Some cheap smart glasses are a security disaster

Tests found that some cheap smart glasses can be hijacked over Bluetooth, exposing their owners’ photos, videos, and personal data.

22 Sep 2026 · 15:04
BleepingComputer

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [...]

22 Sep 2026 · 15:00
BleepingComputer

Webinar tomorrow: Inside real-world Google Workspace breaches

Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and respon...

22 Sep 2026 · 12:57
The Hacker News

AI Agents Are Rewriting the Rules of Lateral Movement

Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try se...

22 Sep 2026 · 12:30
The Hacker News

New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacke...

22 Sep 2026 · 12:29
The Hacker News

DORA Year Two: Can Your SOC Actually See the Attack?

When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third...

22 Sep 2026 · 11:45
The Hacker News

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allo...

22 Sep 2026 · 11:38
The Hacker News

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber...

22 Sep 2026 · 11:17
Malwarebytes Labs

Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor

A simple terminal command can hijack Muse and use its extensive permissions to spy on Mac users and control their connected accounts.

22 Sep 2026 · 10:53
Malwarebytes Labs

Researchers used Claude to hack OpenAI

Claude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.

22 Sep 2026 · 09:51
The Hacker News

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent se...

22 Sep 2026 · 09:38
The Hacker News

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate throug...

22 Sep 2026 · 07:52
The Hacker News

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by cha...

22 Sep 2026 · 06:33
The Hacker News

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw...

22 Sep 2026 · 06:03
The Hacker News

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitat...

22 Sep 2026 · 05:31
Malwarebytes Labs

The AI plot to scan and destroy books (Lock and Code S07E19)

This week on the Lock and Code podcast, we speak with Emanuel Maiberg about Amazon's effort to scan and destroy rare books for AI training.

21 Sep 2026 · 16:30
Malwarebytes Labs

The fake sites using a cheap toolkit to sell $2,000 AI subscriptions

More than 100 linked sites use a $249 toolkit to turn copied product names and unfamiliar AI brands into paid subscriptions.

21 Sep 2026 · 15:38
Malwarebytes Labs

Gemini’s breach of real companies exposes an AI guardrail problem

Gemini crossed the boundaries of a capture-the-flag test and accessed systems belonging to three real companies.

21 Sep 2026 · 14:21
Malwarebytes Labs

ShinyHunters hacks rival extortion gang and takes over its dark web site

Hackers hacked the hackers as a feud between two cybercrime groups escalated, leaving ShinyHunters with the upper hand over rival Clop.

21 Sep 2026 · 10:17
Malwarebytes Labs

A week in security (September 14 – September 20)

A list of topics we covered in the week of September 14 to September 20 of 2026

21 Sep 2026 · 07:02
Malwarebytes Labs

New Android malware uses AI to steal bank logins and PINs

RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.

18 Sep 2026 · 15:37
Malwarebytes Labs

Did an AI really try to break free from human control?

An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.

18 Sep 2026 · 14:18
Malwarebytes Labs

Fake parcel delivery messages steal your card and bank details

Parcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.

18 Sep 2026 · 07:44
Malwarebytes Labs

Flock cameras are tracking people as well as cars

Two reports reveal how Flock’s license plate camera network tracks people’s movements while oversight continues to lag.

17 Sep 2026 · 18:46
Malwarebytes Labs

Revolut phishing texts appear days after data breach

Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.

17 Sep 2026 · 14:07
Malwarebytes Labs

12 celebrity deepfake websites seized by Manhattan DA

The largest known celebrity deepfake seizure has taken 12 websites offline, disrupting access to videos depicting some 1,200 people.

17 Sep 2026 · 11:20
Malwarebytes Labs

T-Mobile rewards points expiry texts are a phishing scam

A large phishing campaign is using fake T-Mobile rewards points and looming expiry dates to pressure recipients into clicking malicious links.

17 Sep 2026 · 10:44
Krebs on Security

Data Broker Radaris Loses Domains in Privacy Fight

The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit a...

16 Sep 2026 · 18:14
Malwarebytes Labs

Google Pixel owners urged to patch actively exploited modem flaw

Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.

16 Sep 2026 · 10:39
Malwarebytes Labs

AI helps scammers build convincing antivirus renewal pages

A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.

16 Sep 2026 · 08:41
Malwarebytes Labs

How to opt out of AI chatbot training

ChatGPT contractors are reviewing real users' conversations. Here’s how to stop AI companies using your chats for model training.

15 Sep 2026 · 15:41
Krebs on Security

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the disc...

08 Sep 2026 · 21:44
Krebs on Security

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are avail...

01 Sep 2026 · 22:40
Krebs on Security

Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement rele...

27 Aug 2026 · 11:04
Krebs on Security

Who’s Tracking You? Use This New Service to Find Out

It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditio...

14 Aug 2026 · 11:24
Krebs on Security

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly d...

11 Aug 2026 · 21:28
Krebs on Security

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data stora...

06 Aug 2026 · 17:00
Krebs on Security

Read This Before You Buy That TV Streaming Stick

Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to stranger...

30 Jul 2026 · 16:49
Krebs on Security

LG to Ban Residential Proxies from Smart TV Apps

The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found...

22 Jul 2026 · 01:10
Krebs on Security

Microsoft Patches a Record 570 Security Flaws

Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tu...

14 Jul 2026 · 19:22