On-site only · nothing emailed

What's happening in security.

The latest breaches, malware, and privacy stories from BleepingComputer, The Hacker News, Krebs on Security, and Malwarebytes Labs — short excerpts, always linking back to the original source. Last refreshed 23 Sep 2026 · 16:40.

BleepingComputer

Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers

A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]

23 Sep 2026 · 16:20
BleepingComputer

InfraTrust report warns network management systems under attack

Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]

23 Sep 2026 · 14:35
BleepingComputer

How One Kubernetes YAML Can Hand Over a GCP Organization

A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem c...

23 Sep 2026 · 14:01
BleepingComputer

Arista patches actively exploited VeloCloud Orchestrator zero-day

Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]

23 Sep 2026 · 12:29
BleepingComputer

Microsoft: September Windows updates break Always On VPN connections

Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. [...]

23 Sep 2026 · 11:18
BleepingComputer

Ryuk ransomware member sentenced to 24 months in prison

An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]

23 Sep 2026 · 08:20
BleepingComputer

F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks

F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. [...]

23 Sep 2026 · 07:17
BleepingComputer

Rogue external MFA providers can steal passwords during logins

Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]

22 Sep 2026 · 21:45
BleepingComputer

Sweden fines Miljödata $183,000 over breach affecting 2.2 million

Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]

22 Sep 2026 · 21:40
BleepingComputer

Chinese hackers exploit WordPress, Zyxel flaws to steal govt data

A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]

22 Sep 2026 · 20:35
BleepingComputer

ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]

22 Sep 2026 · 19:13
BleepingComputer

New ClosedQuorum Windows malware uses AI for attack decisions

A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [...]

22 Sep 2026 · 18:04
BleepingComputer

Reducing shadow IT visibility gaps with Wazuh

Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can h...

22 Sep 2026 · 17:17
BleepingComputer

Check Point warns of Management Server zero-day exploited in attacks

Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. [...]

22 Sep 2026 · 16:32
BleepingComputer

EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [...]

22 Sep 2026 · 15:00
BleepingComputer

Webinar tomorrow: Inside real-world Google Workspace breaches

Tomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and respon...

22 Sep 2026 · 12:57