What's happening in security.
The latest breaches, malware, and privacy stories from BleepingComputer, The Hacker News, Krebs on Security, and Malwarebytes Labs — short excerpts, always linking back to the original source. Last refreshed 23 Sep 2026 · 16:40.
Fake Claude Max giveaway hides a Google account phishing trap
A convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.
ShinyHunters claims FBI breach was revenge for “false” report
The extortion group says it stole sensitive data on FBI agents and job applicants, and wants the bureau to retract a warning about its tactics.
Some cheap smart glasses are a security disaster
Tests found that some cheap smart glasses can be hijacked over Bluetooth, exposing their owners’ photos, videos, and personal data.
Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor
A simple terminal command can hijack Muse and use its extensive permissions to spy on Mac users and control their connected accounts.
Researchers used Claude to hack OpenAI
Claude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.
The AI plot to scan and destroy books (Lock and Code S07E19)
This week on the Lock and Code podcast, we speak with Emanuel Maiberg about Amazon's effort to scan and destroy rare books for AI training.
The fake sites using a cheap toolkit to sell $2,000 AI subscriptions
More than 100 linked sites use a $249 toolkit to turn copied product names and unfamiliar AI brands into paid subscriptions.
Gemini’s breach of real companies exposes an AI guardrail problem
Gemini crossed the boundaries of a capture-the-flag test and accessed systems belonging to three real companies.
ShinyHunters hacks rival extortion gang and takes over its dark web site
Hackers hacked the hackers as a feud between two cybercrime groups escalated, leaving ShinyHunters with the upper hand over rival Clop.
A week in security (September 14 – September 20)
A list of topics we covered in the week of September 14 to September 20 of 2026
New Android malware uses AI to steal bank logins and PINs
RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.
Did an AI really try to break free from human control?
An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.
Fake parcel delivery messages steal your card and bank details
Parcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.
Flock cameras are tracking people as well as cars
Two reports reveal how Flock’s license plate camera network tracks people’s movements while oversight continues to lag.
Revolut phishing texts appear days after data breach
Revolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.
12 celebrity deepfake websites seized by Manhattan DA
The largest known celebrity deepfake seizure has taken 12 websites offline, disrupting access to videos depicting some 1,200 people.
T-Mobile rewards points expiry texts are a phishing scam
A large phishing campaign is using fake T-Mobile rewards points and looming expiry dates to pressure recipients into clicking malicious links.
Google Pixel owners urged to patch actively exploited modem flaw
Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.
AI helps scammers build convincing antivirus renewal pages
A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.
How to opt out of AI chatbot training
ChatGPT contractors are reviewing real users' conversations. Here’s how to stop AI companies using your chats for model training.