{"updated":1789144184252,"items":[{"title":"Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain","summary":"From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.","cat":"research","ts":1789141707000,"source":"Dark Reading","link":"https://www.darkreading.com/cyberattacks-data-breaches/papercut-ai-swarm-attack-cyber-kill-chain"},{"title":"Claude Used to Automate Exploitation and Data Theft Across Multiple Victims","summary":"Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and Au","cat":"vulnerability","ts":1789136987000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html"},{"title":"Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection","summary":"Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. ","cat":"nation-state","ts":1789135820000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html"},{"title":"Your Critical Vulnerabilities Might Not Be Your Biggest Risk","summary":"Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually cre","cat":"vulnerability","ts":1789126200000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/your-critical-vulnerabilities-might-not.html"},{"title":"Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors","summary":"Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security ","cat":"vulnerability","ts":1789111865000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html"},{"title":"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor","summary":"A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security c","cat":"vulnerability","ts":1789110849000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html"},{"title":"PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws","summary":"PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exp","cat":"vulnerability","ts":1789109178000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html"},{"title":"Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware","summary":"Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilitie","cat":"ransomware","ts":1789107599000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html"},{"title":"Indonesia Hit by Android Banking App-Cloning Campaign","summary":"The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.","cat":"vulnerability","ts":1789088400000,"source":"Dark Reading","link":"https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign"},{"title":"Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data","summary":"Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.","cat":"ransomware","ts":1789072563000,"source":"Dark Reading","link":"https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data"},{"title":"ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories","summary":"A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phi","cat":"vulnerability","ts":1789062458000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html"},{"title":"Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit","summary":"The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.","cat":"vulnerability","ts":1789054152000,"source":"Dark Reading","link":"https://www.darkreading.com/vulnerabilities-threats/nightmare-eclipse-strikes-again-shieldcrash-windows-exploit"},{"title":"Google Play Early Access Abused to Push Thousands of Deceptive Android Apps","summary":"Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been","cat":"research","ts":1789051007000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html"},{"title":"Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE","summary":"Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to ru","cat":"vulnerability","ts":1789040705000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html"},{"title":"PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances","summary":"A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and b","cat":"vulnerability","ts":1789040513000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html"},{"title":"Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks","summary":"The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report publis","cat":"malware","ts":1789040023000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html"},{"title":"CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requi","cat":"vulnerability","ts":1789036606000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html"},{"title":"Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example \"sk-1234\" Admin Key","summary":"Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gatewa","cat":"breach","ts":1789024375000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html"},{"title":"Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6","summary":"Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised c","cat":"research","ts":1789023841000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html"},{"title":"EU Cyber Resilience Act to Enforce New Reporting Requirements","summary":"Starting Friday, European organizations will have just 24 hours to notify the EU government any time they discover serious product security incidents.","cat":"research","ts":1789023600000,"source":"Dark Reading","link":"https://www.darkreading.com/cybersecurity-operations/eu-cyber-resilience-act-reporting-requirements"},{"title":"Mythos Vulnerability Firehose Hits a Human Bottleneck","summary":"An analysis of Project Glasswing findings shows only a fraction of the bugs it has discovered have reached disclosure, and an even smaller number have been fixed.","cat":"vulnerability","ts":1788988795000,"source":"Dark Reading","link":"https://www.darkreading.com/application-security/mythos-vulnerability-firehose-hits-human-bottleneck"},{"title":"US Government Accuses Chinese AI Firms of Distilling Frontier Models","summary":"US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.","cat":"research","ts":1788983270000,"source":"Dark Reading","link":"https://www.darkreading.com/application-security/us-government-chinese-ai-firms-distilling-frontier-models"},{"title":"U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto","summary":"The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram cha","cat":"research","ts":1788978365000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html"},{"title":"Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week","summary":"Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows","cat":"vulnerability","ts":1788971645000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html"},{"title":"Identity-Based AI Attack Threatens Security of Enterprise Data","summary":"Workflow identity hijacking can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.","cat":"research","ts":1788964784000,"source":"Dark Reading","link":"https://www.darkreading.com/threat-intelligence/identity-based-ai-attack-security-enterprise-data"},{"title":"Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA","summary":"Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create \"stolen keys\" that grant illicit access to tools from model providers like Google, Anthro","cat":"breach","ts":1788963835000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html"},{"title":"Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE","summary":"A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability sc","cat":"breach","ts":1788955056000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/webinar-learn-how-to-answer-are-we.html"},{"title":"DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval","summary":"A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an ag","cat":"vulnerability","ts":1788952627000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html"},{"title":"Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets","summary":"Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from th","cat":"breach","ts":1788950584000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html"},{"title":"U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok","summary":"U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting \"systematic extraction\" of proprietary functionalities and capabilities of Am","cat":"nation-state","ts":1788946346000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html"}]}