{"updated":1789420553668,"items":[{"title":"Maximum Severity GitLab Flaw Puts Supply Chains at Risk","summary":"CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.","cat":"vulnerability","ts":1789417162000,"source":"Dark Reading","link":"https://www.darkreading.com/cyberattacks-data-breaches/maximum-severity-gitlab-flaw-supply-chains-risk"},{"title":"New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing","summary":"Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the proce","cat":"research","ts":1789408933000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/new-ddrop-attack-breaks-intel-tdx-and.html"},{"title":"3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials","summary":"An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCen","cat":"malware","ts":1789408909000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/3bb-attacker-used-meshcentral-backdoor.html"},{"title":"Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports","summary":"A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In T","cat":"vulnerability","ts":1789408696000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/telegram-desktop-flaw-lets-hidden.html"},{"title":"Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries","summary":"A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as p","cat":"vulnerability","ts":1789404990000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/red-heron-exploits-gitea-rce-to.html"},{"title":"Anthropic CEO: Time to Shift From Improving to Controlling AI","summary":"Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?","cat":"research","ts":1789404070000,"source":"Dark Reading","link":"https://www.darkreading.com/cyber-risk/anthropic-ceo-shift-from-improving-to-controlling-ai"},{"title":"WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution","summary":"WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential securit","cat":"research","ts":1789401604000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/wordpress-adds-automated-plugin-reviews.html"},{"title":"⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits","summary":"AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great","cat":"vulnerability","ts":1789396834000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/weekly-recap-rogue-ai-agents-wechat.html"},{"title":"AI Changed the Exposure Problem. Validation Needs to Change With It.","summary":"There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much g","cat":"vulnerability","ts":1789387080000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/ai-changed-exposure-problem-validation.html"},{"title":"Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users","summary":"A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named \"Twitch","cat":"breach","ts":1789370679000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html"},{"title":"Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data","summary":"Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social eng","cat":"research","ts":1789294308000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/attackers-use-passkey-phishing-to.html"},{"title":"CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV","summary":"The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vuln","cat":"vulnerability","ts":1789228485000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html"},{"title":"When the Whole Company Adopts AI: What It Does to Your SOC","summary":"Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents","cat":"research","ts":1789208684000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html"},{"title":"OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers","summary":"The \"major malicious attack\" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Vo","cat":"vulnerability","ts":1789204076000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html"},{"title":"Threat Actor Generates 1M Personalized Fraud Emails in 3 Days","summary":"Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.","cat":"research","ts":1789154468000,"source":"Dark Reading","link":"https://www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days"},{"title":"CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate","summary":"A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.","cat":"breach","ts":1789152243000,"source":"Dark Reading","link":"https://www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate"},{"title":"SpiderSilk Hunts External Threats With AI-Based Scanner","summary":"The Dubai-based threat detection startup uses artificial intelligence tools to scan billions of IP addresses to find exposed assets, leaked data, and zero-day vulnerabilities.","cat":"breach","ts":1789151248000,"source":"Dark Reading","link":"https://www.darkreading.com/endpoint-security/spidersilk-hunts-external-threats-ai-scanning"},{"title":"Why AI Is So Good at Scamming Humans","summary":"Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.","cat":"research","ts":1789150446000,"source":"Dark Reading","link":"https://www.darkreading.com/cyber-risk/ai-scamming-humans"},{"title":"AI Governance Can't Wait","summary":"Adversaries can manipulate AI defensive reasoning to silently compromise target networks.","cat":"research","ts":1789146656000,"source":"Dark Reading","link":"https://www.darkreading.com/cyber-risk/ai-governance-cannot-wait"},{"title":"GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure","summary":"GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in","cat":"vulnerability","ts":1789144218000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html"},{"title":"Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks","summary":"Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhi","cat":"nation-state","ts":1789143329000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html"},{"title":"Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain","summary":"From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.","cat":"research","ts":1789141707000,"source":"Dark Reading","link":"https://www.darkreading.com/cyberattacks-data-breaches/papercut-ai-swarm-attack-cyber-kill-chain"},{"title":"Claude Used to Automate Exploitation and Data Theft Across Multiple Victims","summary":"Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and Au","cat":"vulnerability","ts":1789136987000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html"},{"title":"Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection","summary":"Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. ","cat":"nation-state","ts":1789135820000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html"},{"title":"Your Critical Vulnerabilities Might Not Be Your Biggest Risk","summary":"Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually cre","cat":"vulnerability","ts":1789126200000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/your-critical-vulnerabilities-might-not.html"},{"title":"Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors","summary":"Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security ","cat":"vulnerability","ts":1789111865000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html"},{"title":"China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor","summary":"A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security c","cat":"vulnerability","ts":1789110849000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html"},{"title":"PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws","summary":"PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exp","cat":"vulnerability","ts":1789109178000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html"},{"title":"Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware","summary":"Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilitie","cat":"ransomware","ts":1789107599000,"source":"The Hacker News","link":"https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html"},{"title":"Indonesia Hit by Android Banking App-Cloning Campaign","summary":"The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.","cat":"vulnerability","ts":1789088400000,"source":"Dark Reading","link":"https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign"}]}