Feeds last updated @: UTC - 04:15 - 13/09/2026
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
Read more of this story at Slashdot.
https://www.theregister.com/security
wasm_rt_allocate_funcref_table of the file wasm2c/wasm-rt-impl-tableops.inc of the component Funcref Table. This manipulation causes improper input validation. This vulnerability is tracked as CVE-2026-90648. The attack is possible to be carried out remotely. No exploit exists.https://www.debian.org/security/
https://msrc.microsoft.com/update-guide/vulnerability
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-87491
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-76023
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-76022
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-76021
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-76019
https://www.ncsc.nl/alerts/kritieke-kwetsbaarheid-in-gitlab-wordt-actief-misbruikt-update-nu
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3306
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-3229
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2382
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2208
https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-1870
https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html
https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html
https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html
https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html
https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html
https://techrepublic.com/topic/security
Anthropic says researchers used Claude for biological work that could support weapons development, exposing new challenges for AI safeguards.
The post Anthropic Says Claude Used in Possible Bioweapon Research appeared first on TechRepublic.
https://www.techrepublic.com/article/news-anthropic-claude-bioweapon-research/
ENISA has gained access to Anthropic’s Mythos 5, giving EU officials a chance to independently test the cyber AI after months of negotiations.
The post EU Gets Access to Anthropic Cyber AI — But Not Its Newest Model appeared first on TechRepublic.
https://www.techrepublic.com/article/news-enisa-anthropic-mythos-5-cyber-ai-access-europe-emea/
See what you missed in Daily Tech Insider from Sept. 7–11.
The post AI Agents, Foldables, Cyberthreats, and Chip Deals Define This Week in Tech appeared first on TechRepublic.
US agencies accuse six Chinese AI firms of distilling frontier models and recommend new defenses that could affect enterprise AI access and API use.
The post US Accuses Six Chinese AI Firms of Distilling Frontier ModelsUS Accuses Six Chinese AI Firms of Distilling Frontier Models appeared first on TechRepublic.
https://www.techrepublic.com/article/news-chinese-ai-model-distillation-apac-china/
CISA’s ChatGPT incident exposes a growing AI governance gap as enterprises struggle to define who is accountable for actions taken by AI agents.
The post CISA’s ChatGPT Incident Exposes a Bigger AI Governance Problem appeared first on TechRepublic.
https://www.techrepublic.com/article/news-cisa-chatgpt-ai-agent-governance-accountability/
https://www.bleepingcomputer.com/
https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/
https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/
https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/
https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/
https://krebsonsecurity.com/2026/08/microsoft-plugs-nearly-400-security-holes/
I think what really resonates with me this week is being able to completely turn the tables on perceptions around things like AI being the big bad hacking tool the news would have you believe. There's the stat I talk about where it's had literally 0%
I've started playing around with YouTube's "create video thumbnail", which hopefully will give me back a bit of time in my day (it used to be a manual job in Photoshop) and be a bit more interesting. And on that note, the imagery it&
It does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the "normal" NDC infosec talk, the cyber-broken talk with Scott in Copenhagen and then those ratbag hackers keep dumping more
You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here:
🚨Cyber
https://www.troyhunt.com/a-cautionary-tale-about-data-breach-claims-verification-and-carhartt/
I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all into a residential house and have it make sense. There are a few basic tenets:
Smells awful:
But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association.
Ogg said anyone familiar with the fishing industry understands what happens when a large catch sits for an extended period.
“If you think about what happens after four or five days, it’s a gooey mess,” he said.
The odor has become a defining feature of the operation, and the beach remains closed to the public while crews work on a removal plan...
Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I’m really proud of the talk, and the fact that it gained over 100K views on YouTube in just a few days.
Also online is an interview with me in the AI Village.
https://www.schneier.com/blog/archives/2026/09/my-talk-at-def-con.html
In August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago.
Great fun.
https://www.schneier.com/blog/archives/2026/09/cliff-stolls-def-con-talk.html
Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.
What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.
Simon Willison comments:
Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe...
https://www.schneier.com/blog/archives/2026/09/ais-compress-exploit-timeline.html
A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.
https://www.schneier.com/blog/archives/2026/09/drivers-license-data-for-sale.html