Cybersecurity

Feeds last updated @: UTC - 04:15 - 13/09/2026

Security.nl

https://www.security.nl






Slashdot

https://slashdot.org/

Anthropic CEO Dario Amodei Calls For AI Slowdown

  Pagina openen
An anonymous reader quotes a report from The New York Times: The chief executive of Anthropic called for a global slowdown of artificial intelligence development in a 3,800-word essay on Saturday, just days after one of the company's employees quit over concerns about the safety of the technology. Dario Amodei, who co-founded Anthropic to focus on securely and carefully building A.I., wrote that while he believed the technology could bring many benefits, it was advancing at too quick a pace for researchers to continue safely. "Over the last few months, I have become convinced that fully addressing the risks requires even more prudence -- not just investing in risk prevention, but pacing the rate of capabilities advancement so that risk prevention has time to keep up," Mr. Amodei said. "We must slow the pace at which we improve the capabilities of A.I. models. Progress will still seem fast, and we must make wise use of the time we gain." [...] "Left unchecked, it could outrun our ability to understand and control these systems, and so must be pursued very carefully, if at all," Mr. Amodei said. [...] In his essay on Saturday, Mr. Amodei suggested actions that the industry might take to slow down the pace of development. Mr. Amodei said all A.I. labs could agree to third-party technology assessments from "embedded evaluators," or outside specialists who can verify best safety practices across companies. He also suggested that countries with democratic governance systems coordinate to create safety standards, which could take the form of regulatory action. He added that it would probably require a global effort working with other nations, including authoritarian ones, to properly coordinate a slowdown. Mr. Amodei stressed in his essay that he still finds A.I. capable of bringing "incredible benefits" to humanity, including potentially curing diseases and accelerating economic growth. But even so, Mr. Amodei said the risks of A.I. were too great to not proceed with extreme caution. "The measures I propose to advance the frontier at a safe pace will not be easy," Mr. Amodei wrote. "But I believe we owe it to humanity to try." Amodei's essay comes just hours after Bloomberg reported that Sam Altman told OpenAI employees the company is open to slowing the pace of AI development amid similar concerns.

Read more of this story at Slashdot.

https://slashdot.org/story/26/09/12/1738240/anthropic-ceo-dario-amodei-calls-for-ai-slowdown?utm_source=rss1.0mainlinkanon&utm_medium=feed


Automattic's Matt Mullenweg Claims He's Back 'In Control'

  Pagina openen
Less than 48 hours after Automattic's board placed Matt Mullenweg on leave, Mullenweg told employees he was back "in control" of the company and that the board was again in agreement. 404 Media cited Slack screenshots late Thursday evening where Mullenweg posted "Don't call it a comeback" and linked to LL Cool J's music video for "Mama Said Knock You Out." "Mullenweg's Slack profile picture currently shows him wearing a pirate hat and eyepatch," the report notes. From the report: "Happy to announce the board is back in agreement, and I'm in control of Automattic," Mullenweg wrote in the company-wide Announcements channel on Slack. "A lot happened in the past 48 hours that we need to sort out, and I hope much of it was a misunderstanding, because I have huge respect and regard for those involved." Mark Davies, Automattic's CFO who was set to act as interim CEO according to a statement from Automattic, had his Slack account deactivated as of at least Friday, sources told 404 Media and TechCrunch similarly reported. Davies, Mullenweg, and Automattic did not respond to 404 Media's requests for comment for this story. Techcrunch reported that Mullenweg told them a blog post is forthcoming. On Friday morning, Mullenweg published a blog post on his personal website, titled "Major Life Announcement." In it he announced he's buying a tugboat. "Anybody who's founded a company and had to find good stewards knows that no one will love a thing quite like the original owner, but sometimes you can find the perfect person to carry the torch," he wrote in the blog. He did not address the confusion surrounding his status at Automattic. The back-and-forth follows years of legal fights, layoffs, employee departures, and controversy surrounding Mullenweg's leadership.

Read more of this story at Slashdot.

https://slashdot.org/story/26/09/12/1751208/automattics-matt-mullenweg-claims-hes-back-in-control?utm_source=rss1.0mainlinkanon&utm_medium=feed


LG Responds to TV Spying Allegations

  Pagina openen
LG is pushing back against reports that its smart TVs are "spying" on users, saying wake-word detection happens locally and that features such as Automatic Content Recognition, voice recognition, and interest-based ads are optional. But critics note that researchers found TVs keeping logs of ambient conversations, and LG's response "did not address broader concerns about how much data it collects, who it shares it with, the potential for bad actors to exploit its features, or the misleading way in which its privacy options are presented," reports The Verge. Here's an excerpt from LG's statement: Some recent media coverage may have contributed to misconceptions about how LG smart TVs work. As an industry leader, LG believes we have a responsibility to provide customers with clear and accurate information about how our smart TVs operate and the privacy controls available to them. We would like to clarify how our smart TVs operate and explain our approach to user privacy. LG smart TVs do not continuously record or transmit users' conversations. Speech-to-text processing begins only if a user activates a voice interaction through a supported wake-word feature or by pressing the voice (or AI) button on the remote control. Audio used for wake-word detection is processed locally on the TV and, if no wake word is detected, audio is not converted to text, stored, or transmitted. Voice-recognition results and related technical logs may be generated as part of processing a voice command. These records are associated with specific voice interactions and do not indicate continuous recording of conversations occurring outside an active voice recognition session. Speech-recognition results may be used to support voice-related features but are not uploaded later when the TV is offline or when connectivity is restored. Features such as Automatic Content Recognition (ACR), voice recognition, and interest-based advertising are optional. These features are not enabled by default. Users can choose to enable these features and can manage or withdraw consent through TV settings. ACR uses audio fingerprinting technology using the TV's internal audio processor (not a speaker) to identify content and does not collect screenshots, screen recordings, video recordings, voice recordings, or other audio recordings from the TV. Where ACR is available and enabled, ACR-related information may be used for audience segmentation and viewing or audience trend analysis. Interest-based advertising and cross-device advertising require separate user consent through the applicable advertising-related agreements. Protecting user privacy is a fundamental principle in the design and operation of LG products and services. The statement goes on to "provide additional details on how LG smart TV features work, how information may be processed, what choices users have, and how LG continues to strengthen privacy, transparency, and security."

Read more of this story at Slashdot.

https://yro.slashdot.org/story/26/09/12/1652215/lg-responds-to-tv-spying-allegations?utm_source=rss1.0mainlinkanon&utm_medium=feed


Scientists Create a New Form of Ice At 2,357 Degrees Celsius

  Pagina openen
Longtime Slashdot reader fahrbot-bot shares a report from ScienceAlert: Scientists have now demonstrated one of the weirdest forms of ice yet -- under preposterous pressures up to 2.3 million atmospheres, and tremendous temperatures up to 2,630 kelvins (2,357 degrees Celsius, or 4,274 degrees Fahrenheit). [...] In their new experiments, a team led by physicist Alexis Forestier of the French Alternative Energies and Atomic Energy Commission subjected tiny samples of water to the sorts of extreme conditions expected in the interiors of ice giant planets. They squeezed the samples between the tips of diamonds to pressures as high as 230 gigapascals, while using lasers to heat them to thousands of degrees. That's 2.3 million times Earth's atmospheric pressure at sea level â" the pressure at the center of Earth, for context, is around 360 gigapascals. Then, using an extremely narrow beam of synchrotron X-rays, they probed for changes in the crystal structure of the ice. What emerged was a configuration predicted theoretically but never unambiguously observed in experiments: hexagonal close-packed, or hcp, ice. As the hcp crystal was heated, its expansion also showed a signature of superionic behavior, suggesting it entered the superionic state at around 1,700 kelvins. [Superionic ice is thought to exist deep inside Uranus and Neptune, where its unusual properties may play a role in generating the planets' equally unusual magnetic fields.] The findings have been published in Physical Review Letters.

Read more of this story at Slashdot.

https://science.slashdot.org/story/26/09/11/2249242/scientists-create-a-new-form-of-ice-at-2357-degrees-celsius?utm_source=rss1.0mainlinkanon&utm_medium=feed


Little Mercury May Be Shrinking Faster Than Scientists Expected

  Pagina openen
A new study suggests Mercury may have shrunk about 30% more than scientists previously thought, losing as much as 14 miles in diameter as its interior cooled and contracted over billions of years. "That's significant for a planet barely 3,000 miles (4,900 kilometers) across," reports the Associated Press. From the report: Mercury's rough surface, continually reshaped by debris hurled from impact craters, may have hidden the true extent of the loss, according to the researchers whose findings appear in the journal Geophysical Research Letters. The news comes one week after a pair of European and Japanese spacecraft shed its cruising platform and advanced toward Mercury. Known as BepiColombo, the linked craft are expected to enter orbit around Mercury in November before splitting up for a fuller survey. BepiColombo's laser instrument should confirm how much Mercury is withering as a result of internal cooling, said Gaku Nishiyama, the study's lead author who is taking part in the space mission. The shrinkage could be even more than his team is estimating based on measurements from NASA's Messenger spacecraft in the 2010s. Only one other spacecraft has ever visited Mercury, NASA's Mariner 10 in the 1970s.

Read more of this story at Slashdot.

https://science.slashdot.org/story/26/09/11/2050204/little-mercury-may-be-shrinking-faster-than-scientists-expected?utm_source=rss1.0mainlinkanon&utm_medium=feed


theregister.com/security

https://www.theregister.com/security






CISO2CISO.com

https://ciso2ciso.com

Vuldb

https://vuldb.com

CVE-2026-90678 | HAProxy up to 3.3.14/3.4.4/3.5-dev5 HTTP/3 Multiplexer request smuggling

  Pagina openen
A vulnerability labeled as problematic has been found in HAProxy up to 3.3.14/3.4.4/3.5-dev5. Impacted is an unknown function of the component HTTP/3 Multiplexer. Executing a manipulation can lead to http request smuggling. This vulnerability is registered as CVE-2026-90678. It is possible to launch the attack remotely. No exploit is available. The affected component should be upgraded.

https://vuldb.com/vuln/403211


CVE-2026-90668 | UnrealIRCd up to 6.2.6 Webserver denial of service

  Pagina openen
A vulnerability identified as problematic has been detected in UnrealIRCd up to 6.2.6. This issue affects some unknown processing of the component Webserver. Performing a manipulation results in denial of service. This vulnerability is cataloged as CVE-2026-90668. It is possible to initiate the attack remotely. There is no exploit available. You should upgrade the affected component.

https://vuldb.com/vuln/403210


CVE-2026-90651 | Socket Firewall up to 1.x TLS Certificate Verification socket.yml api_ssl_verify/upstream_ssl_verify certificate validation

  Pagina openen
A vulnerability categorized as problematic has been discovered in Socket Firewall up to 1.x. This vulnerability affects unknown code of the file socket.yml of the component TLS Certificate Verification. Such manipulation of the argument api_ssl_verify/upstream_ssl_verify leads to improper certificate validation. This vulnerability is listed as CVE-2026-90651. The attack may be performed from remote. There is no available exploit. It is advisable to upgrade the affected component.

https://vuldb.com/vuln/403209


CVE-2026-90648 | wabt up to 1.0.41 Funcref Table wasm-rt-impl-tableops.inc wasm_rt_allocate_funcref_table input validation

  Pagina openen
A vulnerability was found in wabt up to 1.0.41. It has been rated as critical. This affects the function wasm_rt_allocate_funcref_table of the file wasm2c/wasm-rt-impl-tableops.inc of the component Funcref Table. This manipulation causes improper input validation. This vulnerability is tracked as CVE-2026-90648. The attack is possible to be carried out remotely. No exploit exists.

https://vuldb.com/vuln/403208



Microsoft Security

https://msrc.microsoft.com/update-guide/vulnerability






advisories.ncsc.nl

https://advisories.ncsc.nl/

NCSC-2026-0076 [1.03] [H/H] Kwetsbaarheden verholpen in Cisco Secure Firewall Management Center

  Pagina openen
Cisco heeft kwetsbaarheden verholpen in Cisco Secure Firewall Management Center. De kwetsbaarheid met kenmerk CVE-2026-20079 bevindt zich in de webinterface van Cisco Secure Firewall Management Center. Een ongeauthenticeerde externe kwaadwillende kan de authenticatiecontroles omzeilen door een onjuist systeemproces dat bij het opstarten is aangemaakt te misbruiken. De kwaadwillende kan deze kwetsbaarheid misbruiken door speciaal geprepareerde HTTP-verzoeken naar een getroffen apparaat te sturen. Een succesvolle exploit kan de aanvaller in staat stellen verschillende scripts en commando’s uit te voeren die root-toegang tot het apparaat mogelijk maken. De kwetsbaarheid met kenmerk CVE-2026-20131 bevindt zich in de webinterface van Cisco Secure Firewall Management Center. Deze kwetsbaarheid stelt ongeauthenticeerde externe kwaadwillende in staat om willekeurige Java-code uit te voeren met root-rechten. De kwetsbaarheid wordt veroorzaakt door de onveilige deserialisatie van door de gebruiker aangeleverde Java-byte-stromen. Een kwaadwillende kan deze kwetsbaarheid misbruiken door een speciaal geprepareerd, geserialiseerd Java-object naar de webgebaseerde beheerinterface van een getroffen apparaat te sturen. Een succesvolle exploit kan de aanvaller in staat stellen om willekeurige code op het apparaat uit te voeren en de rechten te verhogen tot root-niveau. Als de beheerinterface van Cisco Secure Firewall Management Center geen publieke internettoegang heeft, wordt het aanvalsoppervlak verkleind. Het is niet gebruikelijk om een managementinterface direct publiekelijk aan het internet bloot te stellen. Indien jouw organisatie gebruikmaakt van Cisco Security Cloud Control Firewall Management, dan betreft dit een SaaS-dienst (Software-as-a-Service) die door Cisco Systems automatisch wordt bijgewerkt als onderdeel van regulier onderhoud. Er is in dat geval geen actie van de gebruiker vereist. Het NCSC verwacht op korte termijn een publieke PoC en grootschalige pogingen tot misbruik. Het NCSC adviseert met klem de update zo spoedig mogelijk te installeren. Update 19-03-26: Uit onderzoek van Amazon threat intelligence blijkt dat CVE-2026-20131 vermoedelijk al sinds 26 januari actief is misbruikt voor het uitrollen van Interlock ransomware. Daarnaast is er inmiddels een publieke PoC verschenen voor kwetsbaarheid CVE-2026-20079. Het is daarom van groot belang om - indien dit nog niet gedaan is - te updaten naar de nieuwste versie van Cisco Secure Firewall Management Center. **UPDATE 11-09-26:** Cisco meldt dat succesvolle exploitatie van de kwetsbaarheid met kenmerk CVE-2026-20079 is waargenomen. Organisaties wordt geadviseerd de updates van Cisco direct toe te passen en kwetsbare systemen te controleren op aanwijzingen van misbruik. Raadpleeg de Talos blog voor aanvullende aanbevelingen. **EINDE UPDATE**

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0076


NCSC-2026-0367 [1.00] [H/H] Kwetsbaarheid verholpen in GitLab Community en Enterprise Editions

  Pagina openen
GitLab heeft een kwetsbaarheid verholpen in GitLab Community en Enterprise Editions. De kwetsbaarheid bevindt zich in de repository commits API, waarbij een path traversal mogelijk is. Hierdoor kunnen niet-geauthenticeerde gebruikers willekeurige bestanden op het systeem lezen. De oorzaak ligt in onjuiste path confinement gecombineerd met ontbrekende authenticatiecontroles in de API-endpoint. CISA heeft CVE-2026-85706 opgenomen in de Known Exploited Vulnerabilities-catalogus en er is publieke exploitcode beschikbaar. Vooral internetbereikbare, zelfbeheerde GitLab-installaties lopen risico, omdat een aanvaller zonder inloggegevens gevoelige bestanden kan lezen. Werk kwetsbare systemen direct bij naar GitLab 19.1.8, 19.2.6, 19.3.2 of nieuwer en onderzoek de API-logs op verdachte verzoeken met parameters als file.path. Roteer mogelijk blootgestelde credentials wanneer aanwijzingen voor misbruik worden aangetroffen. Controleer bijgevoegde referenties voor de laatste updates.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0367


NCSC-2026-0271 [1.01] [M/H] Kwetsbaarheid verholpen in Cisco Secure Firewall Management Center

  Pagina openen
Cisco heeft een kwetsbaarheid verholpen in Cisco Secure Firewall Management Center. De kwetsbaarheid bevindt zich in de webinterface van Cisco Secure Firewall Management Center en betreft een hard-coded, statisch wachtwoord voor een laaggeprivilegieerd account. Hierdoor kunnen niet-geauthenticeerde externe aanvallers toegang verkrijgen zonder inloggegevens. Deze toegang kan leiden tot het blootstellen van gevoelige data die door het systeem wordt opgeslagen of beheerd. In combinatie met andere kwetsbaarheden kan deze toegang leiden tot privilege-escalatie. Het Amerikaanse CISA heeft de kwetbaarheid op de Known Exploited Vulnerabilities-lijst geplaatst, wat indicatief is dat er binnen de Amerikaanse Federale Overheid misbruik heeft plaatsgevonden van deze kwetsbaarheid. Het is goed gebruik om web-interfaces van management omgevingingen *niet* publiek toegankelijk te hebben, maar af te steunen in een separate beheer-omgeving. **UPDATE 11-09-26:** Cisco meldt dat succesvolle exploitatie van de kwetsbaarheid met kenmerk CVE-2026-20316 is waargenomen. Organisaties wordt geadviseerd de updates van Cisco direct toe te passen en kwetsbare systemen te controleren op aanwijzingen van misbruik. Raadpleeg de Talos blog voor aanvullende aanbevelingen. **EINDE UPDATE**

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0271


NCSC-2026-0342 [1.01] [H/H] Kwetsbaarheid verholpen in N-central van N-able

  Pagina openen
N-able heeft een kwetsbaarheid verholpen in N-central versies eerder dan 2026.3.1.14. De kwetsbaarheid betreft een pre-authenticatie remote code execution flaw. Een aanvaller kan hierdoor op afstand willekeurige code uitvoeren op het getroffen systeem zonder enige vorm van authenticatie. Alle installaties die draaien op de kwetsbare versies van N-central zijn getroffen. Klanten met een on-premises N-central-omgeving wordt geadviseerd zo snel mogelijk te upgraden naar N-central 2026.3 HF4. Voor gebruikers van een gehoste N-central-instantie (NCOD) zijn de patches al toegepast. Er is op dit moment geen actie vereist. N-able meldt dat pogingen tot exploitatie zijn waargenomen, volg het advies van N-able op om onderzoek te doen naar IoC's. **UPDATE** N-able meldt dat bij klanten succesvolle exploitatie van de kwetsbaarheid is waargenomen. N-able onderzoekt de incidenten verder en werkt rechtstreeks samen met klanten die verdachte activiteiten melden. Volg het advies N-able op, dat staat beschreven in de blog. **EINDE UPDATE**

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0342


NCSC-2026-0366 [1.00] [M/H] Kwetsbaarheden verholpen in Arista EOS

  Pagina openen
Arista heeft kwetsbaarheden verholpen in de Arista EOS-platform. De kwetsbaarheid met kenmerk CVE-2026-73456 bevindt zich in de verwerking van verzoeken die via gNPSI worden aangeboden. Onder de kwetsbare configuratie kan een niet-geauthenticeerde client een kwaadaardig verzoek aanbieden waarmee code-injectie kan worden veroorzaakt. Een kwaadwillende met netwerktoegang tot de gNPSI-service kan zonder authenticatie een speciaal vervaardigd verzoek versturen waarmee willekeurige code kan worden uitgevoerd. Hierdoor kan de kwaadwillende volledige administratieve controle over de getroffen switch verkrijgen. De kwetsbaarheid met kenmerk CVE-2026-73457, kan ertoe leiden dat gNPSI-clientgegevens, waaronder wachtwoorden, in plaintext in lokale of remote accounting logs terechtkomen. Een kwaadwillende met voldoende rechten om de betreffende logs te benaderen, kan deze gegevens vervolgens uitlezen. Volgens Arista is misrbuik mogelijk indien gNPSI is ingeschakeld én de trace facility EosRpcAuth expliciet is geactiveerd. gNPSI is standaard uitgeschakeld. Volgens Arista is misbruik uitsluitend mogelijk wanneer gNPSI is ingeschakeld, in combinatie met specifieke TLS- en authenticatieconfiguraties, dan wel met een expliciet geactiveerde EosRpcAuth trace facility. Aangezien gNPSI standaard is uitgeschakeld, zijn systemen met de fabrieksinstellingen niet kwetsbaar.

https://advisories.ncsc.nl/advisory?id=NCSC-2026-0366


NCSC Nieuws

https://www.ncsc.nl/actueel

Kritieke kwetsbaarheid in GitLab wordt actief misbruikt: update nu

  Pagina openen
Er is een kritieke kwetsbaarheid in GitLab Community Edition en Enterprise Edition gevonden met het kenmerk CVE-2026-85706. De kwetsbaarheid heeft een CVSS-score van 10.0 en wordt actief misbruikt. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en adviseert om zo snel mogelijk beveiligingsupdates te installeren.

https://www.ncsc.nl/alerts/kritieke-kwetsbaarheid-in-gitlab-wordt-actief-misbruikt-update-nu



Kritieke kwetsbaarheden in Check Point VPN-producten met actief misbruik verwacht: update nu

  Pagina openen
Er zijn 2 kritieke kwetsbaarheden in Check Point VPN-producten, met de kenmerken CVE-2026-85102 en CVE-2026-85103. Het gaat om 2 ernstige kwetsbaarheden met een CVSS-score van 9,8. Het NCSC beoordeelt de kans op misbruik en de mogelijke schade als hoog en verwacht dat er snel pogingen tot misbruik zullen plaatsvinden, het advies is dan ook om de updates zo snel mogelijk te installeren.

https://www.ncsc.nl/alerts/kritieke-kwetsbaarheden-in-check-point-vpn-producten-met-actief-misbruik-verwacht-update-nu


Kwetsbaarheden in Adobe Illustrator met risico op code-uitvoering: update onmiddellijk

  Pagina openen
Er zijn 3 kwetsbaarheden gevonden in Adobe Illustrator. Deze kwetsbaarheden hebben een CVSS-score van 7,8 tot 8,6 en zijn beoordeeld als medium kans op misbruik en hoge mogelijke schade. Ze maken het mogelijk dat een aanvaller via speciaal gemaakte bestanden schadelijke code kan uitvoeren op jouw computer.

https://www.ncsc.nl/alerts/kwetsbaarheden-in-adobe-illustrator-met-risico-op-code-uitvoering-update-onmiddellijk


Kwetsbaarheden in Adobe Photoshop Desktop met risico op misbruik: update direct

  Pagina openen
Er zijn meerdere kwetsbaarheden gevonden in Adobe Photoshop Desktop met een CVSS-score tot 8,6. Deze kwetsbaarheden zijn beoordeeld als van normale urgentie om te handelen. Er zijn geen meldingen van actief misbruik. Het NCSC adviseert alsnog om de beschikbare updates van Adobe zo snel mogelijk te installeren om risico's te beperken.

https://www.ncsc.nl/alerts/kwetsbaarheden-in-adobe-photoshop-desktop-met-risico-op-misbruik-update-direct


NIST Cybersecurity

https://www.nist.gov

wid.cert-bund.de

https://wid.cert-bund.de






cert.ssi.gouv.fr

https://www.cert.ssi.gouv.fr






theHackerNews

https://thehackernews.com

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

  Pagina openen
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization

https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html


When the Whole Company Adopts AI: What It Does to Your SOC

  Pagina openen
Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate

https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html


OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

  Pagina openen
The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html


GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

  Pagina openen
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under

https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html


Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

  Pagina openen
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a "teacher" to

https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html


Techrepublic

https://techrepublic.com/topic/security




US Accuses Six Chinese AI Firms of Distilling Frontier ModelsUS Accuses Six Chinese AI Firms of Distilling Frontier Models

  Pagina openen

US agencies accuse six Chinese AI firms of distilling frontier models and recommend new defenses that could affect enterprise AI access and API use.

The post US Accuses Six Chinese AI Firms of Distilling Frontier ModelsUS Accuses Six Chinese AI Firms of Distilling Frontier Models appeared first on TechRepublic.

https://www.techrepublic.com/article/news-chinese-ai-model-distillation-apac-china/



BleepingComputer.com

https://www.bleepingcomputer.com/






securityboulevard.com

https://securityboulevard.com

CXSecurity.com

https://cxsecurity.com/






Brian Krebs

https://krebsonsecurity.com

Microsoft Plugs Nearly 1,000 Security Holes

  Pagina openen
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.

https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/


FBI Probes Service Selling 153M+ Drivers Licenses

  Pagina openen
A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/


Two Alleged ‘TeamPCP’ Hackers Arrested in Australia

  Pagina openen
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses." The AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect's real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP's self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.

https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/


Who’s Tracking You? Use This New Service to Find Out

  Pagina openen
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.

https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/



Troy Hunt

https://www.troyhunt.com

Weekly Update 521: Breach Perception v. Reality

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I think what really resonates with me this week is being able to completely turn the tables on perceptions around things like AI being the big bad hacking tool the news would have you believe. There's the stat I talk about where it's had literally 0%

https://www.troyhunt.com/weekly-update-521/



Weekly Update 519: Breaches & Data Integrity

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

It does feel like I've bitten off too much and am now chewing like crazy this week. The 3D printing talk with Elle in Oslo, the "normal" NDC infosec talk, the cyber-broken talk with Scott in Copenhagen and then those ratbag hackers keep dumping more

https://www.troyhunt.com/weekly-update-519/


A Cautionary Tale About Data Breach Claims, Verification and Carhartt

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

You're not going to believe this, but turns out you can't always take criminals at their word. Actually, I'll walk that back a bit as it may not even be the cybercrime guys who got this wrong, but it all starts here:

🚨Cyber

https://www.troyhunt.com/a-cautionary-tale-about-data-breach-claims-verification-and-carhartt/


Weekly Update 518: IoT Doorlock Nirvana with UniFi

  Pagina openen

Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite

I genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've worked out how to put it all into a residential house and have it make sense. There are a few basic tenets:

  1. Main power (never have to rely on

https://www.troyhunt.com/weekly-update-518/


Bruce Schneier

https://www.schneier.com

Friday Squid Blogging: Rotting Squid on a Beached California Boat

  Pagina openen

Smells awful:

But an estimated 30 to 50 tons of dead squid remain inside the boat’s catch tank, where they have been decomposing for days. “That is nasty. I wouldn’t want to do that,” said commercial fisherman Dick Ogg of the Bodega Bay Fishermen’s Marketing Association.

Ogg said anyone familiar with the fishing industry understands what happens when a large catch sits for an extended period.

“If you think about what happens after four or five days, it’s a gooey mess,” he said.

The odor has become a defining feature of the operation, and the beach remains closed to the public while crews work on a removal plan...

https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-rotting-squid-on-a-beached-california-boat.html


My Talk at DEF CON

  Pagina openen

Last month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I’m really proud of the talk, and the fact that it gained over 100K views on YouTube in just a few days.

Also online is an interview with me in the AI Village.

https://www.schneier.com/blog/archives/2026/09/my-talk-at-def-con.html



AIs Compress Exploit Timeline

  Pagina openen

Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it.

What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.

Simon Willison comments:

Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe...

https://www.schneier.com/blog/archives/2026/09/ais-compress-exploit-timeline.html



Security Affairs

https://securityaffairs.co

Revolut Exposed KYC Data After Fraudulent Government Email Passed Security Checks

  Pagina openen
Revolut handed over KYC documents, selfies, and Bitcoin transaction histories after a fake government email with valid domain credentials passed its checks. Revolut confirmed on September 12, 2026, that it disclosed sensitive customer data to an unauthorized third party after receiving fraudulent information requests sent from an email address operating inside an actual government agency’s [...]

https://securityaffairs.com/198922/data-breach/revolut-exposed-kyc-data-after-fraudulent-government-email-passed-security-checks.html


Anthropic: AI Misuse Is Entering a New Phase: From Cybercrime to Surveillance, Propaganda and Weapons

  Pagina openen
AI is becoming an operational force for cybercrime, surveillance, propaganda, fraud and weapons development, lowering the cost and scale of attacks. Artificial intelligence (AI) is becoming more than a tool for people who want to do something malicious. It is increasingly becoming part of the operational machinery itself. That is the main message emerging from [...]

https://securityaffairs.com/198905/ai/anthropic-ai-misuse-is-entering-a-new-phase-from-cybercrime-to-surveillance-propaganda-and-weapons.html


The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet

  Pagina openen
Researchers found 36,769 exposed AI endpoints, but only 2% had an HTTP authentication gate. Running AI locally is supposed to give organizations more control. Models, prompts and documents stay on infrastructure they manage instead of being sent to a third-party cloud. But that advantage disappears quickly when the infrastructure itself is exposed to the public [...]

https://securityaffairs.com/198898/ai/the-ai-supply-chain-has-a-security-problem-and-much-of-it-is-sitting-on-the-open-internet.html


Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware

  Pagina openen
Three threat groups are exploiting two Cisco FMC flaws to steal credentials, gain root access and deploy Qilin ransomware. Cisco Talos says three separate threat groups are exploiting two recently patched Secure Firewall Management Center (FMC) flaws. The main target is CVE-2026-20079, a critical authentication bypass that lets unauthenticated attackers remotely bypass security controls, run [...]

https://securityaffairs.com/198884/cyber-crime/attackers-exploit-critical-cisco-fmc-flaw-to-deploy-qilin-ransomware.html


UK Council Attack Linked to Mass Exploitation of SonicWall Flaw

  Pagina openen
A critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and enabled Active Directory theft. On July 17, 2026, the Borough Council of King’s Lynn and West Norfolk announced it had detected a cyberattack affecting council services. Hunt.io has since published a detailed technical analysis linking [...]

https://securityaffairs.com/198864/hacking/uk-council-attack-linked-to-mass-exploitation-of-sonicwall-flaw.html


news.sophos.com

https://news.sophos.com