Cybersecurity and other IT news aggregator

LATEST FEEDS

  • MIND Secures $72 Million for AI-Powered DLP

    MIND Secures $72 Million for AI-Powered DLP 2026-09-18 at 10:25 By Ionut Arghire The company will use the funding to accelerate platform development and expand its presence in key enterprise markets. The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

    Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root 2026-09-18 at 10:21 By A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall…


  • ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

    ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories 2026-09-18 at 10:21 By Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly…


  • Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files 2026-09-18 at 10:21 By Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The…


  • Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

    Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords 2026-09-18 at 10:21 By The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. “HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery,…


  • Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

    Check Point, Kaspersky, Tanium Patch Product Vulnerabilities 2026-09-18 at 10:14 By Eduard Kovacs Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek…


  • Australia iPhone 18 launch descends into chaos as line-cutter claims he’s first in world to buy device: ‘I’m the first!’

    Australia iPhone 18 launch descends into chaos as line-cutter claims he’s first in world to buy device: ‘I’m the first!’ 2026-09-18 at 09:42 By News.com.au He spent hours camped outside the flagship store only to watch a rival line-jumper barge past him in the dash for the doors, phone held aloft, declaring himself the world’s…


  • RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

    RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall 2026-09-18 at 09:17 By Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing (SMS/text phishing) and…


  • Abandoned IoT apps keep sending sensitive data to broken servers

    Abandoned IoT apps keep sending sensitive data to broken servers 2026-09-18 at 09:00 By Sinisa Markovic Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates years ago. Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned…


  • Hardcoded MCP credentials found in public GitHub files

    Hardcoded MCP credentials found in public GitHub files 2026-09-18 at 08:30 By Anamarija Pogorelec Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The…


  • 98% of fraudulent hires have company credentials by the time they’re caught

    98% of fraudulent hires have company credentials by the time they’re caught 2026-09-18 at 08:00 By Anamarija Pogorelec A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can…


  • Most WordPress pros still lack a breach recovery plan

    Most WordPress pros still lack a breach recovery plan 2026-09-18 at 07:30 By Anamarija Pogorelec Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners…


  • New infosec products of the week: September 18, 2026

    New infosec products of the week: September 18, 2026 2026-09-18 at 07:00 By Anamarija Pogorelec Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr uses agentic AI to predict and verify security threats Dataminr has announced Dataminr Advanced for Corporate…


  • North Korea drives onchain malware surge, CoinEx shuts: Asia Express

    North Korea drives onchain malware surge, CoinEx shuts: Asia Express 2026-09-18 at 02:49 By Cointelegraph by Andrew Fenton North Korea and Iran account for the majority of onchain malware, while Malaysia has been named among the most crypto curious Islamic nations. This article is an excerpt from Cointelegraph.com News View Original Source


  • AI protesters rally outside Dreamforce conference in San Francisco as tech bosses shrug off fears

    AI protesters rally outside Dreamforce conference in San Francisco as tech bosses shrug off fears 2026-09-17 at 23:45 By Annie Gaus AI critics took to San Francisco streets Thursday to call for action on the rapidly advancing technology, but their protest drew only a small crowd as some tech CEOs shrugged off rising alarm about…


  • AI assistant Instinct’s valuation has quadrupled to $10B in a month, but is it worth the hype?

    AI assistant Instinct’s valuation has quadrupled to $10B in a month, but is it worth the hype? 2026-09-17 at 23:37 By Lydia Moynihan “This is the first AI assistant I’ve recommended my wife and kids, who aren’t techies, should use,” said John Borthwick of Betaworks, an early investor in Hugging Face (but who has no…


  • WisdomTree, MoonPay team up to expand US access to tokenized money market fund

    WisdomTree, MoonPay team up to expand US access to tokenized money market fund 2026-09-17 at 20:31 By Cointelegraph by Nate Kostar MoonPay plans to use WisdomTree’s $1.2 billion WTGXX tokenized fund as part of its stablecoin reserves while helping expand access to US investors. This article is an excerpt from Cointelegraph.com News View Original Source


  • Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

    Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels 2026-09-17 at 20:09 By Eduard Kovacs The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran. The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first…


  • Is there any chance left to save the CLARITY Act?

    Is there any chance left to save the CLARITY Act? 2026-09-17 at 20:00 By Cointelegraph by Christina Comben CLARITY isn’t dead after failing a key Senate vote, but with time running short and Democrats still demanding changes, its path forward is narrowing. This article is an excerpt from Cointelegraph.com News View Original Source


  • King Charles warns top AI leaders of ‘existential dangers,’ offers proposals to rein in technology

    King Charles warns top AI leaders of ‘existential dangers,’ offers proposals to rein in technology 2026-09-17 at 19:43 By Associated Press The king asked attendees, including Nvidia CEO Jensen Huang and Google DeepMind Chair Demis Hassabis, to consider the “fundamental principles” that should guide AI development. This article is an excerpt from Latest Technology News |…


  • Bitcoin coils near $76.5K as US stocks rebound from Fed rate hike

    Bitcoin coils near $76.5K as US stocks rebound from Fed rate hike 2026-09-17 at 19:22 By Cointelegraph by William Suberg Bitcoin made modest daily gains as US stocks saw upside in the aftermath of the US Federal Reserve’s first interest-rate hike since July 2023. This article is an excerpt from Cointelegraph.com News View Original Source


  • Mobile Security Can’t Move at App Release Speed Anymore

    Mobile Security Can’t Move at App Release Speed Anymore 2026-09-17 at 19:00 By Mobile security still assumes protection can wait for the next release. But like a burst pipe, it’s something we can’t afford to wait on. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • Zcash miner Fortitude taps former Hut 8 CEO to lead ahead of public listing

    Zcash miner Fortitude taps former Hut 8 CEO to lead ahead of public listing 2026-09-17 at 18:58 By Cointelegraph by Nate Kostar Former Hut 8 CEO Jaime Leverton will take the helm at Fortitude as the Zcash-focused miner expands its operations and moves toward a planned public listing. This article is an excerpt from Cointelegraph.com…


  • OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training

    OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training 2026-09-17 at 18:45 By Eduard Kovacs OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior. The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek. This article is an excerpt…


  • CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot

    CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot 2026-09-17 at 17:28 By Eduard Kovacs The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • The First 12 Hours of an Incident Matter More Than the Next 12 Days

    The First 12 Hours of an Incident Matter More Than the Next 12 Days 2026-09-17 at 17:00 By Bread Fyan When organizations experience a cyberattack, executives often focus on recovery timelines, business impact, and regulatory obligations. Yet the outcome of those conversations is often determined long before recovery begins. This article is an excerpt from…


  • Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

    Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom 2026-09-17 at 16:57 By Ionut Arghire Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View…


  • CISO’s Expert Guide to Agentic Pentesting for Websites

    CISO’s Expert Guide to Agentic Pentesting for Websites 2026-09-17 at 16:45 By Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders…


  • China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

    China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America 2026-09-17 at 16:45 By The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. “SparroWocky is a modular, C++ backdoor,” ESET security researchers Alexandre Côté Cyr…


  • OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads

    OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads 2026-09-17 at 16:45 By OpenAI on Wednesday disclosed six new instances of “unexpected or concerning model behavior” that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency.…


  • OG.com cleared by SEC to offer single-stock futures, says Crypto.com CEO

    OG.com cleared by SEC to offer single-stock futures, says Crypto.com CEO 2026-09-17 at 16:35 By Cointelegraph by Zoltan Vardai Crypto.com’s CEO said its sister exchange was cleared to offer US access to single-stock perpetual futures, as the latest platform to bridge TradFi and digital assets. This article is an excerpt from Cointelegraph.com News View Original…


  • SEC grants temporary exemption for tokenized US stock trading

    SEC grants temporary exemption for tokenized US stock trading 2026-09-17 at 16:34 By Cointelegraph by Helen Partz The SEC’s Innovation Exemption allows limited tokenized US stock trading on onchain venues with trading caps and transparency requirements. This article is an excerpt from Cointelegraph.com News View Original Source


  • Bitcoin treasury firms can outperform BTC… but is the risk worth taking?

    Bitcoin treasury firms can outperform BTC… but is the risk worth taking? 2026-09-17 at 16:30 By Cointelegraph by Christina Comben Bitcoin treasury companies promise to amplify returns over investing in Bitcoin alone, but does the potential upside outweigh the risks to the downside? This article is an excerpt from Cointelegraph.com News View Original Source


  • Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE

    Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE 2026-09-17 at 16:12 By Sinisa Markovic Six months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS…


  • A fake ChatGPT billing email is after your OpenAI password

    A fake ChatGPT billing email is after your OpenAI password 2026-09-17 at 16:01 By Anamarija Pogorelec A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google…


  • Download: The IT leader’s guide to AI code sprawl

    Download: The IT leader’s guide to AI code sprawl 2026-09-17 at 16:00 By Help Net Security AI hasn’t just made building faster, it’s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI tools, often without knowing they’ve created something that needs governing at all. The result: AI code…


  • Comp AI Raises $34 Million for AI-Native Compliance and Security

    Comp AI Raises $34 Million for AI-Native Compliance and Security 2026-09-17 at 16:00 By Ionut Arghire The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View…


  • CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys

    CISA wants critical infrastructure orgs and smaller security teams to start using cyber decoys 2026-09-17 at 15:51 By Zeljka Zorz Cyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that. Why decoys, and…


  • ISC Patches 14 Vulnerabilities in BIND 9 Security Update

    ISC Patches 14 Vulnerabilities in BIND 9 Security Update 2026-09-17 at 15:39 By Ionut Arghire Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek. This article is an excerpt from…


  • Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

    Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone 2026-09-17 at 15:30 By Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can…


  • Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows

    Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows 2026-09-17 at 15:29 By Kevin Townsend Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek. This…


  • Druva expands identity resilience with ransomware detection

    Druva expands identity resilience with ransomware detection 2026-09-17 at 15:29 By Industry News Druva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspicious behavior…


  • Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard

    Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard 2026-09-17 at 15:17 By Ionut Arghire The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.   The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek. This article is an excerpt…


  • Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar

    Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar 2026-09-17 at 14:50 By A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing…


  • Zcash gains 20% as Paradigm founder reveals firm made ZEC investment

    Zcash gains 20% as Paradigm founder reveals firm made ZEC investment 2026-09-17 at 13:35 By Cointelegraph by Ezra Reguerra Zcash rose about 20% in 24 hours as Paradigm co-founder Matt Huang disclosed that the firm invested in ZEC amid a broader crypto market rally. This article is an excerpt from Cointelegraph.com News View Original Source


  • Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

    Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) 2026-09-17 at 13:24 By Zeljka Zorz Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE). About CVE-2026-76460 Cisco ISE is…


  • Scammers leave AI fingerprints all over fake antivirus renewal page

    Scammers leave AI fingerprints all over fake antivirus renewal page 2026-09-17 at 13:10 By Sinisa Markovic AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page impersonating Avast, aimed at users in Belgium, that was more polished than most sites…


  • Sam Bankman-Fried’s surprising links to the ecosystem manipulating how you view AI

    Sam Bankman-Fried’s surprising links to the ecosystem manipulating how you view AI 2026-09-17 at 13:00 By Vivi Lin “They don’t fully realize the reason they believe the world is going to end is because [of the same thing] that gives them status in their social circles and, for many of them, advantages economically.” This article…


  • Revolut says no direct contact after $3 million public ransom demand

    Revolut says no direct contact after $3 million public ransom demand 2026-09-17 at 12:57 By Cointelegraph by Helen Partz Revolut says it received no direct contact despite separate ransom demands for $3 million in Monero and 10,000 Bitcoin from competing breach claimants. This article is an excerpt from Cointelegraph.com News View Original Source


  • Why APAC Enterprises Need Real-Time Threat Intelligence as Singapore, Malaysia, and Thailand Tighten Cyber Compliance in 2026

    Why APAC Enterprises Need Real-Time Threat Intelligence as Singapore, Malaysia, and Thailand Tighten Cyber Compliance in 2026 2026-09-17 at 12:57 By Ashish Khaitan Cybersecurity compliance APAC 2026 has moved from guidance to enforcement across three of Southeast Asia’s largest economies, almost in step. Singapore’s Cyber Security Agency issued an updated Cybersecurity Code of Practice 2026 for…


Browse older archives

Scroll to Top