Cybersecurity and other IT news aggregator

LATEST FEEDS

  • Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

    Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials 2026-09-26 at 23:05 By The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack…


  • China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

    China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks 2026-09-26 at 21:09 By Associated Press The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents. The post China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks appeared first…


  • AI Agents Can Be Secured. We Can Do It.

    AI Agents Can Be Secured. We Can Do It. 2026-09-26 at 20:47 By Learn of the benefits of safely securing AI agents. This article is an excerpt from Trend Micro Research, News and Perspectives View Original Source


  • Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

    Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells 2026-09-26 at 17:21 By Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw…


  • Zero Trust for AI Agents Starts With Fixing Zero Visibility

    Zero Trust for AI Agents Starts With Fixing Zero Visibility 2026-09-26 at 17:21 By The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a…


  • Kalshi loses appeal, setting up potential Supreme Court case

    Kalshi loses appeal, setting up potential Supreme Court case 2026-09-26 at 16:21 By Cointelegraph by Michael Millard The 6th US Circuit Court of Appeals ruled against prediction market Kalshi, siding with Ohio and Tennessee on regulating sports-event contracts under state laws. This article is an excerpt from Cointelegraph.com News View Original Source


  • New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

    New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining 2026-09-26 at 15:00 By Ionut Arghire The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions. The post New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining appeared first on SecurityWeek. This article is an excerpt from…


  • OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

    OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure 2026-09-26 at 13:15 By Associated Press OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.” The post OpenAI Says Its Models Engaged With US Government Websites in New…


  • Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

    Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack 2026-09-26 at 13:01 By Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. “Kiteworks received credible threat intelligence from…


  • Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

    Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link 2026-09-26 at 12:55 By Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery…


  • SEC Commissioner Hester Peirce to leave post on Oct. 2

    SEC Commissioner Hester Peirce to leave post on Oct. 2 2026-09-26 at 12:02 By Cointelegraph by Michael Millard Peirce, known as “Crypto Mom,” served on the SEC for about eight years, including as director of the Crypto Task Force. This article is an excerpt from Cointelegraph.com News View Original Source


  • SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

    SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild 2026-09-26 at 11:49 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are as follows –…


  • CFTC sues Cash FX, alleges $950M crypto-linked forex scheme

    CFTC sues Cash FX, alleges $950M crypto-linked forex scheme 2026-09-26 at 09:59 By Cointelegraph by Michael Millard The CFTC claimed that Cash FX engaged in minimal forex trading and misappropriated most of the participant funds. This article is an excerpt from Cointelegraph.com News View Original Source


  • TikTok reaches $100M settlement with Alabama over youth addiction claims, ahead of landmark trial

    TikTok reaches $100M settlement with Alabama over youth addiction claims, ahead of landmark trial 2026-09-26 at 02:20 By Reuters It’s TikTok’s first deal with a state as it fights similar claims nationwide. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • OG.com seeks CFTC approval for single-stock perpetual futures

    OG.com seeks CFTC approval for single-stock perpetual futures 2026-09-25 at 23:37 By Cointelegraph by Nate Kostar OG.com, recently spun out of Crypto.com, joins Coinbase, Kalshi and Kraken parent Payward in seeking approval to bring perpetual futures to individual US stocks. This article is an excerpt from Cointelegraph.com News View Original Source


  • Kalshi subject to state gambling laws, appeals court finds — major blow to prediction market giant

    Kalshi subject to state gambling laws, appeals court finds — major blow to prediction market giant 2026-09-25 at 23:34 By Marc Vartabedian A US appeals court ruled Friday that Ohio and Tennessee can regulate Kalshi’s so-called event contracts under gambling laws, dealing the prediction market giant one of its biggest legal blows yet. This article…


  • Ex-CFTC leader to leave Blockchain Association after CLARITY vote fails

    Ex-CFTC leader to leave Blockchain Association after CLARITY vote fails 2026-09-25 at 23:26 By Cointelegraph by Turner Wright Former CFTC Commissioner Summer Mersinger joined the Blockchain Association in 2025 after resigning during her second term at the federal commodities regulator. This article is an excerpt from Cointelegraph.com News View Original Source


  • Instagram made ‘attorney-client privilege’ swag hats for employees who concealed kids safety docs in court battle

    Instagram made ‘attorney-client privilege’ swag hats for employees who concealed kids safety docs in court battle 2026-09-25 at 22:29 By Thomas Barrabi A photo of the so-called “swag” hats surfaced in documents released in California federal court where a coalition of school districts have accused Meta of fueling social media addiction. The “a/c/priv” hats were…


  • Tether says it had ‘limited’ exposure to bank linked to $84M US seizure

    Tether says it had ‘limited’ exposure to bank linked to $84M US seizure 2026-09-25 at 21:56 By Cointelegraph by Turner Wright US prosecutors alleged that a payments business illegally transferred hundreds of millions of dollars at the direction of EQIBank, where Tether holds some assets. This article is an excerpt from Cointelegraph.com News View Original…


  • Meta’s Facebook found liable for deceiving users in Cambridge Analytica scandal

    Meta’s Facebook found liable for deceiving users in Cambridge Analytica scandal 2026-09-25 at 21:38 By Associated Press The case stemmed from allegations that political consulting firm Cambridge Analytica obtained data from millions of Facebook users without their consent. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • Meta users are hot for ‘thicc’ new AI assistant mascot — Jolly: ‘Some of y’all way too thirsty’

    Meta users are hot for ‘thicc’ new AI assistant mascot — Jolly: ‘Some of y’all way too thirsty’ 2026-09-25 at 21:17 By Ben Cost They want to get their Jollies off. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • Oktoberfest Ride Strikes, Kills Security Guard

    Oktoberfest Ride Strikes, Kills Security Guard 2026-09-25 at 20:00 By Aleksandar Spasic, 52, died after being struck by a moving ride at Oktoberfest. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • Inside the thirst-trapping world of ‘Corgi girls’ — unhinged dating demands, bizarre ‘N-word’ posts and outrageous online behavior

    Inside the thirst-trapping world of ‘Corgi girls’ — unhinged dating demands, bizarre ‘N-word’ posts and outrageous online behavior 2026-09-25 at 19:49 By Annie Gaus A California tech startup known for hiring “hot” girls has devolved into public chaos. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • Appeals court declines to block Pentagon’s blacklisting of Anthropic

    Appeals court declines to block Pentagon’s blacklisting of Anthropic 2026-09-25 at 19:13 By Reuters The ruling ⁠came in a lawsuit by Anthropic challenging its designation by the Pentagon as a national security supply ​chain risk. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • Staying Ahead of the Ransomware Industry

    Staying Ahead of the Ransomware Industry 2026-09-25 at 19:00 By A conversation about how ransomware is evolving — and how organizations can stay ahead.  This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

    Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware 2026-09-25 at 18:57 By Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below – actions-cool/issues-helper…


  • PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence 2026-09-25 at 18:57 By Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation…


  • Gen Z craves nostalgia, resorting to pre-tech era, new study says

    Gen Z craves nostalgia, resorting to pre-tech era, new study says 2026-09-25 at 18:19 By Aurielle Weiss Gen Zers have scrolled right past the digital era, officially falling back into the analog age.  This article is an excerpt from Latest Technology News | New York Post View Original Source


  • In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

    In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure 2026-09-25 at 18:07 By SecurityWeek News Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul. The post In Other News: Clop Leak Site Takeover, Docker…


  • New Russian Infostealer Targeting Ukrainian Users

    New Russian Infostealer Targeting Ukrainian Users 2026-09-25 at 18:00 By A four-stage attack chain linked to the Lunex Malware-as-a-Service platform has been identified and reverse-engineered.  This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • North Korea Suspected in $351 Million Bitget Crypto Heist

    North Korea Suspected in $351 Million Bitget Crypto Heist 2026-09-25 at 17:16 By Eduard Kovacs Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen. The post North Korea Suspected in $351 Million Bitget Crypto Heist appeared first on SecurityWeek. This article is an…


  • SlowMist has yet to confirm crypto theft from iPhone Safari attack

    SlowMist has yet to confirm crypto theft from iPhone Safari attack 2026-09-25 at 16:05 By Cointelegraph by Helen Partz The analyzed Safari sample targets iOS 18.4–18.6.2 using previously patched flaws, while its effectiveness on iOS 26.5 remains unverified. This article is an excerpt from Cointelegraph.com News View Original Source


  • The SOC Doesn’t Need to Start Over with Every Alert

    The SOC Doesn’t Need to Start Over with Every Alert 2026-09-25 at 16:05 By Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like this. An attacker lands on…


  • CoinMarketCap buys CoinGlass to expand crypto derivatives data

    CoinMarketCap buys CoinGlass to expand crypto derivatives data 2026-09-25 at 15:44 By Cointelegraph by Yohan Yun CoinGlass will retain its brand and team, while its website, app, free tools, API and pricing will remain unchanged following the acquisition. This article is an excerpt from Cointelegraph.com News View Original Source


  • CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

    CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks 2026-09-25 at 15:39 By Eduard Kovacs Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July.  The post CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • IBIT options price trading more calmly after Bitcoin rebound

    IBIT options price trading more calmly after Bitcoin rebound 2026-09-25 at 15:23 By Cointelegraph by Yohan Yun IBIT’s expected volatility sits near the bottom of its 12-month range, according to Saxo Bank’s analysis of options data from Sept. 23. This article is an excerpt from Cointelegraph.com News View Original Source


  • Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

    Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court 2026-09-25 at 15:16 By Ionut Arghire Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services. The post Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court appeared first on SecurityWeek. This article is an excerpt from…


  • Threat detection dashboards are masking security coverage gaps

    Threat detection dashboards are masking security coverage gaps 2026-09-25 at 15:04 By Sinisa Markovic A detection rule can show up as deployed on a coverage dashboard and still never fire when an attacker uses the technique it was built to catch. Conifers assessed 14,652 detections in its customer base, including rules written by customers and…


  • Windows, Linux, Android File Notification Systems Leak User Activity

    Windows, Linux, Android File Notification Systems Leak User Activity 2026-09-25 at 13:53 By Eduard Kovacs Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events. The post Windows, Linux, Android File Notification Systems Leak User Activity appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original…


  • Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

    Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise 2026-09-25 at 13:35 By Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.  “At 18:31 UTC on September 24, 2026, Bitget’s security systems identified unauthorized transfers involving a limited number of hot wallets,” BitGet…


  • Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

    Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild 2026-09-25 at 13:14 By The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail…


  • Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data

    Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data 2026-09-25 at 13:00 By A flaw in Cloudflare Containers let a paying customer read data that other customers’ containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space…


  • WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

    WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV 2026-09-25 at 13:00 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed…


  • Magic Eden scare puts 3,832 NFTs in whitehat protective custody

    Magic Eden scare puts 3,832 NFTs in whitehat protective custody 2026-09-25 at 12:48 By Cointelegraph by Ezra Reguerra Yuga Labs’ 0xQuit said the NFTs are safe and will be returned once the risk passes, while holders were urged to revoke NFT permissions. This article is an excerpt from Cointelegraph.com News View Original Source


  • ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

    ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration 2026-09-25 at 12:27 By Ionut Arghire Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks. The post ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View…


  • MacSync info-stealing malware hides malicious commands in an iCloud calendar

    MacSync info-stealing malware hides malicious commands in an iCloud calendar 2026-09-25 at 12:22 By Sinisa Markovic A new MacSync variant targets Mac users with an infostealer and persistent backdoor designed to steal credentials, crypto wallet data, and files, according to Kaspersky. Researchers found the malware spreading through a crypto wallet app called Toria, which had…


  • KelpDAO sues LayerZero, CEO over $292M rsETH bridge exploit

    KelpDAO sues LayerZero, CEO over $292M rsETH bridge exploit 2026-09-25 at 11:51 By Cointelegraph by Ezra Reguerra KelpDAO says LayerZero endorsed its bridge setup before the attack, while CEO Bryan Pellegrino has dismissed the lawsuit as meritless. This article is an excerpt from Cointelegraph.com News View Original Source


  • Inside the Telecom Attack Surface: SS7, BGP Hijacking, and the Technical Reality of Nation-State Intrusions 

    Inside the Telecom Attack Surface: SS7, BGP Hijacking, and the Technical Reality of Nation-State Intrusions  2026-09-25 at 11:50 By Ashish Khaitan Nation-state operators rarely need a zero-day to get inside a carrier. Much of the telecom stack still runs protocols designed when every participant was a known, trusted operator. SS7 assumes that the node sending…


  • Docker introduces OCI-based Kits to package agents and their guardrails

    Docker introduces OCI-based Kits to package agents and their guardrails 2026-09-25 at 10:57 By Industry News Docker has announced Docker Cloud Sandboxes, a new solution for secure, isolated AI agent execution that enables complex agentic workflows to continue running in the cloud long after a developer’s laptop shuts down. Launched at WeAreDevelopers North America, Docker…


  • Fake payroll desktop apps hand attackers a route to company paychecks

    Fake payroll desktop apps hand attackers a route to company paychecks 2026-09-25 at 10:52 By Sinisa Markovic An attacker has been offering “desktop apps” for three large US payroll and HR platforms that have never released one, Allure Security have found. Anyone who runs the installer gets a copy of ScreenConnect, a legitimate remote access…


Browse older archives

Scroll to Top