Cybersecurity and other IT news aggregator

LATEST FEEDS

  • A tale of two cities: San Francisco banning data centers, while Santa Clara is building more

    A tale of two cities: San Francisco banning data centers, while Santa Clara is building more 2026-09-19 at 00:31 By Vivi Lin Santa Clara collects an estimated $29.5 million a year from server farms which gets spent on police, parks, libraries and other resident services. This article is an excerpt from Latest Technology News |…


  • Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

    Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root 2026-09-19 at 00:22 By A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few…


  • Inside the phony, incestuous web of woke AI ‘watchdogs’ that Anthropic claims will save us from an AI apocalypse

    Inside the phony, incestuous web of woke AI ‘watchdogs’ that Anthropic claims will save us from an AI apocalypse 2026-09-18 at 23:11 By Thomas Barrabi Redwood Research – a Berkeley, Calif.-based group that co-authored a bombshell report last month detailing how a swarm of rogue OpenAI agents hacked rival firm Hugging Face – is one…


  • Binance launches 24/7 FX perps with weekend pricing system

    Binance launches 24/7 FX perps with weekend pricing system 2026-09-18 at 22:06 By Cointelegraph by Nate Kostar Binance is joining a growing number of crypto exchanges offering around-the-clock exposure to foreign exchange markets through perpetual futures. This article is an excerpt from Cointelegraph.com News View Original Source


  • Tech watchdogs cry foul as Google’s adtech monopoly left intact by judge: ‘Embarrassing capitulation’

    Tech watchdogs cry foul as Google’s adtech monopoly left intact by judge: ‘Embarrassing capitulation’ 2026-09-18 at 21:28 By Thomas Barrabi US District Judge Leonie Brinkema’s 106-page decision ordered Google to share more data about its ad auctions with publishers and appoint an independent antitrust monitor to police its business practices, among other changes. The order…


  • Crypto stocks rebound after CLARITY Act selloff

    Crypto stocks rebound after CLARITY Act selloff 2026-09-18 at 20:55 By Cointelegraph by Nate Kostar Coinbase, Strategy and other crypto-linked stocks rallied Friday as the CFTC and SEC moved ahead with crypto-related actions under existing authority. This article is an excerpt from Cointelegraph.com News View Original Source


  • New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

    New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution 2026-09-18 at 19:56 By WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without…


  • Part 1: Why “Less Is More” in Symantec PAM Clustering

    Part 1: Why “Less Is More” in Symantec PAM Clustering 2026-09-18 at 19:20 By Mickey Why adding nodes to your primary site hurts performance, and how to scale with secondary sites instead This article is an excerpt from SECURITY.COM View Original Source


  • CFTC submits crypto market regulation plan for White House review

    CFTC submits crypto market regulation plan for White House review 2026-09-18 at 19:04 By Cointelegraph by Nate Kostar The US commodities regulator submitted a new crypto market regulatory action for White House review days after the Senate failed to advance the CLARITY Act. This article is an excerpt from Cointelegraph.com News View Original Source


  • Edge Processing Is Quietly Changing Physical Security — Here’s Why It Matters

    Edge Processing Is Quietly Changing Physical Security — Here’s Why It Matters 2026-09-18 at 19:00 By Examining edge and cloud processing in detail, including the benefits and trade-offs of each.  This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • ‘Human GPS’ can pinpoint precise spot where obscure photos are taken, ‘might be FBI.’

    ‘Human GPS’ can pinpoint precise spot where obscure photos are taken, ‘might be FBI.’ 2026-09-18 at 18:56 By Ben Cost He found the owner’s lost “dog.” This article is an excerpt from Latest Technology News | New York Post View Original Source


  • Bitcoin hits $81K as US bond yields rebound on global oil woes

    Bitcoin hits $81K as US bond yields rebound on global oil woes 2026-09-18 at 18:35 By Cointelegraph by William Suberg Bitcoin price action made swift gains at the start of Friday’s Wall Street trading session as US 30-year bond yields began rising again. This article is an excerpt from Cointelegraph.com News View Original Source


  • Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

    Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 2026-09-18 at 18:24 By The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the…


  • Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

    Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation 2026-09-18 at 17:47 By Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. “Missing authentication…


  • An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

    An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. 2026-09-18 at 17:47 By In July 2025, someone registered a domain that used to belong to a content delivery network.  The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not…


  • Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

    Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents 2026-09-18 at 17:47 By A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed…


  • In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

    In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw 2026-09-18 at 17:25 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Mandiant’s 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical…


  • Banks double on EU MiCA crypto provider list as share hits 23%

    Banks double on EU MiCA crypto provider list as share hits 23% 2026-09-18 at 17:04 By Cointelegraph by Helen Partz Banks now represent nearly one in four providers on ESMA’s MiCA register after roughly doubling their presence since late June. This article is an excerpt from Cointelegraph.com News View Original Source


  • The Best Way to Thank Security Officers Is to Give Them the Support They Deserve

    The Best Way to Thank Security Officers Is to Give Them the Support They Deserve 2026-09-18 at 16:05 By National Security Officer Appreciation Week is about more than recognition. It’s about giving officers the tools and support they need to succeed. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original…


  • AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

    AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code 2026-09-18 at 15:45 By Eduard Kovacs Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.  The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View…


  • 23 Million User Records Compromised in Gyazo Data Breach 

    23 Million User Records Compromised in Gyazo Data Breach  2026-09-18 at 14:38 By Eduard Kovacs Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek…


  • Larry Ellison’s about-face on an Oracle stock sale sparks chatter in Silicon Valley, Hollywood 

    Larry Ellison’s about-face on an Oracle stock sale sparks chatter in Silicon Valley, Hollywood  2026-09-18 at 14:00 By Charles Gasparino Was this Ellison being crazy like a fox? This article is an excerpt from Latest Technology News | New York Post View Original Source


  • Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

    Microsoft Patches 18 Vulnerabilities in AI, Cloud Products 2026-09-18 at 13:57 By Eduard Kovacs Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

    WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage 2026-09-18 at 13:40 By Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the…


  • Bots with good manners are better at fooling people on social media

    Bots with good manners are better at fooling people on social media 2026-09-18 at 13:15 By Sinisa Markovic Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability…


  • Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

    Brevo Supply Chain Attack Injects Malware Into 100,000 Websites 2026-09-18 at 12:46 By Ionut Arghire Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

    Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer 2026-09-18 at 12:40 By A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. “The developer likely wrote the malware using a large language model (LLM),…


  • Stablecoin payments firm dtcpay closes $25M round with SBI backing

    Stablecoin payments firm dtcpay closes $25M round with SBI backing 2026-09-18 at 12:14 By Cointelegraph by Ezra Reguerra Dtcpay plans to expand its merchant network and payment products after completing a $25 million Series A backed by Japan’s SBI Group. This article is an excerpt from Cointelegraph.com News View Original Source


  • Beyond 1999: The Case for AI-Augmented Vulnerability Orchestration

    Beyond 1999: The Case for AI-Augmented Vulnerability Orchestration 2026-09-18 at 12:00 By Threat actors use AI and automation to weaponize flaws in milliseconds. Meanwhile, defensive teams remain shackled to spreadsheets, ticket chains, and 30-day approval cycles.  This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • Arcjet brings security controls and audit trails to AI agents

    Arcjet brings security controls and audit trails to AI agents 2026-09-18 at 11:55 By Industry News Arcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams the governance and compliance evidence they need. Arcjet brings observability, enforcement, and audit capabilities across…


  • Binance brushes off Lagarde MiCA speculation, reaffirms Europe commitment

    Binance brushes off Lagarde MiCA speculation, reaffirms Europe commitment 2026-09-18 at 11:50 By Cointelegraph by Helen Partz Binance declined to address reports of ECB intervention in its Greek MiCA bid, saying it remains committed to securing authorization in Europe. This article is an excerpt from Cointelegraph.com News View Original Source


  • Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

    Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched 2026-09-18 at 11:49 By Sinisa Markovic Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the…


  • Bitcoin cycle bottom may already be in at $58K, says analyst James Check

    Bitcoin cycle bottom may already be in at $58K, says analyst James Check 2026-09-18 at 11:47 By Cointelegraph by Ezra Reguerra Onchain analyst James Check says Bitcoin may have bottomed near $58,000 after two capitulations and warns against anchoring to an October low. This article is an excerpt from Cointelegraph.com News View Original Source


  • Critical Orkes Conductor Vulnerability Exploited in Attacks

    Critical Orkes Conductor Vulnerability Exploited in Attacks 2026-09-18 at 11:42 By Ionut Arghire CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Android apps can now check security patches down to individual device components

    Android apps can now check security patches down to individual device components 2026-09-18 at 11:38 By Anamarija Pogorelec New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status…


  • MIND Secures $72 Million for AI-Powered DLP

    MIND Secures $72 Million for AI-Powered DLP 2026-09-18 at 10:25 By Ionut Arghire The company will use the funding to accelerate platform development and expand its presence in key enterprise markets. The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

    Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root 2026-09-18 at 10:21 By A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall…


  • ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

    ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories 2026-09-18 at 10:21 By Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly…


  • Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

    Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files 2026-09-18 at 10:21 By Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The…


  • Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

    Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords 2026-09-18 at 10:21 By The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. “HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery,…


  • Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

    Check Point, Kaspersky, Tanium Patch Product Vulnerabilities 2026-09-18 at 10:14 By Eduard Kovacs Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek…


  • Australia iPhone 18 launch descends into chaos as line-cutter claims he’s first in world to buy device: ‘I’m the first!’

    Australia iPhone 18 launch descends into chaos as line-cutter claims he’s first in world to buy device: ‘I’m the first!’ 2026-09-18 at 09:42 By News.com.au He spent hours camped outside the flagship store only to watch a rival line-jumper barge past him in the dash for the doors, phone held aloft, declaring himself the world’s…


  • RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

    RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall 2026-09-18 at 09:17 By Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing (SMS/text phishing) and…


  • Abandoned IoT apps keep sending sensitive data to broken servers

    Abandoned IoT apps keep sending sensitive data to broken servers 2026-09-18 at 09:00 By Sinisa Markovic Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates years ago. Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned…


  • Hardcoded MCP credentials found in public GitHub files

    Hardcoded MCP credentials found in public GitHub files 2026-09-18 at 08:30 By Anamarija Pogorelec Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The…


  • 98% of fraudulent hires have company credentials by the time they’re caught

    98% of fraudulent hires have company credentials by the time they’re caught 2026-09-18 at 08:00 By Anamarija Pogorelec A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can…


  • Most WordPress pros still lack a breach recovery plan

    Most WordPress pros still lack a breach recovery plan 2026-09-18 at 07:30 By Anamarija Pogorelec Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners…


  • New infosec products of the week: September 18, 2026

    New infosec products of the week: September 18, 2026 2026-09-18 at 07:00 By Anamarija Pogorelec Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr uses agentic AI to predict and verify security threats Dataminr has announced Dataminr Advanced for Corporate…


  • North Korea drives onchain malware surge, CoinEx shuts: Asia Express

    North Korea drives onchain malware surge, CoinEx shuts: Asia Express 2026-09-18 at 02:49 By Cointelegraph by Andrew Fenton North Korea and Iran account for the majority of onchain malware, while Malaysia has been named among the most crypto curious Islamic nations. This article is an excerpt from Cointelegraph.com News View Original Source


  • AI protesters rally outside Dreamforce conference in San Francisco as tech bosses shrug off fears

    AI protesters rally outside Dreamforce conference in San Francisco as tech bosses shrug off fears 2026-09-17 at 23:45 By Annie Gaus AI critics took to San Francisco streets Thursday to call for action on the rapidly advancing technology, but their protest drew only a small crowd as some tech CEOs shrugged off rising alarm about…


Browse older archives

Scroll to Top