Cybersecurity and other IT news aggregator

LATEST FEEDS

  • Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

    Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens 2026-09-16 at 09:41 By A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic…


  • What happens when AI agent governance is missing at scale

    What happens when AI agent governance is missing at scale 2026-09-16 at 09:00 By Mirko Zorz In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what an agent does, since…


  • Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

    Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells 2026-09-16 at 08:48 By Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. “This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors,…


  • DeepZero: Open-source hunting for vulnerable Windows drivers

    DeepZero: Open-source hunting for vulnerable Windows drivers 2026-09-16 at 08:30 By Mirko Zorz DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and asks a language model whether…


  • The modern attack chain: Rethinking Google Workspace security in the age of AI

    The modern attack chain: Rethinking Google Workspace security in the age of AI 2026-09-16 at 08:00 By Help Net Security Over the past two months, I’ve written about the Vercel breach and the Composio breach separately. Both offer lessons to learn on their own. But reading them together, I keep coming back to the same…


  • US charges ex-Robinhood engineers over alleged pre-listing crypto trades

    US charges ex-Robinhood engineers over alleged pre-listing crypto trades 2026-09-16 at 07:48 By Cointelegraph by Ezra Reguerra The former employees allegedly earned more than $50,000 each by trading Hyperliquid perpetuals ahead of Robinhood token listings. This article is an excerpt from Cointelegraph.com News View Original Source


  • MSPs say nearly half their customers rely on them for CISO services

    MSPs say nearly half their customers rely on them for CISO services 2026-09-16 at 07:30 By Anamarija Pogorelec MSPs estimate that 46% of their customers, on average, look to them to act as CISOs, according to Sophos. Most of those providers do that job without the full set of compliance services, and many spread the…


  • Bitcoin ETFs shed $450M in biggest outflow since June

    Bitcoin ETFs shed $450M in biggest outflow since June 2026-09-16 at 07:05 By Cointelegraph by Felix Ng The $450 million withdrawal came as Bitcoin fell 2.5% and the CLARITY Act failed to advance in the Senate, with Fidelity and BlackRock funds leading the outflows. This article is an excerpt from Cointelegraph.com News View Original Source


  • Crypto industry turns to US regulators after CLARITY setback

    Crypto industry turns to US regulators after CLARITY setback 2026-09-16 at 05:24 By Cointelegraph by Felix Ng The CLARITY Act still has a procedural path after Senator Thom Tillis moved to reconsider the failed cloture vote, though industry executives are divided over whether Congress has enough time left. This article is an excerpt from Cointelegraph.com…


  • Anthropic CEO Dario Amodei’s handpicked AI watchdog has deep ties to woke Effective Altruism movement: ‘a complete joke’

    Anthropic CEO Dario Amodei’s handpicked AI watchdog has deep ties to woke Effective Altruism movement: ‘a complete joke’ 2026-09-16 at 01:40 By Thomas Barrabi Anthropic’s CEO Dario Amodei says he has found an outside team that can regulate AI and make sure it doesn’t destroy the world — and it just so happens to have…


  • BIS paper finds major gap in Bitcoin onchain transfer estimates

    BIS paper finds major gap in Bitcoin onchain transfer estimates 2026-09-16 at 00:23 By Cointelegraph by Nate Kostar A BIS study found widely used crypto metrics can obscure economic activity, with measurement challenges spanning Bitcoin, Ethereum and stablecoins. This article is an excerpt from Cointelegraph.com News View Original Source


  • Forget data privacy, AI chatbots already know more than your own mother

    Forget data privacy, AI chatbots already know more than your own mother 2026-09-16 at 00:12 By Rikki Schlott AI companies are now in possession of heaps of personal information that social media giants could only dream of. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • Crypto stocks slide after CLARITY Act fails to advance in Senate

    Crypto stocks slide after CLARITY Act fails to advance in Senate 2026-09-15 at 23:37 By Cointelegraph by Nate Kostar Circle and Coinbase shares fell about 10% as the failed Senate vote weighed on crypto-linked equities, with Bitcoin miners and treasury companies also declining. This article is an excerpt from Cointelegraph.com News View Original Source


  • Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

    Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? 2026-09-15 at 23:24 By Associated Press Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech…


  • Google DeepMind researcher quits with chilling AI warning: It could ‘kill us all’

    Google DeepMind researcher quits with chilling AI warning: It could ‘kill us all’ 2026-09-15 at 23:11 By Ariel Zilber Bilal Chughtai said Monday that he had become deeply worried about the direction of the technology after watching its rapid development firsthand. This article is an excerpt from Latest Technology News | New York Post View…


  • “We Think the Security Control Is Working” Is No Longer Good Enough

    “We Think the Security Control Is Working” Is No Longer Good Enough 2026-09-15 at 22:30 By Sravish Sridhar Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek.…


  • Majority of Organizations Have Over 50 AI Agents

    Majority of Organizations Have Over 50 AI Agents 2026-09-15 at 21:54 By A report by Zentera Systems analyzed the deployment of AI agents within organizations. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

    KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens 2026-09-15 at 21:54 By Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat…


  • US Senate fails to advance CLARITY Act

    US Senate fails to advance CLARITY Act 2026-09-15 at 21:46 By Cointelegraph by Sam Bourgi The failed procedural vote leaves the CLARITY Act facing an uncertain future after months of negotiations over crypto oversight and ethics provisions. This article is an excerpt from Cointelegraph.com News View Original Source


  • Stablecoin growth could boost dollar dominance, US Treasury demand: BoE official

    Stablecoin growth could boost dollar dominance, US Treasury demand: BoE official 2026-09-15 at 20:53 By Cointelegraph by Sam Bourgi A Bank of England policy maker said digital dollars could expand access to the US currency while turning stablecoin issuers into bigger buyers of government debt. This article is an excerpt from Cointelegraph.com News View Original…


  • Binance adds 11 US-listed ETFs to wealth management offering

    Binance adds 11 US-listed ETFs to wealth management offering 2026-09-15 at 20:22 By Cointelegraph by Nate Kostar The crypto exchange is expanding its traditional finance offerings with 11 US-listed exchange-traded funds focused on US Treasurys and investment-grade bonds. This article is an excerpt from Cointelegraph.com News View Original Source


  • Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

    Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists 2026-09-15 at 19:29 By Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the…


  • Bitcoin price falls to $75.6K September low as global bonds hit multidecade highs

    Bitcoin price falls to $75.6K September low as global bonds hit multidecade highs 2026-09-15 at 19:02 By Cointelegraph by William Suberg Bitcoin price action weakened over market nerves prior to the Senate CLARITY Act vote, while surging bond yields pressured risk assets across the board. This article is an excerpt from Cointelegraph.com News View Original…


  • $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

    $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws 2026-09-15 at 19:00 By Kevin Townsend AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage. The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Standard Chartered says Arbitrum could outperform Bitcoin, Ether through 2030

    Standard Chartered says Arbitrum could outperform Bitcoin, Ether through 2030 2026-09-15 at 18:50 By Cointelegraph by Sam Bourgi Standard Chartered sees Robinhood Chain as an early sign that tokenization could transform Arbitrum’s economics and drive ARB sharply higher by 2030. This article is an excerpt from Cointelegraph.com News View Original Source


  • Exein Secures $270M at $1.7B Valuation for Physical AI Security

    Exein Secures $270M at $1.7B Valuation for Physical AI Security 2026-09-15 at 18:45 By Ionut Arghire The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion. The post Exein Secures $270M at $1.7B Valuation for Physical AI Security appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View…


  • Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

    Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data 2026-09-15 at 18:30 By Eduard Kovacs A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems. The post Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View…


  • BambooToken Malware Uses MQTT to Control Windows and Linux Systems

    BambooToken Malware Uses MQTT to Control Windows and Linux Systems 2026-09-15 at 18:23 By Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at…


  • Digital Risk Protection in the Age of AI

    Digital Risk Protection in the Age of AI 2026-09-15 at 17:00 By Aaron Cookstra Digital risk has expanded far beyond the traditional security perimeter. This article is an excerpt from LevelBlue Blog View Original Source


  • F5 Bot Defense uses real-time risk scoring to detect fraud and abuse

    F5 Bot Defense uses real-time risk scoring to detect fraud and abuse 2026-09-15 at 16:55 By Industry News F5 has announced enhancements to F5 Distributed Cloud Bot Defense, introducing new device intelligence capabilities and specialized agentic AI protections. These capabilities bring persistent device context and continuous risk decisioning to application security, giving organizations the real-time…


  • Postman Passport controls API access without exposing credentials

    Postman Passport controls API access without exposing credentials 2026-09-15 at 16:40 By Industry News Postman has announced the general availability of Passport by Postman, marking the company’s expansion into API security with a standalone product that gives organizations a secure way to consume APIs as human and non-human identities increasingly work side by side. The…


  • USDT payments feature in Polish energy giant’s failed $230M oil deal: FT

    USDT payments feature in Polish energy giant’s failed $230M oil deal: FT 2026-09-15 at 16:37 By Cointelegraph by Zoltan Vardai Tether’s USDT stablecoin was part of a failed oil trade that reportedly cost a Polish energy giant $230 million in late 2023. This article is an excerpt from Cointelegraph.com News View Original Source


  • UltraViolet Cyber Equinox measures detection coverage against MITRE frameworks

    UltraViolet Cyber Equinox measures detection coverage against MITRE frameworks 2026-09-15 at 16:33 By Industry News UltraViolet Cyber has announced the launch of Equinox, its proprietary detection engineering platform, built and operated by the Threat Intelligence & Detection Engineering (TIDE) team. Equinox maximizes detection coverage across customers’ Security Information and Event Management (SIEM) and Endpoint Detection…


  • Thai Broadband Provider Hacked via Fortinet Vulnerability

    Thai Broadband Provider Hacked via Fortinet Vulnerability 2026-09-15 at 16:33 By Ionut Arghire The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked via Fortinet Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Globalgig expands managed security portfolio to protect enterprise AI

    Globalgig expands managed security portfolio to protect enterprise AI 2026-09-15 at 16:21 By Industry News Globalgig has expanded its managed security portfolio to cover enterprise AI, bringing together services that discover, assess, and protect the AI applications, agents, models, and data enterprises are putting into production. The services are delivered through the same managed model…


  • eBook: Identity-First Threat Intelligence

    eBook: Identity-First Threat Intelligence 2026-09-15 at 16:00 By Help Net Security Attackers increasingly bypass traditional defenses by logging in with credentials that have already been stolen, exposed, or sold on the Dark Web. As infostealer malware accelerates credential theft, organizations need greater visibility into identity risk across Active Directory, IAM, and authentication environments. Download the…


  • Ransomware Doesn’t Just Break Systems. It Breaks People.

    Ransomware Doesn’t Just Break Systems. It Breaks People. 2026-09-15 at 16:00 By The most enduring impact of ransomware attacks is human: stress, fear, job loss, and long-term consequences that rarely show up in incident reports. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks

    Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks 2026-09-15 at 15:32 By Sinisa Markovic A new AI subscription service called Luciferus is being marketed on a hacking forum as an alternative to jailbreaking ChatGPT or Claude, Sophos found. The Counter Threat Unit (CTU) spotted the advertisement on August 24 on…


  • Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

    Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds 2026-09-15 at 14:52 By With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In…


  • 240,000 Hit by Data Breach at Japan’s Digital Agency

    240,000 Hit by Data Breach at Japan’s Digital Agency 2026-09-15 at 14:45 By Ionut Arghire Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people. The post 240,000 Hit by Data Breach at Japan’s Digital Agency appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View…


  • Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

    Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point 2026-09-15 at 14:26 By Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And,…


  • Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

    Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers 2026-09-15 at 14:12 By Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that’s designed to steal cloud credentials, configurations from Amazon…


  • Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

    Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) 2026-09-15 at 14:09 By Zeljka Zorz Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor’s Product Security Incident Response Team became aware of active exploitation of this vulnerability in September 2025, and has shared…


  • Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases 

    Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  2026-09-15 at 14:06 By Ionut Arghire The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks. The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  appeared first on…


  • Microsoft sets security and safety rules for its AI models

    Microsoft sets security and safety rules for its AI models 2026-09-15 at 13:50 By Anamarija Pogorelec Microsoft AI has published the first draft of its Humanist AI Code of Conduct, a training manual outlining how it develops AI models and intends them to behave during deployment. The draft is open for public consultation for six…


  • Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz

    Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz 2026-09-15 at 13:10 By Sinisa Markovic Attackers compromised the verified official HBO Max Reddit account, u/hbomax, and used its trusted advertising status to launch a ClickFix campaign targeting macOS and Windows devices with information-stealing malware. Screenshot of the fraudulent ad (Source: Alex Cutts) ClickFix has…


  • US House crypto tax package omits mining, staking reward deferral

    US House crypto tax package omits mining, staking reward deferral 2026-09-15 at 13:04 By Cointelegraph by Ezra Reguerra The 114-page bill would change the tax treatment of crypto fees, stablecoins and lending while leaving existing reward-tax timing unchanged. This article is an excerpt from Cointelegraph.com News View Original Source


  • US seeks $61M in USDT allegedly tied to sanctioned Iranian oil sales

    US seeks $61M in USDT allegedly tied to sanctioned Iranian oil sales 2026-09-15 at 13:02 By Cointelegraph by Ezra Reguerra Tether froze $61.19 million across 10 Tron addresses in 2025 that prosecutors allege were connected to black-market Iranian oil proceeds. This article is an excerpt from Cointelegraph.com News View Original Source


  • Ethereum, Base wallet standards talks fail, Ethlabs researcher says

    Ethereum, Base wallet standards talks fail, Ethlabs researcher says 2026-09-15 at 12:40 By Cointelegraph by Zoltan Vardai Ethereum and Base are pursuing different account abstraction designs after talks failed, according to Ethlabs researcher Derek Chiang. This article is an excerpt from Cointelegraph.com News View Original Source


  • Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

    Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints 2026-09-15 at 12:40 By Eduard Kovacs The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints appeared first on SecurityWeek.…


Browse older archives

Scroll to Top