September 2026

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data 2026-09-15 at 18:30 By Eduard Kovacs A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems. The post Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data Read More »

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

BambooToken Malware Uses MQTT to Control Windows and Linux Systems 2026-09-15 at 18:23 By Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at […]

BambooToken Malware Uses MQTT to Control Windows and Linux Systems Read More »

F5 Bot Defense uses real-time risk scoring to detect fraud and abuse

F5 Bot Defense uses real-time risk scoring to detect fraud and abuse 2026-09-15 at 16:55 By Industry News F5 has announced enhancements to F5 Distributed Cloud Bot Defense, introducing new device intelligence capabilities and specialized agentic AI protections. These capabilities bring persistent device context and continuous risk decisioning to application security, giving organizations the real-time […]

F5 Bot Defense uses real-time risk scoring to detect fraud and abuse Read More »

Postman Passport controls API access without exposing credentials

Postman Passport controls API access without exposing credentials 2026-09-15 at 16:40 By Industry News Postman has announced the general availability of Passport by Postman, marking the company’s expansion into API security with a standalone product that gives organizations a secure way to consume APIs as human and non-human identities increasingly work side by side. The […]

Postman Passport controls API access without exposing credentials Read More »

USDT payments feature in Polish energy giant’s failed $230M oil deal: FT

USDT payments feature in Polish energy giant’s failed $230M oil deal: FT 2026-09-15 at 16:37 By Cointelegraph by Zoltan Vardai Tether’s USDT stablecoin was part of a failed oil trade that reportedly cost a Polish energy giant $230 million in late 2023. This article is an excerpt from Cointelegraph.com News View Original Source

USDT payments feature in Polish energy giant’s failed $230M oil deal: FT Read More »

UltraViolet Cyber Equinox measures detection coverage against MITRE frameworks

UltraViolet Cyber Equinox measures detection coverage against MITRE frameworks 2026-09-15 at 16:33 By Industry News UltraViolet Cyber has announced the launch of Equinox, its proprietary detection engineering platform, built and operated by the Threat Intelligence & Detection Engineering (TIDE) team. Equinox maximizes detection coverage across customers’ Security Information and Event Management (SIEM) and Endpoint Detection […]

UltraViolet Cyber Equinox measures detection coverage against MITRE frameworks Read More »

Thai Broadband Provider Hacked via Fortinet Vulnerability

Thai Broadband Provider Hacked via Fortinet Vulnerability 2026-09-15 at 16:33 By Ionut Arghire The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked via Fortinet Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Thai Broadband Provider Hacked via Fortinet Vulnerability Read More »

Globalgig expands managed security portfolio to protect enterprise AI

Globalgig expands managed security portfolio to protect enterprise AI 2026-09-15 at 16:21 By Industry News Globalgig has expanded its managed security portfolio to cover enterprise AI, bringing together services that discover, assess, and protect the AI applications, agents, models, and data enterprises are putting into production. The services are delivered through the same managed model […]

Globalgig expands managed security portfolio to protect enterprise AI Read More »

eBook: Identity-First Threat Intelligence

eBook: Identity-First Threat Intelligence 2026-09-15 at 16:00 By Help Net Security Attackers increasingly bypass traditional defenses by logging in with credentials that have already been stolen, exposed, or sold on the Dark Web. As infostealer malware accelerates credential theft, organizations need greater visibility into identity risk across Active Directory, IAM, and authentication environments. Download the […]

eBook: Identity-First Threat Intelligence Read More »

Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks

Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks 2026-09-15 at 15:32 By Sinisa Markovic A new AI subscription service called Luciferus is being marketed on a hacking forum as an alternative to jailbreaking ChatGPT or Claude, Sophos found. The Counter Threat Unit (CTU) spotted the advertisement on August 24 on […]

Uncensored AI sold on hacking forum as alternative to ChatGPT and Claude jailbreaks Read More »

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds 2026-09-15 at 14:52 By With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In […]

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds Read More »

240,000 Hit by Data Breach at Japan’s Digital Agency

240,000 Hit by Data Breach at Japan’s Digital Agency 2026-09-15 at 14:45 By Ionut Arghire Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people. The post 240,000 Hit by Data Breach at Japan’s Digital Agency appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

240,000 Hit by Data Breach at Japan’s Digital Agency Read More »

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point 2026-09-15 at 14:26 By Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, […]

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point Read More »

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers 2026-09-15 at 14:12 By Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that’s designed to steal cloud credentials, configurations from Amazon […]

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers Read More »

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461)

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) 2026-09-15 at 14:09 By Zeljka Zorz Attackers have leveraged a zero-day SQL injection vulnerability (CVE-2026-76461) to compromise Cisco Secure Email Gateway appliances, Cisco confirmed on Monday. The vendor’s Product Security Incident Response Team became aware of active exploitation of this vulnerability in September 2025, and has shared […]

Cisco patches actively exploited email gateway zero-day (CVE-2026-76461) Read More »

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases 

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  2026-09-15 at 14:06 By Ionut Arghire The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks. The post Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  appeared first on […]

Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases  Read More »

Microsoft sets security and safety rules for its AI models

Microsoft sets security and safety rules for its AI models 2026-09-15 at 13:50 By Anamarija Pogorelec Microsoft AI has published the first draft of its Humanist AI Code of Conduct, a training manual outlining how it develops AI models and intends them to behave during deployment. The draft is open for public consultation for six […]

Microsoft sets security and safety rules for its AI models Read More »

Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz

Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz 2026-09-15 at 13:10 By Sinisa Markovic Attackers compromised the verified official HBO Max Reddit account, u/hbomax, and used its trusted advertising status to launch a ClickFix campaign targeting macOS and Windows devices with information-stealing malware. Screenshot of the fraudulent ad (Source: Alex Cutts) ClickFix has […]

Attackers hijack HBO Max’s Reddit account for 48-hour malvertising blitz Read More »

Scroll to Top