September 2026

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites 2026-09-18 at 12:46 By Ionut Arghire Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Brevo Supply Chain Attack Injects Malware Into 100,000 Websites Read More »

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer 2026-09-18 at 12:40 By A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. “The developer likely wrote the malware using a large language model (LLM), […]

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer Read More »

Stablecoin payments firm dtcpay closes $25M round with SBI backing

Stablecoin payments firm dtcpay closes $25M round with SBI backing 2026-09-18 at 12:14 By Cointelegraph by Ezra Reguerra Dtcpay plans to expand its merchant network and payment products after completing a $25 million Series A backed by Japan’s SBI Group. This article is an excerpt from Cointelegraph.com News View Original Source

Stablecoin payments firm dtcpay closes $25M round with SBI backing Read More »

Beyond 1999: The Case for AI-Augmented Vulnerability Orchestration

Beyond 1999: The Case for AI-Augmented Vulnerability Orchestration 2026-09-18 at 12:00 By Threat actors use AI and automation to weaponize flaws in milliseconds. Meanwhile, defensive teams remain shackled to spreadsheets, ticket chains, and 30-day approval cycles.  This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source

Beyond 1999: The Case for AI-Augmented Vulnerability Orchestration Read More »

Arcjet brings security controls and audit trails to AI agents

Arcjet brings security controls and audit trails to AI agents 2026-09-18 at 11:55 By Industry News Arcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams the governance and compliance evidence they need. Arcjet brings observability, enforcement, and audit capabilities across […]

Arcjet brings security controls and audit trails to AI agents Read More »

Binance brushes off Lagarde MiCA speculation, reaffirms Europe commitment

Binance brushes off Lagarde MiCA speculation, reaffirms Europe commitment 2026-09-18 at 11:50 By Cointelegraph by Helen Partz Binance declined to address reports of ECB intervention in its Greek MiCA bid, saying it remains committed to securing authorization in Europe. This article is an excerpt from Cointelegraph.com News View Original Source

Binance brushes off Lagarde MiCA speculation, reaffirms Europe commitment Read More »

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched 2026-09-18 at 11:49 By Sinisa Markovic Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the […]

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched Read More »

Bitcoin cycle bottom may already be in at $58K, says analyst James Check

Bitcoin cycle bottom may already be in at $58K, says analyst James Check 2026-09-18 at 11:47 By Cointelegraph by Ezra Reguerra Onchain analyst James Check says Bitcoin may have bottomed near $58,000 after two capitulations and warns against anchoring to an October low. This article is an excerpt from Cointelegraph.com News View Original Source

Bitcoin cycle bottom may already be in at $58K, says analyst James Check Read More »

Critical Orkes Conductor Vulnerability Exploited in Attacks

Critical Orkes Conductor Vulnerability Exploited in Attacks 2026-09-18 at 11:42 By Ionut Arghire CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Orkes Conductor Vulnerability Exploited in Attacks Read More »

Android apps can now check security patches down to individual device components

Android apps can now check security patches down to individual device components 2026-09-18 at 11:38 By Anamarija Pogorelec New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status […]

Android apps can now check security patches down to individual device components Read More »

MIND Secures $72 Million for AI-Powered DLP

MIND Secures $72 Million for AI-Powered DLP 2026-09-18 at 10:25 By Ionut Arghire The company will use the funding to accelerate platform development and expand its presence in key enterprise markets. The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

MIND Secures $72 Million for AI-Powered DLP Read More »

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root 2026-09-18 at 10:21 By A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall […]

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root Read More »

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories 2026-09-18 at 10:21 By Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly […]

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Read More »

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files 2026-09-18 at 10:21 By Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The […]

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files Read More »

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords 2026-09-18 at 10:21 By The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. “HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, […]

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords Read More »

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities 2026-09-18 at 10:14 By Eduard Kovacs Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities Read More »

Australia iPhone 18 launch descends into chaos as line-cutter claims he’s first in world to buy device: ‘I’m the first!’

Australia iPhone 18 launch descends into chaos as line-cutter claims he’s first in world to buy device: ‘I’m the first!’ 2026-09-18 at 09:42 By News.com.au He spent hours camped outside the flagship store only to watch a rival line-jumper barge past him in the dash for the doors, phone held aloft, declaring himself the world’s […]

Australia iPhone 18 launch descends into chaos as line-cutter claims he’s first in world to buy device: ‘I’m the first!’ Read More »

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall 2026-09-18 at 09:17 By Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing (SMS/text phishing) and […]

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall Read More »

Abandoned IoT apps keep sending sensitive data to broken servers

Abandoned IoT apps keep sending sensitive data to broken servers 2026-09-18 at 09:00 By Sinisa Markovic Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates years ago. Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned […]

Abandoned IoT apps keep sending sensitive data to broken servers Read More »

Hardcoded MCP credentials found in public GitHub files

Hardcoded MCP credentials found in public GitHub files 2026-09-18 at 08:30 By Anamarija Pogorelec Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The […]

Hardcoded MCP credentials found in public GitHub files Read More »

Scroll to Top