2026

Critical Orkes Conductor Vulnerability Exploited in Attacks

Critical Orkes Conductor Vulnerability Exploited in Attacks 2026-09-18 at 11:42 By Ionut Arghire CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Critical Orkes Conductor Vulnerability Exploited in Attacks Read More »

Android apps can now check security patches down to individual device components

Android apps can now check security patches down to individual device components 2026-09-18 at 11:38 By Anamarija Pogorelec New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status […]

Android apps can now check security patches down to individual device components Read More »

MIND Secures $72 Million for AI-Powered DLP

MIND Secures $72 Million for AI-Powered DLP 2026-09-18 at 10:25 By Ionut Arghire The company will use the funding to accelerate platform development and expand its presence in key enterprise markets. The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

MIND Secures $72 Million for AI-Powered DLP Read More »

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root 2026-09-18 at 10:21 By A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall […]

Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root Read More »

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories 2026-09-18 at 10:21 By Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly […]

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories Read More »

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files 2026-09-18 at 10:21 By Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The […]

Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files Read More »

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords 2026-09-18 at 10:21 By The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. “HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, […]

Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords Read More »

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities 2026-09-18 at 10:14 By Eduard Kovacs Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Check Point, Kaspersky, Tanium Patch Product Vulnerabilities Read More »

Australia iPhone 18 launch descends into chaos as line-cutter claims he’s first in world to buy device: ‘I’m the first!’

Australia iPhone 18 launch descends into chaos as line-cutter claims he’s first in world to buy device: ‘I’m the first!’ 2026-09-18 at 09:42 By News.com.au He spent hours camped outside the flagship store only to watch a rival line-jumper barge past him in the dash for the doors, phone held aloft, declaring himself the world’s […]

Australia iPhone 18 launch descends into chaos as line-cutter claims he’s first in world to buy device: ‘I’m the first!’ Read More »

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall 2026-09-18 at 09:17 By Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. “Distributed primarily via targeted smishing (SMS/text phishing) and […]

RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall Read More »

Abandoned IoT apps keep sending sensitive data to broken servers

Abandoned IoT apps keep sending sensitive data to broken servers 2026-09-18 at 09:00 By Sinisa Markovic Millions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates years ago. Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned […]

Abandoned IoT apps keep sending sensitive data to broken servers Read More »

Hardcoded MCP credentials found in public GitHub files

Hardcoded MCP credentials found in public GitHub files 2026-09-18 at 08:30 By Anamarija Pogorelec Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The […]

Hardcoded MCP credentials found in public GitHub files Read More »

98% of fraudulent hires have company credentials by the time they’re caught

98% of fraudulent hires have company credentials by the time they’re caught 2026-09-18 at 08:00 By Anamarija Pogorelec A 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can […]

98% of fraudulent hires have company credentials by the time they’re caught Read More »

Most WordPress pros still lack a breach recovery plan

Most WordPress pros still lack a breach recovery plan 2026-09-18 at 07:30 By Anamarija Pogorelec Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners […]

Most WordPress pros still lack a breach recovery plan Read More »

New infosec products of the week: September 18, 2026

New infosec products of the week: September 18, 2026 2026-09-18 at 07:00 By Anamarija Pogorelec Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr uses agentic AI to predict and verify security threats Dataminr has announced Dataminr Advanced for Corporate […]

New infosec products of the week: September 18, 2026 Read More »

North Korea drives onchain malware surge, CoinEx shuts: Asia Express

North Korea drives onchain malware surge, CoinEx shuts: Asia Express 2026-09-18 at 02:49 By Cointelegraph by Andrew Fenton North Korea and Iran account for the majority of onchain malware, while Malaysia has been named among the most crypto curious Islamic nations. This article is an excerpt from Cointelegraph.com News View Original Source

North Korea drives onchain malware surge, CoinEx shuts: Asia Express Read More »

AI protesters rally outside Dreamforce conference in San Francisco as tech bosses shrug off fears

AI protesters rally outside Dreamforce conference in San Francisco as tech bosses shrug off fears 2026-09-17 at 23:45 By Annie Gaus AI critics took to San Francisco streets Thursday to call for action on the rapidly advancing technology, but their protest drew only a small crowd as some tech CEOs shrugged off rising alarm about […]

AI protesters rally outside Dreamforce conference in San Francisco as tech bosses shrug off fears Read More »

AI assistant Instinct’s valuation has quadrupled to $10B in a month, but is it worth the hype?

AI assistant Instinct’s valuation has quadrupled to $10B in a month, but is it worth the hype? 2026-09-17 at 23:37 By Lydia Moynihan “This is the first AI assistant I’ve recommended my wife and kids, who aren’t techies, should use,” said John Borthwick of Betaworks, an early investor in Hugging Face (but who has no […]

AI assistant Instinct’s valuation has quadrupled to $10B in a month, but is it worth the hype? Read More »

WisdomTree, MoonPay team up to expand US access to tokenized money market fund

WisdomTree, MoonPay team up to expand US access to tokenized money market fund 2026-09-17 at 20:31 By Cointelegraph by Nate Kostar MoonPay plans to use WisdomTree’s $1.2 billion WTGXX tokenized fund as part of its stablecoin reserves while helping expand access to US investors. This article is an excerpt from Cointelegraph.com News View Original Source

WisdomTree, MoonPay team up to expand US access to tokenized money market fund Read More »

Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels 2026-09-17 at 20:09 By Eduard Kovacs The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran. The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first […]

Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels Read More »

Scroll to Top