2026

This Key Will Self-Destruct: An Open Standard for Revocable API Keys

This Key Will Self-Destruct: An Open Standard for Revocable API Keys 2026-09-09 at 13:00 By Matt Honea Every leaked credential should be dead, or dying, within sixty seconds of being found. Here’s a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on […]

This Key Will Self-Destruct: An Open Standard for Revocable API Keys Read More »

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser 2026-09-09 at 13:00 By Kevin Townsend Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first […]

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser Read More »

Chinese AI firms are siphoning capabilities from American models, CISA warns

Chinese AI firms are siphoning capabilities from American models, CISA warns 2026-09-09 at 12:55 By Anamarija Pogorelec China-based AI companies are using large-scale knowledge distillation campaigns to copy capabilities from leading U.S. AI models, according to a joint cybersecurity advisory from the CISA, NSA, and FBI. Knowledge distillation is a standard AI training technique that […]

Chinese AI firms are siphoning capabilities from American models, CISA warns Read More »

Securin Platform helps security teams prove when attack paths are closed

Securin Platform helps security teams prove when attack paths are closed 2026-09-09 at 12:52 By Industry News Securin has announced the general availability of the Securin Platform, an AI-native Preemptive Exposure Management platform designed to answer three questions security teams struggle with every day: What can attackers actually exploit? What should we fix first? And […]

Securin Platform helps security teams prove when attack paths are closed Read More »

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed 2026-09-09 at 12:20 By The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which […]

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed Read More »

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution 2026-09-09 at 12:20 By SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS […]

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution Read More »

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox 2026-09-09 at 12:11 By Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug […]

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox Read More »

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor 2026-09-09 at 12:04 By Zeljka Zorz September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days. Another “new normal” is the anonymous security researcher Nightmare Eclipse publishing […]

September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor Read More »

Security’s Most Influential People in Security 2026

Security’s Most Influential People in Security 2026 2026-09-09 at 12:00 By The 2026 Most Influential People in Security have shaped the future of security and risk management through leadership, innovation and commitment to progress across the industry. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source

Security’s Most Influential People in Security 2026 Read More »

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root 2026-09-09 at 11:19 By cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack […]

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root Read More »

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491)

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) 2026-09-09 at 10:53 By Sinisa Markovic Google has fixed 230 vulnerabilities in Chrome, including a zero-day flaw, CVE-2026-87491, with an in-the-wild exploit. “Google is aware that an exploit for CVE-2026-87491 exists in the wild,” the company said in a Tuesday security advisory. The fix has been […]

Google fixes yet another actively exploited Chrome zero-day (CVE-2026-87491) Read More »

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans 2026-09-09 at 10:36 By Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any […]

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans Read More »

Iran eases currency rules to bypass US sanctions with crypto: Report

Iran eases currency rules to bypass US sanctions with crypto: Report 2026-09-09 at 10:36 By Cointelegraph by Zoltan Vardai Exporters can now fund imports with overseas earnings without first selling their foreign currency at official rates, the Financial Times reported. This article is an excerpt from Cointelegraph.com News View Original Source

Iran eases currency rules to bypass US sanctions with crypto: Report Read More »

Jack Dorsey’s Block seeks US trust bank charter for Bitcoin, stablecoin

Jack Dorsey’s Block seeks US trust bank charter for Bitcoin, stablecoin 2026-09-09 at 10:36 By Cointelegraph by Ezra Reguerra The proposed Builders Bank would offer federally supervised digital asset custody but would not accept deposits or issue loans. This article is an excerpt from Cointelegraph.com News View Original Source

Jack Dorsey’s Block seeks US trust bank charter for Bitcoin, stablecoin Read More »

AI-Infra-Guard: Open-source security scanner for AI systems

AI-Infra-Guard: Open-source security scanner for AI systems 2026-09-09 at 10:13 By Mirko Zorz Tencent’s Zhuque Lab built AI-Infra-Guard, an open-source security scanner for AI systems. It fingerprints running services such as Ollama, vLLM and ComfyUI and checks them against more than 1,600 known CVEs, inspects MCP servers and agent skills across 14 categories of risk, […]

AI-Infra-Guard: Open-source security scanner for AI systems Read More »

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days 2026-09-09 at 10:13 By Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office […]

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days Read More »

Gemini receives Singapore payment license for crypto services

Gemini receives Singapore payment license for crypto services 2026-09-09 at 08:27 By Cointelegraph by Ezra Reguerra Gemini’s local entity is authorized to provide digital payment token and cross-border money transfer services without standard transaction-volume limits. This article is an excerpt from Cointelegraph.com News View Original Source

Gemini receives Singapore payment license for crypto services Read More »

Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results

Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results 2026-09-09 at 08:00 By Help Net Security In the Gartner report Validate the Promises of AI SOC Agents With These Key Questions, analysts Craig Lawson and Andrew Davies posit that “By 2028, 70% of large SOCs will pilot AI agents to augment […]

Gartner: 70% of SOCs will pilot AI agents. Only 15% will see results Read More »

Scroll to Top