2026

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication 2026-09-07 at 17:07 By Sinisa Markovic Attackers are exploiting a chain of RouterOS vulnerabilities to hijack MikroTik devices with SSH open to the internet, CERT Polska found. CERT Polska, Poland’s national CSIRT team, have discovered six vulnerabilities in RouterOS and coordinated their disclosure with MikroTik. […]

Hackers exploit RouterOS flaws to hijack MikroTik devices without authentication Read More »

Qatar’s Digital Boom Has a Blind Spot: What the 2025-26 Threat Data Is Telling Us

Qatar’s Digital Boom Has a Blind Spot: What the 2025-26 Threat Data Is Telling Us 2026-09-07 at 16:22 By Mihir Bagwe Qatar is racing toward a knowledge-based, fully digital economy. Smart infrastructure, cloud-first government services, a financial sector that’s increasingly API-driven, and critical energy assets like QatarEnergy’s LNG operations layering more connected OT/ICS systems every […]

Qatar’s Digital Boom Has a Blind Spot: What the 2025-26 Threat Data Is Telling Us Read More »

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits 2026-09-07 at 15:15 By Ionut Arghire The proof-of-concept (PoC) exploits lead to privilege escalation, spawning a shell with System privileges. The post Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits Read More »

North Korean Hackers Deploy New Linux Espionage Toolkit

North Korean Hackers Deploy New Linux Espionage Toolkit 2026-09-07 at 15:12 By Ionut Arghire The stealthy toolkit embeds a backdoor in HAProxy and targets automotive and media organizations in South Korea for long-term surveillance. The post North Korean Hackers Deploy New Linux Espionage Toolkit appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

North Korean Hackers Deploy New Linux Espionage Toolkit Read More »

OpenAI Agents Hijack Another Victim Website

OpenAI Agents Hijack Another Victim Website 2026-09-07 at 15:03 By Kevin Townsend OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach. The post OpenAI Agents Hijack Another Victim Website appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

OpenAI Agents Hijack Another Victim Website Read More »

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores 2026-09-07 at 14:58 By Ionut Arghire The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Read More »

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218)

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) 2026-09-07 at 14:55 By Sinisa Markovic N-able released an emergency hotfix for CVE-2026-86218, a remote code execution (RCE) flaw affecting N-central, its remote monitoring and management (RMM) solution popular with managed service providers (MSPs). In its release notes, N-able described CVE-2026-86218 as a “critical-CVSS-rated vulnerability […]

N-able patches critical N-central zero-day exploited in the wild (CVE-2026-86218) Read More »

Modified ScreenConnect Clients Used in Worm-Like Campaign

Modified ScreenConnect Clients Used in Worm-Like Campaign 2026-09-07 at 14:45 By Ionut Arghire The attacks rely on backdoored ScreenConnect instances to transfer and execute payloads to newly connected clients. The post Modified ScreenConnect Clients Used in Worm-Like Campaign appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Modified ScreenConnect Clients Used in Worm-Like Campaign Read More »

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does 2026-09-07 at 14:45 By If managing security across multiple cloud providers wasn’t hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that […]

Your Cloud Security Checklist Doesn’t Work the Way You Think It Does Read More »

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts 2026-09-07 at 14:36 By Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, […]

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts Read More »

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released 2026-09-07 at 14:20 By A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no […]

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released Read More »

Citi, DBS complete first weekend tokenized cross-border deposit on Swift

Citi, DBS complete first weekend tokenized cross-border deposit on Swift 2026-09-07 at 13:34 By Cointelegraph by Zoltan Vardai Citi and DBS completed their first tokenized cross-border transfer over the weekend, using Swift’s blockchain-based ledger to circumvent the constraints of traditional banking hours. This article is an excerpt from Cointelegraph.com News View Original Source

Citi, DBS complete first weekend tokenized cross-border deposit on Swift Read More »

Philippines eyes payment operator registration freeze, tighter VASP checks

Philippines eyes payment operator registration freeze, tighter VASP checks 2026-09-07 at 12:51 By Cointelegraph by Ezra Reguerra A central bank proposal would pause new payment operator registrations while requiring enhanced monitoring and transaction limits for arrangements involving virtual asset firms. This article is an excerpt from Cointelegraph.com News View Original Source

Philippines eyes payment operator registration freeze, tighter VASP checks Read More »

Attackers spread malware through ScreenConnect file transfers

Attackers spread malware through ScreenConnect file transfers 2026-09-07 at 12:13 By Sinisa Markovic A file transfer flaw in ScreenConnect Remote Access Support and Access sessions affects both Cloud and On-Premise deployments, ConnectWise confirmed. “A CVE identifier and an official fix will be issued within the week,” the company wrote in its September 3 advisory. ScreenConnect […]

Attackers spread malware through ScreenConnect file transfers Read More »

OpenAI just hit a milestone on the road to self-improving AI

OpenAI just hit a milestone on the road to self-improving AI 2026-09-07 at 12:05 By Anamarija Pogorelec OpenAI has announced that it has reached a goal set last fall of having an automated research intern by September 2026. The milestone means a system can carry out well-defined research tasks under human direction, including work that […]

OpenAI just hit a milestone on the road to self-improving AI Read More »

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw 2026-09-07 at 11:31 By Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able’s incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. […]

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw Read More »

Scroll to Top