Cybersecurity and other IT news aggregator

LATEST FEEDS

  • 545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent

    545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent 2026-09-23 at 18:34 By Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose,…


  • Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests

    Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests 2026-09-23 at 18:34 By Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a “major step up from Opus 5,”…


  • FBI Hacked, Employee Data Reportedly Exposed

    FBI Hacked, Employee Data Reportedly Exposed 2026-09-23 at 18:00 By The cybercriminal group ShinyHunters claims it has hacked the FBI. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source


  • Bitcoin long liquidations hit $280M as BTC price dips under $84K

    Bitcoin long liquidations hit $280M as BTC price dips under $84K 2026-09-23 at 17:52 By Cointelegraph by William Suberg Bitcoin long liquidations mounted as BTC/USD briefly traded below $84,000, while analysis flagged key support to hold. This article is an excerpt from Cointelegraph.com News View Original Source


  • This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

    This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move 2026-09-23 at 17:17 By A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker’s server, Cisco Talos said on September 22. The models can choose to steal…


  • Cofense measures employee readiness against real-world phishing threats

    Cofense measures employee readiness against real-world phishing threats 2026-09-23 at 17:01 By Industry News Cofense has announced an expansion of its AI-driven Phishing Defense Platform through Cofense Command Center, its orchestration layer for measurement and reporting. The new Competency Dashboard measures how employees recognize, report and respond to phishing threats, giving security teams evidence of…


  • 80,000 relay servers help users in China slip past U.S. AI region bans

    80,000 relay servers help users in China slip past U.S. AI region bans 2026-09-23 at 16:57 By Sinisa Markovic More than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U.S. AI models, according to Team Cymru. “What we have uncovered is an entire ecosystem designed explicitly to break the frontier…


  • Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

    Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI 2026-09-23 at 16:52 By Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep,…


  • Portnox detects and removes unauthorized AI applications from managed devices

    Portnox detects and removes unauthorized AI applications from managed devices 2026-09-23 at 16:49 By Industry News Portnox has announced new capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy, restricting, quarantining, or removing unapproved or risky applications the moment they’re detected. The capability addresses shadow AI: generative AI…


  • Network Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure

    Network Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure 2026-09-23 at 16:40 By Industry News Network Solutions has launched Dark Web Monitoring, a new security capability that alerts small businesses when information associated with their domain appears in known breach data and provides steps they can take to reduce risk. Stolen credentials…


  • DarkMe RAT trades zero-days for plain phishing emails

    DarkMe RAT trades zero-days for plain phishing emails 2026-09-23 at 16:24 By Zeljka Zorz DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again. This time around, its distribution has been simplified: instead of leveraging zero-day exploits,…


  • Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare

    Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare 2026-09-23 at 15:17 By Eduard Kovacs Only 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature. The post Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare appeared first on SecurityWeek. This article is an…


  • New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

    New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control 2026-09-23 at 15:16 By A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take “full control of the server,” the company said on September 22. A second bug in the WP Toolkit…


  • Adobe Patches Critical Flaws in Connect, AEM Forms

    Adobe Patches Critical Flaws in Connect, AEM Forms 2026-09-23 at 14:40 By Ionut Arghire The nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft

    AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft 2026-09-23 at 14:23 By Eduard Kovacs The cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original…


  • Chrome 154 Patches 108 Vulnerabilities

    Chrome 154 Patches 108 Vulnerabilities 2026-09-23 at 13:36 By Ionut Arghire The browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances

    Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances 2026-09-23 at 13:22 By Zeljka Zorz Check Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026. The company also confirmed that a pre-authentication remote code…


  • A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk

    A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk 2026-09-23 at 13:20 By Associated Press Debates over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons. The post A Look at AI Doomsday Scenarios That Researchers Say Could Put…


  • GPT-6 Sol and Luna arrive with 50% lower API prices

    GPT-6 Sol and Luna arrive with 50% lower API prices 2026-09-23 at 13:08 By Anamarija Pogorelec OpenAI has expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models. Both are available in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise, and Edu users. Free and Go users can access GPT-6 Luna in the desktop…


  • CFTC chair pushes tokenization as SEC opens door to onchain stocks

    CFTC chair pushes tokenization as SEC opens door to onchain stocks 2026-09-23 at 13:06 By Cointelegraph by Ezra Reguerra Michael Selig said tokenization could reshape financial markets as the CFTC and SEC continue advancing onchain initiatives despite the CLARITY Act setback. This article is an excerpt from Cointelegraph.com News View Original Source


  • Bitcoin bull market ‘confirmed’ but $90K presents profit-taking risk: Analysis

    Bitcoin bull market ‘confirmed’ but $90K presents profit-taking risk: Analysis 2026-09-23 at 13:05 By Cointelegraph by William Suberg BTC price analysis concluded that onchain signals had “confirmed” the new Bitcoin bull market. This article is an excerpt from Cointelegraph.com News View Original Source


  • Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm

    Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm 2026-09-23 at 13:00 By Kevin Townsend Emerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions. The post Outerlimit Raises $16 Million to Stop Rogue AI Agents From…


  • Raiffeisen to offer crypto trading across 11 European markets via Bitpanda

    Raiffeisen to offer crypto trading across 11 European markets via Bitpanda 2026-09-23 at 12:42 By Cointelegraph by Helen Partz Bitpanda will provide crypto infrastructure to Raiffeisen network banks, potentially extending digital asset access to about 18 million customers. This article is an excerpt from Cointelegraph.com News View Original Source


  • WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)

    WordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902) 2026-09-23 at 12:01 By Sinisa Markovic WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active…


  • Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes

    Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes 2026-09-23 at 11:34 By Sinisa Markovic The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft. With authorization from the US District Court for…


  • Arista Urges Immediate Patching of Exploited VCO Zero-Day

    Arista Urges Immediate Patching of Exploited VCO Zero-Day 2026-09-23 at 11:33 By Ionut Arghire Remote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI

    Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI 2026-09-23 at 11:30 By Anamarija Pogorelec Claude Opus 5.5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure. Developers can access it through the Claude Platform using the model name claude-opus-5-5. It includes watermarking measures designed to comply with the…


  • F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers 2026-09-23 at 11:29 By Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an…


  • Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

    Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware 2026-09-23 at 11:29 By A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046,…


  • BitMEX ends crypto trading, keeps withdrawals open after closure

    BitMEX ends crypto trading, keeps withdrawals open after closure 2026-09-23 at 11:18 By Cointelegraph by Helen Partz BitMEX officially ended exchange operations after more than 11 years, while withdrawals remain open as the crypto derivatives platform urges users to remove their funds. This article is an excerpt from Cointelegraph.com News View Original Source


  • Zcash’s November upgrade could freeze funds in legacy Sprout pool

    Zcash’s November upgrade could freeze funds in legacy Sprout pool 2026-09-23 at 11:07 By Cointelegraph by Ezra Reguerra The proposed NU7 change would disable version 4 transactions, leaving ZEC in Zcash’s legacy Sprout shielded pool unspendable. This article is an excerpt from Cointelegraph.com News View Original Source


  • Critical F5 BIG-IP Vulnerability Exploited as Zero-Day

    Critical F5 BIG-IP Vulnerability Exploited as Zero-Day 2026-09-23 at 10:34 By Ionut Arghire Unauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report

    ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report 2026-09-23 at 10:13 By Eduard Kovacs The cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information.  The post ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report appeared first on SecurityWeek. This article is an excerpt from SecurityWeek…


  • Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

    Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input 2026-09-23 at 10:04 By A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values…


  • Check Point Patches Exploited Management Server Zero-Day

    Check Point Patches Exploited Management Server Zero-Day 2026-09-23 at 09:14 By Ionut Arghire The critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts. The post Check Point Patches Exploited Management Server Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Prismor: Open-source runtime control plane for AI agents

    Prismor: Open-source runtime control plane for AI agents 2026-09-23 at 08:30 By Anamarija Pogorelec Prismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before…


  • ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

    ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants 2026-09-23 at 08:30 By The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. “We have compromised the FBI. We hold…


  • Product showcase: Scamwise checks the red flags before you take the bait

    Product showcase: Scamwise checks the red flags before you take the bait 2026-09-23 at 08:00 By Anamarija Pogorelec Scamwise is a free scam-checking service from Savi that examines suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud. The service works in any web browser on desktop, mobile, or tablet, with…


  • CFTC issues warning over risky prediction market ‘mention’ contracts

    CFTC issues warning over risky prediction market ‘mention’ contracts 2026-09-23 at 03:18 By Cointelegraph by Felix Ng The warning comes weeks after the CFTC fined a former White House teleprompter operator who made more than $107,000 trading prediction contracts tied to President Trump’s speeches. This article is an excerpt from Cointelegraph.com News View Original Source


  • ShinyHunters hackers say they breached FBI, stole data on bureau employees

    ShinyHunters hackers say they breached FBI, stole data on bureau employees 2026-09-23 at 00:46 By Reuters The notorious hacking group says it targeted the FBI after the agency detailed its methods and advised against paying ransoms. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • Arch Lending eyes tokenized stocks as next collateral market

    Arch Lending eyes tokenized stocks as next collateral market 2026-09-23 at 00:06 By Cointelegraph by Nate Kostar Arch Lending’s Himanshu Sahay said on Cointelegraph’s Chain Reaction podcast that the lender plans to move into tokenized equities as onchain stocks gain traction as collateral. This article is an excerpt from Cointelegraph.com News View Original Source


  • Republican senator calls for probe into US presidents’ sons, citing crypto ventures

    Republican senator calls for probe into US presidents’ sons, citing crypto ventures 2026-09-22 at 23:57 By Cointelegraph by Turner Wright Many Democrats have previously called for investigations into the Trump family’s crypto ventures, but now a Republican is asking for an inquiry based on ties to the presidency. This article is an excerpt from Cointelegraph.com…


  • Tyler Hassen defends DOGE: ‘Don’t just drain the swamp, flood it with talent’

    Tyler Hassen defends DOGE: ‘Don’t just drain the swamp, flood it with talent’ 2026-09-22 at 23:40 By Lydia Moynihan “So much of the narrative about Doge has been written from people who weren’t inside the room,” Tyler Hassen told The Post. This article is an excerpt from Latest Technology News | New York Post View…


  • Seniors struggling worse than teens with screens, AI and algorithms

    Seniors struggling worse than teens with screens, AI and algorithms 2026-09-22 at 22:28 By Rikki Schlott We talk a lot about young people’s dependence on technology, but what if their parents and grandparents are quietly developing the same concerning digital habits? This article is an excerpt from Latest Technology News | New York Post View…


  • Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks 2026-09-22 at 21:29 By Attackers exploited a previously unknown flaw in Check Point’s Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server’s web service to run scripts on…


  • 30-year-old Praxis CEO planning AI-powered utopia in Uruguay — with first residents expected next year

    30-year-old Praxis CEO planning AI-powered utopia in Uruguay — with first residents expected next year 2026-09-22 at 21:15 By Thomas Barrabi “Having, like, an actual place is, like, really, really fire,” Brown told the outlet. This article is an excerpt from Latest Technology News | New York Post View Original Source


  • WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers 2026-09-22 at 21:03 By WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing…


  • Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

    Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials 2026-09-22 at 20:58 By Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named “tw-pkgprobe-7731,” was first uploaded to…


  • BigCommerce Data Stolen via Ribon Apps Hack

    BigCommerce Data Stolen via Ribon Apps Hack 2026-09-22 at 20:58 By Ionut Arghire The attackers used a compromised BigCommerce application key held by Ribon to access customer data. The post BigCommerce Data Stolen via Ribon Apps Hack appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source


  • Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

    Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises 2026-09-22 at 20:03 By Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.” The action, carried out with authorization from the U.S. District Court for…


Browse older archives

Scroll to Top