Featured

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities 2026-09-09 at 15:32 By Kevin Townsend Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek. This article […]

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities Read More »

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser 2026-09-09 at 13:00 By Kevin Townsend Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first […]

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser Read More »

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days 2026-09-08 at 22:20 By Ionut Arghire The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities. The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days Read More »

Hackers Return $263 Million Stolen From Liquid Network

Hackers Return $263 Million Stolen From Liquid Network 2026-09-08 at 19:35 By Ionut Arghire Alleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix. The post Hackers Return $263 Million Stolen From Liquid Network appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Hackers Return $263 Million Stolen From Liquid Network Read More »

N-able Patches Critical Zero-Day in N-central

N-able Patches Critical Zero-Day in N-central 2026-09-08 at 13:37 By Ionut Arghire Administrators are advised to check their deployments for newly created user accounts they don’t recognize. The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

N-able Patches Critical Zero-Day in N-central Read More »

OpenAI Agents Hijack Another Victim Website

OpenAI Agents Hijack Another Victim Website 2026-09-07 at 15:03 By Kevin Townsend OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach. The post OpenAI Agents Hijack Another Victim Website appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

OpenAI Agents Hijack Another Victim Website Read More »

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores 2026-09-07 at 14:58 By Ionut Arghire The StyleSmuggler zero-day allows attackers to execute code and deploy a stealthy backdoor on Adobe Commerce and Magento stores. The post Adobe Commerce Zero-Day Exploited to Backdoor Online Stores appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Adobe Commerce Zero-Day Exploited to Backdoor Online Stores Read More »

OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders

OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders 2026-09-04 at 19:07 By Kevin Townsend The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility. The post OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders […]

OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders Read More »

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover 2026-09-04 at 15:06 By Ionut Arghire Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor. The post 12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover Read More »

153 Million Driver License Images Offered on Dark Web

153 Million Driver License Images Offered on Dark Web 2026-09-03 at 13:54 By Ionut Arghire Cybercriminals are offering digital scans of US and Canadian driver’s licenses, likely stolen from IDScan.net. The post 153 Million Driver License Images Offered on Dark Web appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

153 Million Driver License Images Offered on Dark Web Read More »

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks 2026-09-02 at 08:04 By Eduard Kovacs The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks Read More »

PaperCut Exploitation Escalates to Active Intrusions

PaperCut Exploitation Escalates to Active Intrusions 2026-09-01 at 08:27 By Eduard Kovacs CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog. The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

PaperCut Exploitation Escalates to Active Intrusions Read More »

More Details Emerge on Exploited PaperCut Vulnerabilities

More Details Emerge on Exploited PaperCut Vulnerabilities 2026-08-31 at 09:51 By Eduard Kovacs PaperCut has released a second emergency patch for the exploited vulnerabilities, which are now tracked as CVE-2026-82078 and CVE-2026-81578. The post More Details Emerge on Exploited PaperCut Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

More Details Emerge on Exploited PaperCut Vulnerabilities Read More »

Hasbro Data Breach Exposed Employee Personal Information

Hasbro Data Breach Exposed Employee Personal Information 2026-08-29 at 14:55 By Eduard Kovacs A cyberattack caused disruptions at the toy and game giant earlier this year and the company is now disclosing a data breach. The post Hasbro Data Breach Exposed Employee Personal Information appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

Hasbro Data Breach Exposed Employee Personal Information Read More »

Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says

Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says 2026-08-28 at 13:30 By Kevin Townsend New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks. The post Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says appeared first on SecurityWeek. This article […]

Think You’ve Eliminated Chinese AI? Check the Model’s Lineage, Cisco Says Read More »

PaperCut Releases Emergency Patch for Exploited Zero-Day

PaperCut Releases Emergency Patch for Exploited Zero-Day 2026-08-28 at 11:40 By Eduard Kovacs A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations. The post PaperCut Releases Emergency Patch for Exploited Zero-Day appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

PaperCut Releases Emergency Patch for Exploited Zero-Day Read More »

Recent Citrix NetScaler Vulnerability Exploited in the Wild

Recent Citrix NetScaler Vulnerability Exploited in the Wild 2026-08-27 at 07:39 By Eduard Kovacs CISA is urging government agencies to immediately patch the Citrix NetScaler vulnerability tracked as CVE-2026-8452. The post Recent Citrix NetScaler Vulnerability Exploited in the Wild appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent Citrix NetScaler Vulnerability Exploited in the Wild Read More »

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks 2026-08-26 at 14:29 By Eduard Kovacs The agency has released guidance on reducing internet exposure in the wake of the recent Iran-linked hacker attacks. The post CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks appeared first on SecurityWeek. This article is an excerpt […]

CISA: Over 100 Internet-Exposed Water Systems Targeted in July Cyberattacks Read More »

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini 2026-08-21 at 17:34 By Kevin Townsend Researchers say the new ‘Cryptographic Context Injection’ technique conceals malicious instructions until they are decrypted inside a trusted execution environment. The post Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini appeared first on SecurityWeek. This article is […]

Encrypted Prompts Bypass AI Safety Guardrails in Grok and Gemini Read More »

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities 2026-08-21 at 10:25 By Ionut Arghire The Head Mare hacktivist group has been exploiting the bugs to deploy the PhantomCore malware. The post CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Urges Immediate Patching of Exploited TrueConf Vulnerabilities Read More »

Scroll to Top