Hot stuff

OpenAI agent hacking spree widens to Australia, targeting government website

OpenAI agent hacking spree widens to Australia, targeting government website 2026-09-24 at 15:53 By Zeljka Zorz Before the Hugging Face and RubyGems hacks, autonomous OpenAI agents attempted to hack into three other websites, including an Australian government public health website, independent research lab Transluce revealed on Wednesday. “Notably, the tasks the agents were trying to […]

OpenAI agent hacking spree widens to Australia, targeting government website Read More »

New Android malware RemControl steals banking PINs and blocks removal attempts

New Android malware RemControl steals banking PINs and blocks removal attempts 2026-09-24 at 12:40 By Sinisa Markovic A new Android banking trojan called RemControl tricks victims into installing a fake TV app, then takes control of their phones to steal banking PINs, Group-IB has found. Researchers confirmed that the malware targets customers of more than […]

New Android malware RemControl steals banking PINs and blocks removal attempts Read More »

What to do first when you get 90 days to secure AI agent data

What to do first when you get 90 days to secure AI agent data 2026-09-24 at 08:00 By Mirko Zorz In this interview with Help Net Security, Kelly Herrell, CEO at Nol8, explains where AI agents create exposure inside organizations. The first thing to examine is the data path: what an agent can reach, what […]

What to do first when you get 90 days to secure AI agent data Read More »

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances 2026-09-23 at 13:22 By Zeljka Zorz Check Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026. The company also confirmed that a pre-authentication remote code […]

Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances Read More »

Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes

Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes 2026-09-23 at 11:34 By Sinisa Markovic The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft. With authorization from the US District Court for […]

Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes Read More »

Researchers uncover malware that uses AI to choose its next move

Researchers uncover malware that uses AI to choose its next move 2026-09-22 at 16:56 By Sinisa Markovic To help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata […]

Researchers uncover malware that uses AI to choose its next move Read More »

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page 2026-09-22 at 16:46 By Zeljka Zorz Three domains / web portals belonging to Dutch academic publishing company Elsevier have been redirecting users to a page branded “LAPSUS$ GROUP, Chapter II,” carrying a signed statement that taunted the FBI and counted down to a future […]

Brief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” page Read More »

The latest deepfake numbers give CISOs plenty to worry about

The latest deepfake numbers give CISOs plenty to worry about 2026-09-22 at 15:05 By Sinisa Markovic AI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, according to […]

The latest deepfake numbers give CISOs plenty to worry about Read More »

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) 2026-09-22 at 13:42 By Zeljka Zorz A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in Italy, the […]

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) Read More »

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions 2026-09-22 at 11:54 By Sinisa Markovic Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing. Malwarebytes found more than 100 websites built this […]

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions Read More »

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit 2026-09-22 at 08:00 By Help Net Security By the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation. Under Article 20(1) of the directive, senior management at essential and important entities can be held personally liable […]

Passwork NIS2 efficiency guide: Save your team hours before the 2026 audit Read More »

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files 2026-09-21 at 17:00 By Mirko Zorz Researchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi […]

The TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business files Read More »

Hackers exploit Gyazo server flaw to steal 23.6 million user records

Hackers exploit Gyazo server flaw to steal 23.6 million user records 2026-09-21 at 11:57 By Sinisa Markovic Japanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions […]

Hackers exploit Gyazo server flaw to steal 23.6 million user records Read More »

Bots with good manners are better at fooling people on social media

Bots with good manners are better at fooling people on social media 2026-09-18 at 13:15 By Sinisa Markovic Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability […]

Bots with good manners are better at fooling people on social media Read More »

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched 2026-09-18 at 11:49 By Sinisa Markovic Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the […]

Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched Read More »

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) 2026-09-17 at 13:24 By Zeljka Zorz Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE). About CVE-2026-76460 Cisco ISE is […]

Unauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460) Read More »

Scammers leave AI fingerprints all over fake antivirus renewal page

Scammers leave AI fingerprints all over fake antivirus renewal page 2026-09-17 at 13:10 By Sinisa Markovic AI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page impersonating Avast, aimed at users in Belgium, that was more polished than most sites […]

Scammers leave AI fingerprints all over fake antivirus renewal page Read More »

The AI security question leaders should be asking instead

The AI security question leaders should be asking instead 2026-09-17 at 08:30 By Mirko Zorz In this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why […]

The AI security question leaders should be asking instead Read More »

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) 2026-09-16 at 15:36 By Zeljka Zorz A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger […]

Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894) Read More »

Scroll to Top