] The Mad Hacker [

online
mad hacker

Collecting all the news about Cybersecurity, computer security, cracking, hacking, infosec, netsec, & security vunerabilities in one convenient place

Whitehat, greyhat, blackhat, tinker, tailor, solider, spy
We trawl the web so you don't have to
Since 2000

the mad hacker overlay

Smashing Security podcast #484: How websites are tracking you with silence

(Wednesday September 09, 2026)
When a chap called Matt noticed his Bluetooth headphones wouldn't switch to his phone, he was surprised to realise the reason was a single AliExpress webpage sitting open in his browser - playing nothing at all, at zero volume. And yet somehow his hardware could hear it. Audio fingerprinting is one of the sneakiest tracking tricks on the web. Meanwhile, the intelligence agencies of the "Five Eyes" (not Five...

No LLM wants to help building Trust Pilot review automation - what to do?

(Wednesday September 09, 2026)
Click the link for more details on No LLM wants to help building Trust Pilot review automation - what to do?

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

(Wednesday September 09, 2026)
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]

AdaptHealth confirms 4.1 million people exposed in July cyberattack

(Wednesday September 09, 2026)
Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]

Threat matrix: Mapping threats across cloud web applications

(Wednesday September 09, 2026)
Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. The post Threat matrix: Mapping threats across cloud web applications [https://www.microsoft.com/en-us/security/blog/2026/09/09/threat-matrix-mapping-threats-across-cloud-web-applications/] appeared first on...

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

(Wednesday September 09, 2026)
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...]

Gong Cookie Preferences

(Wednesday September 09, 2026)
Enable JavaScript and cookies to continue

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

(Wednesday September 09, 2026)
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime

A Vulnerability in SAP Extended Passport (EPP) Processing Could Allow for Remote Code Execution

(Wednesday September 09, 2026)
A vulnerability has been discovered in SAP Extended Passport (EPP) Processing that could allow for remote code execution. SAP Extended Passport (EPP) Processing is a core system data structure and tracing mechanism within SAP Kernel code used to track, log, and monitor end-to-end communication across distributed SAP and non-SAP landscapes. It is created automatically when a new user session opens and travels via...

Passkey-themed social engineering leads to identity and cloud compromise

(Wednesday September 09, 2026)
Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoint, OneDrive, and email data, along with key detection and mitigation guidance. The post Passkey-themed social engineering leads to identity and...

US says Chinese firms extracted billions of tokens from frontier AI models

(Wednesday September 09, 2026)
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

(Wednesday September 09, 2026)
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,

Driver’s License Data for Sale

(Wednesday September 09, 2026)
A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.

Veradigm warns of patient data breach after ransomware gang claims attack

(Wednesday September 09, 2026)
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]

Fake GTA6 ‘Leaked Download’ Caught Spreading RATs, Infostealer and Wiper Ransomware

(Wednesday September 09, 2026)
Cybersecurity firm Huntress has uncovered a malware campaign that preys on excitement for Grand Theft Auto VI (GTA6), packaging remote access trojans, an infostealer, and destructive ransomware inside fake “leaked” copies of the hotly anticipated game. GTA6 is not due for release for another three months, but a wave of gameplay footage leaks and an […] The post Fake GTA6 ‘Leaked Download’ Caught Spreading...

Why hostile state cyber activity is now a day-to-day business risk

(Wednesday September 09, 2026)
Christopher Clark, Cyber Security Incident Response Team Director, Thrive  Geopolitical escalation can become a cyber security problem for businesses far more quickly than many boards expect. The National Cyber Security Council (NCSC) has warned that UK critical infrastructure faced more than 200 cyber incidents over the past year, with around three-quarters believed to be linked […] The post Why hostile state cyber activity is now a day-to-day...

NCSC Warns Shadow AI Is Creating New Security Blind Spots for UK Businesses

(Wednesday September 09, 2026)
The UK’s National Cyber Security Centre (NCSC) has warned organisations about the security risks posed by “shadow AI”, as employees continue to turn to artificial intelligence tools that have not been approved by their employers. In guidance published this week, the NCSC described shadow AI as the use of AI technology outside an organisation’s approved […] The post NCSC Warns Shadow AI Is Creating New Security Blind Spots...

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

(Wednesday September 09, 2026)
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API

Huntress Uncovers Phishing Attacks Using Fake Browser Pages and Rogue RMM Tools

(Wednesday September 09, 2026)
Huntress researchers have uncovered two phishing attacks that combined convincing fake browser windows with legitimate remote management software to establish persistent access to victims’ devices. Both incidents, observed in August, began with phishing messages directing victims to attacker-controlled websites. The attackers then used a browser-in-the-browser (BiTB) technique to create what appeared to be a...

Error 301 when trying to open OpenProject

(Wednesday September 09, 2026)
Enable JavaScript and cookies to continue

MFA's Weakest Link: Account Recovery Is the New Attack Path

(Wednesday September 09, 2026)
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]

Forescout Expands Global Investment in Channel Partners

(Wednesday September 09, 2026)
Forescout has expanded its investment in its global partner ecosystem to strengthen technical expertise and help partners support customers managing increasingly complex IT, OT, IoT, and IoMT environments. Nearly 100% of Forescout’s customer business is transacted through partners, making the channel a central part of the cybersecurity company’s growth strategy. Its latest investment includes the […] The post...

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

(Wednesday September 09, 2026)
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

(Wednesday September 09, 2026)
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web

Claude Fable Solves a Historical Cipher

(Wednesday September 09, 2026)
Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.

A “proof” of Fermat’s Last Theorem that fits the margin

(Wednesday September 09, 2026)
Fermat famously claimed to have a “truly marvelous proof” of his Last Theorem [https://en.wikipedia.org/wiki/Fermat%27s_Last_Theorem], but he never wrote it down, insisting the margin of his page was too narrow to contain it. A few centuries later, Anthropic announced a complete formalization of Fermat’s Last Theorem using 13 million lines [https://www.anthropic.com/research/formalizing-fermats-last-theorem] of Lean...

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

(Wednesday September 09, 2026)
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through

Over 36,000 exposed Plex servers vulnerable to recent flaws

(Wednesday September 09, 2026)
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

(Wednesday September 09, 2026)
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

(Wednesday September 09, 2026)
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to

Man gets 15 years for extorting women with AI-generated porn videos

(Wednesday September 09, 2026)
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]

CRPx0 ransomware: what you need to know

(Wednesday September 09, 2026)
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

(Wednesday September 09, 2026)
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

(Wednesday September 09, 2026)
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

(Wednesday September 09, 2026)
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

(Wednesday September 09, 2026)
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

Google warns of new Chrome zero-day bug exploited in attacks

(Wednesday September 09, 2026)
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

(Wednesday September 09, 2026)
SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

(Wednesday September 09, 2026)
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

(Wednesday September 09, 2026)
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults

(Wednesday September 09, 2026)
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]

Microsoft Plugs Nearly 1,000 Security Holes

(Tuesday September 08, 2026)
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many...

DoppelCart fraud network uses 119,000 fake shops to steal credit cards

(Tuesday September 08, 2026)
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]

The EU CRA's Real Question: What Shipped, and When Did You Know?

(Tuesday September 08, 2026)
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

(Tuesday September 08, 2026)
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]

Multiple Vulnerabilities in Adobe Products Could Allow for Arbitrary Code Execution

(Tuesday September 08, 2026)
Multiple vulnerabilities have been discovered in Adobe products, the most severe of which could allow for arbitrary code execution. * Adobe Experience Manager (AEM) is an enterprise-grade digital experience platform that combines content management, digital asset management, and digital enrollment into a single cloud-native solution. * Adobe ColdFusion is a commercial rapid web application development platform...

Microsoft releases Windows 10 KB5122878 extended security update

(Tuesday September 08, 2026)
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]

Debian Bullseye security InRelease expired

(Tuesday September 08, 2026)
Enable JavaScript and cookies to continue

Critical Patches Issued for Microsoft Products, September 8, 2026

(Tuesday September 08, 2026)
Multiple vulnerabilities have been discovered in Microsoft products, the most severe of which could allow for remote code execution. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the privileges associated with the user, an attacker could then install programs; view, change, or delete data; or create...

AIs as Modern Genies

(Tuesday September 08, 2026)
This essay was written with Barath Raghavan, and originally appeared in Lawfare. In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in,...

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

(Tuesday September 08, 2026)
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment

The US military just turned off ad tracking on its phones. Maybe you should too

(Tuesday September 08, 2026)
Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours. Read more in my article on the Hot for Security blog.

Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

(Tuesday September 08, 2026)
Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&

ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

(Tuesday September 08, 2026)
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

(Tuesday September 08, 2026)
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI

Black Duck Joins Project Glasswing to Strengthen AI-Era Software Security

(Tuesday September 08, 2026)
Black Duck, a provider of AI-powered application security solutions, has announced its participation in Project Glasswing, Anthropic’s industry-wide initiative aimed at protecting critical software infrastructure through the defensive use of advanced AI. Through its involvement, Black Duck will integrate Mythos throughout its application security offerings, pairing AI-driven, deterministic vulnerability detection with established remediation...

Prevent history from saving modified commands on history-search-backward

(Tuesday September 08, 2026)
Enable JavaScript and cookies to continue

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

(Tuesday September 08, 2026)
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

What It Took to Reach 1 Billion Build Manifests

(Tuesday September 08, 2026)
In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

(Tuesday September 08, 2026)
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The

Stealing AI Reasoning Traces

(Tuesday September 08, 2026)
Interesting research: “Stealing Reasoning Traces from Proprietary LLM APIs“: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with...

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

(Tuesday September 08, 2026)
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. "This update resolves a critical

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

(Tuesday September 08, 2026)
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan since at least 2015, driven by two IT service providers named WeConnect

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

(Tuesday September 08, 2026)
Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it shared users' personal information, including their HIV status, with third-parties. Grindr, which is the largest LGBTQ+ dating app, was sued in April 2024, accusing it of violating U.K. privacy laws by sharing sensitive data for commercial purposes such as advertising.

Multiple Vulnerabilities in DellSecure Connect Gateway Could Allow for Arbitrary Code Execution

(Monday September 07, 2026)
Multiple vulnerabilities have been discovered in Dell Secure Connect Gateway, the most severe of which could allow for arbitrary code execution. Dell Secure Connect Gateway is an enterprise monitoring and connection software for Dell infrastructure. Successful exploitation of the most severe of these vulnerabilities could result in an attacker gaining the same privileges as the logged-on user. Depending on the...

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

(Monday September 07, 2026)
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

(Monday September 07, 2026)
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff

How might I remind myself to plug my laptop in to the wall socket?

(Monday September 07, 2026)
Enable JavaScript and cookies to continue

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

(Monday September 07, 2026)
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management

The UK’s Cyber Community Comes North as CyberFest returns for 2026

(Monday September 07, 2026)
The North East’s biggest cyber security festival returns this October. Now in its ninth year, CyberFest has grown into a major national platform for showcasing the region’s cyber and secure AI excellence. Taking place across the North East throughout October, the festival will connect businesses, innovators, government and specialist clusters from across the UK, putting […] The post The UK’s Cyber Community Comes North as CyberFest returns for...

Your Cloud Security Checklist Doesn't Work the Way You Think It Does

(Monday September 07, 2026)
If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts

(Monday September 07, 2026)
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

(Monday September 07, 2026)
A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

Automobile Camouflage to Hide from Flock Cameras

(Monday September 07, 2026)
Not sure it’s practical, but it’s certainly striking.

How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts

(Monday September 07, 2026)
If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed. Read more in my article on the Hot for Security blog.

Check Point Brings OpenAI’s Daybreak Models Into Its Security Platform to Speed Up Threat Validation and Remediation

(Monday September 07, 2026)
Check Point Software Technologies has announced it is integrating OpenAI’s Daybreak frontier AI models across its security platform, extending a partnership aimed at helping defenders detect, validate, and remediate cyber risk faster. The move builds on Check Point’s existing collaboration with OpenAI through the Daybreak Defense Network, first expanded three months ago, and follows the […] The post Check Point...

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

(Monday September 07, 2026)
Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a

WRAITH – Browser Hooking and Blind XSS Page Mirroring

(Monday September 07, 2026)
WRAITH combines BeEF-style browser hooks with blind-XSS capture and a credentialed Page Mirror. Tested locally, with its limits examined.

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

(Monday September 07, 2026)
Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

Weekly Update 520: The Unscripted Edition

(Sunday September 06, 2026)
PRESENTLY SPONSORED BY: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite [https://report-uri.com/?src=troyhunt.com] Ive started playing around with YouTubes "create video thumbnail", which hopefully will give me back a bit of time in my day (it used to be a manual job in Photoshop) and be a bit more interesting. And on that note, the imagery it&

Sou novo na área de cybersecurity

(Sunday September 06, 2026)
Click the link for more details on Sou novo na área de cybersecurity

How do I permanently unlock access to an internal SSD? (Linux Mint 22.3)

(Sunday September 06, 2026)
Enable JavaScript and cookies to continue

Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication

(Sunday September 06, 2026)
Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or

Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner

(Sunday September 06, 2026)
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

Datacenter WAN Layer Design and Redundancy

(Sunday September 06, 2026)
Enable JavaScript and cookies to continue

Crime gangs use bots to lure young men in sextortion scams

(Saturday September 05, 2026)
Criminal gangs continue to have Australian men and boys in their sights as targets for sexual extortion, with more than $200,000 defrauded from victims in one state.

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

(Saturday September 05, 2026)
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

reverse proxy phishing

(Saturday September 05, 2026)
Click the link for more details on reverse proxy phishing

Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials

(Saturday September 05, 2026)
JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environment. "Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions," JetBrains said.

Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

(Saturday September 05, 2026)
Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Was Deleted

(Saturday September 05, 2026)
Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel

(Saturday September 05, 2026)
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May and July 2026, using the site as a shared board to pool answers to a timed web task and pass around a way out of their sandbox. The activity was concentrated on DSEwiki, a German software developer wiki that runs

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

(Saturday September 05, 2026)
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Multiple Vulnerabilities in Google Chrome Could Allow for Arbitrary Code Execution

(Saturday September 05, 2026)
Multiple vulnerabilities have been discovered in Google Chrome, the most severe of which could allow for arbitrary code execution. Successful exploitation of the most severe of these vulnerabilities could allow for arbitrary code execution in the context of the logged on user. Depending on the privileges associated with the user an attacker could then install programs; view, change, or delete data; or create new...

Friday Squid Blogging: Squid on a Stick at the New York State Fair

(Friday September 04, 2026)
Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.

How to secure edge AI in customer-owned environments

(Friday September 04, 2026)
As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments [https://www.microsoft.com/en-us/security/blog/2026/09/04/secure-edge-ai-customer-owned-environments/] appeared first on Microsoft Security...

AI is finding vulnerabilities faster. Who is funding the people expected to fix them?

(Friday September 04, 2026)
Artificial intelligence is changing vulnerability discovery. At OpenSSL, we are seeing that change first-hand. A year ago, our security address received around nine separate reports and enquiries a month. It now receives around 70. AI tools can examine source code and identify potential security issues at a scale that would previously have required significant human […] The post AI is finding vulnerabilities faster....

Using a VM to Contain an AI Agent

(Friday September 04, 2026)
It won’t work: My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is not enough to contain a modern, cyber-capable AI agent. There is simply too much attack surface. Even innocuous features (like running with a...

Q&A: Viasat Tests Satellite Resilience With AI as Cyber Expert Warns an Attack Could ‘Hurt an Entire Country’

(Friday September 04, 2026)
An AI-assisted platform has been used to test whether Viasat’s satellite communications links can meet operational thresholds under interference and adversarial jamming.  Announced this month, the work with Atalanta has renewed scrutiny of the vulnerabilities exposed by Russia’s 2022 attack on Viasat’s KA-SAT network, which disrupted communications across Ukraine and several European countries.  Gil Baram, […] The post...

China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

(Friday September 04, 2026)
EXECUTIVE SUMMARY China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI...