2026-09-03 14:39 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 16:45 UTC
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada. West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names
P0
2026-09-03 14:38 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-03 15:00 UTC
The incident demonstrates how frontier AI agents can dramatically compress an attack timeline and coordinate a large-scale breach, according to researchers.
P0
2026-09-03 13:50 UTC
Security Journalism
BleepingComputer · Sponsored by Flare · indexed 2026-09-03 14:00 UTC
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. [...]
P0
2026-09-03 13:17 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-03 14:00 UTC
412,000 The Town 2025 festival buyer records are being sold for $10,000, with Brazil’s data openly marketed for bank fraud, loans and SIM registration. A seller on a Russian-language data-trading forum listed what they’re calling a Ticketmaster database on September 2, claiming over 412,000 Latin American purchase records with a heavy concentration of Brazilian data. […]
P0
2026-09-03 12:16 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-03 12:25 UTC
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. [...]
P0
2026-09-03 12:00 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-03 12:15 UTC
Brazil's most sophisticated threat group is making light work of the country's financial systems, putting money directly into its own pocket.
P0
2026-09-03 12:00 UTC
Security Journalism
The Record · indexed 2026-09-03 12:15 UTC
Sealed court information and sensitive personal data were exposed in a breach of a Thomson Reuters records platform affecting courts in at least 12 U.S. states, the U.S. Virgin Islands and Canada.
P0
2026-09-03 12:00 UTC
Government
CERT-EU Threat Intelligence · indexed 2026-09-03 10:25 UTC
Cyber Briefs are monthly executive reports that aim to present an overview of the most relevant developments in cyber security, based exclusively on open sources, with a view to inform political leadership and senior management in its constituency. Additional information on any item in this Brief can be provided upon request. Cyber Briefs are TLP:CLEAR.
P0
2026-09-03 11:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 12:45 UTC
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
P0
2026-09-03 11:02 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-03 11:15 UTC
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]
P0
2026-09-03 10:43 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 11:30 UTC
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads. According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026. "The technique's appeal is that node.exe (the
P0
2026-09-03 10:36 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 11:30 UTC
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have
P0
2026-09-03 10:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Reese Lewis and Sara McBroom · indexed 2026-09-03 10:20 UTC
Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42.
P0
2026-09-03 09:52 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-03 10:40 UTC
Chaotic Eclipse released FalconFlank, a PoC exploit for a Crowdstrike Falcon ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Crowdstrike Falcon cybersecurity platform. The researcher named the exploit FalconFlank, it triggers a privilege escalation flaw. According to the researcher, FalconFlank abuses […]
P35
2026-09-03 08:55 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-03 09:05 UTC
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]
P0
2026-09-03 08:43 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 10:00 UTC
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of
P0
2026-09-03 08:12 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-03 08:20 UTC
2,000 leaked files expose Bauman University’s hidden Department No. 4, which trained GRU-linked hackers and propagandists linked to APT28 and Sandworm. Leaked Documents Expose Bauman University’s Hidden Department That Trained Hackers, Propagandists, and Malware Developers for the GRU More than 2,000 internal documents from Bauman Moscow State Technical University have been reviewed by an international […]
P0
2026-09-03 06:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 06:45 UTC
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in
P35
2026-09-03 05:19 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-03 06:45 UTC
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated
P35
2026-09-03 02:02 UTC
Community
SANS Internet Storm Center · indexed 2026-09-03 02:10 UTC
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
P0
2026-09-03 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-03 02:10 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-09-02 22:51 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Sagar Patil, Arlette Umuhire Sangwa, Jesse Birch and Ravikant Tiwari · indexed 2026-09-03 00:10 UTC
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from social engineering to lateral movement using legitimate tools, and how Microsoft Defender helps detect and disrupt the activity. The post Impersonating IT support: how threat actors turn a remote session into enterprise-wide access appeared first on Microsoft …
P0
2026-09-02 21:31 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-02 21:35 UTC
OpenAI says Astra can autonomously find zero-days and build exploits, marking its first model to reach the “Critical” cyber risk level. Astra is now officially OpenAI’s highest-risk cybersecurity model. In August, OpenAI said it “couldn’t rule out” that its upcoming model had reached the highest cybersecurity risk level in its Preparedness Framework. In a new […]
P25
2026-09-02 21:14 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-09-02 22:00 UTC
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
P0
2026-09-02 21:00 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-02 21:15 UTC
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
P20
2026-09-02 20:43 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-09-02 21:00 UTC
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
P40
2026-09-02 20:36 UTC
Vendor Research
AWS Security Blog · Xiaoxue Xu · indexed 2026-09-02 20:55 UTC
September 2, 2026: This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center manages user access to Amazon Web Services (AWS) resources, including both AWS accounts and applications. You can use IAM Identity Center to create and manage user identities within the Identity Center identity store […]
P0
2026-09-02 20:32 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-09-02 20:50 UTC
Bulletin ID: 2026-094-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/02/2026 13:30 AM PDT Description: Amazon Ion-C (ion-c) is the C implementation of the Amazon Ion data serialization format. It is distributed as an open-source library (amazon-ion/ion-c) that applications embed to read and write Ion text and binary data. We identified CVE-2026-84851, an uncontrolled recursion issue in versions before 1.1.6 that might allow a remote unauthenticated actor to cra…
P5
2026-09-02 19:46 UTC
Security Journalism
Dark Reading · Kristina Beek · indexed 2026-09-02 20:30 UTC
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
P0
2026-09-02 19:28 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-02 19:35 UTC
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]
P0