2026-09-01 14:01 UTC
Security Journalism
BleepingComputer · Sponsored by Spur Intelligence · indexed 2026-09-01 14:15 UTC
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. [...]
P0
2026-09-01 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-01 03:50 UTC
Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In thi…
P0
2026-09-01 13:56 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-01 14:50 UTC
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
P0
2026-09-01 13:50 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 14:40 UTC
Five Venezuelan nationals pleaded guilty after failed ATM jackpotting attempts in Kansas. The FBI recorded 700+ cases in 2025, causing $20M in losses. Five Venezuelan nationals have pleaded guilty after trying to steal cash from ATMs in Kansas using the popular ATM jackpotting technique. The U.S. Department of Justice announced the case on August 31, […]
P0
2026-09-01 13:08 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 13:20 UTC
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking the
P0
2026-09-01 12:38 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 12:50 UTC
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
P10
2026-09-01 12:33 UTC
Security Journalism
The Record · indexed 2026-09-01 12:50 UTC
In a report published Tuesday, Kaspersky said it first discovered NodeRabbit on a system in Afghanistan and later identified variants on systems in Egypt and Ethiopia.
P0
2026-09-01 12:28 UTC
Security Journalism
The Record · indexed 2026-09-01 12:35 UTC
Andrew Bailey, chair of the Financial Stability Board, called on financial institutions and technology providers to “prepare for more severe scenarios involving simultaneous disruption across multiple firms or shared technology dependencies.”
P0
2026-09-01 12:00 UTC
Vendor Research
Google Security Blog · Eric Lynch · indexed 2026-09-01 12:15 UTC
Checking phone to see image of digital credential
P0
2026-09-01 11:30 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 11:50 UTC
The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting
P0
2026-09-01 11:08 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 11:20 UTC
Huntress found five DPRK-linked workers hired in 2026 using fake identities, remote-access setups and proxy tools to infiltrate legitimate companies. Companies keep accidentally hiring North Korea-linked individuals as remote workers, and Huntress just published the receipts. The security firm’s investigation documents five confirmed cases in 2026 alone where DPRK-aligned workers, tracked under the name FAMOUS […]
P0
2026-09-01 09:34 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 10:20 UTC
Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Kaspersky Endpoint Security. The researcher named the exploit HardBreacher, it triggers a privilege escalation flaw. Nightmare Eclipse […]
P35
2026-09-01 09:15 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 09:25 UTC
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]
P0
2026-09-01 09:05 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 10:35 UTC
METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered "two notable security incidents" where external actors attempted to gain unauthorized access to its systems. No sensitive information is believed to
P0
2026-09-01 08:26 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:55 UTC
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language model's (LLM) safety mechanisms and prevent its
P0
2026-09-01 08:13 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-01 09:05 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: PaperCut, the print management software running in schools, hospitals, and offices worldwide, recently confirmed that a pre-authentication remote code execution flaw, tracked as CVE-2026-81578, […]
P50
2026-09-01 07:48 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-01 08:05 UTC
Two security vulnerabilities in the PaperCut NG and MF print management software, patched last week after being exploited as zero-days, are now being abused in data theft attacks. [...]
P25
2026-09-01 07:22 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-01 08:00 UTC
Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka
P15
2026-09-01 02:00 UTC
Community
SANS Internet Storm Center · indexed 2026-09-01 02:10 UTC
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
P0
2026-08-31 21:08 UTC
Security Journalism
Dark Reading · Jai Vijayan · indexed 2026-08-31 21:35 UTC
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
P0
2026-08-31 20:47 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-31 21:00 UTC
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. [...]
P0
2026-08-31 20:31 UTC
Security Journalism
The Record · indexed 2026-08-31 20:50 UTC
Federal law enforcement continued to warn about ATM jackpotting gangs as it announced guilty pleas from five Venezuelan nationals.
P0
2026-08-31 20:25 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-08-31 20:50 UTC
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
P0
2026-08-31 20:09 UTC
Security Journalism
Dark Reading · Arielle Waldman · indexed 2026-09-01 12:50 UTC
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.
P0
2026-08-31 20:00 UTC
Community
SANS Internet Storm Center · indexed 2026-08-31 20:10 UTC
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session — history, filesystem output, working paths, and the agent's local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.
P0
2026-08-31 19:45 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-08-31 20:50 UTC
ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to […]
P0
2026-08-31 19:45 UTC
Security Journalism
The Record · indexed 2026-08-31 19:50 UTC
At least $6 million was stolen from crypto platform Tectonic after an attacker manipulated the price of the Tonic coin over the weekend.
P0
2026-08-31 19:00 UTC
Vendor Research
AWS Security Blog · Michael Fuller · indexed 2026-08-31 19:05 UTC
When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists because customers told us what was working for them in enterprise security […]
P0
2026-08-31 18:51 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-08-31 19:05 UTC
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. [...]
P0
2026-08-31 18:41 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-31 18:55 UTC
Bulletin ID: 2026-092-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/31/2026 11:30 AM PDT Description: OpenSearch is an open-source search and analytics engine. We identified CVE-2026-83497 where a remote authenticated user with basic read/search permissions can run arbitrary code on the server by providing a crafted cursor parameter to the plugins/sql endpoint. Affected Products & Versions: OpenSearch SQL Plugin (open-source, self-managed): - Affected: v2.8 to…
P5