2026-10-02 18:33 UTC
Security Journalism
BleepingComputer · Ionut Ilascu · indexed 2026-10-02 18:35 UTC
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]
P15
2026-10-02 15:51 UTC
Security Journalism
Dark Reading · Alexander Culafi · indexed 2026-10-02 16:00 UTC
"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.
P0
2026-10-02 14:30 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-10-02 14:30 UTC
Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats appeared first on SecurityWeek.
P0
2026-10-02 14:05 UTC
Security Journalism
The Record · indexed 2026-10-02 14:20 UTC
The group is exploiting a variety of vulnerabilities impacting Microsoft SharePoint, according to a new report from Symantec Threat Hunter Team.
P15
2026-10-02 11:46 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-02 12:00 UTC
Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft’s Official X Account appeared first on SecurityWeek.
P0
2026-10-02 09:34 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-10-02 09:40 UTC
The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek.
P0
2026-10-02 09:29 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-02 09:30 UTC
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. [...]
P0
2026-10-02 05:47 UTC
Other
Group-IB · indexed 2026-10-02 08:20 UTC
Group-IB descubre BraZetsu, un nuevo malware para Windows basado en Python que funciona como un toolkit maestro para Initial Access Brokers y potencia un marketplace clandestino único, mejorado con IA, para comercializar objetivos comprometidos en Iberoamérica y Latinoamérica.
P0
2026-10-01 19:32 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-10-01 19:40 UTC
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams struggle to keep pace. [...]
P0
2026-10-01 14:00 UTC
Vendor Research
Microsoft Security Blog · Matthew Thomas · indexed 2026-10-01 14:40 UTC
According to this year’s Microsoft Digital Defense Report, government agencies and services were the sector most impacted by cyber threats in 2026, accounting for 27% of observed activity, up from 17% in 2025. The post Preparing governments for an era of interconnected cyber risk appeared first on Microsoft Security Blog.
P0
2026-10-01 14:00 UTC
Vendor Research
Microsoft Security Blog · Terrell Cox · indexed 2026-10-01 14:40 UTC
Read highlights from the 2026 Microsoft Digital Defense Report, which reflects a security environment that continues to grow more interconnected. The post Insights from the 2026 Microsoft Digital Defense Report appeared first on Microsoft Security Blog.
P0
2026-10-01 13:33 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-02 07:20 UTC
Google unveils Gemini 4 Argon, a frontier AI model built for coding, enterprise work, and autonomous cybersecurity defense, rolling out to trusted testers. Google announced Gemini 4 Argon, and it’s not going straight to the public. It’s rolling out first to a set of trusted cyber defenders through what Google calls the Fairwind Program, which […]
P0
2026-10-01 13:33 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-10-01 14:40 UTC
Google unveils Gemini 4 Argon, a frontier AI model built for coding, enterprise work, and autonomous cybersecurity defense, rolling out to trusted testers. Google announced Gemini 4 Argon, and it’s not going straight to the public. It’s rolling out first to a set of trusted cyber defenders through what Google calls the Fairwind Program, which […]
P0
2026-10-01 13:00 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-10-01 13:20 UTC
As AI takes on more of the enrichment, correlation, and initial assessment inside the SOC, roles, skills, and KPIs still require deliberate redesign. Security leaders need to decide where automation is dependable, where human judgment should remain decisive, and how teams should be measured when alert handling is no longer the center of the operating modelThe Gartner® report, The Roles Required for the AI-Enabled Security Operations Center (SOC), examines the roles and capabilities Gartner expe…
P0
2026-10-01 11:14 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-10-01 11:30 UTC
Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2. [...]
P0
2026-10-01 07:52 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-10-01 08:10 UTC
The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide. The post Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders appeared first on SecurityWeek.
P10
2026-10-01 07:49 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 08:55 UTC
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," Koray Kavukcuoglu,
P0
2026-10-01 05:21 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-10-01 05:55 UTC
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security products, including a zero-day vulnerability, and recovered a customized tool used by the attacker
P25
2026-10-01 05:00 UTC
Other
Zero Day Initiative · indexed 2026-10-01 19:10 UTC
This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-50375.
P15
2026-09-30 19:31 UTC
Vendor Research
Microsoft Security Blog · Lindsay Myers · indexed 2026-09-30 21:30 UTC
This year at Microsoft Ignite, we spotlight our AI-first, end-to-end security platform designed to protect identities, devices, data, applications, clouds, infrastructure, and the AI agents now working alongside your teams. The post Secure what’s next: Your guide to Microsoft Security at Microsoft Ignite 2026 appeared first on Microsoft Security Blog.
P0
2026-09-30 19:21 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P5
2026-09-30 18:56 UTC
Security Journalism
Dark Reading · indexed 2026-09-30 19:45 UTC
New Swimlane research underscores a paradox: While AI detection and response is essential to giving defenders an edge, one in four security pros say AI limits their skill development.
P0
2026-09-30 17:30 UTC
Security Journalism
Huntress · indexed 2026-09-07 17:30 UTC
See how attackers like GootKit and WhisperGate abuse Windows Defender exclusions to hide malware from AV scans — and how Huntress detects it.
P0
2026-09-30 16:46 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 17:55 UTC
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system command injection flaw that can lead to remote code execution when Simple Network Management Protocol
P20
2026-09-30 16:32 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-30 17:55 UTC
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installer, distributed under a deceptive file name established remote management access on affected
P0
2026-09-30 14:16 UTC
Vendor Research
Rapid7 · Rapid7 · indexed 2026-09-30 15:05 UTC
Higher education faces a difficult security equation. Universities hold large volumes of sensitive student, financial, health, and research data while supporting open networks, distributed users, legacy infrastructure, and increasingly complex cloud environments. Attackers have taken notice, and the pressure on security teams continues to grow.In Q2 2025, universities faced an average of 4,388 cyberattacks per organization per week, up 24% from the same period in 2024. Nine in ten universities …
P40
2026-09-30 14:00 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Mahesh Mandava and Rajesh Kumar Natarajan · indexed 2026-09-30 15:00 UTC
Microsoft Threat Intelligence examines CVE-2026-73570 exploitation in Zimbra, including observed attack paths, detection opportunities, and mitigation guidance. The post Unauthenticated command injection on internet-facing mail servers: tracking CVE-2026-73570 appeared first on Microsoft Security Blog.
P5
2026-09-30 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Google Threat Intelligence Group · indexed 2026-09-30 14:45 UTC
Written by: Robin Grunewald, Supriya Mazumdar, Kelli Vanderlee Introduction Google Threat Intelligence Group (GTIG) examines vulnerability disclosure and exploitation statistics to evaluate the impact of artificial intelligence (AI) on the vulnerability threat landscape. We found that AI is measurably changing not just the pace of vulnerability discovery and exploitation, but also the types and typical risk profiles of vulnerabilities that are being discovered. Key findings: Vulnerability discl…
P60
2026-09-30 13:37 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-30 13:50 UTC
Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month. [...]
P0
2026-09-30 11:11 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-30 11:15 UTC
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]
P25