2026-09-14 20:52 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-14 20:55 UTC
Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]
P5
2026-09-14 20:35 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-14 20:45 UTC
Frontier AI is compressing the attack lifecycle from vulnerability discovery to exploitation, forcing defenders to detect, patch and respond at machine speed. Cybersecurity has always been a race between attackers and defenders. ENISA’s latest assessment suggests that frontier AI is changing the speed of that race, and the gap between discovering a vulnerability and exploiting […]
P0
2026-09-14 18:34 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-14 18:45 UTC
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware. [...]
P0
2026-09-14 18:01 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 19:45 UTC
An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of
P0
2026-09-14 16:02 UTC
Security Journalism
The Record · indexed 2026-09-14 16:30 UTC
The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices.
P0
2026-09-14 11:58 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-14 12:25 UTC
There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, while defenders still have to work out which findings actually deserve their action. In the first half of 2026, a whopping 35,853 CVEs were published, roughly 49% more than in the
P0
2026-09-14 11:51 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-14 12:10 UTC
The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely. The post Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution appeared first on SecurityWeek.
P0
2026-09-14 09:50 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-14 10:05 UTC
Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems. [...]
P5
2026-09-14 08:08 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-14 08:20 UTC
Microsoft has confirmed that USB audio devices may fail on some Windows systems after installing the KB5124008and KB5124012 September 2026 security updates. [...]
P5
2026-09-14 07:57 UTC
Other
Group-IB · indexed 2026-09-14 08:30 UTC
A deep technical analysis of the Smishing Triad’s JWR phishing kit and Outsider operator cluster, revealing its real-time victim control, encrypted WebSocket communications, multi-stage credential theft, AES-256-CTR implementation, infrastructure, and actionable indicators for defenders.
P0
2026-09-13 14:26 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-13 14:45 UTC
Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor. [...]
P15
2026-09-13 10:11 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-13 10:25 UTC
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers
P0
2026-09-12 11:10 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-12 11:10 UTC
Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments. The post BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days appeared first on SecurityWeek.
P25
2026-09-11 18:40 UTC
Security Journalism
The Record · indexed 2026-09-11 17:50 UTC
Researchers analyzed a flood of fraudulent business emails and found that the threat actors had doubled-up on tactics to make them appear legitimate, including help from AI.
P0
2026-09-11 17:26 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-11 17:35 UTC
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. [...]
P0
2026-09-11 13:35 UTC
Vendor Research
Rapid7 · Brendan Watters · indexed 2026-09-11 14:05 UTC
This One Goes to Sixteen!Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers!New module content (16)Elasticsearch ingest-attachment Apache Tika XFA XXE Local File ReadAuthors: Bourbon Offensive Security Services and Jean-Marie BourbonType: AuxiliaryPull request: #21739 cont…
P100
2026-09-11 09:39 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-11 09:40 UTC
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]
P0
2026-09-11 07:14 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-11 07:40 UTC
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns
P0
2026-09-10 20:36 UTC
Security Journalism
Dark Reading · Nate Nelson · indexed 2026-09-10 21:00 UTC
Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.
P0
2026-09-10 20:34 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 20:45 UTC
Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality. [...]
P5
2026-09-10 19:07 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-10 19:15 UTC
Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. [...]
P5
2026-09-10 17:23 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research · indexed 2026-09-10 19:15 UTC
Microsoft examines an AI-assisted business email compromise campaign that used executive impersonation and fake invoices to target finance teams with ACH payment fraud. The post Protecting organizations from AI-assisted executive impersonation and invoice fraud appeared first on Microsoft Security Blog.
P0
2026-09-10 16:00 UTC
Vendor Research
Microsoft Security Blog · Rob Lefferts · indexed 2026-09-10 18:15 UTC
See how Microsoft Defender detects and disrupts AI-themed phishing, malware, and multi-stage attacks across the attack chain. The post Detect and disrupt AI-themed attacks with Microsoft Defender appeared first on Microsoft Security Blog.
P0
2026-09-10 15:29 UTC
Security Journalism
Dark Reading · Elizabeth Montalbano · indexed 2026-09-10 16:00 UTC
The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.
P25
2026-09-10 14:11 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-10 14:15 UTC
Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. [...]
P25
2026-09-10 13:21 UTC
Other
Proofpoint Threat Insight · indexed 2026-09-10 09:20 UTC
P0
2026-09-10 11:14 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-10 11:30 UTC
Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. [...]
P0
2026-09-10 08:08 UTC
Security Journalism
BleepingComputer · Sergiu Gatlan · indexed 2026-09-10 08:15 UTC
Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices. [...]
P0
2026-09-10 08:06 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-10 08:55 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-75650 (CVSS score of 10.0) is an Adobe Commerce and Magento improper neutralization of special elements in a […]
P35
2026-09-10 07:09 UTC
Security Journalism
Security Week · Ionut Arghire · indexed 2026-09-10 07:15 UTC
The exploit provides full System privileges on Windows machines running the September 2026 patches. The post New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender appeared first on SecurityWeek.
P25