Cyber Security News
- Get link
- X
- Other Apps
"Hackers hide phishing behind trusted senders, redirect chains and URL obfuscation."
Views expressed in this cybersecurity, cybercrime update are those of the reporters and correspondents. Accessed on 15 September 2026, 1026 UTC.
Content and Source: "Cyber Security News" via email subscription from https://feedly.com.
https://feedly.com/i/collection/content/user/f401222a-bca6-4c45-9cc1-183f239e8d86/category/0ce2e207-9c3a-4916-959e-00213c9be23b
Please check subscription link or scroll down to read your selections. Thanks for joining us today.
Russ Roberts (https://www.hawaiicybersecurityjournal.net).
Cyber Security News
28
Today
Cybercriminals are increasingly using trusted-looking senders, multi-stage redirect chains, and obfuscated URLs to bypass email security tools, according to Virus Bulletin’s Q3 2026 VBSpam test. The 16-day test examined 11 publicly tested email-security products against 103,969 emails, including 103,380 spam messages. While leading products recorded phishing detection rates near 100%, the test sh
Yesterday
A stored cross-site scripting vulnerability in Telegram Desktop’s HTML chat-export feature could let attackers steal the contents of exported conversations. The flaw, tracked internally through Telegram Desktop’s source repository but not assigned a CVE, affected exports generated before Beta version 6.9.4 and stable version 7.0.1. ExPatch Vulnerability Research disclosed the issue after Telegram
A critical security flaw in the WooCommerce Wholesale Lead Capture plugin is being actively exploited, allowing remote attackers to upload malicious files and potentially take full control of vulnerable WordPress sites. The vulnerability, tracked as CVE-2026-27540, affects WooCommerce Wholesale Lead Capture versions 2.0.3.1 and earlier. The premium plugin, used by an estimated 6,000 websites, hel
A threat actor exploited a pre-authentication remote code execution flaw in marimo to harvest AWS credentials, retrieve an SSH private key from AWS Secrets Manager, and authenticate to a bastion host in eight seconds. Tracked as CVE-2026-39987, the vulnerability affects marimo versions through 0.20.4. The flaw stems from missing authentication on /terminal/ws , exposing an interactive PTY shell t
Cyber Security News / 1h
Security researchers have disclosed DDRop, a low-cost hardware attack that can undermine confidential-computing protections in Intel TDX, Intel Scalable SGX, and AMD SEV-SNP systems. The attack uses a custom DDR5 memory interposer costing about $159 in parts and requires privileged software access plus brief physical access to the target server. Trusted Execution Environments, or TEEs, are design
Microsoft has expanded its bug bounty incentives for security researchers targeting vulnerabilities in Dynamics 365 and Power Platform services, with rewards ranging from $1,250 to $60,000 for qualifying submissions. The initiative targets security flaws with direct and demonstrable impact in Microsoft-supported cloud products. Microsoft is especially prioritizing cross-tenant vulnerabilities, wh
Nintendo has patched a high-severity vulnerability in the Nintendo Switch that could allow nearby attackers to execute unauthorized code or access information stored on affected consoles by abusing QR-code-based local wireless connections. Tracked as CVE-2026-82079, the flaw affects Nintendo Switch systems running firmware versions earlier than 23.0.0. Nintendo released system update 23.0.0 on Se
Cyber Security News / 3h
Quick Answer: Startups can run a credible container stack free Trivy (Aqua), Falco (Sysdig lineage), Kubescape , and Calico OSS cover scan, runtime, posture, and network. Paid depth comes from Aqua and Sysdig (lifecycle + runtime), Snyk (developer fixes), Red Hat ACS (OpenShift-native), Prisma Cloud (breadth), and Rapid7 (platform unification). Containers ship faster than any security team can re
Cyber Security News / 3h
Quick Answer: Tenable (Ermetic lineage) and Wiz lead standalone-grade CIEM inside broader platforms; CyberArk and Delinea (Authomize) bring identity-security DNA; SailPoint extends governance into cloud entitlements. Consolidation defines this market most pure-play CIEM startups were acquired, so verify ownership before shortlisting. Cloud entitlements are the quietest catastrophe in security: th
The UK government has begun rolling out passkey authentication across GOV.UK One Login, extending passwordless sign-in capabilities to more than 23 million users and strengthening defenses against phishing-led account compromise. The initiative, announced on September 14, enables citizens to access government services using a device-based passkey authenticated through a fingerprint, Face ID, or l
Cyber Security News / 3h
Quick Answer: Standalone CASB is effectively over the capability now lives inside SSE platforms. Microsoft Defender for Cloud Apps wins bundled economics for M365 estates; Netskope leads dedicated SaaS-control depth; Zscaler and Cloudflare deliver CASB as SSE policy; Skyhigh carries the deepest pure-CASB heritage. Ownership notes: Bitglass is Forcepoint , Cloudlock is Cisco’s legacy line. Shadow
Cyber Security News / 3h
Quick Answer: For most mid-market and enterprise estates, Wiz (agentless correlation) and Microsoft Defender for Cloud (free tier → published plans) are the rational anchors; Orca matches agentless speed; Sysdig and Sweet Security add runtime depth; Prisma Cloud wins breadth; Rapid7 unifies with VM/SIEM programs; Data Theorem covers the API/app edge. The cloud-native application protection platfo
Cyber Security News / 3h
Where CSPM secures how your cloud is configured, cloud workload protection (CWPP) secures what actually runs virtual machines, containers, Kubernetes, and serverless functions across their lifecycle from build to runtime. As workloads become ephemeral and cloud-native, protection must span image scanning, configuration, and real-time runtime detection without crippling performance. The right CWPP
Threat actors are mass-scanning internet-exposed Vite development servers to steal cloud credentials, environment files, and Infrastructure-as-Code secrets. F5 Labs honeynet telemetry recorded 807 session-grouped attacks and roughly 32,000 raw events during August 2026, marking a sharp rise from only 1,732 Vite-related events observed across the prior three months. The campaign exploits CVE-2026-
Threat actors are increasingly using autonomous AI agents to speed up cyberattacks, automate vulnerability research, and steal cloud credentials at scale. Google Threat Intelligence Group (GTIG) has uncovered an exposed command-and-control server running an automated reconnaissance and credential-management platform called Recon , which was used to organize and validate more than 23,800 stolen se
Windows Volume Shadow Copy Service, or VSS, is designed to create point-in-time copies of files and volumes. Administrators and backup products use it to restore data after accidental deletion, corruption, or system failure. However, attackers increasingly abuse the same Windows feature to steal credentials, disrupt recovery, and prepare ransomware attacks . Shadow copies are not a complete backu
Threat actors exploited the critical FortiGate SSL-VPN vulnerability tracked as CVE-2024-21762 to access infrastructure linked to Thai broadband provider 3BB. The attackers then deployed MeshCentral remote-management agents for persistent access, targeted RADIUS databases, and prepared scripts to erase evidence while retaining control of compromised systems. Hunt.io discovered the operation after
Cybercriminals hijacked HBO Max’s verified Reddit account and used it to run malicious advertisements targeting Windows and macOS users with ClickFix malware . The campaign, linked to a wider operation dubbed PasteSwitch, used trusted branding and fake software downloads to convince victims to manually run malicious commands. Reddit paused the ads and began an internal investigation after communi
A newly disclosed Linux kernel local privilege escalation vulnerability, tracked as CVE-2026-43502, affects the Reliable Datagram Sockets (RDS) zerocopy send path. Dubbed “ZcopyReaper,” the flaw can allow an unprivileged local user to elevate privileges on vulnerable systems under specific kernel configuration conditions . Yuan Tan of NebuSec reported the vulnerability, and it was introduced in L
Cisco has disclosed a critical SQL injection vulnerability in Cisco AsyncOS Software for Secure Email Gateway that attackers are actively exploiting to run arbitrary commands as root on vulnerable appliances. Tracked as CVE-2026-76461, the flaw carries a CVSS v3.1 score of 9.8 and stems from insufficient validation in the product’s email-parsing logic. According to Cisco, an unauthenticated remot
Welcome to this edition of the CyberPress weekly cybersecurity newsletter your cybersecurity bulletin covering the 50 most important stories from September 7 to 12, 2026, organized day by day. AI ran through the week: threat actors weaponized Claude agents to automate attacks, hundreds of AI agents mass-exploited PaperCut, and OpenAI stood up a ‘Defense Factory’ and a $1 billion Daybreak initiati
A browser extension marketed as a Twitch enhancement tool has been found forwarding live OAuth session tokens belonging to more than 30,000 users to proxy infrastructure linked to a Russian-language bot service. Socket’s Threat Research Team identified the extension, named “Twitch Enhanced Viewer | JeetBot,” across both the Chrome Web Store and Firefox Add-ons repository. The Chrome version, trac
- Get link
- X
- Other Apps
Comments
Post a Comment
Please leave a comment about our recent post.