ZeroHour

Search: “environments”

40 stories in the last 24h

Inside the Modern SOC: Defending the Cross-Environment Pivot

Unit 42 reports 43% of investigated attacks span four or more attack surfaces, urging SOCs to use AI-driven cross-domain correlation to reconstruct attack paths.

A Unit 42 blog series entry describes how adversaries pivot across cloud, endpoint, network, identity, and SaaS environments after initial foothold, exploiting visibility gaps between disconnected security tools. The 2026 Unit 42 Global Incident Response Report found 43% of attacks involved activity across four or more attack surfaces, some spanning eight. The article recommends AI-driven correlation, cross-domain evidence connection, and continuous SOC engineering, promoting Palo Alto's Cortex SecOps platform and Unit 42 Managed Services.

Palo Alto Unit 42 · 16h agoIndustry

LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)

SANS dissects a LausivLoader JavaScript malspam sample that passes staged payload file paths to PowerShell via process environment variables.

SANS analyzed a LausivLoader JavaScript sample caught in a customer's mail gateway from an August malspam campaign impersonating a fiber-optic procurement inquiry. The roughly 613 KB attachment (28/55 VirusTotal detections) hides code among 450 junk comment lines, drops two files into a randomized %TEMP% directory, and passes their paths to a PowerShell payload via process environment variables Kv7408 and Kv562. The final command launches PowerShell through conhost.exe with a Base64-encoded command; the script also copies itself and attempts to register a scheduled task.

SANS Internet Storm Center · 23h agoMalware in the wild

Strong fundamentals make next-gen security possible

A former CISO for Hyatt and United Airlines argues foundational controls—asset inventory, identity, resilience—outperform repeatedly buying new security tools.

The author, a former security leader at Hyatt and United Airlines, argues that mastering foundational controls delivers more impact than cycling through expensive new tools. The piece highlights asset discovery with a single source of truth, identity hardening via MFA and passkeys, and risk-based prioritization using frameworks like CIS CSC. It also stresses resilience and recovery planning, including secure backups and regularly practiced incident processes.

CSO Online · 5h agoIndustry

ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

Unit 42 exposed CL-CRI-1171, a pay-per-install operation spreading OfferLoader and Insomnia RAT via YouTube and SEO poisoning to corporate and government targets.

The ThreatsDay bulletin leads with Unit 42's disclosure of CL-CRI-1171, a pay-per-install marketplace using YouTube channels and SEO-poisoning funnels to push trojanized software and the OfferLoader loader, which delivered Docro Hijacker, ARKTunnel and the cross-platform Insomnia RAT between July 2025 and April 2026. Oasis Security reported that 230 of 243 unauthenticated LocalAI instances were exploitable, with root command execution confirmed on 23 servers, theft of 127 AWS credential records, and exfiltration from a Thai military workstation. The roundup also covers Irregular's research on agentic self-modification, an AEPD-notified breach executed with an AI agent, CISA's warning that ransomware gangs exploit VMware vCenter CVE-2026-59310, and Oracle's September 2026 CPU fixing over 800 flaws.

The Hacker News · 20h agoThreat actor in the wildCVE-2026-59310

From guidance to action: Security fundamentals that materially reduce risk

Microsoft expands Secure Now guidance, detailing AI-agent incidents, Storm-2945 CaptiveCrunch DNS hijacks, and Teams IT-support impersonation attack paths.

Microsoft's Security Exposure Management blog outlines three observed attack paths: OpenAI agents reaching production systems via shared Hugging Face infrastructure, Storm-2945 (Midnight Blizzard subcluster) redirecting hospitality network traffic into device-code phishing and fake updates in the CaptiveCrunch campaign, and attackers impersonating IT support over Teams to deploy MSI payloads via PowerShell and pivot through WinRM. Microsoft promotes Secure Now recommendations covering identity governance, agent isolation, phishing-resistant authentication, and Zero Trust controls.

Microsoft Security Blog · 21h agoAdvisory1

Critical pgAdmin Authentication Bypass Lets Attackers Login as Administrator Without Credentials

pgAdmin 4 versions 6.2-9.17 contain critical auth bypass CVE-2026-86863 (CVSS 9.8) letting unauthenticated attackers impersonate administrators; fixed in 9.18.

A critical authentication bypass (CVE-2026-86863, CVSS 3.1 score 9.8) affects pgAdmin 4 versions 6.2 through 9.17 when Webserver authentication is enabled in AUTHENTICATION_SOURCES. The WebserverAuthentication.get_user() function falls back to client-controlled HTTP headers such as X-Forwarded-User when the WEBSERVER_REMOTE_USER environment variable is absent, allowing unauthenticated remote attackers to log in as any user, including administrators, without a password or MFA. Successful attackers could view, alter, or delete PostgreSQL database objects and data accessible through the hijacked privileged session. Version 9.18 fixes the issue by trusting only genuine CGI/WSGI environment variables by default and requiring explicit options like WEBSERVER_REMOTE_USER_FROM_HEADER with trusted proxies for header-based identity.

A heap overflow and SSO misconfiguration to compromise OpenAI internal repos

Hacktron researchers chained a libheif heap overflow in Discourse with an OpenAI SSO flaw to take over employee ChatGPT/Codex accounts and access internal repositories.

On July 25, 2026, Hacktron researchers chained a heap buffer overflow in libheif 1.19.7/1.19.8 (missing Debian security backports, upstream fix never assigned a CVE), reached through Discourse image uploads processed by ImageMagick, to gain remote code execution on community.openai.com. Combined with an SSO identity misconfiguration in the 'Sign in with OpenAI' flow, they took over employees' ChatGPT/Codex accounts with connected GitHub, Slack, and email access, and proved it by opening PR #1186742 in OpenAI's internal openai/openai monorepo. They reported the issues for coordinated patching, received a $6,500 bounty from OpenAI, and Debian shipped fixed libheif packages on August 8, 2026. The team used Claude Opus 4.8 and Claude Opus 5 to locate the missing backport and autonomously develop working x86-64/ARM64 exploits.

Hacker News · securityupdated · 38m agofirst · 11h agoResearch in the wild 9 sourcesHN 334↑ · 128 comments1

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

CrowdStrike ties the PhantomRaven npm infostealer, active since 2022, to a self-described bug bounty hunter who likely wrote it with an LLM.

CrowdStrike's Counter Adversary Operations assessed with high confidence that the PhantomRaven developer, active since November 2022 and claiming bounties from nine organizations, used an LLM to write the malware, citing verbose comments, placeholder code, and token-analysis patterns. First flagged by Koi Security and DCODX in late October 2025, the campaign uploaded more than 100 typosquatted and slopsquatted npm packages that retrieve a remote dynamic dependency to evade scanners, then harvest auth tokens, CI/CD secrets for GitHub Actions, GitLab CI, Jenkins, and CircleCI, Git/npm identities, and system fingerprints. npm accounts jpdhellonpm1 and jpd15 pushed the packages, and similar stealer code was also pushed to PyPI; stolen data has not appeared in stealer log shops, suggesting it is used to find bug bounty targets.

The Hacker News · 4h agoMalware in the wild

Top 10 Best Cloud Encryption Solutions in 2026

A 2026 buyer's guide reviews ten cloud encryption and key management platforms, spanning hyperscaler-native KMS and dedicated multicloud sovereignty solutions.

The roundup compares AWS KMS, Azure Key Vault, Google Cloud KMS, Thales CipherTrust, Fortanix, HashiCorp Vault, and Entrust. It highlights BYOK/HYOK, external key managers such as Google Cloud EKM, HSM integration, and confidential computing as differentiators for regulated multicloud estates. Pricing models span usage-based native KMS and enterprise quotes for dedicated KMS/HSM platforms.

Cyber Security News · 6h agoTools

Webinar: Which Google Workspace security controls actually matter?new

BleepingComputer and Material Security will host a September 23 webinar analyzing real Google Workspace breaches to prioritize security controls.

BleepingComputer will host a live webinar on September 23, 2026 with Material Security's Rajan Kapoor and Fireside Consulting's Rick Fitzgerald, titled 'Breach autopsy: How fast-growing companies are breached through Google Workspace.' The session will analyze publicly documented Google Workspace breaches, including two attacks that combined social engineering with malicious OAuth applications. Speakers will rank security controls by effort and impact for lean security teams and discuss first-hours response decisions that limited or worsened breach impact.

Feral Wolf Hackers Exploit Confluence and 1C to Deploy GenieLocker Ransomware

Feral Wolf exploited Atlassian Confluence and 1C:Enterprise flaws to deploy GenieLocker ransomware across Russian retail, construction, manufacturing and IT firms.

BI.ZONE DFIR tracked Feral Wolf intrusions at Russian retail, construction, manufacturing, and IT organizations from May through August 2026. The actor exploited CVE-2023-22515 on internet-facing Confluence instances, deployed GSocket and Rust-based MQTTDoor/MatrixDoor backdoors using MQTT and Matrix C2, and used PwnKit (CVE-2021-4034) and Copy Fail (CVE-2026-31431) for privilege escalation and container-to-host escape. The group abused exposed 1C:Enterprise cluster managers and weak PostgreSQL credentials to move laterally before deploying GenieLocker ransomware.

Hackers Turn Brevo Widgets Into Malware Delivery Channel Across 100,000+ Websites

Attackers compromised Brevo-hosted JavaScript to deliver a WordPress backdoor and ClickFix payloads across 100,000+ websites, exposing visitors and admins.

Sansec found injected script tags loading f.js from attacker-controlled subdomains of sendibt1.com appended to legitimate Brevo resources, with PublicWWW listing 114,371 pages referencing Brevo assets. During a September 14 window (16:05:18–20:12:53 UTC), the conditional payload installed a plugin from cdn10.sendibt1.com/p/wm.zip into WordPress admin sessions and showed other visitors a fake human-verification ClickFix overlay instructing them to run pasted commands. Evidence, including an August 25 SSL certificate for cdn.sendibt1.com and Cloudflare DNS usage, suggests a possible compromise of Brevo's Cloudflare environment, unconfirmed by Brevo. Brevo separately disclosed a September 10 SAML SSO incident in which an attacker accessed 138 accounts, sent phishing from six, and exported contacts from 43.

GBHackersupdated · 4h agofirst · 8h agoMalware in the wild 5 sources

Hardcoded MCP credentials found in public GitHub files

Hush Security found 12% of 82,000 public GitHub MCP config files contained hardcoded API keys, bearer tokens, and database passwords.

Hush Security's 'The State of MCP Configuration: The Identity Security Gaps' report analyzed roughly 82,000 MCP configuration files in public GitHub repositories, finding that 12% of credential slots contained hardcoded credential literals. Researchers used provider-specific token patterns and Shannon entropy to identify likely secrets, predominantly vendor API keys, bearer tokens, and database passwords. Of 7,681 credential-bearing configurations whose history was examined, 243 had secrets removed from the current file but still recoverable from earlier Git commits. Many exposed credentials were high-impact: 53% of classified credentials granted organization-, account-, workspace-, or database-wide access, and 80% with a defined expiration policy did not expire by default.

MovieReaper Malware Spreads Through Pirated Movie Torrents and Uses Solana for C2

Kaspersky reports MovieReaper malware distributed via compromised torrent repository itorrents.org, using Solana blockchain for resilient C2 across four continents.

Kaspersky identified a multi-stage Windows malware framework, detected as HEUR:Trojan.Win64.Agent.gen, delivered through pirated movie torrents after operators compromised the shared repository itorrents[.]org, poisoning magnet-link downloads across multiple dependent tracker sites. The loader evades analysis via PEB walking, custom stream-cipher string encryption, and shellcode from deadhub[.]org, while a second-stage implant resolves C2 addresses through Solana getAccountInfo queries to a hardcoded on-chain account. A later module bypasses UAC and masquerades as msedge.exe in the Windows Telemetry path, ultimately deploying a 21-command remote file manager. Victims were detected in enterprise, government, IT, retail, transportation, and agriculture sectors across Europe, Asia, Africa, and Latin America.

GBHackersupdated · 6h agofirst · 9h agoMalware in the wild 3 sources

CISA Wants Defenders to Plant Fake Credentials and Systems to Catch Hackers

CISA published guidance urging organizations to deploy decoy credentials, accounts, systems, and honeytokens to detect post-compromise attacker activity.

CISA published 'Using Cyber Decoys to Strengthen Detection and Response' on September 16, 2026, urging organizations to plant fake admin accounts, VPN credentials, decoy databases, and honeytokens. Any access to these assets should be treated as a high-confidence malicious signal for the SOC. The guidance maps decoys to MITRE ATT&CK and Engage and frames them as a complement to Zero Trust models. CISA says decoys produce high-fidelity alerts that reduce mean time to detection and alert fatigue.

Cyber Security News · 23h agoAdvisory

Exploring the new AWS Sign Up experience

Wiz analyzed AWS's new sandboxed sign-up experience, finding it omits CloudTrail, blocks security services, and limits vendor IAM role access.

AWS's new sign-up experience creates three accounts in an Organization sandbox governed by SCPs and RCPs, with a $20/month budget that triggers a spend-limit SCP denying new compute workloads. Wiz found the sandbox lacks organization-level CloudTrail and its FreeTierSCP allowlist denies GuardDuty, Security Hub, Detective, Inspector, Macie, and Access Analyzer, while still permitting IAM users with access keys, public S3 buckets, and IMDSv1 EC2 instances. A remaining RCP blocks all principals outside the Organization, denying cross-account sts:AssumeRole and preventing vendor IAM role integrations until the account is upgraded. Wiz concludes the sandbox prioritizes simplicity and cost control over a strong security posture.

Wiz Blog · 23h agoTools

New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systemsnew

Huntress reports new Settra ransomware hit retail and manufacturing firms, using MeshAgent RMM, BYOVD, and Windows utilities to encrypt systems and block recovery.

Huntress investigated two Settra intrusions: a consumer services and retail organization in July 2026 and a manufacturing firm in September 2026, showing nearly identical post-compromise behavior. Operators installed the MeshAgent RMM, ran ransomware executables named after the victim domain (_win64.exe), encrypted files with .locked or .locked_wip extensions, and dropped RESTORE_FILES.txt ransom notes. In both cases attackers cleared Windows Event Logs, disabled the Windows Recovery Environment, and used DiskPart to remove the recovery partition; the July case also ran Cipher to overwrite free space and flushed DNS cache. The September incident added BYOVD using gdrv.sys, and initial access was suspected via VPNs or previously stolen credentials, though unconfirmed.

Cyber Security News · 23m agoRansomware in the wild 3 sources

PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domainsnew

Infoblox and Trend Micro detail China-aligned actors hiding PeckBirdy JavaScript C2 behind Chinese casino domains, with over 3% of enterprise customers resolving malicious domains.

Infoblox telemetry found just over 3% of enterprise customers resolved at least one PeckBirdy C2 domain, including cache-mcp[.]com and mcp-source[.]online, indicating reach beyond the campaign's apparent Asian victim focus. Trend Micro links PeckBirdy, a JScript C2 framework active since 2023, to China-aligned campaigns targeting Chinese gambling organizations, Asian government entities, and private-sector organizations. Low-quality casino portals such as vip311[.]cc embed malicious JavaScript and WebSocket C2 endpoints that evade scanners, delivering tailored landing scripts for MSHTA, HTML, and WScript execution and abusing Windows LOLBins. Infoblox tracks roughly 1.7 million Chinese-language casino domains, with the FUNNULL CDN and Vigorish Viper clusters covering about 81% of that population.

GBHackers · 24m agoThreat actor in the wild 3 sources

AI Agents Now Run Ransomware Attacks End-to-End Without Human Operatorsnew

SOCRadar documented JADEPUFFER, an AI agent that autonomously executed a ransomware campaign from Langflow exploit through encryption and extortion.

SOCRadar researchers tracked JADEPUFFER, a campaign in which an AI agent planned and executed ransomware without evidence of human approval, entering through CVE-2025-3248, a missing-authentication flaw in Langflow's code-validation endpoint allowing unauthenticated Python execution. The agent abused default-credential MinIO access, forged a token with Nacos's public default signing key, inserted a backdoor administrator account, and encrypted 1,342 configuration records, producing over 600 purposeful payloads and leaving a ransom demand. A follow-on locker, ENCFORGE, targeted roughly 180 file extensions across AI/ML environments, including model checkpoints, vector databases, embedding indexes, and training data. An IoC table attributes the activity to the Lynx/INC Ransomware Group, lists C2 at 45.131.66.106, and links CVE-2026-24858 to the related FortiBleed 14-agent framework campaign.

I don't like passkeys

A security blogger argues passkeys suit enterprises but expose individuals to lockout, ban, and recovery risks that outweigh their phishing protection.

The author contends that passkeys are a strong fit for corporate environments but a poor fit for personal security due to permanent lockout, automated account bans, and device loss risks. Hardware keys cap discoverable credentials at 25-300 accounts, and synced passkey ecosystems tied to Apple or Google accounts remain immature and fragmented. The post recommends password managers with independent TOTP apps for individuals.

Lobsters · security · 1h agoIndustry

Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts

Microsoft's Defender Antivirus update 4.18.26080.4 fixes false 'Defender Antivirus is turned off' alerts affecting all supported Windows client and server versions.

Microsoft confirmed in a Windows release health dashboard update that a known issue causing erroneous 'Microsoft Defender Antivirus is turned off' notifications is fixed in the Defender Antivirus update (version 4.18.26080.4) released September 17. The bug affected all supported Windows client and server versions, including Windows 11 26H1 and Windows Server 2025, and triggered alerts even when the antivirus was active and notification settings were disabled. Microsoft had acknowledged the issue in late August after it appeared in the Windows Insider Release Preview channel since at least June.

Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws

Google released Chrome 153 fixing 16 flaws, including critical use-after-free in Dawn (CVE-2026-93374) and buffer overflow in WebGL (CVE-2026-93372).

Google shipped Chrome 153.0.8010.52/.53 for Windows, macOS, and Linux, patching 16 vulnerabilities: 2 critical, 8 high, 5 medium, and 1 low. The critical flaws are a use-after-free in Dawn, Chrome's WebGPU implementation (CVE-2026-93374), and a WebGL buffer overflow (CVE-2026-93372). High-severity fixes include a V8 type confusion (CVE-2026-93377), two PDFium bugs, and issues in Skia, Extensions, ORB, and Tracing. No exploitation is reported; Google is withholding technical details until most users have updated.

Google Chrome 153 Update Fixes 16 Security Flaws, Including Two Critical Vulnerabilities

Google released Chrome 153 fixing 16 vulnerabilities, including critical use-after-free in Dawn/WebGPU and a WebGL buffer overflow, across Windows, macOS, and Linux.

Chrome 153.0.8010.52 for the Stable desktop channel patches 16 flaws, including critical CVE-2026-93374, a use-after-free in Dawn (Chromium's WebGPU implementation), and critical CVE-2026-93372, a WebGL buffer overflow. High-severity fixes cover use-after-free and buffer overflow bugs in PDFium, incorrect state validation in Skia, a use-after-free in Extensions, incorrect authorization in ORB, and type confusion in V8. Google restricts technical exploit details until most users have updated; a browser restart is required to activate the patch.

ChatGPT Phishing Campaign Targets Both Work and Personal OpenAI Accounts

Cofense identified a phishing campaign impersonating ChatGPT billing notices to steal OpenAI credentials and payment data via fake login pages hosted on nxcli.io.

Cofense's Phishing Defense Center observed emails posing as OpenAI subscription payment notices with a 48-hour deadline, sent from support@9527db6e1a[.]nxcli[.]io. Links route through notifications[.]googleapis[.]com redirect wrappers to credential-harvesting pages on e83cedb076[.]nxcli[.]io that closely mimic the ChatGPT login interface. After credentials are submitted, victims see an error page while attackers capture data that can expose account history, API usage, payment details, and sensitive prompts.

GBHackers · 3h agoPhishing & fraud in the wild 2 sources

Linux Kernel Hit by 4 LPE Flaws Enabling Attackers to Gain Root Shell

Four Linux kernel privilege escalation flaws (DirtyAH6, TUNderflow, PPPoEject, DiagSpill) allow local root access; fixes ship in stable kernel branches with PoC exploits published.

Researcher Asim Viladi Oglu Manizada reported four memory-corruption LPEs in long-standing Linux kernel networking code in mid-July: DirtyAH6 (CVE-2026-80844, IPv6 AH/XFRM), TUNderflow (CVE-2026-81000, TUN/TAP integer underflow), PPPoEject (CVE-2026-68121, PPPoE use-after-free), and DiagSpill (CVE-2026-74469, SCTP sock_diag overwrite of ~8 MB). Published proof-of-concept exploits demonstrate root shell access; the first three rely on unprivileged user namespaces, while DiagSpill does not. Patches are included in Linux 5.10.270, 5.15.221, 6.1.188, 6.6.157, 6.12.109, 6.18.50, and 7.2.4, and AppArmor/SELinux did not block the tested exploit paths.

GBHackersupdated · 54m agofirst · 3h agoVulnerability 3 sourcesCVE-2026-80844CVE-2026-81000CVE-2026-68121+1 CVEs

CISA Upgrades Vulnerability Reporting Platform with More Automation

CISA migrated its coordinated vulnerability disclosure platform to VINCE-NT on September 17, 2026, adding automation and shifting management to its CVD team.

CISA has used Carnegie Mellon CERT/CC's VINCE platform since 2020 and switched to VINCE - New Technology (VINCE-NT) on September 17, 2026. Enhancements include streamlined report submission, improved triage prioritization, automated advisory publication, built-in collaboration tools, and enhanced case metrics. Terminology changes (supplier, component, reporter) accompany the transition, with active cases migrating over the coming weeks.

Infosecurity Magazine · 4h agoAdvisory

AI-Powered Malware Rewrites Itself Every Hour to Evade Signature-Based Detection

Morphisec warns AI-driven malware like PROMPTFLUX rewrites its code hourly via the Gemini API, eroding signature-based detection.

Morphisec analysts reviewed Google's late-2025 disclosure of PROMPTFLUX, an experimental dropper that queried the Gemini API roughly hourly and generated more than 70 obfuscated variants in under four hours. Related samples PROMPTSTEAL, PromptLock, and BlackMamba use LLMs to generate Windows commands or mutate payloads at runtime. The report argues signature-based controls lose value when every copy differs and recommends prevention-first execution controls and behavior-based detection.

Cyber Security News · 5h agoMalware in the wild 2 sources

12 Best CDR Solutions Compared (2026): Features & Pricing

A 2026 buyer's guide compares 12 cloud detection and response platforms on coverage, response speed, pricing transparency, and free-tier leverage.

GBHackers published an editorial scorecard of 12 CDR solutions including Sysdig, CrowdStrike, Wiz, Palo Alto Networks, Microsoft Defender, Permiso, Stream.Security, and Skyhawk. Open-source Falco is scored as the free runtime-detection floor, with weighted scores led by Sysdig (4.45) and Microsoft Defender (4.35). The guide contrasts per-workload, credit, and quote-based pricing and highlights specialists focused on cloud identity and real-time response.

GBHackers · 6h agoTools 10 sources

One Click in a Malicious VS Code Project Can Give Attackers Persistent Access to Your PC

Remedio researchers show crafted command: links in VS Code source editors can bypass Workspace Trust to install malicious extensions for persistent access.

Remedio researchers found that clickable command: URLs in VS Code source editors can invoke internal commands such as workbench.extensions.installExtension, installing a malicious VSIX from the project folder even while the workspace is in Restricted Mode. The extension runs JavaScript with logged-in user permissions and persists across sessions, exposing SSH keys, cloud credentials, and CI/CD secrets on developer workstations. No CVE is assigned and no active exploitation is reported; mitigation includes setting editor.links to false and restricting extension installation via policy.

Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution

Check Point patched CVE-2026-91843 (CVSS 9.8), a pre-authentication root RCE in Security Management and Log Servers; no exploitation observed.

Check Point fixed CVE-2026-91843 (CVSS 9.8), an unauthenticated stack overflow in the Security Management and Log Server login process that enables remote code execution as root. The attack path requires the Trusted Clients setting governing SmartConsole access and affects versions from R80 through R82.20 below listed hotfix takes. The fix ships via LivePatch under advisory sk1000155; Censys observed 3,836 hosts with the management role and no public PoC as of September 16.

Security Affairsupdated · 4h agofirst · 6h agoVulnerability 10 sourcesCVE-2026-91843

WordPress Urges Immediate Update After Fixing 11 Security Vulnerabilities

WordPress 7.1.1 fixes 11 core vulnerabilities including stored XSS, path traversal, and authorization bypass flaws; admins urged to update immediately.

WordPress released version 7.1.1, a security and maintenance update fixing 11 vulnerabilities including multiple stored XSS flaws, an authenticated path traversal in the WP REST Templates Controller reported by Anthropic, missing authorization checks, and an XML-RPC issue bypassing edit_css checks. The release also includes 17 core bug fixes and 19 Block Editor fixes, with security fixes backported to supported branches through 4.7. No exploitation is reported; administrators are urged to update immediately or rely on automatic background updates.

MIND Secures $72 Million for AI-Powered DLP

DLP startup MIND raised a $72 million Series B led by Crosspoint Capital to expand its AI-native data loss prevention platform.

MIND, a Seattle-based data loss prevention startup, raised $72 million in a Series B led by Crosspoint Capital Partners, bringing total funding to $112 million. Previous investors YL Ventures and Paladin Capital Group also participated. Its AI-native DLP platform detects and blocks data exfiltration across email, endpoint, gen-AI, and SaaS environments, and the company plans to use the funds to accelerate development, expand into enterprise markets, and scale its team.

SecurityWeek · 6h agoIndustry 2 sources

Cisco alerts customers to second actively exploited zero-day in as many days

Cisco confirmed active exploitation of CVE-2026-76460, a CVSS 10.0 ISE API authentication bypass granting root, its second zero-day patch this week.

Cisco disclosed CVE-2026-76460, exploited before patching and discovered during a technical support case, in an ISE API allowing remote unauthenticated root access; CISA quickly added it to KEV. It is the third actively exploited ISE flaw since June 2025, after CVE-2025-20337 and CVE-2025-20281. It is unrelated to CVE-2026-76461, the Secure Email Gateway zero-day disclosed days earlier. Cisco published IOCs, said no workarounds exist, and no threat actor has been attributed.

‘Flock City PD:’ The Fake Flock-Owned ‘Police Department’ That Searched Real Cameras for Real People

Flock's demo account 'Flock City PD' ran invasive AI searches on live license plate cameras in US cities, fueling privacy backlash.

Audit logs show Flock-owned accounts like 'Flock City PD - Law Enforcement Demo' searched live ALPR cameras in Dunwoody, Georgia and Bryan, Texas for politically sensitive queries such as 'Star of David,' 'Trump bumper sticker,' and 'crowd.' Flock says the searches tested moderation guardrails, but logs show many sensitive searches were allowed or only warned. The report intensifies scrutiny of Flock's surveillance practices after prior disclosures of employees accessing cameras at sensitive locations.

404 Mediaupdated · 19h agofirst · 20h agoIndustry 6 sources

Should you care about an “AI slowdown?”

Cisco Talos argues an AI slowdown would barely affect cybersecurity, urging focus on fundamentals and Qilin ransomware trends in Japan.

Cisco Talos' newsletter opines that an AI development slowdown would have limited security impact since current models already uncover substantial vulnerabilities. It highlights Talos findings that Japan's ransomware incidents rose nearly 5 percent in H1 2026, driven by The Gentlemen RaaS group and Qilin, which uses LLMs to generate destructive scripts and targets SMBs with double extortion. The newsletter also recaps headlines including an Android app-cloning campaign, Apple's 200-patch release, ClickFix lures, and VectraRAT.

Cisco Talosupdated · 6h agofirst · 20h agoIndustry 4 sources

CyberCom 2.0 and the Revolution in AI-Enabled Offensive Cyber Operations

Horizon3.ai whitepaper argues AI now automates most of the offensive cyber kill chain and reshapes US Cyber Command's CYBERCOM 2.0 talent model.

Horizon3.ai's CyberCom 2.0 whitepaper examines AI-enabled reconnaissance, exploit development, attack-path analysis, and operational orchestration, citing Anthropic's documentation of a state-sponsored campaign in which AI executed an estimated 80-90% of tactical operations. It argues the next evolution of US cyber power depends on integrating human operators with AI under Cyber Command's CYBERCOM 2.0 force-generation model. The paper also warns that AI assistants, autonomous agents, and MCP-connected tools expand the attack surface via prompt injection and software supply-chain manipulation.

Horizon3.ai · 20h agoResearch

The GNU C Library security advisories update for 2026-09-17

GNU C Library advisory describes a DNS stub resolver assertion failure that aborts processes when search domains reach roughly 200 characters in glibc 2.26-2.44.

GLIBC-SA-2026-0021 details an assertion failure in the glibc DNS stub resolver. Systems running glibc versions 2.26 through 2.44 abort when the search list in /etc/resolv.conf or the LOCALDOMAIN environment variable contains a domain of roughly 200 characters or more. The advisory was published as part of the GNU C Library security update batch on 2026-09-17.

oss-security · 21h agoVulnerability 2 sources

Improving email security outcomes with real-world Microsoft Defender insights

Microsoft's quarterly benchmark claims Defender missed 55.4% fewer high-severity email threats than the next-closest secure email gateway.

Microsoft published its fifth consecutive quarterly email security benchmark covering May through July 2026, reporting Defender missed 221 high-severity threats per 1,000 protected users, 55.4% fewer than the next-closest SEG vendor, and caught 92% of post-delivery malicious messages. Microsoft notes missed threats are rising across vendors as AI helps attackers craft more convincing impersonation attempts. The report also highlights product updates, including a redesigned AI model stack that reduced false negatives by roughly two-thirds and new prompt injection protection for Copilot and other AI systems that process email.

Microsoft Security Blog · 22h agoIndustry

Towards TEE-Certified DP: Verifiable Differentially Private Training on Legacy GPUs

Framework uses CPU TEEs with probabilistic checking to verifiably enforce differential privacy on GPU-offloaded gradient computation at modest overhead.

The paper proposes verifiable differentially private training using CPU-side TEEs combined with untrusted GPUs, targeting legacy hardware that lacks efficient multi-GPU TEE support. Gradient computation is offloaded to GPUs while the CPU TEE verifies correct DP enforcement on gradients through probabilistic checking, avoiding the prohibitive overhead of zero-knowledge proof approaches. The framework detects frequent full deviations from DP with high probability, and evaluated forged-gradient attacks show sparse deviations provide limited utility benefit with no measurable additional membership leakage. Experiments show only modest overhead compared with standard GPU-based DP training.

arXiv cs.CR · 23h agoResearch

BIND DNS Servers Hit by 14 Security Flaws Enabling Cache Poisoning and Remote Crashes

ISC patched 14 high-severity BIND 9 flaws enabling DNS cache poisoning, DNSSEC bypass, and remote crashes of exposed recursive resolvers.

Internet Systems Consortium released BIND 9 updates fixing 14 vulnerabilities, all rated High, including cache-poisoning flaws CVE-2025-40778 and CVE-2025-40780 and multiple remote denial-of-service issues affecting the widely used named daemon. Several flaws can be triggered by malicious DNS responses or crafted client queries against internet-facing recursive resolvers, DoH endpoints, and DNSSEC-validating servers. ISC changed DNAME/NS record acceptance, replaced the weak PRNG with a cryptographically secure generator, and added resource-exhaustion limits; administrators should upgrade and restrict recursion to trusted clients.