Latest Cybersecurity News and Articles
09 September 2026
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime
09 September 2026
The company will increase its US market presence and will expand its engineering and go-to-market teams.
The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek.
09 September 2026
Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG.
The post AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns appeared first on SecurityWeek.
09 September 2026
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.
The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,
09 September 2026
The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.
The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek.
09 September 2026
Major chipmakers announced patches for vulnerabilities recently discovered in their products.
The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek.
09 September 2026
The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic.
The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.
09 September 2026
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.
Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
09 September 2026
Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.
The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.
09 September 2026
Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data.
The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek.
09 September 2026
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed?
For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act.
As AI accelerates vulnerability discovery and research, that delay matters more
09 September 2026
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command.
The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web
09 September 2026
AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.
The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek.
09 September 2026
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet.
Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through
09 September 2026
Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.
The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek.
09 September 2026
Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block.
The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek.
09 September 2026
Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default.
The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek.
09 September 2026
The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible.
The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek.
09 September 2026
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks.
The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to
09 September 2026
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.
The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine.
"Out-of-bounds write in V8 in Google Chrome prior to