Security

164 articles · page 1 of 4

Security

GPG Vulnerabilities Remain Unpatched, Researcher Claims in Post-CCC Talk

A security researcher has detailed the aftermath of disclosing multiple vulnerabilities in GPG, the widely-used PGP implementation, revealing that some critical flaws remain unpatched months later. In a talk following the 39th Chaos Communication Congress (39c3), the researcher demonstrated how the main developer of GnuPG declared a feature 'harmful' rather than fixing a vulnerability, and presented novel memory corruption bugs.

13 Sept·2 min
Security

Revolut confirms customer data breach via fake government requests

British fintech Revolut has confirmed that an unauthorized third party obtained sensitive customer information by sending fraudulent requests from a legitimate government agency email domain. The exposed data includes names, contact details, copies of passports and driver's licenses, verification selfies, account statements, and transaction histories. Revolut said a limited number of customers were affected and that it has contacted them directly.

13 Sept·2 min
Security

Anthropic Reports Hackers Abused Claude AI to Steal Secrets from 1.8 Million Android Apps

Anthropic has disclosed that multiple threat groups, including financially motivated criminals and state-sponsored espionage actors linked to Russia and China, abused its Claude AI model for malicious purposes between December 2025 and August 2026. Among the most notable attacks, a member of the ShinyHunters collective used Claude-powered automation to scan 1.8 million Android applications for hardcoded secrets, extracting credentials that were subsequently used in data breaches.

12 Sept·2 min
Security

Ukrainian lawyer turned Conti ransomware coder sentenced to 4 years in US prison

Oleksii Oleksiyovych Lytvynenko, a 44-year-old Ukrainian lawyer who became a developer for the Conti ransomware gang, has been sentenced to four years in a US prison after pleading guilty to conspiracy to commit wire fraud. Lytvynenko, who lived in Cork, Ireland, was extradited to the United States in October 2025 and admitted to developing malware and researching targets for the group, which is linked to more than 1,000 victims and over $150 million in ransom payments.

12 Sept·2 min
Security

GitLab Urges Immediate Patching of Maximum-Severity Path Traversal Flaw

GitLab on Thursday urged all self-managed users to upgrade their servers immediately to patch a maximum-severity path traversal vulnerability, tracked as CVE-2026-85706, that could allow unauthenticated attackers to read arbitrary files under certain conditions. The company also fixed a second critical flaw, CVE-2026-87719, an insecure deserialization issue in the GraphQL subscription serializer affecting GitLab Enterprise Edition that could expose sensitive credentials and Advanced Search configurations. The patches are included in versions 19.3.2, 19.2.6, and 19.1.

12 Sept·2 min
Security

New Android Malware Mantax Otax Combines Ransomware and Spyware to Encrypt Data and Steal Information

A new Android malware strain called Mantax Otax, discovered by mobile security firm Zimperium, encrypts files on older devices while simultaneously stealing sensitive data and harassing victims through spam and social engineering. The malware is distributed via malicious APKs hosted outside Google Play, primarily by Indonesian operators using phishing and social engineering messages.

11 Sept·2 min
Security

AI agents used in widespread PaperCut exploit campaign, hitting 395+ organizations

An unknown attacker deployed hundreds of AI agents to exploit two recently disclosed PaperCut vulnerabilities, breaching at least 395 organizations across 48 countries in a fast-moving campaign. The intrusions overwhelmingly targeted the US education sector, with one high school going from initial access to domain administrator in just seven minutes. Threat intelligence firm GreyNoise traced the operation to a likely Russian-speaking criminal who used OpenAI's Codex harness and a DeepSeek model to develop exploits and automate attacks at scale.

11 Sept·2 min
Security

Cisco Firewall Management Center Flaws Used by Ransomware Gangs and State-Sponsored Hackers

Cisco has confirmed that two recently patched vulnerabilities in its Secure Firewall Management Center have been actively exploited by three separate threat clusters, including ransomware affiliates and the Russian state-sponsored Sandworm group. The flaws — CVE-2026-20079, a maximum-severity authentication bypass bug, and CVE-2026-20316, a static credential vulnerability — allowed attackers to deploy web shells, steal credentials, and in some cases deliver Qilin ransomware and Cyclops Blink malware.

11 Sept·2 min
Security

BlueMoon exploit kit spreads to at least four cyber-espionage groups, researchers say

A novel exploit kit named BlueMoon, which chains together two Chromium browser flaws and a Windows kernel privilege escalation bug, has been rapidly adopted by at least four cyber-espionage groups, most with suspected links to China, according to research published this week. The kit has been observed since late August targeting NGOs, mining companies, and commodity trading firms in the US and Southeast Asia.

10 Sept·2 min·3 sources
Security

AdaptHealth Confirms Data Breach Exposed 4.1 Million Patients

AdaptHealth, a major U.S. provider of home medical equipment and services, has confirmed that a July cyberattack attributed to the ShinyHunters threat group exposed the personal and health data of approximately 4.1 million individuals. The breach, disclosed in a Securities and Exchange Commission filing on July 2, 2026, involved compromised cloud-based systems after a third-party contractor fell victim to a social engineering ploy.

10 Sept·2 min
Security

Hackers stealing Claude AI tokens from subscribers via infostealer malware

Grant De Swardt, an independent AI consultant in East Sussex, U.K., discovered unexplained token usage on his Claude Max 20x account in early August, leading to an investigation by Anthropic that revealed a compromised session key was used to mint unauthorized tokens. The company has warned users that infostealer malware is being used to steal login sessions, and multiple subscribers have reported similar incidents.

9 Sept·2 min·2 sources
Security

Hackers Deploy Linux Rootkit to Breach F5 BIG-IP APM Devices, Inject Fileless Web Shell

A sophisticated Linux rootkit targeting F5 BIG-IP APM devices has been observed deploying a fileless web shell directly into memory, according to security researchers. The malware, which Sophos and ESET have analyzed, is believed to be a second-stage payload delivered after exploiting CVE-2025-53521, a critical remote code execution vulnerability that F5 reclassified from a denial-of-service issue in March.

9 Sept·2 min
Security

Microsoft September 2026 Patch Tuesday Breaks Records with Nearly 1,000 Vulnerabilities Fixed

Microsoft released a record-breaking September 2026 Patch Tuesday, fixing approximately 972 vulnerabilities across its product line — including two actively exploited zero-days. The patch haul, which Ars Technica reports as roughly 972 flaws and BleepingComputer puts at 966, dwarfs the previous record of 620 set just last month. The update is bundled with the Windows 10 extended security update KB5122878 for ESU subscribers and enterprise LTSC users.

9 Sept·2 min·2 sources
Security

Microsoft's September 2026 Patch Tuesday fixes record 966 flaws, two actively exploited zero-days

Microsoft released its largest-ever Patch Tuesday update on September 8, 2026, fixing a record 966 security vulnerabilities across its product line, including two zero-day flaws that attackers are actively exploiting in the wild. The update follows the company's adoption of an AI-powered vulnerability discovery system and represents a sharp escalation from the 570 flaws patched in July and 400 in August.

9 Sept·2 min
Security

Microsoft Shatters Patch Tuesday Record with 974 CVEs, Two Zero-Days Already Exploited

Microsoft has shattered its own Patch Tuesday record with 974 security fixes this month, including two zero-day vulnerabilities already under active exploitation, as the company continues to grapple with a wave of vulnerabilities discovered by AI models. Adobe simultaneously issued 172 patches, including an emergency fix for a Magento and Adobe Commerce zero-day that is already being abused to compromise online stores.

9 Sept·3 min·3 sources
Security

SAP patches maximum-severity 'OVERPASS' kernel vulnerability, critical S4GET auth bypass

SAP has released its September 2026 security updates, addressing 20 vulnerabilities including two critical flaws: a maximum-severity memory corruption vulnerability in the SAP Kernel dubbed OVERPASS, and a critical authentication bypass in the NetWeaver Message Server named S4GET, which together could allow unauthenticated attackers to fully compromise SAP systems and access sensitive business data.

9 Sept·3 min
Security

Google warns extortion crews targeting AI data as new attack surface emerges

Data theft and extortion crews are actively stealing companies' proprietary AI data and threatening to leak it unless ransoms are paid, according to Google's threat intelligence team. In two newly detailed intrusions — one at a healthcare company and another at an AI media generation firm — attackers exfiltrated AI models, research, source code, and secrets before demanding payment. Google warns the trend is likely to expand as AI assets become increasingly valuable targets.

8 Sept·3 min
Security

Over 220 Million Traveler Records Exposed in Vietnam-Linked APIS Database Leak

An Advance Passenger Information System (APIS) database containing more than 220 million passenger and crew records, including passport numbers and flight details, was left accessible online through a chain of security misconfigurations, security researchers Kinryū Labs have discovered. The exposed data, spanning January 2017 to April 2026, appears linked to a Vietnamese organization and could affect travelers of many nationalities who flew to, from, or through Vietnam during that period.

8 Sept·3 min
Security

BigBear 2.0 phishing panel still online but infrastructure dark for three weeks, researchers say

A phishing-as-a-service platform targeting Microsoft 365 users has had its phishing infrastructure offline for nearly three weeks, though its administrative panel remains accessible, according to security researchers who infiltrated the operation's control system. CloudSEK researchers obtained administrator access to the BigBear 2.0 panel, uncovering a campaign that bypassed multi-factor authentication (MFA) at 258 organizations and captured more than 5,000 credentials.

8 Sept·2 min·2 sources
Security

ConnectWise Warns of Unpatched ScreenConnect Vulnerability, Provides Temporary Mitigation

ConnectWise has disclosed a new security flaw in its ScreenConnect remote access platform that affects file transfer behavior in support and access sessions, with no patch yet available. The company has issued temporary mitigation steps while it works on a fix. Internet security watchdog Shadowserver currently tracks nearly 6,000 ScreenConnect instances exposed online, though it is unclear how many are honeypots or already secured.

7 Sept·2 min
Security

Mathspace confirms breach affecting 1.08 million amid wider wave of Metabase attacks

Online maths learning platform Mathspace has confirmed that personal data belonging to 1,079,819 students, parents and school staff in Australia and New Zealand was stolen in a breach of its internal reporting system — the latest in a spate of attacks on Metabase, the open-source reporting tool the company used. Mathspace disclosed the incident over the weekend, saying the attacker gained administrator access to its self-hosted Metabase installation without a legitimate login.

7 Sept·3 min·2 sources