Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data | Cybersecurity
Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach…
Read moreCISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV | Cybersecurity
Ravie LakshmananSep 12, 2026Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its…
Read moreOpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers | Cybersecurity
The “major malicious attack” that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas…
Read moreCrypto customers targeted by scammers after email marketing provider breach | Malware
An attacker breached an email marketing platform and launched targeted attacks against the newsletter subscribers of some of its customers, especially those working in cryptocurrency and adjacent fields. The incident…
Read moreGitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure | Cybersecurity
Ravie LakshmananSep 11, 2026Vulnerability / Web Security GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure….
Read moreAndroid malware creates a hidden copy of your banking app | Malware
Researchers at Group-IB found that the Android banking Trojan Gigabud can create a separate work profile on an infected phone and run a cloned banking app inside it. The attacker…
Read moreYour Critical Vulnerabilities Might Not Be Your Biggest Risk | Cybersecurity
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path…
Read moreAttackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors | Cybersecurity
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz…
Read moreUpdate Chrome now to protect against an actively exploited vulnerability | Malware
Chrome is rolling out an update for its desktop browser. The update includes 230 security fixes, one of which is known to be actively exploited. The stable channel has been updated to…
Read moreWill AI kill us all within the next decade? | Malware
The Wall Street Journal reports that concerns are rising inside AI labs that competition is pushing tech companies to race toward self-improving models that could spiral out of human control….
Read moreThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories | Cybersecurity
Ravie LakshmananSep 10, 2026Hacking News / Cybersecurity News A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An…
Read moreBlueMoon exploit kit turns Chrome and Windows flaws into attacks | Malware
BlueMoon, a shared Chrome and Windows exploit kit, shows why “patch later” is becoming a dangerous gamble. Security updates are easy to put off. The browser still opens, Windows still…
Read moreCheck Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE | Cybersecurity
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run…
Read moreCopyright scammers get Instagram accounts suspended and demand payment | Malware
Scammers are abusing Meta’s copyright-reporting system to suspend people’s Instagram accounts and then hold them for ransom, according to the BBC. Criminals file fake copyright complaints with Instagram, claiming that…
Read moreNearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example “sk-1234” Admin Key | Cybersecurity
Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup guide. LiteLLM is an open-source…
Read moreThe push to stop algorithms controlling social media feeds has begun | Malware
Remember when social media was filled only with posts from your friends, rather than what an algorithm decided you wanted to see? So does the Australian government, and it wants…
Read moreU.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto | Cybersecurity
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to…
Read moreMore than 100,000 fake stores are out to steal your card details | Malware
Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores. The researchers describe it as the largest publicly documented fake-shop…
Read moreInfostealer Logs Expose Replayable AI Tokens That Can Bypass MFA | Cybersecurity
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create “stolen keys” that grant illicit access to tools from model providers like Google, Anthropic, and others….
Read moreWebinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE | Cybersecurity
The Hacker NewsSep 09, 2026Security Operations / Artificial Intelligenc A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security…
Read moreMicrosoft fixes record 964 flaws, including 2 exploited zero-days | Malware
Microsoft’s September 2026 Patch Tuesday addresses 964 CVEs, including 104 rated Critical and 860 rated Important, making it the company’s largest Patch Tuesday release on record. Microsoft lists 974 CVEs…
Read moreMicrosoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days | Cybersecurity
Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild….
Read moreMikroTik router flaws allow takeover without a password | Malware
CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet. Although the warning comes from Poland’s…
Read moreSlim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution | Cybersecurity
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster…
Read moreGrindr settles HIV status data-sharing lawsuit for $35 million | Malware
Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with…
Read moreFreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials | Cybersecurity
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group,…
Read moreA week in security (August 31 – September 6) | Malware
Last week on Malwarebytes Labs: The hidden work of modernizing Malwarebytes X Money rollout linked to password-reset attacks Free streaming boxes may be routing criminal traffic through your home StreamRat…
Read moreLG TV flaws could let attackers listen in, even in standby mode | Malware
Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the…
Read morePEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution | Cybersecurity
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. “Requiring prior administrative or code execution access,…
Read moreLoyalty points fraud is funding hacker holidays (Lock and Code S07E18) | Malware
This week on the Lock and Code podcast… Crooks are taking a holiday. They’re counting on you to fund it. For decades, cybercriminals have stolen roughly the same types of…
Read more