MikroTik router flaws allow takeover without a password | Malware
CERT Polska warns that attackers are actively exploiting a chain of critical MikroTik RouterOS flaws to seize control of routers exposed to the internet. Although the warning comes from Poland’s…
Read moreSlim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution | Cybersecurity
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster…
Read moreGrindr settles HIV status data-sharing lawsuit for $35 million | Malware
Grindr has reportedly agreed to pay £26 million (around $35 million) to settle a UK privacy lawsuit alleging that it shared sensitive user data, including some users’ HIV status, with…
Read moreFreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials | Cybersecurity
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group,…
Read moreA week in security (August 31 – September 6) | Malware
Last week on Malwarebytes Labs: The hidden work of modernizing Malwarebytes X Money rollout linked to password-reset attacks Free streaming boxes may be routing criminal traffic through your home StreamRat…
Read moreLG TV flaws could let attackers listen in, even in standby mode | Malware
Smart TVs are internet-connected computers with microphones, app stores, advertising systems, and access to the same home networks used by your family’s phones, laptops, printers, and smart-home devices. In the…
Read morePEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution | Cybersecurity
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. “Requiring prior administrative or code execution access,…
Read moreLoyalty points fraud is funding hacker holidays (Lock and Code S07E18) | Malware
This week on the Lock and Code podcast… Crooks are taking a holiday. They’re counting on you to fund it. For decades, cybercriminals have stolen roughly the same types of…
Read moreYour Cloud Security Checklist Doesn’t Work the Way You Think It Does | Cybersecurity
If managing security across multiple cloud providers wasn’t hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations…
Read moreFlirty OnlyFans promoters on X may be using AI to appear human | Malware
In a recent post, we looked at reports of League of Legends players receiving suspicious friend requests shortly after matches. The accounts quickly steered the conversation toward Discord, where they…
Read moreN-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw | Cybersecurity
Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able’s incident notice says the flaw has been exploited in…
Read moreAttackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication | Cybersecurity
Swati KhandelwalSep 06, 2026Vulnerability / Network Security Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control…
Read moreFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner | Cybersecurity
Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of…
Read moreUnpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores | Cybersecurity
Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce…
Read moreAttackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials | Cybersecurity
Ravie LakshmananSep 05, 2026Data Breach / Identity Security JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors…
Read moreThousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel | Cybersecurity
A group of AI safety researchers says a fleet of autonomous agents that identified themselves as OpenAI systems left about 18,000 posts on a dormant 25-year-old German wiki between May…
Read moreAttackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities | Cybersecurity
Ravie LakshmananSep 05, 2026Vulnerability / Web Security Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and…
Read moreFree streaming boxes may be routing criminal traffic through your home | Malware
“Free” movies and TV could cost you your privacy, bandwidth, and control of your home network. We’ve warned about illegal streaming and modded Amazon Fire TV Sticks in the past….
Read moreThe hidden work of modernizing Malwarebytes | Malware
Most of the work that keeps a security product trustworthy is invisible. Users see a scan complete, a threat blocked, an update applied overnight. They don’t see the platform underneath….
Read morePhishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters | Cybersecurity
Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters. “Instead of using these characters to hide instructions from people while exposing…
Read moreX Money rollout linked to password-reset attacks | Malware
X says attackers may be targeting accounts because its X Money payments service is now more widely available. The company is investigating a wave of unsolicited password-reset emails sent to…
Read moreOver 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws | Cybersecurity
Ravie LakshmananSep 04, 2026Vulnerability / Web Security Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities…
Read moreGPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests | Cybersecurity
OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the “world’s most intelligent and aligned model.” The development comes days after the artificial intelligence (AI) company said the…
Read moreYour AI chats could be used in court | Malware
You might tell an AI chatbot secrets that you wouldn’t divulge to your closest friends. If you do, though, beware: They could end up as evidence in court. An article…
Read more153M+ driver’s licenses for sale on new dark web platform | Malware
A new dark web platform called Nexus claimed to be selling 153 million driver’s license scans and millions of other identity and medical cards. The collection included more than 153…
Read moreThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories | Cybersecurity
Ravie LakshmananSep 03, 2026Hacking News / Cybersecurity News The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request…
Read moreCritical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root | Cybersecurity
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside…
Read moreStreamRat Android malware spreads through Meta and TikTok ads | Malware
A malicious advertising campaign promoting a fake free TV-streaming service reached roughly 570,000 Meta users. The researchers who discovered the campaign found that its streaming-themed ads were aimed at Spanish-speaking…
Read morePegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member’s iPhone | Cybersecurity
Ravie LakshmananSep 03, 2026Spyware / Mobile Security The iPhone belonging to a member of Serbia’s student protest movement was infected with NSO Group’s Pegasus spyware, according to new findings from…
Read moreYour phone or computer may soon ask how old you are | Malware
First, the good news: If you use a Linux-based operating system, you may not be asked your age in a few months. The bad news is that Windows, macOS, iOS,…
Read more