Cybersecurity News and Vulnerability Aggregator

Cybersecurity news aggregator

Top Cybersecurity Stories Today

The Hacker News Sep 5

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

The Hacker News Sep 5

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

The Hacker News 20h ago

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

The Hacker News Sep 3

An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses

Latest

Sunday, September 6
r/cybersecurity 2h ago

O CiberAventuras é um projeto voluntário de educação em segurança digital que ajuda crianças, adolescentes, pais, idosos e toda a comunidade a reconhecer e evitar golpes, fraudes e outros riscos da internet por meio de uma linguagem simples e acessível. Nosso objetivo é promover a conscientização e a prevenção, fortalecendo famílias e protegendo pessoas antes que se tornem vítimas. Acreditamos que compartilhar conhecimento é uma forma de cuidar do próximo e contribuir para uma comunidade mais segura, informada e preparada para os desafios do mundo digital. Não é uma autopromoção, não quero aparecer se for possível, tenho um historia que me motivou a criar esse serviço para a comunidade. [https://ciberaventuras.com.br/](https://ciberaventuras.com.br/)

r/cybersecurity 7h ago

I've answered a version of "can I run my ISMS or GRC programme from spreadsheets" in various subs a bunch of times over the last few months. My answer is always yes, with caveats, but a comment box isn't really enough space to cover everything I'd like to say. So I've taken a bit of time this weekend to write up how to do it properly, based on a number of projects I've run in UK financial services organisations. [How to run an ISO 27001 ISMS on spreadsheets](https://www.riskquilt.com/blog/isms-on-spreadsheets) If you're new to GRC frameworks I'll go a bit stronger than "you **can**" — I think you **should** start on spreadsheets, because they give you space for messy early thinking. The question is what the pain points are that make a platform worth having as you grow. What I've covered: * What the critical success factors are for certification * Why a smaller risk register is more use than a large one (there's a free taxonomy CSV in there if it saves you a job) * Why control definition deserves the most of your time * How to write controls that are designed to be evidenced — including approval and review controls, which read fine on paper and leave nothing behind when they happen verbally or in a Teams thread * Naming and filing — arranging records and folders so you can actually find things later * Compliance mapping and the SoA without a tool And the growing pains that will probably push you towards a platform eventually: multiple editors, a second framework, and the volume of action tracking. **Disclosure:** I've built my own GRC SaaS, so I have a dog in this fight and I do see the value in a platform. But I'd argue against rushing to buy one straight away.

The Hacker News 7h ago

Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or

The Hacker News 8h ago

Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner. The company named the four programs ProManager, WinUpdate, SoftManager, and

r/cybersecurity 16h ago

I was browsing Reddit and saw an ad displaying `u/hbomax` as the author - this advertised a macOS HBO Max app which I'd not heard of and was interested in. The user is verified and appears to have posted many times in the official HBO Max subreddits. The advert takes you to `hbomaxx[.]us` which looks somewhat legitimate, and has a join button / download. Clicking these opens up the classic infostealer/clickfix paste this command to download. Having checked, this downloads an executable with other capabilities for account compromise (obviously all done in a full sandbox - inspecting the output only, not running anything). My guess is that the reddit account is compromised - I did consider some sort of character substitution in the username but clicking it took me to the profile - but I'm trying to think if there is any other explanation for this as I'd be very surprised for it to actually be a HBO Max issue. I've reported to Reddit / HBO but just interested in any viewpoints (My role is cybersecurity adjacent but not a technical specialist) Screenshots: [https://files.catbox.moe/q0ee7d.png](https://files.catbox.moe/q0ee7d.png) [https://files.catbox.moe/6nw1vc.png](https://files.catbox.moe/6nw1vc.png) [https://files.catbox.moe/v1ycvm.png](https://files.catbox.moe/v1ycvm.png)

Saturday, September 5
The Hacker News 20h ago

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is

The Hacker News Sep 5

Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code. "A

The Hacker News Sep 5

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

The Hacker News Sep 5

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as

Friday, September 4
The Hacker News Sep 4

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said. The

The Hacker News Sep 4

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host and

The Hacker News Sep 4

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including

The Hacker News Sep 4

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users

The Hacker News Sep 4

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote

The Hacker News Sep 4

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering,

Thursday, September 3
Cloudflare Sep 3

Your scanner just flagged 4,000 new vulnerabilities, 78 of them critical. Which one do you fix first? To answer that question, Cloudflare is announcing early access to Vulnerability Discovery and Remediation, now part of Cloudflare Managed Defense . Vulnerability Discovery and Remediation is a new, invitation-only Cloudflare service that helps customers detect and mitigate vulnerabilities in their codebases. Through the OpenAI Daybreak Defense Network , we use OpenAI Daybreak models, including GPT-5.6 Cyber, for reconnaissance, hunting, and validation against codebases that you authorize us to access. If we detect a vulnerability, we will then propose solutions to you, automatically checking each proposed patch and any accompanying proposed mitigation before presenting them for review. Importantly, you are in the driver’s seat: while we may propose code patches and other mitigations, you decide whether they are implemented. Choosing what to fix first has always been hard. It's getting harder. Large language models can now surface weaknesses across a codebase in minutes , which means the number of findings keeps climbing. But the real problem is speed. Attackers can use AI to accelerate parts of vulnerability discovery and exploitation, giving security teams and developers less time to decide what matters and act on it. Imagine that your scanner tells you there's a vulnerability in a handler. It doesn't tell you whether that code is deployed. It doesn't tell you whether anyone is actually hitting that route, what security activity surrounds it, or what controls you already have

The Hacker News Sep 3

The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, fake login pages, old account links, and software guides that point to unsafe downloads. One wrong letter in a web address can be enough. There is also

CERT/CC Sep 3
CVE

Overview Casdoor is an open-source Access Management (IAM) platform used to manage web applications. An authorization bypass vulnerability affects Casdoor versions 3.115.0 and earlier. The vulnerability allows a non-global organization administrator to perform unauthorized administrative actions against arbitrary organizations by exploiting inconsistent object resolution between the authorization layer and downstream controllers. In multi-tenant deployments, an attacker with administrative privileges within a single organization can bypass tenant isolation and perform administrative operations against other organizations. Description CVE-2026-15630. The vulnerability stems from a desynchronization between authorization and action in multiple POST /api/{add,delete}- endpoints (e.g., /api/add-user, /api/delete-user, /api/add-permission) . While the global authorization filter ( routers/authzfilter.go ) correctly uses the ?id= URL query parameter as the authoritative target for authorization decisions, the affected controllers ( controllers/user.go , controllers/permission.go , etc.) ignore ?id= and operate solely on the owner and name fields in the JSON request body. As a result, authorization is evaluated against one object while the requested operation is executed against another, allowing an authenticated organization administrator ( IsAdmin=true ) to perform unauthorized administrative actions across tenant boundaries. Impact An attacker with administrative privileges in a single organization can compromise the isolation guarantees of a multi-tenant Casdoor deployment. Depending on the exposed endpoints and de

The Hacker News Sep 3

Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. "Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial

Synack Sep 3

You know what you spent on penetration testing last year. But can you explain what that investment covered between engagements? For many organizations the honest answer is that it covered the weeks the testers were working against a scope agreed before they started. That was a reasonable arrangement when systems changed a few times a year. It is worth revisiting, now that many of them change weekly. The post Offensive Security Is Becoming a Program, Not a Purchase appeared first on Synack .

Heimdal Security Sep 3
APT

Heimdal’s SOC flagged a surge in detections tied to a program called Shift Browser on 2 September 2026. Our team confirmed activity on more than 50 client environments in a single day. The installers we captured trace to a malvertising lure. Shift Browser also runs a documented paid creator and affiliate marketing operation, though we […] The post Shift Browser is signed adware that fingerprints your endpoint before it drops payload appeared first on Heimdal Security Blog .

The Hacker News Sep 3

An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries. Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses

WIRED Sep 3

WIRED rebuilt Flock’s latest search tool from code the company sends to a police officer’s browser. Its AI can keep watch across multiple cameras for anyone fitting a written description.

Compass Security Sep 3

While the full implementation of the Cyber Resilience Act (CRA) won’t take effect until December 2027, another critical milestone is already approaching much sooner. Starting from 11 September 2026 , all manufacturers selling products with digital elements in countries of the European Union will be required to report actively exploited vulnerabilities in their digital products, as well as related security incidents, as well as security incidents that affect or compromise products already placed on the market. Incidents or vulnerabilities limited to development or internal environments are therefore only relevant if they result in (or could result in) a compromise of production devices. Although the platform itself is not yet available, the landmark legislation has already established a detailed framework and set of requirements. This article aims to summarize the most important aspects of the reporting process in order to help you prepare for these upcoming changes. Additionally, it provides clear guidelines for determining when a vulnerability or incident becomes mandatory to report. Overview In Chapter I, Article 14, §1, the Cyber Resilience Act states the following: A manufacturer shall notify any actively exploited vulnerability contained in the product with digital elements that it becomes aware of simultaneously to the CSIRT designated as coordinator, in accordance with paragraph 7 of this Article, and to ENISA. In the context of the CRA, an “ actively exploited vulnerability ” is defined as a “vulnerability for whic

Wednesday, September 2
Synack Sep 2
CVE

Expert judgment is the scarcest resource in offensive security. Making it accessible to more of the world, continuously, is an engineering problem. The post Putting Experts on the Problems Only Experts Can Solve appeared first on Synack .

Synack Sep 2

Why we merged NetSPI and Synack to bet against the loudest idea in security. The post Autonomy Was Never the Goal appeared first on Synack .

r/computerforensics Sep 2
CVE

A new 13Cubed episode is out! 🍎 Windows forensics on a Mac usually means firing up a VM first. Not anymore. IRFlow Timeline is a free, open-source DF/IR timeline tool built natively for macOS. Feed it EVTX, Plaso, $MFT, or $J and go straight to process inspection, lateral movement, persistence, and VirusTotal enrichment. Featuring the tool's author, Renzon Cruz 👇 [https://www.youtube.com/watch?v=W9xHbNgZuT0](https://www.youtube.com/watch?v=W9xHbNgZuT0)

Tuesday, September 1
Krebs on Security Sep 1

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images. A record available at this identity theft service that includes the drivers license for U.S. Defense Secretary Pete Hegseth, one of several high-ranking U.S. government officials whose drivers licenses can be found for sale. On Monday, Aug. 31, a source alerted KrebsOnSecurity to a service advertised by a new user on the Russian cybercrime forum Exploit , offering access to digital scans of identity documents on more than 170 million people in North America. The source brought it to my attention because the proprietor of this identity theft service offered my Virginia drivers license as a free sample in their initial sales thread on Exploit. The service, dubbed Nexus , claims to have more than 153 million dri

r/Malware Sep 1

This new fork includes strong ransomware detection with low fp rate. You can write a rule to detect any type of malware with this fork. Note: I don't recommend you install this on main machine because it requires to disable secure boot. Topic: [https://forum.xcitium.com/t/i-forked-comodo-openedr-to-improve-zero-day-ransomware-detection-via-behavior-detection/21302/1](https://forum.xcitium.com/t/i-forked-comodo-openedr-to-improve-zero-day-ransomware-detection-via-behavior-detection/21302/1) Video: Look repo Repo (Only install on VM): [http://github.com/hydraDragonAntivirus/HydraDragonAntivirus/](http://github.com/hydraDragonAntivirus/HydraDragonAntivirus/)

Cloudflare Sep 1

Memory costs are increasing dramatically. Both RAM and hard disk drive prices have exploded over the past year. At Cloudflare, we run several massively distributed storage products (including our famous CDN) that rely on making efficient use of the memory we have deployed so we can continue to serve all of our customers. With this in mind, we prototyped a way to expand effective cache capacity. By encoding eligible assets with Zstandard inside Pingora , the architecture trades a minor CPU increase for significant storage and cross-data center bandwidth savings. We have been prototyping a system called Cache Transcoding, which I built during my internship at Cloudflare as part of the 1.1.1.1 Intern Program . When an eligible response enters the cache, we encode it using Zstandard, or zstd, before writing it to disk. We keep that compressed form while the asset lives in the cache and moves between data centers via Tiered Cache , then decode it before serving the response to the client. In our initial testing, this encoding shrunk eligible assets to ⅓ of their original on-disk size on average. The estimated extra CPU cost in our origin-facing proxy was small, but that is the trade. A small increase in CPU gives Cloudflare petabytes of effective cache capacity and reduces the data transferred between our data centers. The encoding cost is paid once when an asset enters the cache. The storage and bandwidth savings continue every single time that asset is

Synack Sep 1

SOC 2 does not prescribe a universal penetration testing requirement for every organization. A pentest is still commonly used as evidence supporting security, risk assessment, and monitoring controls, and auditor expectations depend on the organization's risks, system boundary, and testing policies. Type II examinations require evidence that controls operated over a defined period, not merely that they existed on one date. A vulnerability scan should not be presented as equivalent to a penetration test, and findings, remediation, and retesting evidence matter as much as the original report. The post Penetration Testing for SOC 2 Compliance: What Auditors Expect appeared first on Synack .

Monday, August 31
Cloudflare Aug 31
APT

Modern bot threats are increasingly driven by determined, sophisticated attackers. Often it is not even one person, but a group trading techniques with each other or a commercial service sold to anyone willing to pay. For many of them, getting past bot detection is a full-time job they genuinely enjoy. Block them and they get to work, finding a workaround. AI has simplified this further, making it even easier to set up complex configurations for attackers, lowering the overhead of an attack. This shift puts defenders at an economic disadvantage. Responding and adapting to new attacks takes care, evidence, and effort to ensure efforts to block attackers don’t impact real users on the way. Attackers have no such concerns and are primarily constrained by their time and their pool of proxies, and ensuring their infrastructure providers don’t shut down their accounts. Their advantage is the cost of adaptation. Attackers can adapt as often and continuously as they need, while most defenses are deployed in discrete, managed releases. Cloudflare analyzes more than a trillion requests a day for signs of automated abuse, so we see how fast attackers change tactics. That gap in responsiveness is widening. The inconvenient truth: bot detection across the industry often rests on a hopeful assumption that if you make the wall tall enough, attackers stay out. In reality, a determined attack always finds a way through. The question is not whether a determined attacker can get through. They will. The question is what happens when they do. Today we are launching Adaptive Intelligence, a new bot detection engine that starts from the opposite idea. Rather than betting on a wall that keeps every attacker out, Adaptive Intelligence makes getting through so slow and costly that the attack stops being worth running. We believe that no other bot detection works this way. One attacker, many disguises Not every attack is obvious

GreyNoise Aug 31

Today we’re announcing an expanded integration between GreyNoise and the CrowdStrike Falcon® platform, with new content for CrowdStrike Falcon® Next-Gen SIEM and CrowdStrike Charlotte Agentic SOAR. The expanded integration includes a purpose-built Falcon Next-Gen SIEM dashboard, correlation rules that detect allowed inbound traffic from malicious infrastructure, and SOAR playbooks that bring GreyNoise threat context into automated response workflows.

Story Overview