Latest Cybersecurity News and Articles
11 September 2026
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.
The post Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack appeared first on SecurityWeek.
11 September 2026
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise.
A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker
11 September 2026
Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.
The post Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison appeared first on SecurityWeek.
11 September 2026
Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.
The post Check Point Patches Critical VPN Vulnerabilities appeared first on SecurityWeek.
11 September 2026
Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars.
The post Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance appeared first on SecurityWeek.
11 September 2026
A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.
The post Surfshark Systems Targeted by Hackers appeared first on SecurityWeek.
11 September 2026
Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model.
The post Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion appeared first on SecurityWeek.
11 September 2026
A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.
The post PaperCut Flaws Exploited in AI-Powered Attacks appeared first on SecurityWeek.
11 September 2026
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report.
Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.
11 September 2026
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday.
The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns
11 September 2026
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.
The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.
"These are Regular Maintenance Releases (MR) that
11 September 2026
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.
The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass
10 September 2026
Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board.
The post Mandiant Founder Kevin Mandia Joins Amazon Board appeared first on SecurityWeek.
10 September 2026
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”
An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already
10 September 2026
Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.
The post Cybersecurity M&A Roundup: 33 Deals Announced in August 2026 appeared first on SecurityWeek.
10 September 2026
Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns.
The post Anthropic Researcher Resigns With Warning About the Dangers of AI Development appeared first on SecurityWeek.
10 September 2026
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content.
Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their
10 September 2026
Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox.
The post Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster appeared first on SecurityWeek.
10 September 2026
Deceptive apps in Early Access are being used by dishonest developers for their own benefit.
The post Deceptive Android Apps Exploit Google Play Early Access to Evade Reviews appeared first on SecurityWeek.
10 September 2026
Join the webinar for a focused, 20-minute discussion on Frontier Pace Governance, an approach to balancing automation, policy, and business risk as IT operations accelerate.
The post Webinar Today: Keep Pace With AI – A New Operating Model for Endpoint Remediation appeared first on SecurityWeek.