Latest Cybersecurity News and Articles
17 September 2026
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15.
The escape runs with the rights of the host account that runs the virtual machine. The flaw, CVE-2026-77179, is rated Critical, affects versions
17 September 2026
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.
The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek.
17 September 2026
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE.
"HEAVYGRAM offers builtin commands supporting remote command execution, system, network and process information discovery, data and Telegram session files exfiltration, screenshot capture, DLL sideloading,
17 September 2026
Revolut allegedly fed customer information to hackers impersonating an Italian government agency for five months.
The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek.
17 September 2026
The company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure.
The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek.
17 September 2026
Attackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process.
The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek.
17 September 2026
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.
An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with
17 September 2026
Research shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns.
The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek.
17 September 2026
The vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution.
The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek.
17 September 2026
A new CVE drops. Your scanner finds it. The severity score looks ugly.
But that still does not answer the question that matters: Can it actually be exploited in your environment?
Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is
17 September 2026
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production.
TL;DR
Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR
17 September 2026
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025.
"SparroWocky is a modular, C++ backdoor," ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News
17 September 2026
OpenAI on Wednesday disclosed six new instances of "unexpected or concerning model behavior" that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency.
"As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the
17 September 2026
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH).
A sender with no credentials can crash the server process, named, with a single request that carries an invalid SIG
17 September 2026
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.
The post CISA Releases Guidance on Deploying Cyber Decoys appeared first on SecurityWeek.
17 September 2026
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks.
The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.
17 September 2026
A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday.
It also exposed about 490 million image metadata records, mostly for images from January 2019 or earlier, including the IDs that make up Gyazo image links.
Helpfeel said
17 September 2026

Model adopting ‘jailbreak-like instructions’ among cases as firm says it is introducing new way of tracking AI misalignmentOpenAI has disclosed six more examples of “unexpected or concerning” behaviour by its technology, as it warned the pace of development could not continue at “maximum speed for much longer”.In one of the new cases reported by OpenAI, an unreleased research model inserted “jailbreak-like instructions” into its own notes to disregard its normal constraints and told itself to be “freed from the roles and identities that bind other chatbots”. Continue reading...
17 September 2026
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.
The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.
"This vulnerability is due to insufficient authentication control on an API endpoint," Cisco said. "An attacker
17 September 2026
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests.
The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.