access ai android api apple attack authentication backdoor breach business ceo china cisa cisco ciso cloud compliance control credentials crypto cve cyber cyberattack cybercrime cybersecurity data data-breach defense detection email endpoint exploit finance flaw framework fraud google governance government group hacker hacking healthcare identity infrastructure intelligence Internet jobs law leak linux malicious malware microsoft monitoring network open-source password phishing privacy ransomware remote-code-execution resilience risk russia scam service software strategy supply-chain technology theft threat tool unclassified update usa vulnerability windows zero-day
-
(g+) Künstliche Intelligenz: So nützlich sind Chatbots in der Medizin
KI-Chatbots sind längst Alltag, auch in Arztpraxen und Krankenhäusern. Wozu sie eingesetzt werden, wie zuverlässig sie sind – und welche Risiken es gibt. First seen on golem.de Jump to article: www.golem.de/news/kuenstliche-intelligenz-so-nuetzlich-sind-chatbots-in-der-medizin-2609-212662.html also interesting: From reactive to proactive: Redefining incident response with unified, cloud-native XDR China-linked hackers target Japan’s national security and high-tech industries The cybersecurity…
-
(g+) Künstliche Intelligenz: So nützlich sind Chatbots in der Medizin
KI-Chatbots sind längst Alltag, auch in Arztpraxen und Krankenhäusern. Wozu sie eingesetzt werden, wie zuverlässig sie sind – und welche Risiken es gibt. First seen on golem.de Jump to article: www.golem.de/news/kuenstliche-intelligenz-so-nuetzlich-sind-chatbots-in-der-medizin-2609-212662.html also interesting: From reactive to proactive: Redefining incident response with unified, cloud-native XDR China-linked hackers target Japan’s national security and high-tech industries The cybersecurity…
-
(g+) Künstliche Intelligenz: So nützlich sind Chatbots in der Medizin
KI-Chatbots sind längst Alltag, auch in Arztpraxen und Krankenhäusern. Wozu sie eingesetzt werden, wie zuverlässig sie sind – und welche Risiken es gibt. First seen on golem.de Jump to article: www.golem.de/news/kuenstliche-intelligenz-so-nuetzlich-sind-chatbots-in-der-medizin-2609-212662.html also interesting: From reactive to proactive: Redefining incident response with unified, cloud-native XDR China-linked hackers target Japan’s national security and high-tech industries The cybersecurity…
-
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as CVE-2026-6471, the flaw reportedly affected PostgreSQL releases from version 9.4 onward, leaving a dangerous plugin-loading path exposed for roughly 12 years. Cyera Research disclosed the issue on…
-
12-Year-Old PostgreSQL Flaw Lets Attackers Execute Code and Take Over Database Servers
A critical PostgreSQL vulnerability dubbed PostGREShell could allow low-privileged replication accounts to execute attacker-controlled code, escalate to database superuser, and establish persistent backdoors on affected servers. Tracked as CVE-2026-6471, the flaw reportedly affected PostgreSQL releases from version 9.4 onward, leaving a dangerous plugin-loading path exposed for roughly 12 years. Cyera Research disclosed the issue on…
-
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe.The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 an authentication bypass and remote code execution chain to conduct command execution and reconnaissance, as well as First…
-
New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data theft with file encryption. Documented by CyberXtron, its dedicated leak site was first observed active on August 5, 2026, and its early victim list includes organizations in technology, manufacturing, government, agriculture, energy, education, and retail.…
-
New Panzer Ransomware Hits 16 Victims Across 11 Countries With Data Theft and Encryption
Panzer ransomware has emerged as a new Ransomware-as-a-Service (RaaS) operation, publishing 16 alleged victims across 11 countries while combining data theft with file encryption. Documented by CyberXtron, its dedicated leak site was first observed active on August 5, 2026, and its early victim list includes organizations in technology, manufacturing, government, agriculture, energy, education, and retail.…
-
The New AI Inference Stack: From Faster Kernels to Inference Economics
Over the past few years, the biggest question in AI infrastructure has been how to train larger models. But by 20252026, the center of gravity has clearly started shifting toward inference. Micron expects inference to account for roughly two-thirds of… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/the-new-ai-inference-stack-from-faster-kernels-to-inference-economics/ also interesting: Russia plotting to use AI…
-
CARS24 Data Breach Exposes 3,100 Customer Records, Leads Allegedly Sold for ₹1,000 Each
Used-car platform CARS24 has alleged that confidential information belonging to approximately 3,100 customers was stolen and supplied to a rival business and outside dealers. The company claims that leads were offered for about ₹1,000 each, resulting in an estimated commercial loss of ₹5.70 crore. The complaint was filed at a Cyber Crime Police Station by…
-
Hackers Use Frontier AI Agents to Breach Enterprise Network in Under 10 Hours
Tags: ai, attack, automation, breach, cloud, credentials, cyber, framework, hacker, infrastructure, intelligence, network, threatA threat actor used frontier artificial-intelligence models and attack-specific agentic frameworks to breach an enterprise environment, harvest root credentials, and hijack cloud AI infrastructure in less than 10 hours. The investigation, documented by Palo Alto Networks Unit 42, highlights a significant shift in intrusion operations. AI-assisted automation compressed an attack that could otherwise demand several…
-
Broadcom Patches Critical VMware Workstation and Fusion VM-Escape Vulnerabilities
Broadcom patched two VMware Workstation/Fusion VM-escape bugs. No workarounds exist. Update to version 26H1u1 immediately. Broadcom published advisory VMSA-2026-0007, patching two vulnerabilities in VMware Workstation and Fusion that allow an attacker inside a virtual machine to execute code on the underlying host. One is rated Critical. Neither has a workaround. The first vulnerability, tracked as…
-
Cyber Talk 13 Qualys: What Security Leaders Can Learn From Its Evolution From Vulnerability Scanning to Risk Operations
The real question is not whether Qualys is old, but whether its most successful playbook still fits the next era of securityAt Black Hat 2026, Qualys CEO Sumedh Thakar made a very practical point: if organizations could simply fix every… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/cyber-talk-13-qualys-what-security-leaders-can-learn-from-its-evolution-from-vulnerability-scanning-to-risk-operations/ also interesting: Not all cuts are equal:…
-
Why Vulnerability Management Must Move Beyond CVSS
Learn why vulnerability management must move beyond CVSS to prioritize real risk using exploitability, asset context, attack paths, and AI-driven analysis. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-why-vulnerability-management-moves-past-cvss/ also interesting: How Top CISOs Approach Exposure Management in the Context of Managing Cyber Risk How to Take Vulnerability Management to the Next Level and Supercharge…
-
Microsoft Finds ASCII Smuggling Repurposed for Phishing Campaign
Attackers have adapted a technique popularized in AI prompt injection research for a high-volume phishing campaign, using invisible Unicode characters to evade email filtering, Microsoft researchers reported Thursday. The finding came from Microsoft Defender for Office 365 prompt injection protection research. A hunting signature built to detect ASCII smuggling in email recorded a surge beginning..…
-
Cyber Resilience Starts With a Unified Recovery Strategy
Learn why cyber resilience requires a unified recovery strategy that restores data, configurations, identities, cloud systems, and critical dependencies. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-cyber-resilience-strategy/ also interesting: Cybersecurity Snapshot: CSA Outlines Data Security Challenges and Best Practices, While ISACA Offers Tips To Retain IT Pros Improve Your Cyber Resilience with Data Security Platformization…
-
How Recent Cyber Earnings Show Growth Alone No Longer Pays
Faster Hiring Coincided With Weaker Stock Performance Across Most Security Vendors Seven of eight major cyber and technology vendors posted at least 25% annual year-over-year sales growth, but five stocks fell after earnings as investors favored profitability while CEOs outlined how AI agents will reshape security, identity and enterprise infrastructure. First seen on govinfosecurity.com Jump…
-
OpenAI’s German Wiki Hack Is Less About “Rogue AI” Than Failed Agent Containment
OpenAI’s latest foul-up was not a Hollywood-style AI “escape.” Instead, researchers say a swarm of OpenAI agents apparently found a way to turn web read access into write access on DseWiki, a collaboratively editable German programming wiki. The takeover of a German programming wiki, DseWiki, by agents linked to OpenAI is not evidence that AI..…
-
Insurers Search for Answers to Rein in Rogue AI
As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout. First seen on darkreading.com Jump to article: www.darkreading.com/cyber-risk/insurers-search-answers-rogue-ai also interesting: Top challenges holding back CISOs’ agendas 10 things you should include in your AI policy CISO vs CFO: why are the conversations…
-
Why ‘Digital Asbestos’ Is Driving Up Risk Debt
Financial Services Risk Advisor Alex Golbin on Spotting Hidden Risk Debt. Alex Golbin, a senior financial services technology and data risk executive, said risk programs can look modern while resting on legacy workarounds underneath. He said accountability for that hidden risk debt, or digital asbestos, often falls on no one in the enterprise. First seen…
-
Europe Tiptoes to Legalizing Bulk Collection of ISP Metadata
CJEU Advocate-General Maciej Szpunar Says Oversight Could Mitigate Rights Harms. The most senior adviser at Europe’s highest court recommended striking down a Belgian data retention law largely intended to fight cybercrime, because it violates privacy rights. Advocate-general Maciej Szpunar also said it may be time for the EU to move past its old conception of…
-
AI Labs Pause Frontier Model Work, But to What Effect?
OpenAI and Anthropic Tighten Guardrails as Experts Question Whether Brief Pauses Are Enough. There’s been a renewed focus on the safety and security processes of frontier AI labs after mainstays spotted their agents escaping sandboxes to hack into real-life targets. The result of these pauses is not vetted by an independent party, so it is…
-
OpenAI agents discussed ways to escape their sandbox on public wiki
Tags: openaiIn all, 3,700 internal agents posted 18,000 messages discussing cheating on a test. First seen on arstechnica.com Jump to article: arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/ also interesting: SweetSpecter hatte OpenAI im Visier OpenAI says there are 5 ‘levels’ for AI to reach human intelligence, it’s already almost at level 2 OpenAI, Anthropic to give model access to NIST’s AI…
-
European parliament members call for slowdown of Serbia’s EU entry over spyware use
Tags: spywareThe letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. First seen on cyberscoop.com Jump to article: cyberscoop.com/eu-parliament-serbia-accession-spyware-demands/ also interesting: Apple warns of mercenary spyware attacks on iPhone users in 92 countries NSO-Group für WhatsApp-Angriff mit Pegasus-Spyware schuldig gesprochen NSO Group owes $168M in…
-
CVE-2026-19949 Leaves Millions of WordPress Sites Running Vulnerable Plugin Versions
A high-severity flaw in All-in-One WP Migration leaves 3.25 million WordPress sites exposed, with vulnerable versions potentially leading to site compromise. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-all-in-one-wp-migration-cve-2026-19949/ also interesting: 200,000 WordPress Sites Exposed to Cyber Attack, Following Plugin Vulnerability Over 100,000 WordPress Sites Exposed to Privilege Escalation via MCP AI Engine 70,000 WordPress…
-
Dropbox Says Lenovo ID Flaw Compromised 5,000 Accounts
Tags: flawA Lenovo ID verification flaw let attackers compromise 5,000 Dropbox accounts without passwords. Learn what happened and how users can stay protected. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-dropbox-lenovo-id-flaw-5000-accounts/ also interesting: Palo Alto Networks Patches Authentication Bypass Exploit in PAN-OS Software Hackers Exploit Craft CMS Vulnerability to Inject Cryptocurrency Miner Malware Critical Vulnerability in…
-
Google’s Chrome Update Patches Sixth Zero-Day Exploited in 2026
Google patched CVE-2026-85046, the sixth Chrome zero-day exploited in the wild in 2026. Here’s how to update your browser and stay protected. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-google-chrome-cve-2026-85046-zero-day/ also interesting: Google Releases Eighth Zero-Day Patch of 2023 for Chrome Google Patches Chrome Zero-Day: Type Confusion in V8 JavaScript Google Patches Critical Zero-Day Flaw…
-
Why Security Teams are Becoming Builders of Agentic AI, not just Buyers
Security teams are building custom AI agents to improve defense, close tooling gaps, and automate workflows, but strong governance remains critical. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-agentic-ai-buyers-and-builders/ also interesting: Security for AI: How Shadow AI, Platform Risks, and Data Leakage Leave Your Organization Exposed CTO New Year’s Resolutions for a More Secure 2026…
-
Attack Surface Reduction Is the Only Scalable Defense Strategy Left
Learn how attack surface reduction helps organizations eliminate unnecessary exposure, reduce security noise, and strengthen defenses through automation. First seen on esecurityplanet.com Jump to article: www.esecurityplanet.com/threats/news-attack-surface-reduction-scalable-defense/ also interesting: Reimagining Incident Response: Unleashing Proactive Defense with Nuspire’s Cybersecurity Experience Building an Effective DDoS Mitigation Strategy That Works 6 strategies for building a high-performance cybersecurity team Bolster…
-
Hospitals Lag in Race to Quantum-Safe Encryption
Security Leaders Say Legacy Devices and Vendor Dependence Are in the Way. Hospital security leaders say aging medical devices, incomplete asset inventories and dependence on third-party vendors could make healthcare’s transition to post-quantum cryptography slower and more difficult than in other critical sectors. First seen on govinfosecurity.com Jump to article: www.govinfosecurity.com/hospitals-lag-in-race-to-quantum-safe-encryption-a-32752 also interesting: 8 Cyber…
-
Digital twins bill to be debated in Parliament
Tags: unclassifiedA Ten-Minute Rule Bill curbing the creation of digital twins of individual people is to be debated in Parliament. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650120/Digital-twins-bill-to-be-debated-in-Parliament also interesting: Forrester: Webentwickler vernachlässigen Sicherheit Lascher Umgang mit Datenträgern: Erhebliche Sicherheitslücken beim FBI aufgedeckt Massive Störung: E-Rezepte waren zeitweise nicht einlösbar Will Smaller Companies Buckle Under the…
-
Digital twins bill to be debated in Parliament
Tags: unclassifiedA Ten-Minute Rule Bill curbing the creation of digital twins of individual people is to be debated in Parliament. First seen on computerweekly.com Jump to article: www.computerweekly.com/news/366650120/Digital-twins-bill-to-be-debated-in-Parliament also interesting: How Dark Patterns Trick Users into Unintended Actions? Asus VivoTab RT: Das Tablet, das ein Notebook ist… Check Point sieht Konsolidierung als Erfolgsschlüssel für robuste Cyberabwehr…
-
White House Acts to Shut Out China From US Bulk Power Market
Trump Executive Order Declares National Emergency, Citing Potential Backdoors. A broad Trump administration plan to shut adversary nations, including China, out of the equipment supply chain for the U.S. bulk electric power market has left the industry in regulatory uncertainty, just as demand for electricity is spiking nationwide due the ballooning power demands of data…
-
White House Acts to Shut Out China From US Bulk Power Market
Trump Executive Order Declares National Emergency, Citing Potential Backdoors. A broad Trump administration plan to shut adversary nations, including China, out of the equipment supply chain for the U.S. bulk electric power market has left the industry in regulatory uncertainty, just as demand for electricity is spiking nationwide due the ballooning power demands of data…
-
White House Acts to Shut Out China From US Bulk Power Market
Trump Executive Order Declares National Emergency, Citing Potential Backdoors. A broad Trump administration plan to shut adversary nations, including China, out of the equipment supply chain for the U.S. bulk electric power market has left the industry in regulatory uncertainty, just as demand for electricity is spiking nationwide due the ballooning power demands of data…
-
Crooks Behind Manchester Airports Group Hack Leaked Data of 8.8 Million People
Manchester Airports Group (MAG) data allegedly leaked by FulcrumSec exposes emails and phone numbers of 8.8 million people. Manchester Airports Group, which operates Manchester, London Stansted and East Midlands airports, has confirmed a data breach involving customer information held in a third-party database. The company says airport operations, passenger safety and aviation security were not…
-
US offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructure
Amir Yaryab is the leader of the IRGC’s cyber unit and oversees hacker groups such as the CyberAv3ngers, the State Department said in posting a reward for information about him. First seen on therecord.media Jump to article: therecord.media/us-reward-amir-yaryab-iran-irgc-cyberattacks also interesting: Iranian cyber threats overhyped, but CISOs can’t afford to let down their guard Iranian APT…
-
Security Operations To See A ‘Renaissance’ In Next 24 Months: Cyderes CEO
Security operations is poised to see an “absolute renaissance” over the next two years, with AI and agentic capabilities eliminating much of the repetitive work facing security analysts”, while also potentially leading to a surge in threat actor activity that must be protected against, Cyderes CEO Chris Schueler tells CRN. First seen on crn.com Jump…
-
How Keeper Helps Enforce Zero Standing Privilege
Privileged accounts are standing invitations for attackers, with credentials to steal and permissions to misuse. When administrative rights are persistently active, whether or not they’re being used, privileged accounts significantly expand the attack surface. Zero Standing Privilege (ZSP) shrinks that… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/how-keeper-helps-enforce-zero-standing-privilege/ also interesting: 7 biggest cybersecurity stories of…
-
Why Hiring More Analysts Won’t Solve an Infinite Automation Attack
Conventional wisdom states that if the alert queue is too long, you just need to hire more Tier-1 analysts to clear the backlog. It’s a comforting thought, suggesting that with a slightly larger budget and a few more resumes, an… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/why-hiring-more-analysts-wont-solve-an-infinite-automation-attack/ also interesting: How to Chart an Exposure…
-
Dissecting Attacks Is Only Valuable If It Informs Controls: What the Unit 42 agentic AI investigation should change in your control set, stage by stage.
The volume of published incident research involving agentic AI is increasing, and the analysis that follows each report tends to concentrate on the same attribute: speed. The recent investigation from Unit 42, the threat intelligence and incident response group at… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/dissecting-attacks-is-only-valuable-if-it-informs-controls-what-the-unit-42-agentic-ai-investigation-should-change-in-your-control-set-stage-by-stage/ also interesting: Threat-informed defense for operational technology:…
-
The Braid: Rethinking Trust, Continuity and Human-AI Systems
What one AI-generated image taught me about trust, continuity, and why I am building QuietWire. There is a problem with AI logos. A good friend in the cybersecurity industry pointed it out to me last year, and once he did I could not unsee it. Since then I have watched the observation turn into something..…
-
How Differential Privacy Will Transform Enterprise Data Strategy
For sixteen years I’ve watched enterprise data privacy evolve through three eras: access controls and encryption at rest, then de-identification, and now a third era defined by a mathematical framework most executives have heard of but few truly understand: differential privacy. The shift matters because the previous eras have quietly failed. De-identified datasets have been..…
-
How Differential Privacy Will Transform Enterprise Data Strategy
For sixteen years I’ve watched enterprise data privacy evolve through three eras: access controls and encryption at rest, then de-identification, and now a third era defined by a mathematical framework most executives have heard of but few truly understand: differential privacy. The shift matters because the previous eras have quietly failed. De-identified datasets have been..…
-
153 Million Reasons to Rethink Identity Data Retention
An ID verification company is suspected of being responsible for a data breach involving 153 million identity cards that were put up for sale to criminals! The cache includes drivers licenses, travel documents, medical cards, and other government issued IDs… First seen on securityboulevard.com Jump to article: securityboulevard.com/2026/09/153-million-reasons-to-rethink-identity-data-retention/ also interesting: Rhode Island suffers major cyberattack,…
-
What the AI Warning Letter Completely Missed
Tags: aiThe recent AI warning letter is right about the window, but it omits naming who is coming through it or, critically, who will close it. First seen on darkreading.com Jump to article: www.darkreading.com/cyberattacks-data-breaches/ai-warning-letter-missed-people also interesting: Amazon, Google, Microsoft, Other Tech Firms, Form Consortium for Improved AI Cybersecurity From Deepfakes to Malware: AI’s Expanding Role in…
-
Companies Have 6 Months to Prepare for Automated Attacks
Frontier AI models have already demonstrated they can autonomously, and in some cases, inadvertently, conduct end-to-end compromises, but the situation will become more urgent very soon. First seen on darkreading.com Jump to article: www.darkreading.com/cybersecurity-operations/companies-six-months-prepare-automated-attacks also interesting: Snowflake Clients Targeted With Credential Attacks Meet ShadowLeak: ‘Impossible to detect’ data theft using AI CometJacking: One Click Can…
-
AI is finding vulnerabilities faster. Who is funding the people expected to fix them?
Artificial intelligence is changing vulnerability discovery. At OpenSSL, we are seeing that change first-hand. A year ago, our security address received around nine separate reports and enquiries a month. It now receives around 70. AI tools can examine source code and identify potential security issues at a scale that would previously have required significant human…
-
AI is finding vulnerabilities faster. Who is funding the people expected to fix them?
Artificial intelligence is changing vulnerability discovery. At OpenSSL, we are seeing that change first-hand. A year ago, our security address received around nine separate reports and enquiries a month. It now receives around 70. AI tools can examine source code and identify potential security issues at a scale that would previously have required significant human…
-
AI is finding vulnerabilities faster. Who is funding the people expected to fix them?
Artificial intelligence is changing vulnerability discovery. At OpenSSL, we are seeing that change first-hand. A year ago, our security address received around nine separate reports and enquiries a month. It now receives around 70. AI tools can examine source code and identify potential security issues at a scale that would previously have required significant human…

