Security news

Latest security news

70 of 1,256 storiesTopic: Nation StateClear all

Thu, 10 Sept 2026

  1. New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

    Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.

    BleepingComputerGoogle, Microsoft, Windows
  2. Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

    State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. Two FMC vulnerabilities under active attack “Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software,” the company’s researchers confirmed on Wednesday. These are the above mentioned CVE-2026-20079 and CVE-2026-20316, which Cisco flagged … More →

    CriticalUsed in attacksHelp Net SecurityCisco
  3. 4.1 Million Impacted by AdaptHealth Data Breach

    In June 2026, hackers stole personal, health, and insurance information from AdaptHealth’s systems.

    SecurityWeek
  4. Apple is building photo verification for the people who need it most

    Apple has introduced Apple Reference Image, an opt-in feature designed to verify the authenticity of photos taken with iPhone 18 Pro models. Apple Reference Image provides users with an unalterable reference photo, visually confirming what the sensor saw at the moment of capture. (Source: Apple) Apple said the technology would be particularly important for photojournalists and photographers, as well as everyday viewers. The company will also add support for the SynthID standard in a software … More →

    Help Net SecurityApple

Wed, 9 Sept 2026

  1. AdaptHealth confirms 4.1 million people exposed in July cyberattack

    Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group.

    BleepingComputer
  2. Chinese espionage groups swarm to exploit triple-link chain of zero-days

    Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen.

    CyberScoop
  3. Cisco security advisory (AV26-197) – Update 3

    Serial number: AV26-197 Date: March 5, 2026 Updated: September 9, 2026 On March 4, 2026, Cisco published security advisories to address vulnerabilities in the following products. Included were critical updates for the following: Cisco Security Cloud Control (SCC) Firewall Management – all versions Cisco Secure Firewall Management Center (FMC) – all versions Cisco Secure Firewall Adaptive Security Appliance (ASA) – versions prior to 9.20.4.14 Cisco Secure Firewall Threat Defense (FTD) – all versions Update 1 On March 18, 2026, Cisco stated that CVE-2026-20131 is being actively exploited. Update 2 On March 19, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20131 to their Known Exploited Vulnerabilities (KEV) Database. Update 3 On September 9, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-20079 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested recommendations, and apply the necessary updates when available. Cisco Secure Firewall Management Center Software Authentication Bypass Vulnerability Cisco Secure Firewal

    CriticalUsed in attacksCanadian Centre for Cyber SecurityCisco
  4. AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

    Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG.

    SecurityWeekGoogle
  5. Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

    Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,

    The Hacker NewsGoogle, Microsoft, Windows

Mon, 7 Sept 2026

  1. North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters

    Sekoia and Kudelski Security have observed that North Korea's Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion

    Infosecurity Magazine

About this news

1,256
Stories
39
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets