Security news
Latest security news
Yesterday · Tue, 15 Sept 2026
- Who's governing your AI? A trust framework for enterprise agents and models
SPONSORED FEATURE: DigiCert wants to hand every agent a passport, complete with an expiry date and a named human owner
The Register - Companies’ AI strategies don’t account for agentic tools
Businesses are taking AI governance seriously, but their plans lag behind the technology they’re using, according to an EY survey.
Cybersecurity Dive - AI the Top Priority for New Spend as Cyber Budgets Flatline
IANS finds AI is dominating net-new budgets even as overall funding for the function is flat
Infosecurity Magazine - Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise. But no matter how much you validate against these
The Hacker News - Meta AI builds detailed profiles of children from years of family posts
A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.
Malwarebytes Labs - Supreme Court denies Trump request to allow USPS mail ballot changes
One justice said the attempt to change the rules ahead of the 2026 elections would be "arbitrary and capricious” and violated the Administrative Procedures Act.
CyberScoop
Mon, 14 Sept 2026
- Twitch extension with 30K installs exposes users’ OAuth tokens
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service.
BleepingComputerChrome, Firefox - New hardware device can RAM into encrypted memory, expose your data
Attackers would need physical access to the server to pull off the DDR5 trick
The Register - New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit
The Hacker NewsIntel, AMD - WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin
The Hacker NewsWordPress
About this news
- 1,256
- Stories
- 40
- Added in the last 24 hours
- 19
- Critical in the last 7 days
- 4
- Reported by several outlets