Security news

Latest security news

Mon, 14 Sept 2026

  1. 14th September – Threat Intelligence Report

    For the latest discoveries in cyber research for the week of 14th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES IDScan.net, a US identity verification provider, has disclosed a data breach after detecting unauthorized access on September 1. Exposed data included names and government identification numbers, while a criminal marketplace advertised a

    Check Point Research
  2. Hackers Exploit Maximum Severity Flaw in GitLab

    CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0

    Infosecurity MagazineGitLab
  3. Telus Warns Customers of Account Breaches

    Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.

    SecurityWeek
  4. Revolut discloses data breach exposing financial info, passports

    Fintech company Revolut has disclosed a data breach after sharing data from an undisclosed number of customers with a threat actor impersonating a government agency.

    BleepingComputer
  5. ISC Stormcast For Monday, September 14th, 2026 https://isc.sans.edu/podcastdetail/10092, (Mon, Sep 14th)

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

    SANS Internet Storm Center

Sun, 13 Sept 2026

  1. Hackers exploit Tencent app flaw to deploy GrayRabbit malware

    Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.

    BleepingComputerWindows
  2. Attackers Use Passkey Phishing to Hijack Microsoft Cloud Accounts and Exfiltrate Data

    Microsoft has disclosed details of two campaigns in which threat actors are abusing third-party email delivery infrastructure to blast financial fraud scam messages and using passkey-themed social engineering to breach cloud environments. The first campaign, per the tech giant, involved sending over a million scam emails between August 3 and 5, 2026, by masquerading as chief executive officers

    The Hacker NewsMicrosoft

Sat, 12 Sept 2026

  1. BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments.

    SecurityWeekWindows, Chrome
  2. OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

    The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the

    The Hacker News
  3. Researchers say OpenAI agents were behind May hacking campaign targeting RubyGems

    OpenAI confirmed their agents were behind a campaign in May that researchers say flooded the popular online code repository with malicious software packages.

    CyberScoop

About this news

1,256
Stories
40
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets