Security news

Latest security news

Thu, 10 Sept 2026

  1. Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)

    [This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]

    SANS Internet Storm Center
  2. FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors

    The new document appears to be part of a broader shift by the US government towards the proactive disruption of cyber threat actors

    Infosecurity Magazine
  3. ISC Stormcast For Thursday, September 10th, 2026 https://isc.sans.edu/podcastdetail/10088, (Thu, Sep 10th)

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

    SANS Internet Storm Center
  4. Trezor warns users of email provider breach, phishing attacks

    Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks.

    BleepingComputer
  5. Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

    The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

    SecurityWeekFortinet
  6. Cybercriminals are building phishing pages that exist only inside victims’ browsers

    A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. “Instead of delivering a phishing page from a web server, the malicious content is assembled inside the victim’s browser using a blob URL — a temporary browser-generated URL that points to content stored locally in memory rather than on a website,” researchers explained. The attack … More →

    Help Net SecurityMicrosoft, Barracuda

Wed, 9 Sept 2026

  1. Scans for Proxmox Servers, (Wed, Sep 9th)

    About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported for a couple of years now.

    SANS Internet Storm Center
  2. ClickFix Moves into the Browser to Steal Cryptocurrency

    ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency

    Infosecurity MagazineGoogle
  3. ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

    SANS Internet Storm Center

Tue, 8 Sept 2026

  1. Attackers Use Multi-Hop Google Redirects for Phishing Campaign

    Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.

    Dark ReadingGoogle

About this news

1,259
Stories
34
Added in the last 24 hours
17
Critical in the last 7 days
4
Reported by several outlets