Security news

Latest security news

Fri, 11 Sept 2026

  1. [Control systems] Schneider Electric security advisory (AV26-912)

    Serial number: AV26-912 Date: September 11, 2026 As of September 9, 2026, Schneider Electric is affected by vulnerabilities in the following products: EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) Versions 9.1.2 and prior PowerLogic T300 Versions 2.9.8-5620 and prior The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates. Multiple Vulnerabilities on EcoStruxure™ IT Data Center Expert Improper Neutralization of Special Elements used in an OS Command vulnerability on PowerLogic T300 Schneider Electric Security Notifications

    Canadian Centre for Cyber Security
  2. The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)

    I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own.

    SANS Internet Storm Center
  3. Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial

    The Hacker News
  4. MongoDB security advisory (AV26-911)

    Serial Number: AV26-911 Date: September 11, 2026 As of September 10, 2026, MongoDB is affected by vulnerabilities in the following products: Java Driver Prior to 5.11.1 Laravel MongoDB (PHP) Prior to 5.11.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. [PHPLARA-260] Query builder: force literal equality when 3-arg where uses '=' with an array value [JAVA-6276] Native heap use-after-free via cancellation racing KMS credential fetch in reactive encryption Alerts | MongoDB

    Canadian Centre for Cyber Security
  5. Metasploit Wrap Up: This One Goes to Sixteen!

    This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516 Description: Adds an auxiliary scanner module for CVE-2025-54988/CVE-2025-66516. The module validates an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed through the Elasticsearch attachment ingest processor. SPIP Unauthenticated Blind SQLi via Date Field Escaping Bypass Authors: Benoit Hua, Franck Chevalier, Julien Voisin, and ka3n1x Type: Auxiliary Pull request: #21791 contributed by jvoisin Path: scanner/http/spip_annee_sqli Description: Adds modules/auxiliary/scanner/http/spip_annee_sqli.rb which exploits a blind SQL injection in SPIP's date column escaping logic. M

    Rapid7 BlogPaperCut, SonicWall, Cisco
  6. The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

    Introduction The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal collaboration to capture actionable intelligence. With fraud damages anticipated to approach hundreds of billions of USD , security teams must navigate numerous non-compliant channels while ingesting and processing diverse data formats—such as documents, imagery, video, and unformatted text—linked to organizational assets. The recent introduction of a new Fraud framework by the MITRE organization underscores the critical need to combat fraud and highlights the significant danger these threat actors pose to all organizations. The MITRE organization has been taking a positive step towards standardizing the fight against fraud, while helping organizations target the relevant directions to look

    Rapid7 Blog
  7. HashiCorp security advisory (AV26-910)

    Serial Number: AV26-910 Date: September 11, 2026 As of September 10, 2026, HashiCorp is affected by vulnerabilities in the following products: Consul Prior to 2.0.4 Consul Enterprise 1.0 Prior to 1.21.18 21.0 Prior to 1.21.18 9.0 Prior to 1.21.18 consul-template Prior to 0.43.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HCSEC-2026-34 - Consul vulnerable to an authorization bypass in the catalog node-write path HCSEC-2026-38 - Consul-template vulnerable to an information disclosure issue in error handling HCSEC-2026-37 - Consul vulnerable to an authorization bypass in the Connect service mesh Security - HashiCorp Discuss

    Canadian Centre for Cyber Security
  8. EU's Cyber Resilience Act starts the 24-hour vulnerability clock

    Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform

    The Register
  9. Your Critical Vulnerabilities Might Not Be Your Biggest Risk

    Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker

    The Hacker News
  10. GitLab urges users to patch max severity path traversal flaw

    GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.

    BleepingComputerGitLab

About this news

1,263
Stories
35
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets