Security news

Latest security news

Thu, 10 Sept 2026

  1. Cisco FMC bugs exploited by nation-state and ransomware actors (CVE-2026-20079, CVE-2026-20316)

    State-sponsored and financially-motivated attackers are actively exploiting CVE-2026-20079, a critical authentication bypass vulnerability in Cisco Secure Firewall Management Center (FMC), which is used for centrally managing multiple Cisco Secure Firewall devices across a network. Two FMC vulnerabilities under active attack “Cisco Talos is actively tracking the exploitation of two vulnerabilities in Cisco’s Secure Firewall Management Center (FMC) Software,” the company’s researchers confirmed on Wednesday. These are the above mentioned CVE-2026-20079 and CVE-2026-20316, which Cisco flagged … More →

    CriticalUsed in attacksHelp Net SecurityCisco
  2. Update Chrome now to protect against an actively exploited vulnerability

    Chrome issues another monster update, fixing an actively exploited V8 vulnerability and 229 other flaws.

    Malwarebytes LabsChrome
  3. [object Object]

    Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source. Simon Willison comments : Anil points out that this rate of discovery appears incompatible with existing open source embargo practices for new issues. If an issue can become an exploit this fast, we need to figure out new processes for keeping our communities safe...

    Schneier on Security
  4. CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication

    CriticalThe Hacker NewsCitrix, Cisco, Fortinet
  5. Scytale expands vendor risk management with AI-powered TPRM tools

    Scytale has announced the launch of their latest AI-powered third-party risk management (TPRM) capabilities within its Vendors module. The release further extends vendor risk management from a periodic review exercise into a continuously updated vendor risk intelligence engine, giving security and GRC teams a current view of every vendor in their ecosystem. Scytale’s AI GRC platform automates vendor discovery, risk scoring, and evidence collection across compliance frameworks. (Source: Scytale) The expansion arrives as third-party exposure … More →

    Help Net Security
  6. WordPress adds automated security checks to block risky plugin releases

    WordPress’ automated security review will now assess every plugin release before it is distributed through the WordPress.org update API. Releases considered a potential security risk will be blocked automatically. “A plugin can be secure today and introduce a vulnerability, or malicious code, in a future release. Until now there was no consistent review step between a release being committed and that release reaching millions of sites,” David Perez, Co-Lead, WordPress Official Plugin Repository Team, explained. … More →

    Help Net SecurityWordPress
  7. Organizations Warned of Cisco Secure FMC Exploitation

    Cisco and CISA have flagged exploitation of CVE-2026-20079, a vulnerability disclosed in March 2026.

    CriticalSecurityWeekCisco
  8. The Machine With Many Faces: Post-Exploitation Identity Misuse in SPIFFE/SPIRE

    Learn how root access on a compromised K8s node allows attackers to utilize SPIFFE/SPIRE metadata to spoof and harvest co-located workload identities.

    Unit 42
  9. CISA: WatchGuard RCE flaw now exploited in ransomware attacks

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December.

    BleepingComputer
  10. Apple is building photo verification for the people who need it most

    Apple has introduced Apple Reference Image, an opt-in feature designed to verify the authenticity of photos taken with iPhone 18 Pro models. Apple Reference Image provides users with an unalterable reference photo, visually confirming what the sensor saw at the moment of capture. (Source: Apple) Apple said the technology would be particularly important for photojournalists and photographers, as well as everyday viewers. The company will also add support for the SynthID standard in a software … More →

    Help Net SecurityApple

About this news

1,264
Stories
35
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets