Security news

Latest security news

Thu, 10 Sept 2026

  1. Microsoft fixes bug that wiped Windows desktop settings

    Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices.

    BleepingComputerMicrosoft, Windows
  2. Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

    Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every

    The Hacker News
  3. New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

    The exploit provides full System privileges on Windows machines running the September 2026 patches.

    SecurityWeekMicrosoft, Windows
  4. EU Cyber Resilience Act to Enforce New Reporting Requirements

    Starting Friday, businesses operating in the EU will have just 24 hours to notify the government any time they discover serious product security incidents.

    Dark Reading
  5. Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

    The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.

    SecurityWeekFortinet
  6. AI adoption brings new security headaches for already stretched CISOs

    CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the CISO report. The Al mandate expands faster than resources (Source: Proofpoint) AI adds to security responsibilities GenAI is creating new concerns around sensitive data, access and employee activity. Seventy-eight percent of CISOs consider it a security risk, with the potential loss … More →

    Help Net Security

Wed, 9 Sept 2026

  1. Novel Blue Moon kit targeting Chrome and Windows reflects new reality of AI-driven exploits

    Mind the patch gap, please and thank you

    The RegisterWindows, Chrome
  2. Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

    Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.

    CriticalBleepingComputerCisco
  3. Mythos Vulnerability Firehose Hits a Human Bottleneck

    An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.

    Dark Reading
  4. Chinese espionage groups swarm to exploit triple-link chain of zero-days

    Multiple China-aligned threat groups exploited the defects quickly to target various organizations. Proofpoint said the activity is ongoing and expects it to widen.

    CyberScoop

About this news

1,264
Stories
33
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets