Security news

Latest security news

Tue, 8 Sept 2026

  1. OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

    OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities.

    BleepingComputer2 outlets
  2. ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

    Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel

    The Hacker News
  3. Mikrotik security advisory (AV26-887)

    Serial Number: AV26-887 Date: September 8, 2026 As of September 5, 2026, Mikrotik is affected by vulnerabilities in the following product: RouterOS Prior to 6.49.21 Prior to 7.23.4 Prior to 7.24.2 Prior to 7.25 beta 3 Open-source reporting indicates that CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060 related to MikroTik are being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Vulnerabilities in Mikrotik RouterOS software September 2026 vulnerability

    Canadian Centre for Cyber Security
  4. Dell security advisory (AV26-886)

    Serial Number: AV26-886 Date: September 8, 2026 As of September 7, 2026, Dell is affected by vulnerabilities in the following products: Dell OpenManage Network Integration Prior to 3.10 or later Dell iDRAC9 Versions prior to 7.30.10.50 and 7.00.00.184 Dell iDRAC10 Prior to 1.30.30.50 or later Dell PowerEdge Server for Intel 2026 Multiple versions and models Dell Open Manage Python SDK (omsdk) Prior to 1.2.519 or later Dell Avamar Multiple versions Dell Networker Virtual Edition (NVE) Multiple versions Dell PowerProtect DP Series Appliance Multiple versions Dell Integrated Data Protection Appliance (IDPA) Multiple versions Dell PowerScale OneFS Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Security Advisories, Notices and Resources | Dell Canada

    Canadian Centre for Cyber SecurityDell, Intel
  5. SonicWall security advisory (AV26-884)

    Serial Number: AV26-884 Date: September 4, 2026 As of September 4, 2026, SonicWall is affected by vulnerabilities in the following product: Network Security Manager (NSM) On-Prem (VMWare, Hyper-V, Azure and KVM) 4.3.0 and earlier versions The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SonicWall NSM On-Prem Affected By Multiple Vulnerabilities Security Advisory

    Canadian Centre for Cyber SecurityVMware, SonicWall
  6. Adobe fixes critical Magento zero-day exploited to backdoor servers

    Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce.

    CriticalUsed in attacksBleepingComputerAdobe
  7. WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

    Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

    The Hacker NewsAndroid
  8. FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

    A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The

    The Hacker NewsLinux
  9. CVE-2026-86206, CVE-2026-86207: N-able N-central Authentication Bypass (FIXED)

    Overview While conducting research into a recent N-able N-central authentication bypass vulnerability ( CVE-2026-18577 ), Rapid7 Labs discovered two new vulnerabilities affecting the latest version of N-central. When chained together, these two vulnerabilities allow a remote unauthenticated attacker to bypass authentication and create a new attacker-controlled System administrator account on an affected server. CVE ID Description CWE CVSSv4 CVE-2026-86206 Semicolon/Forwarded access-control bypass CWE-791 6.9 (Medium) CVE-2026-86207 UserTwoFactorLogin authentication bypass CWE-305 7.7 (High) Both CVE-2026-86206 and CVE-2026-86207 have been patched by the vendor via N-central 2026.3 Hotfix 3. Product description N-able N-central is an enterprise-grade Remote Monitoring and Management (RMM) platform designed for Managed Service Providers (MSPs) and IT departments to monitor, manage, and secure complex, large-scale networks from a centralized dashboard. Credit These vulnerabilities were discovered by Stephen Fewer, Senior Principal Security Researcher at Rapid7 , and are being disclosed in accordance with Rapid7's vulnerability disclosure policy . Technical analysis CVE-2026-86206 N-ce

    CriticalUsed in attacksRapid7 BlogN-able
  10. MikroTik router flaws allow takeover without a password

    Attackers are exploiting critical RouterOS flaws to take control of routers with SSH exposed to the internet.

    Malwarebytes Labs

About this news

1,276
Stories
28
Added in the last 24 hours
11
Critical in the last 7 days
4
Reported by several outlets