Security news

Latest security news

Mon, 7 Sept 2026

  1. LG TV flaws could let attackers listen in, even in standby mode

    Testing found that LG smart TVs can track viewing and scan home networks, while security flaws could let attackers record conversations.

    Malwarebytes Labs
  2. Hackers drain $320M in Bitcoin from Liquid Network, claim they're the good guys

    Self-described white hats promise to return 'most' of the 4,000 BTC once the vulnerability is fixed

    The Register
  3. N-able Releases Hotfix for Critical Remote Code Execution Vulnerability

    The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself

    CriticalUsed in attacksInfosecurity MagazineN-able
  4. Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

    A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

    The Hacker NewsOracle, Progress
  5. Hackers exploit new MikroTik RouterOS flaws to hijack routers

    Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet.

    BleepingComputer
  6. ConnectWise warns of new ScreenConnect flaw without patch

    ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week.

    BleepingComputer
  7. N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

    Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a

    The Hacker News
  8. Researcher Publishes CrowdStrike Privilege Escalation Zero Day

    A security researcher has posted a zero-day exploit in CrowdStrike which could allow hackers to escalate privileges

    Infosecurity Magazine
  9. JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies

    Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

    The Hacker NewsGoogle
  10. N-able patches max severity N-central flaw amid ongoing attacks

    N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform.

    BleepingComputer

About this news

1,265
Stories
19
Added in the last 24 hours
13
Critical in the last 7 days
4
Reported by several outlets