Security news
Latest security news
Mon, 14 Sept 2026
- Twitch extension with 30K installs exposes users’ OAuth tokens
A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service.
BleepingComputerChrome, Firefox - Five alleged leaders of Black Axe’s operations in South Africa extradited to US
Officials said the five individuals concocted various long-running romance scams to trick U.S.-based victims into sending them money.
CyberScoop - Hackers hijack HBO Max Reddit account to push malware in ClickFix ads
Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.
BleepingComputerWindows - Apple Updates Everything, (Mon, Sep 14th)
Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors' "post-AI" patch releases.
SANS Internet Storm CenterApple - New hardware device can RAM into encrypted memory, expose your data
Attackers would need physical access to the server to pull off the DDR5 trick
The Register - OpenAI's malicious bot swarm attacked RubyGems
Ruby are you ok? Ruby are you ok? Are you ok Ruby?
The Register - New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit
The Hacker NewsIntel, AMD - 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials
An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of
The Hacker News - Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports
A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to
The Hacker News - Android security advisory – September 2026 monthly rollup (AV26-920)
Serial Number: AV26-920 Date: September 14, 2026 As of September 8, 2026, Android published a security bulletin to address vulnerabilities affecting Android devices. The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Android Security Bulletin—September 2026
Canadian Centre for Cyber SecurityAndroid
About this news
- 1,263
- Stories
- 35
- Added in the last 24 hours
- 16
- Critical in the last 7 days
- 4
- Reported by several outlets