Security news

Latest security news

Mon, 14 Sept 2026

  1. Twitch extension with 30K installs exposes users’ OAuth tokens

    A browser extension called Twitch Enhanced Viewer | JeetBot, available in the official Chrome and Firefox stores, sends users' Twitch OAuth session tokens to a commercial bot service.

    BleepingComputerChrome, Firefox
  2. Five alleged leaders of Black Axe’s operations in South Africa extradited to US

    Officials said the five individuals concocted various long-running romance scams to trick U.S.-based victims into sending them money.

    CyberScoop
  3. Hackers hijack HBO Max Reddit account to push malware in ClickFix ads

    Hackers compromised HBO Max's official Reddit account and used it to push malicious ads that launched ClickFix attacks to infect Windows and macOS devices with information-stealing malware.

    BleepingComputerWindows
  4. Apple Updates Everything, (Mon, Sep 14th)

    Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever patched, but the increase is not as significant as other vendors' "post-AI" patch releases.

    SANS Internet Storm CenterApple
  5. New hardware device can RAM into encrypted memory, expose your data

    Attackers would need physical access to the server to pull off the DDR5 trick

    The Register
  6. OpenAI's malicious bot swarm attacked RubyGems

    Ruby are you ok? Ruby are you ok? Are you ok Ruby?

    The Register
  7. New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

    Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server's memory, so the processor keeps reading old encrypted data as if it were current. The attack requires an attacker who already controls the server's software and can briefly access the machine to insert a small circuit

    The Hacker NewsIntel, AMD
  8. 3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

    An attacker was operating inside the network of 3BB, one of Thailand's largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat intelligence firm Hunt.io said. The company uncovered the intrusion by examining a server the attacker had left open on the internet, which held the attacker's own tools and a list of

    The Hacker News
  9. Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

    A flaw in Telegram Desktop let a bot's message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12. In Telegram, the message looked ordinary, with a link button, and the script ran only when someone opened the export file in a web browser. It could then copy every message in that file to

    The Hacker News
  10. Android security advisory – September 2026 monthly rollup (AV26-920)

    Serial Number: AV26-920 Date: September 14, 2026 As of September 8, 2026, Android published a security bulletin to address vulnerabilities affecting Android devices. The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Android Security Bulletin—September 2026

    Canadian Centre for Cyber SecurityAndroid

About this news

1,263
Stories
35
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets