Security news
Latest security news
Mon, 14 Sept 2026
- Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries
A suspected Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of a multi-national campaign. "Red Heron scanned 1,386 Gitea instances across seven countries and maintained a separate dataset of 477 Taiwan-based systems," Acronis Threat Research Unit (TRU)
The Hacker News - Anthropic CEO: Time to Shift From Improving to Controlling AI
Dario Amodei says it's time to slow the pace of frontier AI improvements so that security and risk prevention efforts can catch up. What does this mean for enterprises?
Dark Reading - Hackers target exposed Vite dev servers to steal AWS, Azure secrets
A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments.
BleepingComputerAWS - Pro-Ukraine Hacking Cat group deploying new malware against Russian targets
The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.
The Record - Hundreds of fake government websites target users in Central Asia
The sites are designed to collect victims’ contact details, which scammers then use to target them through phone or email to steal money, personal information or gain access to their devices.
The Record - WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
WordPress has announced it's launching an automated security review for every release of a plugin before it's distributed through the WordPress.org update API so as to analyze it for potential security issues and ensure there are no risks involved. "New plugins are reviewed before they enter the directory, but updates ship continuously after that," David Perez, WordPress Official Plugin
The Hacker NewsWordPress - Security teams increasingly outflanked by AI agents
A report warns that non-human identities are growing beyond the ability of existing systems to track.
Cybersecurity Dive - Samsung mobile security advisory (AV26-919)
Serial number: AV26-919 Date: September 14, 2026 As of September 8, 2026, Samsung published a security update to address vulnerabilities in the following product: Samsung mobile devices – versions prior to SMR-SEP-2026 The most recent security update resolves multiple identified vulnerabilities. The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary update. Samsung Security Updates
Canadian Centre for Cyber SecuritySamsung - Malicious Twitch Extension Exposes 31,000 Users' OAuth Tokens
Socket has discovered a Twitch browser extension forwarding users' OAuth tokens to a Russian bot service
Infosecurity Magazine - Rapid7 Named Among Notable Vendors in Forrester MDR Landscape: Why the Future is Exposure-informed, Preemptive MDR
The managed detection and response (MDR) market has reached a turning point. We’ve gone beyond the baseline of 24/7 monitoring focusing on the speed of detection and moved to a world with a convergence of exposure management and response to deliver measurable, outcome-based defenses of a larger, AI-driven attack surface. For anyone evaluating MDR right now, the Managed Detection and Response Services Landscape, Q3 2026 report by Forrester is a useful map that lays out where the market is heading. This is a market that has moved beyond "do you cover my telemetry?" to “Can a provider connect and prove that its activity is tied to real reduction in risk?”. Rapid7 was named among the notable providers in this Forrester MDR Landscape. Being included matters to us, but the more interesting story is in what Forrester says about the market itself. Detection and exposure are becoming one service One of the report's clearest signals is directional: Forrester writes that "MDR services will converge with exposure and posture improvement.” That convergence is the whole basis of Rapid7 MDR and our Command Platform strategy. Most MDR services react after an attacker has already broken in. Rapid7
Rapid7 Blog
About this news
- 1,263
- Stories
- 35
- Added in the last 24 hours
- 16
- Critical in the last 7 days
- 4
- Reported by several outlets