Security news

Latest security news

Mon, 14 Sept 2026

  1. Revolut gave customer IDs and financial data to a government impostor

    The digital bank was tricked into releasing sensitive customer information, including IDs, to an attacker using a legitimate government email domain.

    Malwarebytes Labs
  2. CISOs Race to Control AI Agents Without Destroying Their Value

    Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm.

    SecurityWeek
  3. CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild

    Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability ( CWE-22 ) in the repository commits API with a CVSSv3.1 score of 10.0 . According to GitLab, improper path confinement and missing authentication enforcement could allow an unauthenticated user to read arbitrary files from an affected GitLab server under certain conditions. On September 11, 2026, CVE-2026-85706 was added to the U.S. Cybersecurity and Infrastructure Security Agency's (CISA) Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. CISA set a remediation due date of September 14, 2026, for affected Federal Civilian Executive Branch agencies and marked the vulnerability as subject to forensic triage requirements under Binding Operational Directive 26-04. Organizations running affected self-managed GitLab instances should remediate CVE-2026-85706 on an emergency basis, outside of normal patch cycles. Mitigation guidance A vendor-supplied update is available to remediate CVE-2026-85706. Organizations running affected self-mana

    CriticalUsed in attacksRapid7 BlogGitLab
  4. Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection

    We designed a behavioral clustering model to map cloud identity roles from audit logs, enabling continuous threat detection using standard SQL queries.

    Unit 42
  5. Hackers Exploit Maximum Severity Flaw in GitLab

    CISA warns that threat actors are exploiting a vulnerability with a CVSS score of 10.0

    Infosecurity MagazineGitLab
  6. Telus Warns Customers of Account Breaches

    Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.

    SecurityWeek
  7. Microsoft: September updates cause RDS failures on Windows Server

    Microsoft has confirmed reports that the September 2026 security updates cause Remote Desktop Services (RDS) failures on Windows Server systems.

    BleepingComputerMicrosoft, Windows
  8. UK.gov begins killing off passwords for 23 million users

    Passkeys promise fewer phishing headaches – and £600 a day off Whitehall's SMS bill

    The Register
  9. Security teams are adopting AI faster than they trust it

    New survey data reveals a widening gap between AI adoption and AI trust.

    Cybersecurity Dive
  10. Zero trust is the future. But enterprises still need their VPNs.

    Zero trust shouldn’t mean sacrificing the stability and flexibility enterprises still depend on.

    Cybersecurity Dive

About this news

1,264
Stories
36
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets