Security news

Latest security news

71 of 1,256 storiesAWSClear all

Fri, 11 Sept 2026

  1. EU's Cyber Resilience Act starts the 24-hour vulnerability clock

    Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform

    The Register
  2. Check Point Patches Critical VPN Vulnerabilities

    Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

    SecurityWeek
  3. PaperCut Flaws Exploited in AI-Powered Attacks

    A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

    SecurityWeekPaperCut
  4. Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

    Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.

    The Hacker News
  5. PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

    PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that

    The Hacker NewsPaperCut
  6. Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

    CriticalUsed in attacksThe Hacker NewsCisco

Thu, 10 Sept 2026

  1. ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

    A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already

    The Hacker NewsAndroid
  2. AI-powered attack exploited PaperCut flaws to hack 395 organizations

    A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.

    BleepingComputerPaperCut
  3. BlueMoon exploit kit turns Chrome and Windows flaws into attacks

    Four different espionage groups used the same exploit kit to target recently fixed flaws, showing why “patch later” is a dangerous gamble.

    Malwarebytes LabsWindows, Chrome
  4. Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

    Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.

    BleepingComputerCisco

About this news

1,256
Stories
35
Added in the last 24 hours
18
Critical in the last 7 days
4
Reported by several outlets