Security news

Latest security news

24 of 1,259 storiesContiClear all

Thu, 10 Sept 2026

  1. Conti ransomware crew member sentenced to four years in prison

    Oleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies.

    CyberScoop
  2. Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit

    The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.

    Dark ReadingMicrosoft, Windows
  3. Scytale expands vendor risk management with AI-powered TPRM tools

    Scytale has announced the launch of their latest AI-powered third-party risk management (TPRM) capabilities within its Vendors module. The release further extends vendor risk management from a periodic review exercise into a continuously updated vendor risk intelligence engine, giving security and GRC teams a current view of every vendor in their ecosystem. Scytale’s AI GRC platform automates vendor discovery, risk scoring, and evidence collection across compliance frameworks. (Source: Scytale) The expansion arrives as third-party exposure … More →

    Help Net Security

Wed, 9 Sept 2026

  1. CISOs are feeling the security burden of accelerated AI use

    A report shows CISOs face increased pressures related to cyber resilience and business continuity.

    Cybersecurity Dive

Tue, 8 Sept 2026

  1. Patch Tuesday - September 2026

    Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will ever return to the lower volumes we saw prior to 2026. Microsoft is aware of exploitation in the wild for two of the vulnerabilities published today. Windows ALPC: zero-day EoP The eternal game of elevation of privilege whack-a-mole between Microsoft and attackers continues. This month, the battle is centered on the Windows Advanced Local Procedure Call (ALPC) mechanism, a kernel capability that facilitates inter-process communication. Microsoft is aware of exploitation in the wild already. Successful abuse of the flaw underlying CVE-2026-85880 grants an attacker SYSTEM via a buffer overflow that enables an out-of-bounds write, and as we all know by now, this is exactly what would happen duri

    CriticalUsed in attacksRapid7 BlogMicrosoft, Windows
  2. Why federal cyber defense demands an offense-driven mindset

    Static checklists and annual penetration tests leave agencies with dangerous blind spots. True resilience requires moving from reactive attestation to continuous, automated validation.

    CyberScoop
  3. Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

    Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI

    The Hacker NewsGoogle

Thu, 3 Sept 2026

  1. Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means

    In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs. Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have

    The Hacker News

Wed, 19 Aug 2026

  1. Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America

    Cássio De Alcântara is Director, LATAM Sales at Rapid7. Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, but also introduce greater complexity and expanding attack surfaces. In this environment, security leaders are being asked to understand where risk exists across increasingly distributed environments and quickly eliminate blind spots like Shadow IT and Shadow AI – all without adding operational complexity. To help security leaders and practitioners address this complexity, Rapid7 is excited to announce a new strategic distribution partnership with Licencias OnLine (LOL) across Latin America. Helping organizations stay ahead of evolving threats In order to keep day-to-day business operations moving, organizations need security solutions that not only protect critical assets but also support innovation, regulatory compliance, and long-term digital transformation. Rapid7's AI-powered cybersecurity operations platform helps organizations strengthen cyber resilience by unifying continuous exposure management, AI-driven threat detection and response, and securit

    Rapid7 Blog

Mon, 17 Aug 2026

  1. Africa’s Cybersecurity Challenge Is Bigger Than Access to Technology

    Gopan Sivasankaran is Rapid7's Regional Director, Middle East & Africa. Across Egypt, Nigeria, and Kenya, organizations are expanding their use of cloud infrastructure, artificial intelligence, digital services, and connected operations. But more technology does not automatically create stronger security operations; many security teams are not short on data, but rather on time, context, and specialist capacity. As environments expand, the challenge is no longer finding another security product. It is turning existing technology and new investments into clearer risk decisions, faster investigations, and more consistent response, which requires more than software. Rapid7 and StarLink: From access to operational capability Africa has been an important region for Rapid7 for many years, and we’re proud of the role we’ve played in protecting organizations across the continent. We see significant opportunity ahead and remain committed to investing in our presence, partner ecosystem, and customer relationships across the region. That continued investment is why Rapid7 is expanding its partnership with StarLink across Egypt, Nigeria, and Kenya. Security teams are often managing data across

    Rapid7 Blog

About this news

1,259
Stories
34
Added in the last 24 hours
17
Critical in the last 7 days
4
Reported by several outlets