Security news

Latest security news

Fri, 11 Sept 2026

  1. Passkey-themed phishing attacks lead to Microsoft 365 data theft

    Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services.

    BleepingComputerMicrosoft
  2. Phishing Research Challenges Conventional Security Awareness Testing

    Analysis of 2.47 million simulated attacks shows why organizations should measure credential leaks and reporting, not just clicks.

    SecurityWeek
  3. AI Governance Can't Wait

    Adversaries can manipulate AI defensive reasoning to silently compromise target networks.

    Dark Reading
  4. GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

    GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under

    The Hacker NewsGitLab
  5. Artifactory flaws chained in attacks deploying backdoor malware

    Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.

    BleepingComputer
  6. Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

    Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a "teacher" to

    The Hacker News
  7. GitLab Vulnerability Exploited One Day After Disclosure

    The critical-severity path traversal flaw allows unauthenticated attackers to read arbitrary files from the GitLab server.

    SecurityWeekGitLab
  8. [Control Systems] National Instruments security advisory (AV26-914)

    Serial number: AV26-914 Date: September 11, 2026 As of September 10, 2026, National Instruments is affected by vulnerabilities in the following products: SystemLink Prior to or equal to 2026 Q3 Patch 1 SystemLink Server Prior to or equal to 2026 Q3 Patch 1 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available./p> Improper Access Controls in NI SystemLink Storage of Sensitive Information in Cleartext in NI SystemLink Available Security Updates for NI Software: 2026

    Canadian Centre for Cyber Security
  9. Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain

    From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.

    Dark ReadingPaperCut
  10. [Control systems] GeoVision security advisory (AV26-913)

    Serial number: AV26-913 Date: Septembre 11, 2026 As of September 10, 2026, GeoVision is affected by vulnerabilities in the following product:: GV-LPC2011/LPC2211 Firmware version 1.13 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. GeoVision Security Advisory - GV-LPC-2026-09-01 Cyber Security - GeoVision

    Canadian Centre for Cyber Security

About this news

1,265
Stories
32
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets