Security news

Latest security news

Fri, 11 Sept 2026

  1. State authorities warn they lack resources to address cyber threat to critical sectors

    State CIOs and CISOs need additional funding, personnel and training to protect water, energy and healthcare, according to a new report.

    Cybersecurity Dive
  2. [Control systems] Schneider Electric security advisory (AV26-912)

    Serial number: AV26-912 Date: September 11, 2026 As of September 9, 2026, Schneider Electric is affected by vulnerabilities in the following products: EcoStruxure™ IT Data Center Expert (Formerly known as StruxureWare Data Center Expert) Versions 9.1.2 and prior PowerLogic T300 Versions 2.9.8-5620 and prior The Cyber Centre encourages users and administrators to review the provided web links, perform the suggested mitigations and apply the necessary updates. Multiple Vulnerabilities on EcoStruxure™ IT Data Center Expert Improper Neutralization of Special Elements used in an OS Command vulnerability on PowerLogic T300 Schneider Electric Security Notifications

    Canadian Centre for Cyber Security
  3. Crypto customers targeted by scammers after email marketing provider breach

    A breach at email marketing company Brevo exposed Trezor, CoinTracking, and BitBox customers to phishing emails, but others may also be at risk.

    Malwarebytes Labs
  4. The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)

    I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own.

    SANS Internet Storm Center
  5. Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

    Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial

    The Hacker News
  6. In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.

    SecurityWeek
  7. Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

    Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight

    The Hacker News
  8. How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

    Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures.

    BleepingComputer
  9. MongoDB security advisory (AV26-911)

    Serial Number: AV26-911 Date: September 11, 2026 As of September 10, 2026, MongoDB is affected by vulnerabilities in the following products: Java Driver Prior to 5.11.1 Laravel MongoDB (PHP) Prior to 5.11.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. [PHPLARA-260] Query builder: force literal equality when 3-arg where uses '=' with an array value [JAVA-6276] Native heap use-after-free via cancellation racing KMS credential fetch in reactive encryption Alerts | MongoDB

    Canadian Centre for Cyber Security
  10. Metasploit Wrap Up: This One Goes to Sixteen!

    This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516 Description: Adds an auxiliary scanner module for CVE-2025-54988/CVE-2025-66516. The module validates an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed through the Elasticsearch attachment ingest processor. SPIP Unauthenticated Blind SQLi via Date Field Escaping Bypass Authors: Benoit Hua, Franck Chevalier, Julien Voisin, and ka3n1x Type: Auxiliary Pull request: #21791 contributed by jvoisin Path: scanner/http/spip_annee_sqli Description: Adds modules/auxiliary/scanner/http/spip_annee_sqli.rb which exploits a blind SQL injection in SPIP's date column escaping logic. M

    Rapid7 BlogPaperCut, SonicWall, Cisco

About this news

1,265
Stories
30
Added in the last 24 hours
16
Critical in the last 7 days
4
Reported by several outlets