Security news
Latest security news
Fri, 11 Sept 2026
- The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment
Introduction The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal collaboration to capture actionable intelligence. With fraud damages anticipated to approach hundreds of billions of USD , security teams must navigate numerous non-compliant channels while ingesting and processing diverse data formats—such as documents, imagery, video, and unformatted text—linked to organizational assets. The recent introduction of a new Fraud framework by the MITRE organization underscores the critical need to combat fraud and highlights the significant danger these threat actors pose to all organizations. The MITRE organization has been taking a positive step towards standardizing the fight against fraud, while helping organizations target the relevant directions to look
Rapid7 Blog - Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails
Infosecurity MagazineMicrosoft - HashiCorp security advisory (AV26-910)
Serial Number: AV26-910 Date: September 11, 2026 As of September 10, 2026, HashiCorp is affected by vulnerabilities in the following products: Consul Prior to 2.0.4 Consul Enterprise 1.0 Prior to 1.21.18 21.0 Prior to 1.21.18 9.0 Prior to 1.21.18 consul-template Prior to 0.43.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HCSEC-2026-34 - Consul vulnerable to an authorization bypass in the catalog node-write path HCSEC-2026-38 - Consul-template vulnerable to an information disclosure issue in error handling HCSEC-2026-37 - Consul vulnerable to an authorization bypass in the Connect service mesh Security - HashiCorp Discuss
Canadian Centre for Cyber Security - Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack
Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.
SecurityWeek - Anthropic caught Russia-linked spies using Claude in hacking operations
Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.
The Record - Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars
Swapping legal work for malware development ended in extradition and a guilty plea
The Register - Android malware creates a hidden copy of your banking app
The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
Malwarebytes LabsAndroid - Accountability, oversight and AI: Inside Microsoft’s security transformation
Stung by years of embarrassing hacks, the tech giant overhauled how it approached cybersecurity. Company leaders now say they’re seeing results.
Cybersecurity DiveMicrosoft - Ukrainian hacker gets four years in US prison over Conti ransomware attacks
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.
The Record - EU's Cyber Resilience Act starts the 24-hour vulnerability clock
Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform
The Register
About this news
- 1,265
- Stories
- 28
- Added in the last 24 hours
- 14
- Critical in the last 7 days
- 4
- Reported by several outlets