Security news

Latest security news

Fri, 11 Sept 2026

  1. Your Critical Vulnerabilities Might Not Be Your Biggest Risk

    Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker

    The Hacker News
  2. Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison

    Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

    SecurityWeek
  3. GitLab urges users to patch max severity path traversal flaw

    GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.

    BleepingComputerGitLab
  4. Check Point Patches Critical VPN Vulnerabilities

    Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

    SecurityWeek
  5. Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance

    Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars.

    SecurityWeek
  6. Surfshark Systems Targeted by Hackers

    A misconfigured test server containing engineering material, including internal configurations, was accessed by threat actors.

    SecurityWeek
  7. Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs

    Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday.

    BleepingComputerMicrosoft, Windows, Outlook
  8. Most Organizations Skip Permissions Reviews Before Deploying AI Tools

    A new Syskit study has shown that only 43% of organizations with AI agents deployed in Microsoft 365 environments completed a permission review before doing so

    Infosecurity MagazineMicrosoft
  9. Anthropic Says Russian Hackers Used Claude AI to Automate Malware Evasion

    Anthropic reveals how criminal groups are increasingly targeting AI vendors' own infrastructure, including to steal a pre-release Claude model.

    SecurityWeek
  10. PaperCut Flaws Exploited in AI-Powered Attacks

    A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.

    SecurityWeekPaperCut

About this news

1,265
Stories
23
Added in the last 24 hours
13
Critical in the last 7 days
4
Reported by several outlets