Security news

Latest security news

Thu, 10 Sept 2026

  1. New Android malware encrypts files, steals data, and harasses victims

    A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims.

    BleepingComputerAndroid
  2. Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023

    As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers.

    The Record
  3. Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

    Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.

    Dark ReadingMicrosoft
  4. September Windows Server updates break Remote Desktop Services

    Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality.

    BleepingComputerWindows
  5. Conti ransomware crew member sentenced to four years in prison

    Oleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies.

    CyberScoop
  6. Mandiant Founder Kevin Mandia Joins Amazon Board

    Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board.

    SecurityWeekAmazon
  7. Hawley probes OpenAI over Hugging Face breach

    The Republican lawmaker called OpenAI’s leadership decisions “reckless,” and used recent warnings about the existential risk of AI to bolster his inquiry.

    CyberScoop
  8. AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060

    Number: AL26-020 Date: September 10, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre is aware of vulnerabilities impacting MikroTik RouterOS devices, especially if the SSH service is exposed to the Internet Footnote 1 . In response to the vendor advisory released on September 3, 2026, the Cyber Centre released AV26-887 on September 8, 2026 Footnote 2 . Tracked as CVE-2026-67277 Footnote 3 , this vulnerability is a Missing Authentication for Critical Function vulnerability (CWE-306) Footnote 4 that may allow a remote attacker to obtain potentially sensitive information. Tracked as CVE-2026-86060 Footnote 5 , this vulnerability is an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability (CWE-88) Footnote 6 that may allow a remote at

    CriticalUsed in attacksCanadian Centre for Cyber SecurityMikroTik
  9. Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent

    War is peace. Freedom is slavery. Privacy is surveillance

    The RegisterApple
  10. AI lets small actors run state-level hacking campaigns, Anthropic report finds

    The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations.

    CyberScoop

About this news

1,276
Stories
25
Added in the last 24 hours
11
Critical in the last 7 days
4
Reported by several outlets