Security news

Latest security news

Thu, 10 Sept 2026

  1. Surfshark VPN says hackers breached internal testing, proxy servers

    Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet.

    BleepingComputer
  2. Microsoft Excel KB5002914 update breaks copy and paste for some users

    Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality.

    BleepingComputerMicrosoft
  3. IDScan confirms breach after hackers offer 153 million driver’s license scans for sale

    A notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected.

    The Record
  4. Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script

    Human operator: don't touch CIS orgs. AI agents: look a squirrel!

    The RegisterPaperCut
  5. Cyber Command turns to veteran of intelligence agencies for top AI role

    Ronzelle Green, most recently a senior official at the National Geospatial-Intelligence Agency, will be U.S. Cyber Command's chief AI officer.

    The Record
  6. HPE security advisory (AV26-909)

    Serial number: AV26-909 Date: September 10, 2026 As of September 9, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: ClearPass Policy Manager (CPPM) Prior to or equal to 6.11.14 Prior to or equal to 6.12.8 HPE IceWall products Multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HPESBNW05130 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking ClearPass Policy Manager (CPPM) HPESBMU05142 rev.1 - HPE IceWall products, Remote Bypass of Security Restrictions HPESBMU05147 rev.1 - HPE IceWall products, Denial of Service vulnerability HPE Security Bulletin Library

    Canadian Centre for Cyber Security
  7. We've got one word for it, and it's usually the wrong one

    In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.

    Cisco Talos
  8. ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

    A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already

    The Hacker NewsAndroid

About this news

1,276
Stories
22
Added in the last 24 hours
11
Critical in the last 7 days
4
Reported by several outlets