Security news

Latest security news

Thu, 10 Sept 2026

  1. WebPros security advisory (AV26-908)

    Serial number: AV26-908 Date: September 10, 2026 As of September 10, 2026, WebPros is affected by vulnerabilities in the following products: cPanel & WebHost Manager (WHM) software Prior to 11.110.0.143 Prior to 11.134.0.55 Prior to 11.136.0.39 Prior to 11.138.0.4 Prior to WP2: 11.138.1.9 ConfigServer Security & Firewall (CSF) software Versions 14.00 to 16.29 (CVE-2026-65638) Versions 2.15 to 16.29 (CVE-2026-65639) The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel's EmailTrack Functionality - September 8, 2026 Security: CVE-2026-65638 CSF Security Release Security: CVE-2026-65639 CSF Security Release cPanel Security

    Canadian Centre for Cyber Security
  2. Cybersecurity M&A Roundup: 33 Deals Announced in August 2026

    Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.

    SecurityWeekFortinet, Palo Alto
  3. Threat groups enhance cyberattack capabilities with AI

    A report shows state-linked and criminal hackers are incorporating automation and agentic technology to find new victims and bypass traditional defenses.

    Cybersecurity Dive
  4. Adobe security advisory (AV26-808) – Update 1

    Serial number: AV26-808 Date: August 12, 2026 Updated: September 10, 2026 As of August 11, 2026, Adobe is affected by vulnerabilities in the following products: Adobe Campaign Classic Prior to or equal to ACC v7: 7.4.3 build 9399 Adobe Commerce Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-aug, 2.4.7-2026-aug, 2.4.6-2026-aug, 2.4.5-2026-aug and 2.4.4-2026-aug Adobe Commerce B2B Prior to or equal to 1.5.3-2026-jul, 1.5.2-2026-jul, 1.4.2-2026-jul, 1.3.4-2026-jul and 1.3.3-2026-jul ColdFusion 2023 Prior to or equal to 2023.0.22 ColdFusion 2025 Prior to or equal to 2025.0.11 Content Credentials Command-Line Tool Prior to or equal to c2patool-v0.27.5 Content Credentials JS SDK Prior to or equal to @contentauth/c2pa-web@0.12.0 Content Credentials Rust SDK Prior to or equal to c2pa-v0.90.5 Lightroom Classic Prior to or equal to 15.4, 15.4.1, 15.3, 15.3.1, 15.2, 15.2.1 Magento Open Source Prior to or equal to 2.4.9-2026-jul, 2.4.8-2026-jul, 2.4.7-2026-jul and 2.4.6-2026-jul Update 1 Open-source reporting indicates that CVE-2026-71362 is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as the

    CriticalCanadian Centre for Cyber SecurityAdobe
  5. AI-powered attack exploited PaperCut flaws to hack 395 organizations

    A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers.

    BleepingComputerPaperCut
  6. BlueMoon exploit kit turns Chrome and Windows flaws into attacks

    Four different espionage groups used the same exploit kit to target recently fixed flaws, showing why “patch later” is a dangerous gamble.

    Malwarebytes LabsWindows, Chrome
  7. Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers

    Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks.

    BleepingComputerCisco
  8. Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit

    The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.

    Dark ReadingMicrosoft, Windows
  9. IDScan confirms breach tied to 153 million stolen driver’s licenses

    Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans.

    BleepingComputer
  10. Anthropic Researcher Resigns With Warning About the Dangers of AI Development

    Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns.

    SecurityWeek

About this news

1,276
Stories
22
Added in the last 24 hours
10
Critical in the last 7 days
4
Reported by several outlets