Security news
Latest security news
Wed, 9 Sept 2026
- Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
The Hacker NewsGoogle - U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to
The Hacker News
Tue, 8 Sept 2026
- Microsoft Plugs Nearly 1,000 Security Holes
Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.
Krebs on SecurityMicrosoft, Windows - CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The deputy director cited Operation Absolute Resolve as evidence that cyber teams have become central to CIA missions.
CyberScoop - JetBrains security advisory (AV26-891)
Serial Number: AV26-891 Date: September 8, 2026 As of September 7, 2026, JetBrains is affected by vulnerabilities in the following products: GoLand Prior to 2026.2.2.1 Hub Prior to 2026.2.52442 IntelliJ IDEA Prior to 2026.2.2 YouTrack Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Fixed security issues
Canadian Centre for Cyber Security - Dell security advisory (AV26-886)
Serial Number: AV26-886 Date: September 8, 2026 As of September 7, 2026, Dell is affected by vulnerabilities in the following products: Dell OpenManage Network Integration Prior to 3.10 or later Dell iDRAC9 Versions prior to 7.30.10.50 and 7.00.00.184 Dell iDRAC10 Prior to 1.30.30.50 or later Dell PowerEdge Server for Intel 2026 Multiple versions and models Dell Open Manage Python SDK (omsdk) Prior to 1.2.519 or later Dell Avamar Multiple versions Dell Networker Virtual Edition (NVE) Multiple versions Dell PowerProtect DP Series Appliance Multiple versions Dell Integrated Data Protection Appliance (IDPA) Multiple versions Dell PowerScale OneFS Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Security Advisories, Notices and Resources | Dell Canada
Canadian Centre for Cyber SecurityDell, Intel - Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI
The Hacker NewsGoogle
Mon, 7 Sept 2026
- 7th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 7th Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Thomson Reuters, a global information and technology company, has disclosed a breach of its C-Track court case-management platform affecting courts across 11 US states and Canada. An unauthorized party obtained C-Track files
Check Point Research
Sun, 6 Sept 2026
Fri, 4 Sept 2026
- Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian.
BleepingComputerCitrix
About this news
- 1,256
- Stories
- 35
- Added in the last 24 hours
- 18
- Critical in the last 7 days
- 4
- Reported by several outlets