Security news

Latest security news

Thu, 10 Sept 2026

  1. Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

    Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their

    The Hacker NewsGoogle, Android
  2. PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector

    Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g. ”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. An LLM with limited

    Check Point Research
  3. Hacker Conversations: Vinnie Liu, Performer Turned Ringmaster

    Vinnie Liu was recruited by the NSA when he was just 17 years old. He is now the CEO of Bishop Fox.

    SecurityWeek
  4. White House sees water cybersecurity partnership in Texas as national blueprint

    The government is taking a new approach to protecting critical infrastructure, National Cyber Director Sean Cairncross said.

    Cybersecurity Dive
  5. CISA is on the verge of filling hundreds of critical vacancies

    The agency is also working to finalize an incident-reporting regulation and set up a new industry coordination structure, its acting director said.

    Cybersecurity Dive
  6. New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws

    Multiple cyber-espionage groups deployed an exploit kit dubbed "BlueMoon" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome.

    BleepingComputerGoogle, Microsoft, Windows
  7. The Top 4 Threats We Found by Investigating Every Alert for a Quarter

    Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked.

    BleepingComputer
  8. CISA Updates Insider Threat Guide With New Mitigation Advice

    CISA has updated its insider threat guide with new advice on remote work, AI and risk detection

    Infosecurity Magazine
  9. Governments ‘buying time’ in race between innovation, security, national cyber director says

    Sean Cairncross also said AI has shown long-standing issues in cyber rather than creating new ones.

    CyberScoop

About this news

1,276
Stories
20
Added in the last 24 hours
10
Critical in the last 7 days
4
Reported by several outlets