Security news

Latest security news

Fri, 11 Sept 2026

  1. In Other News: InjectEave Attack, SIM Swapper Sentenced, Glasswing Findings Review

    Noteworthy stories that might have slipped under the radar: Invisible Unicode slips past phishing filters, US puts $10 million bounty on Iranian cyber official, military ties of Chinese hacking group QTFY.

    SecurityWeek
  2. Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

    Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight

    The Hacker News
  3. How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

    Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures.

    BleepingComputer
  4. MongoDB security advisory (AV26-911)

    Serial Number: AV26-911 Date: September 11, 2026 As of September 10, 2026, MongoDB is affected by vulnerabilities in the following products: Java Driver Prior to 5.11.1 Laravel MongoDB (PHP) Prior to 5.11.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. [PHPLARA-260] Query builder: force literal equality when 3-arg where uses '=' with an array value [JAVA-6276] Native heap use-after-free via cancellation racing KMS credential fetch in reactive encryption Alerts | MongoDB

    Canadian Centre for Cyber Security
  5. Metasploit Wrap Up: This One Goes to Sixteen!

    This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739 contributed by kmkz Path: scanner/http/elasticsearch_tika_xfa_xxe CVE reference: CVE-2025-66516 Description: Adds an auxiliary scanner module for CVE-2025-54988/CVE-2025-66516. The module validates an XML External Entity (XXE) vulnerability in Apache Tika's XFA parser exposed through the Elasticsearch attachment ingest processor. SPIP Unauthenticated Blind SQLi via Date Field Escaping Bypass Authors: Benoit Hua, Franck Chevalier, Julien Voisin, and ka3n1x Type: Auxiliary Pull request: #21791 contributed by jvoisin Path: scanner/http/spip_annee_sqli Description: Adds modules/auxiliary/scanner/http/spip_annee_sqli.rb which exploits a blind SQL injection in SPIP's date column escaping logic. M

    Rapid7 BlogPaperCut, SonicWall, Cisco
  6. The Fraud Ecosystem: A Transition From Known Marketplaces to a Fragmented Environment

    Introduction The surge in emerging threat actors directly correlates with the rapid escalation of victim counts and stolen financial resources. Simultaneously, this growth has spurred the proliferation of specialized supply storefronts across social media platforms, dark web channels, and various smaller niche marketplaces. Security teams today face evolving challenges, requiring them to continuously refine monitoring channels, adjust operational strategies, and foster cross-functional internal collaboration to capture actionable intelligence. With fraud damages anticipated to approach hundreds of billions of USD , security teams must navigate numerous non-compliant channels while ingesting and processing diverse data formats—such as documents, imagery, video, and unformatted text—linked to organizational assets. The recent introduction of a new Fraud framework by the MITRE organization underscores the critical need to combat fraud and highlights the significant danger these threat actors pose to all organizations. The MITRE organization has been taking a positive step towards standardizing the fight against fraud, while helping organizations target the relevant directions to look

    Rapid7 Blog
  7. Hackers Favor US Eastern Business Hours in M365 Phishing Campaign

    KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails

    Infosecurity MagazineMicrosoft
  8. HashiCorp security advisory (AV26-910)

    Serial Number: AV26-910 Date: September 11, 2026 As of September 10, 2026, HashiCorp is affected by vulnerabilities in the following products: Consul Prior to 2.0.4 Consul Enterprise 1.0 Prior to 1.21.18 21.0 Prior to 1.21.18 9.0 Prior to 1.21.18 consul-template Prior to 0.43.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HCSEC-2026-34 - Consul vulnerable to an authorization bypass in the catalog node-write path HCSEC-2026-38 - Consul-template vulnerable to an information disclosure issue in error handling HCSEC-2026-37 - Consul vulnerable to an authorization bypass in the Connect service mesh Security - HashiCorp Discuss

    Canadian Centre for Cyber Security
  9. Trezor Says 347,000 Users Received Phishing Emails After Brevo Hack

    Hackers compromised the Brevo marketing platform and used that access to send phishing emails to users of Trezor, BitBox, and CoinTracking.

    SecurityWeek
  10. Anthropic caught Russia-linked spies using Claude in hacking operations

    Anthropic detected and disrupted a Russia-linked cyber-espionage group that used its AI tool Claude in a hacking campaign targeting more than 20 government, intelligence, diplomatic and defense organizations.

    The Record

About this news

1,351
Stories
74
Added in the last 24 hours
11
Critical in the last 7 days
4
Reported by several outlets