Security news

Latest security news

Fri, 11 Sept 2026

  1. Ukrainian lawyer's second career as a Conti coder earns him 4 years behind bars

    Swapping legal work for malware development ended in extradition and a guilty plea

    The Register
  2. Android malware creates a hidden copy of your banking app

    The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.

    Malwarebytes LabsAndroid
  3. Accountability, oversight and AI: Inside Microsoft’s security transformation

    Stung by years of embarrassing hacks, the tech giant overhauled how it approached cybersecurity. Company leaders now say they’re seeing results.

    Cybersecurity DiveMicrosoft
  4. Ukrainian hacker gets four years in US prison over Conti ransomware attacks

    A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more than 1,000 victims worldwide before shutting down in 2022.

    The Record
  5. EU's Cyber Resilience Act starts the 24-hour vulnerability clock

    Manufacturers must now disclose actively exploited flaws and severe security incidents through ENISA's new reporting platform

    The Register
  6. Your Critical Vulnerabilities Might Not Be Your Biggest Risk

    Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker

    The Hacker News
  7. Ukrainian Conti Ransomware Developer Sentenced to 4 Years in US Prison

    Oleksii Oleksiyovych Lytvynenko has been sentenced to 4 years in prison after he was arrested in Ireland in 2023.

    SecurityWeek
  8. GitLab urges users to patch max severity path traversal flaw

    GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706.

    BleepingComputerGitLab
  9. Check Point Patches Critical VPN Vulnerabilities

    Tracked as CVE-2026-85102 and CVE-2026-85103, the flaws could be exploited for remote code execution.

    SecurityWeek
  10. Kiteworks Acquires Bonfy.AI to Fill the AI Gap in Data Governance

    Financials have not been disclosed, but the estimated cost is in the tens of millions of dollars.

    SecurityWeek

About this news

1,351
Stories
71
Added in the last 24 hours
10
Critical in the last 7 days
4
Reported by several outlets