Security news

Latest security news

Fri, 11 Sept 2026

  1. Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

    CriticalUsed in attacksThe Hacker NewsCisco
  2. ISC Stormcast For Friday, September 11th, 2026 https://isc.sans.edu/podcastdetail/10090, (Fri, Sep 11th)

    (c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

    SANS Internet Storm Center
  3. Indonesia Hit by Android Banking App-Cloning Campaign

    The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.

    Dark ReadingAndroid

Thu, 10 Sept 2026

  1. Latest Anthropic horror story chills with tales of kamikaze drone swarms and bioweapons research

    Everyone from ShinyHunters to Russian freelancers is in on the illicit model fun

    The Register
  2. New Android malware encrypts files, steals data, and harasses victims

    A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims.

    BleepingComputerAndroid
  3. Treasury urges banks to file cyber scam reports, noting nearly $13 billion in losses since 2023

    As the cyber scam industry expands globally, the U.S. government wants banks to share more information about what's happening to their customers.

    The Record
  4. Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

    Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.

    Dark ReadingMicrosoft
  5. September Windows Server updates break Remote Desktop Services

    Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality.

    BleepingComputerWindows
  6. Conti ransomware crew member sentenced to four years in prison

    Oleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies.

    CyberScoop
  7. Mandiant Founder Kevin Mandia Joins Amazon Board

    Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board.

    SecurityWeekAmazon

About this news

1,351
Stories
65
Added in the last 24 hours
10
Critical in the last 7 days
4
Reported by several outlets