Security news

Latest security news

Thu, 10 Sept 2026

  1. September Windows Server updates break Remote Desktop Services

    Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality.

    BleepingComputerWindows
  2. Conti ransomware crew member sentenced to four years in prison

    Oleksii Lytvynenko joined the notorious group in 2021 and was directly involved in attacks on at least 12 companies.

    CyberScoop
  3. Mandiant Founder Kevin Mandia Joins Amazon Board

    Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board.

    SecurityWeekAmazon
  4. Hawley probes OpenAI over Hugging Face breach

    The Republican lawmaker called OpenAI’s leadership decisions “reckless,” and used recent warnings about the existential risk of AI to bolster his inquiry.

    CyberScoop
  5. AL26-020 - Vulnerabilities Impacting MikroTik RouterOS - CVE-2026-67276, CVE-2026-67277 and CVE-2026-86060

    Number: AL26-020 Date: September 10, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to recipients. The Canadian Centre for Cyber Security ("Cyber Centre") is also available to provide additional assistance regarding the content of this Alert to recipients as requested. Details The Cyber Centre is aware of vulnerabilities impacting MikroTik RouterOS devices, especially if the SSH service is exposed to the Internet Footnote 1 . In response to the vendor advisory released on September 3, 2026, the Cyber Centre released AV26-887 on September 8, 2026 Footnote 2 . Tracked as CVE-2026-67277 Footnote 3 , this vulnerability is a Missing Authentication for Critical Function vulnerability (CWE-306) Footnote 4 that may allow a remote attacker to obtain potentially sensitive information. Tracked as CVE-2026-86060 Footnote 5 , this vulnerability is an Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability (CWE-88) Footnote 6 that may allow a remote at

    CriticalUsed in attacksCanadian Centre for Cyber SecurityMikroTik
  6. Watch out: Apple timepiece can grab snippets of conversation without both speakers' consent

    War is peace. Freedom is slavery. Privacy is surveillance

    The RegisterApple
  7. AI lets small actors run state-level hacking campaigns, Anthropic report finds

    The report details a Russian-aligned espionage campaign against more than 20 organizations, an exploit foundry run by Chinese undergraduates and ShinyHunters-affiliated breaches, among other disrupted operations.

    CyberScoop
  8. Surfshark VPN says hackers breached internal testing, proxy servers

    Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet.

    BleepingComputer
  9. Microsoft Excel KB5002914 update breaks copy and paste for some users

    Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality.

    BleepingComputerMicrosoft

About this news

1,354
Stories
66
Added in the last 24 hours
10
Critical in the last 7 days
4
Reported by several outlets