Security news
Latest security news
Thu, 10 Sept 2026
- IDScan confirms breach after hackers offer 153 million driver’s license scans for sale
A notice dated September 4 but not widely shared shows that IDScan acknowledged a data breach but did not specify how many people were affected.
The Record - Hundreds of AI agents helped PaperCut attacker hit 395+ orgs, and some went off script
Human operator: don't touch CIS orgs. AI agents: look a squirrel!
The RegisterPaperCut - Cyber Command turns to veteran of intelligence agencies for top AI role
Ronzelle Green, most recently a senior official at the National Geospatial-Intelligence Agency, will be U.S. Cyber Command's chief AI officer.
The Record - HPE security advisory (AV26-909)
Serial number: AV26-909 Date: September 10, 2026 As of September 9, 2026, Hewlett Packard Enterprise (HPE) is affected by vulnerabilities in the following products: ClearPass Policy Manager (CPPM) Prior to or equal to 6.11.14 Prior to or equal to 6.12.8 HPE IceWall products Multiple versions and models The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. HPESBNW05130 rev.1 - Multiple Vulnerabilities in HPE Aruba Networking ClearPass Policy Manager (CPPM) HPESBMU05142 rev.1 - HPE IceWall products, Remote Bypass of Security Restrictions HPESBMU05147 rev.1 - HPE IceWall products, Denial of Service vulnerability HPE Security Bulletin Library
Canadian Centre for Cyber Security - We've got one word for it, and it's usually the wrong one
In this week's Threat Source newsletter, Joe explores why the word "burnout" often fails to capture the true toll of working in the cybersecurity industry and why we need better language to address it.
Cisco Talos - ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already
The Hacker NewsAndroid - WebPros security advisory (AV26-908)
Serial number: AV26-908 Date: September 10, 2026 As of September 10, 2026, WebPros is affected by vulnerabilities in the following products: cPanel & WebHost Manager (WHM) software Prior to 11.110.0.143 Prior to 11.134.0.55 Prior to 11.136.0.39 Prior to 11.138.0.4 Prior to WP2: 11.138.1.9 ConfigServer Security & Firewall (CSF) software Versions 14.00 to 16.29 (CVE-2026-65638) Versions 2.15 to 16.29 (CVE-2026-65639) The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security: CVE-2026-67401 SQL Injection Vulnerability in cPanel's EmailTrack Functionality - September 8, 2026 Security: CVE-2026-65638 CSF Security Release Security: CVE-2026-65639 CSF Security Release cPanel Security
Canadian Centre for Cyber Security - Cybersecurity M&A Roundup: 33 Deals Announced in August 2026
Significant cybersecurity M&A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.
SecurityWeekFortinet, Palo Alto - Threat groups enhance cyberattack capabilities with AI
A report shows state-linked and criminal hackers are incorporating automation and agentic technology to find new victims and bypass traditional defenses.
Cybersecurity Dive
About this news
- 1,354
- Stories
- 65
- Added in the last 24 hours
- 10
- Critical in the last 7 days
- 4
- Reported by several outlets