Security news
Latest security news
Yesterday · Tue, 15 Sept 2026
- Microsoft Issues Emergency Fixes After Massive Patch Tuesday
You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
Dark ReadingMicrosoft - Norway announces investigations into telecom Telenor’s work with Myanmar junta
Oslo-based Telenor potentially enabled crimes against humanity and violated sanctions in its dealings with the military regime that took over Myanmar in 2021, Norwegian authorities said.
The Record - What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies
Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned.
CyberScoop - Low-quality casino sites conceal highly dangerous threat actors
Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites
The Register - “We Think the Security Control Is Working” Is No Longer Good Enough
Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today.
SecurityWeek - Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident
The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, and alignment. Throughout the session, they will share insights that address key topics raised by the Black Hat Review Board, including model safeguards, evaluation and containment practices, defensive use cases for AI, and the broader implications of increasingly autonomous systems for the cybersecurity community. The session will trace the models' attack path, including how frontier models are sandboxed during evaluations, how the models exploited a zero-day vulnerability to gain internet access, and how they identified and leveraged a remote code execution path on Hugging Face infrastructure. Drawing on the joint investigation, the speakers will explain how the activity was detected, contained, and investigated. They will also discuss the changes OpenAI is making to strengthen evaluation environments, containment controls, and monitoring capabilities, as well as the role AI systems pl
Dark Reading - Docker security advisory (AV26-925)
Serial Number: AV26-925 Date: September 15, 2026 As of September 15, 2026, Docker is affected by a vulnerability in the following product: Docker Sandboxes Prior to 0.43.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Docker sbx-releases Docker security announcements
Canadian Centre for Cyber SecurityDocker - Mozilla security advisory (AV26-924)
Serial Number: AV26-924 Date: September 15, 2026 As of September 15, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox ESR Versions prior to 115.41 Versions prior to 140.16 Versions prior to 153.3 Firefox Versions prior to 156 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Vulnerabilities fixed in Firefox 156 — Mozilla Security Vulnerabilities fixed in Firefox ESR 115.41 — Mozilla Security Vulnerabilities fixed in Firefox ESR 140.16 — Mozilla Security Vulnerabilities fixed in Firefox ESR 153.3 — Mozilla Mozilla Foundation Security Advisories — Mozilla
Canadian Centre for Cyber SecurityFirefox - KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
The Hacker NewsGoogle, Chrome - Iranian spies hit Windows machines with Chosen Brick data-stealing malware
'Enemies of the regime' on notice
The RegisterWindows
About this news
- 1,256
- Stories
- 42
- Added in the last 24 hours
- 19
- Critical in the last 7 days
- 4
- Reported by several outlets