Security news
Latest security news
Thu, 10 Sept 2026
- New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender
The exploit provides full System privileges on Windows machines running the September 2026 patches.
SecurityWeekMicrosoft, Windows - Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached "
The Hacker News - Dental contractor set up secret account with access to 4,000 patient records then left the company
Toothless security
The Register - EU Cyber Resilience Act to Enforce New Reporting Requirements
Starting Friday, businesses operating in the EU will have just 24 hours to notify the government any time they discover serious product security incidents.
Dark Reading - Trezor warns users of email provider breach, phishing attacks
Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks.
BleepingComputer - Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks
The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026.
SecurityWeekFortinet - Product showcase: GitGuardian Honeytoken catches credential theft as it happens
Credential harvesting on developer machines has widened. Earlier infostealers worked from a short list of known targets, mostly browser stores and a few cloud credential paths. The families active now cast a much wider net. Shai-Hulud, for instance, ran a secret scanner across the entire filesystem and validated whatever it turned up, rather than checking a handful of expected locations. That breadth is what makes deception practical, and the speed is what makes it urgent. … More →
Help Net Security - Cybercriminals are building phishing pages that exist only inside victims’ browsers
A phishing campaign routes victims through genuine Microsoft OAuth and Teams infrastructure before showing them a fake login page built entirely inside their own browser, according to researchers at Barracuda. “Instead of delivering a phishing page from a web server, the malicious content is assembled inside the victim’s browser using a blob URL — a temporary browser-generated URL that points to content stored locally in memory rather than on a website,” researchers explained. The attack … More →
Help Net SecurityMicrosoft, Barracuda - AI adoption brings new security headaches for already stretched CISOs
CISOs are taking on AI governance without a matching increase in resources or expertise, adding to an already broad remit spanning data protection, identity, resilience and compliance, according to Proofpoint’s 2026 Voice of the CISO report. The Al mandate expands faster than resources (Source: Proofpoint) AI adds to security responsibilities GenAI is creating new concerns around sensitive data, access and employee activity. Seventy-eight percent of CISOs consider it a security risk, with the potential loss … More →
Help Net Security - A new open standard locks AI weights to approved hardware
OPAQUE, a confidential computing company that runs AI workloads inside hardware-isolated environments so operators cannot inspect them, released an open standard that lets AI model builders decide when and where their weights can be decrypted once those weights leave the builder’s own servers. The standard, called Weight Custody Manifest, ships as a developer-preview specification, a Python SDK, and a public test suite covering 91 cases. The release targets a specific squeeze. Enterprises are fine-tuning open … More →
Help Net Security
About this news
- 1,383
- Stories
- 76
- Added in the last 24 hours
- 10
- Critical in the last 7 days
- 4
- Reported by several outlets