Security news
Latest security news
Wed, 9 Sept 2026
- Commvault security advisory (AV26-899)
Serial Number: AV26-899 Date: September 9, 2026 Commvault security advisory (AV26-899) As of September 8, 2026, Commvault is affected by vulnerabilities in the following product: Commvault Cloud 36.0 Prior to 11.36.123 40.0 Prior to 11.40.72 44.0 Prior to 11.44.20 46.0 Prior to 11.46.20 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. Commvault Cloud Security Advisories
Canadian Centre for Cyber Security - Fortinet security advisory (AV26-898)
Serial Number: AV26-898 Date: September 9, 2026 As of September 8, 2026, Fortinet is affected by vulnerabilities in the following products: FortiOS 7.6 Versions 7.6.1 to 7.6.6 FortiProxy 7.6 Versions 7.6.2 to 7.6.6 FortiPAM Chrome Extension 8.0 All versions FortiPAM Chrome Extension 7.4 All versions FortiSandbox 5.0 Versions 5.0.0 to 5.0.5 FortiSandbox 4.4 Versions 4.4.0 to 4.4.8 FortiSandbox Cloud 5.0 Versions 5.0.4 to 5.0.5 FortiSandbox PaaS 5.0 Versions 5.0.4 to 5.0.5 FortiMonitorOnSight 7.2 Versions 7.2.4 to 7.2.7 FortiMonitorOnSight 7.2 Versions 7.2.0 to 7.2.2 The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. Fortinet PSIRT Advisories
Canadian Centre for Cyber SecurityFortinet, Chrome - ClickFix Moves into the Browser to Steal Cryptocurrency
ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency
Infosecurity MagazineGoogle - FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy.
CyberScoop - NHIs Now the Number One Corporate Entry Point for Hackers
SpyCloud claims non-human identities are the most likely route into the enterprise
Infosecurity Magazine - WeChat worm could pwn a friend before they even answered the call
Calif says AI helped turn a VoIP memory bug into cross-platform RCE before Tencent shut it down
The Register - Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more
The Hacker News - DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web
The Hacker News - Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through
The Hacker News - Over 36,000 exposed Plex servers vulnerable to recent flaws
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks.
BleepingComputer
About this news
- 1,393
- Stories
- 43
- Added in the last 24 hours
- 10
- Critical in the last 7 days
- 4
- Reported by several outlets