Security news

Latest security news

Wed, 9 Sept 2026

  1. NVIDIA security advisory (AV26-900)

    Serial Number: AV26-900 Date: September 9, 2026 As of September 8, 2026, NVIDIA is affected by vulnerabilities in the following product: Triton Inference Server Versions 0.0 to 26.03 Versions 0.0 to 26.06 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Bulletin: Triton Inference Server - September 2026 NVIDIA Product Security

    Canadian Centre for Cyber SecurityNvidia
  2. CISOs are feeling the security burden of accelerated AI use

    A report shows CISOs face increased pressures related to cyber resilience and business continuity.

    Cybersecurity Dive
  3. Veradigm warns of patient data breach after ransomware gang claims attack

    Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data.

    BleepingComputer
  4. Credentialed Pre-Port Discovery: Don't Probe the Host, Ask it

    If your scan engine already holds credentials for a host, it can ask that host which ports are open instead of probing for them. Every scan begins with the same question: which ports on this host are open? Everything after it, from identifying services to checking for vulnerabilities to evaluating policy, depends on the answer being right. The traditional answer comes from the outside: the scan engine sends traffic to a range of ports and infers each port's state from how the host responds. That approach is the industry standard, and it works well when a clear network path exists between the engine and the host. Hardened hosts can stay silent rather than replying, which forces the engine to wait out timeouts. Rate limiting and intrusion prevention can throttle a burst of probes, and genuinely open ports go missing when they do. Large port ranges take time to cover thoroughly, and that time comes out of your scan window. There is a more direct route on any host where the scan engine already holds valid credentials: ask the host itself. This is credentialed discovery, so a credential that matches the host is the precondition for everything that follows. The engine connects to the por

    Rapid7 Blog
  5. FBI cyber chief worries private sector not sharing enough cyber threat information

    Brett Leatherman said that industry has the wrong idea about what the FBI does with the data it collects during incidents, which is used to help victims and investigations alike.

    CyberScoop
  6. More than 100,000 fake stores are out to steal your card details

    DoppelCart’s fake stores copy real retailers and steal shoppers’ card details and one-time bank confirmation codes.

    Malwarebytes Labs
  7. Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls

    The hacking tool, built using a combination of AI models, is effective against Android and iOS devices

    Infosecurity MagazineAndroid, iOS
  8. New FBI cyber strategy promises increase in adversary disruptions

    The document also focuses on helping victims, reflecting the bureau’s goal of encouraging more companies to share information with it.

    Cybersecurity Dive
  9. Identity-Based AI Attack Threatens Security of Enterprise Data

    "Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.

    Dark Reading
  10. Gigabud Uses Android App Cloning to Evade Fraud Detection

    Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud

    Infosecurity MagazineAndroid

About this news

1,425
Stories
66
Added in the last 24 hours
10
Critical in the last 7 days
4
Reported by several outlets