Security news

Latest security news

Wed, 9 Sept 2026

  1. Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

    Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through

    The Hacker News
  2. Over 36,000 exposed Plex servers vulnerable to recent flaws

    Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks.

    BleepingComputer
  3. Microsoft fixes record 964 flaws, including 2 exploited zero-days

    Microsoft’s September 2026 Patch Tuesday fixes a record 964 vulnerabilities, including two actively exploited zero-days.

    Malwarebytes LabsMicrosoft
  4. Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure

    An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks.

    Unit 42
  5. Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026

    The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates

    Infosecurity MagazineMicrosoft
  6. U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

    U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to

    The Hacker News
  7. Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

    Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to

    The Hacker NewsGoogle, Chrome
  8. Safe word: What is it and why do you need one?

    AI scams are now hyper-realistic. But there’s one simple way to see through them.

    WeLiveSecurity
  9. Man gets 15 years for extorting women with AI-generated porn videos

    An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content.

    BleepingComputer
  10. CRPx0 ransomware: what you need to know

    CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog.

    Graham Cluley

About this news

1,425
Stories
60
Added in the last 24 hours
10
Critical in the last 7 days
4
Reported by several outlets