Security news
Latest security news
Yesterday · Tue, 15 Sept 2026
- Most Firms Unable to Recover Quickly from Ransomware
Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours
Infosecurity Magazine - IBM security advisory (AV26-922)
Serial number: AV26-922 Date: September 15, 2026 As of September 14, 2026, IBM is affected by vulnerabilities in the following products: Langflow OSS Prior to or equal to 1.10.0 Prior to or equal to 1.10.2 Prior to or equal to 1.11.2 Prior to or equal to 1.11.5 MQ 10.0.0.0 Prior to or equal to 9.1.0.37 LTS Prior to or equal to 9.2.0.43 LTS Prior to or equal to 9.3.0.41 LTS Prior to or equal to 9.3.5.1 CD Prior to or equal to 9.4.0.25 LTS Prior to or equal to 9.4.5.1 CD Sterling File Gateway Prior to or equal to 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. Incomplete Security Scanner Blocklist Enables Network-Based Code Execution IBM MQ Java messaging is vulnerable to remote code execution (CVE-2026-13293) IBM Sterling File Gateway is Vulnerable to Improper Access Control (CVE-2026-19290) IBM Product Security Incident Response
HighCanadian Centre for Cyber SecurityIBM - Electric and gas utility CenterPoint Energy warns of data breach after dark web post
Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.
The Record - What Zero-Day Response Should Be in the Post-Mythos Era
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive.
BleepingComputer - Black Axe Members Extradited to US Over Internet Fraud Claims
Alleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claims
Infosecurity Magazine - Thai Broadband Provider Hacked via Fortinet Vulnerability
The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools.
SecurityWeekFortinet - Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler
The man allegedly wrote the code that powered the Lockergoga, MegaCortex, and Nefilim operations
The Register - AI the Top Priority for New Spend as Cyber Budgets Flatline
IANS finds AI is dominating net-new budgets even as overall funding for the function is flat
Infosecurity Magazine - China spy chief points at US AI models in cyber threat warning
China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.
The Record - OpenAI Investigates Report Linking AI Agents to RubyGems Attack
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity.
SecurityWeek
About this news
- 1,256
- Stories
- 35
- Added in the last 24 hours
- 18
- Critical in the last 7 days
- 4
- Reported by several outlets