Security news

Latest security news

Yesterday · Tue, 15 Sept 2026

  1. Most Firms Unable to Recover Quickly from Ransomware

    Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours

    Infosecurity Magazine
  2. IBM security advisory (AV26-922)

    Serial number: AV26-922 Date: September 15, 2026 As of September 14, 2026, IBM is affected by vulnerabilities in the following products: Langflow OSS Prior to or equal to 1.10.0 Prior to or equal to 1.10.2 Prior to or equal to 1.11.2 Prior to or equal to 1.11.5 MQ 10.0.0.0 Prior to or equal to 9.1.0.37 LTS Prior to or equal to 9.2.0.43 LTS Prior to or equal to 9.3.0.41 LTS Prior to or equal to 9.3.5.1 CD Prior to or equal to 9.4.0.25 LTS Prior to or equal to 9.4.5.1 CD Sterling File Gateway Prior to or equal to 6.2.0.6_1, 6.2.1.0 - 6.2.1.2, 6.2.2.0 - 6.2.2.1 The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. Incomplete Security Scanner Blocklist Enables Network-Based Code Execution IBM MQ Java messaging is vulnerable to remote code execution (CVE-2026-13293) IBM Sterling File Gateway is Vulnerable to Improper Access Control (CVE-2026-19290) IBM Product Security Incident Response

    HighCanadian Centre for Cyber SecurityIBM
  3. Electric and gas utility CenterPoint Energy warns of data breach after dark web post

    Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.

    The Record
  4. What Zero-Day Response Should Be in the Post-Mythos Era

    AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive.

    BleepingComputer
  5. Black Axe Members Extradited to US Over Internet Fraud Claims

    Alleged Black Axe leaders extradited to the US over romance scams, BEC and money laundering claims

    Infosecurity Magazine
  6. Thai Broadband Provider Hacked via Fortinet Vulnerability

    The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools.

    SecurityWeekFortinet
  7. Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler

    The man allegedly wrote the code that powered the Lockergoga, MegaCortex, and Nefilim operations

    The Register
  8. AI the Top Priority for New Spend as Cyber Budgets Flatline

    IANS finds AI is dominating net-new budgets even as overall funding for the function is flat

    Infosecurity Magazine
  9. China spy chief points at US AI models in cyber threat warning

    China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.

    The Record
  10. OpenAI Investigates Report Linking AI Agents to RubyGems Attack

    The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity.

    SecurityWeek

About this news

1,256
Stories
35
Added in the last 24 hours
18
Critical in the last 7 days
4
Reported by several outlets