Security news
Latest security news
Thu, 3 Sept 2026
- Your phone or computer may soon ask how old you are
California and Colorado will require operating systems to collect users’ ages, but open-source software like Linux may be exempt.
Malwarebytes LabsLinux - Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an iMessage zero-click exploit was used to infect the device with NSO Group's Pegasus spyware," the Citizen Lab said. "We found high-confidence indicators of
The Hacker News - International Operation Disrupts Sality P2P Botnet
US-led action sinkholes machines caught up in Sality botnet
Infosecurity Magazine - Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
They had more access than the average Joe, and IT didn't track what needed to be cut off
The Register - To keep the AI hacking genie bottled up, try one-way networks
Sandboxes, permissions, and VMs aren't enough to keep frontier models at bay. "Data diodes" might do the job
The Register - Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a proof-of-concept (PoC) for a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0-day privilege escalation that abuses the office malicious macros remediation in CrowdStrike Falcon Sensor," the researcher said in
The Hacker News - CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows - CVE-2026-83548 (CVSS score: 10.0) - A server-side request forgery vulnerability in SonicWall SMA 1000 Appliances that could allow a remote unauthenticated
CriticalUsed in attacksThe Hacker NewsSonicWall - Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
SANS Internet Storm Center - ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
SANS Internet Storm Center
About this news
- 1,393
- Stories
- 48
- Added in the last 24 hours
- 10
- Critical in the last 7 days
- 4
- Reported by several outlets