Security news

Latest security news

Wed, 2 Sept 2026

  1. Smashing Security podcast #483: This AI helps thieves steal your iPhone

    You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is not from Apple. She's not even human. And she's about to break into your iPhone. Meanwhile, OpenAI, Anthropic, and Meta have all announced - with varying degrees of drama - that their AI agents have "broken out of the sandbox" and gone hacking. James takes a step back and asks the awkward question: is this really an emergent AI apocalypse, or did they just leave the door open? All this and more in episode 483 of the "Smashing Security" podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest James Ball.

    Graham CluleyApple
  2. Claude Mythos only model to complete full cyber kill chain, experts say

    Cyber Weapon Index finds AI attacks 'imminent'

    The Register
  3. AI's Vulnerability Surge May Be More Manageable Than First Feared

    New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.

    Dark Reading
  4. SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

    The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.

    Dark ReadingSonicWall
  5. AI Gives Cybercriminals a Dangerous Time Advantage

    Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.

    Dark Reading
  6. JFrog security advisory (AV26-867) – Update 1

    Serial number: AV26-867 Date: September 1, 2026 Updated: September 2, 2026 As of August 28, 2026, JFrog is affected by a vulnerability in the following product: Artifactory Prior to 7.111.21 Prior to 7.117.28 Prior to 7.125.20 Prior to 7.133.29 Prior to 7.146.38 Prior to 7.161.20 Open-source reporting indicates that CVE-2026-82329 related to JFrog Artifactory is being exploited in the wild. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Update 1 On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-82329 to their Known Exploited Vulnerabilities (KEV) Database. Artifactory Self-Managed Releases JFrog Security Advisories CISA KEV: CVE-2026-82329

    CriticalUsed in attacksCanadian Centre for Cyber SecurityJFrog
  7. SonicWall security advisory (AV26-872) – Update 1

    Serial Number: AV26-872 Date: September 2, 2026 As of September 1, 2026, SonicWall is affected by a vulnerability in the following product: SMA1000 - 6210, 7210, 8200v 12.4.3-03453 (platform-hotfix) and older versions 12.5.0-02835 (platform-hotfix) and older versions SonicWall indicates that CVE-2026-83548 and CVE-2026-83549 are being exploited. Update 1 On September 2, 2026, Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2026-83548 and CVE-2026-83549 to their Known Exploited Vulnerabilities (KEV) Database. The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Advisory SonicWall Security Advisories CISA KEV: CVE-2026-83548 CISA KEV: CVE-2026-83549

    CriticalUsed in attacksCanadian Centre for Cyber SecuritySonicWall
  8. Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs

    Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them

    The Hacker NewsGoogle
  9. Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild

    Overview On September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549 , can be chained to achieve unauthenticated remote code execution (RCE) on affected appliances. CVE-2026-83548 is a critical pre-authentication server-side request forgery (SSRF) vulnerability in the SMA1000 Appliance Work Place interface. The flaw has a CVSS v3.1 base score of 10.0 and can allow a remote, unauthenticated attacker to access sensitive functionality and perform unauthorized operations through an unintended alternate access path. CVE-2026-83549 is a high-severity OS command injection vulnerability in the Appliance Management Console (AMC). On its own, exploitation requires an authenticated administrator and specific system conditions. Although, by leveraging the SSRF vulnerability CVE-2026-83548 an attacker could potentially exploit CVE-2026-83549 to execute arbitrary OS commands without prior authentication. SonicWall SMA1000 appliances are enterprise secure remote access gateways used to provide employees and other authorized users with acces

    CriticalUsed in attacksRapid7 BlogSonicWall

About this news

1,393
Stories
54
Added in the last 24 hours
10
Critical in the last 7 days
4
Reported by several outlets