Security news

Latest security news

Yesterday · Tue, 15 Sept 2026

  1. AI the Top Priority for New Spend as Cyber Budgets Flatline

    IANS finds AI is dominating net-new budgets even as overall funding for the function is flat

    Infosecurity Magazine
  2. China spy chief points at US AI models in cyber threat warning

    China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.

    The Record
  3. OpenAI Investigates Report Linking AI Agents to RubyGems Attack

    The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity.

    SecurityWeek
  4. Manhattan DA takes down 12 AI deepfake porn sites

    Manhattan District Attorney Alvin Bragg held a press conference on Monday touting the takedown of the sites, which hosted AI-generated videos of more than 1,200 people. The sites allowed users to use the faces and bodies of real people to create illegal pornography.

    The Record
  5. CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

    Overview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and business email compromise. Because affected gateways process externally delivered email as part of their normal operation, exploitation does not require access to an administrative interface or authentication. An attacker can reportedly trigger the vulnerability by sending a specially crafted email through a vulnerable gateway. CVE-2026-76461 was added to CISA's Known Exploited Vulnerabilities ( KEV ) catalog on the same day as the vendor disclosed the vulnerability, indicating that CVE-2026-76461 was exploited as a zero-day prior to disclosure. Cisco noted that their PSIRT became aware of active

    CriticalUsed in attacksRapid7 BlogCisco
  6. CISA: Critical VMware RCE flaw now exploited by ransomware gangs

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.

    BleepingComputerVMware
  7. Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

    With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH

    The Hacker News
  8. HBO Max’s verified Reddit account hijacked to spread malware

    Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.

    Malwarebytes Labs
  9. 240,000 Hit by Data Breach at Japan’s Digital Agency

    Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

    SecurityWeek
  10. Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

    Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise. But no matter how much you validate against these

    The Hacker News

About this news

1,259
Stories
34
Added in the last 24 hours
17
Critical in the last 7 days
4
Reported by several outlets