Security news

Latest security news

Tue, 1 Sept 2026

  1. Attackers Pounce on Critical Artifactory Bug Following Disclosure

    CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems.

    CriticalUsed in attacksDark ReadingJFrog
  2. Stronger Security Drives Ransomware Groups to Recruit From Within

    Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.

    Dark Reading
  3. Critical Langflow Vulnerability Exploited as Attacks on AI Platform Rise

    The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year.

    Dark Reading
  4. Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks

    The model provider gave METR the credits for free. An actual customer would not have been so lucky

    The Register
  5. Firefox helps iPhone users bypass ads on web sites while making money showing its own ads

    Baked-in Firefox ad blocking on iOS begins rolling out slowly today, and is off by default

    The RegisteriOS, Firefox
  6. AI Model Evaluator METR Hit by Credential Theft, Probing

    In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.

    Dark Reading
  7. Erlang security advisory (AV26-870)

    Serial number: AV26-870 Date: September 1, 2026 As of September 1, 2026, Erlang is affected by vulnerabilities in the following product: OTP - Multiple versions The Cyber Centre encourages users and administrators to review the provided web link and apply the necessary updates. Erlang Security Advisories

    Canadian Centre for Cyber Security
  8. Rockwell Automation security advisory (AV26-869)

    Serial number: AV26-869 Date: September 1, 2026 As of September 1, 2026, Rockwell Automation is affected by vulnerabilities in the following products: 1756-ENBT Module All versions ArmorStart LT Prior to or equal to v2.001 CompactLogix 5380 / ControlLogix 5580 Prior to or equal to V33 V34.011 to V34.014 V35.011 to V35.013 V36.011 to V36.012 RSLinx Classic Prior to or equal to V4.50 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. SD1797 | Security Advisory | Rockwell Automation | US SD1798 | Security Advisory | Rockwell Automation | US SD1794 | Security Advisory | Rockwell Automation | US SD1792 | Security Advisory | Rockwell Automation | US

    Canadian Centre for Cyber Security
  9. Mozilla security advisory (AV26-868)

    Serial number: AV26-868 Date: September 1, 2026 As of September 1, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox ESR Versions prior to 115.40 Versions prior to 140.15 Versions prior to 153.2 Firefox Versions prior to 155 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Vulnerabilities fixed in Firefox ESR 115.40 — Mozilla Security Vulnerabilities fixed in Firefox ESR 140.15 — Mozilla Security Vulnerabilities fixed in Firefox ESR 153.2 — Mozilla Security Vulnerabilities fixed in Firefox 155 — Mozilla Mozilla Foundation Security Advisories — Mozilla

    Canadian Centre for Cyber SecurityFirefox

About this news

1,383
Stories
68
Added in the last 24 hours
10
Critical in the last 7 days
4
Reported by several outlets