Security news
Latest security news
Yesterday · Tue, 15 Sept 2026
- Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The
The Hacker NewsMicrosoft, AWS, F5 - Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
The updates resolve kernel vulnerabilities that could lead to memory corruption, privilege escalation, system termination, and information leaks.
SecurityWeekApple, iOS - Suspected Black Axe gang leaders face cybercrime charges in the US
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges.
BleepingComputer - Meta AI builds detailed profiles of children from years of family posts
A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.
Malwarebytes Labs - Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison. That should be plenty of time for him to rue the day he agreed to increase his monthly income by helping a SIM swap gang in their attempt to steal over half a million dollars. Read more in my article on the Hot for Security blog.
Graham Cluley - Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints
The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability.
SecurityWeekMicrosoft - Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack
Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.
SecurityWeekWindows - Search results are sending people to fake Bitrefill checkouts
Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.
Malwarebytes Labs - Microsoft confirms KB5002914 Excel update breaks copy and paste
Microsoft has confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 KB5002914 security update.
BleepingComputerMicrosoft - Microsoft Releases Emergency Patch to Fix RDS Snafu
Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday
Infosecurity MagazineMicrosoft
About this news
- 1,259
- Stories
- 33
- Added in the last 24 hours
- 17
- Critical in the last 7 days
- 4
- Reported by several outlets