Security news

Latest security news

71 of 1,256 storiesAWSClear all

Yesterday · Tue, 15 Sept 2026

  1. $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

    AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage.

    SecurityWeekLinux
  2. Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

    Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs. The

    The Hacker NewsMicrosoft, AWS, F5
  3. Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints

    The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability.

    SecurityWeekMicrosoft
  4. China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

    A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

    The Hacker NewsGoogle, Microsoft, Windows

Mon, 14 Sept 2026

  1. Hackers target exposed Vite dev servers to steal AWS, Azure secrets

    A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments.

    BleepingComputerAWS

Sat, 12 Sept 2026

  1. CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. Details of the vulnerabilities are as follows - CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization

    HighThe Hacker NewsJFrog
  2. Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

    The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103.

    BleepingComputer

Fri, 11 Sept 2026

  1. GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

    GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under

    The Hacker NewsGitLab
  2. Artifactory flaws chained in attacks deploying backdoor malware

    Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers.

    BleepingComputer
  3. The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)

    I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own.

    SANS Internet Storm Center

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets