jakob@nyx:~/news$ feed --live --filter breach,ransomware,zero-day
4138 articles indexed • refreshes every 15m • 6 sources active
OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union. [...]

ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes

The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.

Rejetto HFS servers now actively scanned for critical RCE flaw

Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]

IQVIA fined $7.8 million for failing to properly anonymize health data

Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. [...]

Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940, is rated 8.8 on the CVSS scoring system. "Weak authorization in Microsoft Exchange Server allows an authenticated attacker to elevate privileges over a

Chinese Hackers Impersonate US Officials for AI Cyber Espionage

An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.

Denmark population registry data breach affects 8.8 million people

Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]

New Dell System Update flaw lets hackers gain root privileges

Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. [...]

Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP). The post Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports appeared first on SecurityWeek.

South Korea probes bank breaches amid suspected AI-powered attacks

South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. [...]

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. There are actively exploited bugs in the mix, cleaner intrusion paths, smarter automation, and a long patch list waiting behind them. Some attacks are getting more capable. Others

tenfold CE: Our free Identity Governance tool just got 2 new features

tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate suspicious identity activity. [...]

Alleged dev of Ploutus ATM malware appears in US court after arrest

The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]

Need for Speed: AI-Driven Attacks Are Changing Security Strategies

AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.

Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation. The post Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws appeared first on SecurityWeek.

250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

Hackers stole patient information from Clover Health Investments and AngMar Management Services in July. The post 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms appeared first on SecurityWeek.

The Credential Layer Is Expanding Faster Than Security Teams Can See It

Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect, Remediate, and Prevent. The journey starts with detection, because organizations first need to understand what credentials exist, where they live, and what they

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a new propagation technique, but because it repurposes ordinary STUN behavior into a practical command-and-control channel," Nozomi Networks said in a report

Exploitation Hits Rejetto HFS Vulnerability Discovered by AI

CVE-2026-61500 allows attackers to recover the session-cookie signing key and gain administrative access and RCE. The post Exploitation Hits Rejetto HFS Vulnerability Discovered by AI  appeared first on SecurityWeek.

Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach. The post Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity appeared first on SecurityWeek.

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk Access in ways that could put users at risk, exposing everything on their systems—including files, mail, messages, and even browsing history – without users' full knowledge

OpenAI will show visual ads in ChatGPT while you generate images

OpenAI is expanding ads in ChatGPT, and one of the first new formats will show visual ads while you're generating images. [...]

Microsoft: Windows KB5124010 update crashes some games and apps

Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]

Google halts open-source bug bounty program amid AI spam surge

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming from the use of a weak pseudo-random number generator (PRNG) that can lead to a predictable key, which an attacker can then use to gain unauthorized access and

Alleged ShinyHunters Leader Arrested in Jordan

Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group. The post Alleged ShinyHunters Leader Arrested in Jordan appeared first on SecurityWeek.

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, carries a CVSS score of 8.7 out of 10.0. "CVE-2026-88779 is a memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway that can lead to

Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched. The post Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier appeared first on SecurityWeek.

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...]

Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force

The announcement comes after Trump hosted top executives of AI companies at the White House last week. The post Trump Names National Intelligence Director Jay Clayton to Lead a New Federal AI Task Force appeared first on SecurityWeek.

news.jakobhusu.com — 4138 records in db [jakobhusu.com] [git] [blog] [linkedin]