Cybersecurity News and Updates
Why AI Is So Good at Scamming Humans
CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate
Threat Actor Generates 1M Personalized Fraud Emails in 3 Days
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
N-able has released its fourth hotfix in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a
Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication
Successful attacks date to at least September 2. The Hacker News’s September 6 review of the warning found no victim count or
Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner
One of them switches off Windows Update and Microsoft Defender before running a cryptocurrency miner.
The company named the four programs ProManager, WinUpdate, SoftManager, and
Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites
Tracked as CVE-2026-32475 (CVSS score of 9.8), the bug described as an arbitrary file upload issue in the function that handles form submissions.
The post Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites appeared first on SecurityWeek.
Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted
The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company’s hardware wallets
Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code
The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploit to run arbitrary code.
“A
Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials
“Cadence users should immediately revoke or rotate all credentials and secrets that may have been used to run their Cadence executions,” JetBrains said.
Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. “Sansec is
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
The Arctic Wolf Adversary Research Team said it observed attackers exploiting CVE-2026-81578 and CVE-2026-82078 – an authentication bypass and remote code execution chain – to conduct command execution and reconnaissance, as well as
Thousands of OpenAI Agents Quietly Turned an Abandoned Wiki Into Their Coordination Channel
The activity was concentrated on DSEwiki, a German software developer wiki that runs
Recent Comments