🛡Cybersecurity | Privacy | News 🛡
Open in Telegram
👨🏻💻Cybersecurity&Privacy News everyday👨🏻💻 ⚡️ Stay tuned with our channel
Show more9 854
Subscribers
No data24 hours
+207 days
+5030 days
Posts Archive
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks
Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks.
Lawrence Abrams | bleepingcomputer.com • Sep 9, 2026
Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking
The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction.
Bill Toulas | bleepingcomputer.com • Sep 9, 2026
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto
U.S. authorities disrupted Xinbi Guarantee and froze $52.8 million in crypto tied to the scam marketplace and its merchant network.
The Hacker News | thehackernews.com • Sep 9, 2026
US says Chinese firms extracted billions of tokens from frontier AI models
U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024.
Bill Toulas | bleepingcomputer.com • Sep 9, 2026
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within
BlueMoon chains two Chrome V8 zero-days with a Windows flaw in phishing attacks used by APT31 and other espionage clusters.
The Hacker News | thehackernews.com • Sep 9, 2026
Veradigm warns of patient data breach after ransomware gang claims attack
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data.
Bill Toulas | bleepingcomputer.com • Sep 9, 2026
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
Infostealer logs expose replayable AI session tokens and API keys that can bypass login controls and enable unauthorized account access.
The Hacker News | thehackernews.com • Sep 9, 2026
MFA's Weakest Link: Account Recovery Is the New Attack Path
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover.
@BleepinComputer | bleepingcomputer.com • Sep 9, 2026
Webinar: Learn How to Answer “Are We Exposed?” Faster After
Tines unifies SBOM, endpoint, cloud, and vulnerability data to speed exposure assessment with AI-assisted analysis and automation.
The Hacker News | thehackernews.com • Sep 9, 2026
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
A DeepSeek Harness flaw let attacker-supplied text push AI agents to disable the file sandbox; fixed npm releases start at 0.1.2-alpha.2.
The Hacker News | thehackernews.com • Sep 9, 2026
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
Alby warns a critical Hub flaw could let attackers take over internet-exposed wallets; versions 1.19.0 and later are not affected.
The Hacker News | thehackernews.com • Sep 9, 2026
Over 36,000 Plex servers unpatched against recently disclosed flaws
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks.
Sergiu Gatlan | bleepingcomputer.com • Sep 9, 2026
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. agencies accuse six China-based AI firms of industrial-scale distillation to extract proprietary capabilities from frontier AI models.
The Hacker News | thehackernews.com • Sep 9, 2026
Man gets 15 years for extorting women with AI-generated porn videos
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content.
Sergiu Gatlan | bleepingcomputer.com • Sep 9, 2026
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
F5 BIG-IP malware injects a PHP web shell into memory, leaving targeted scripts unchanged on disk while commands run through web requests.
The Hacker News | thehackernews.com • Sep 9, 2026
Google warns of new Chrome zero-day bug exploited in attacks
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.
Sergiu Gatlan | bleepingcomputer.com • Sep 9, 2026
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP patches CVE-2026-44756, an unauthenticated EPP memory corruption flaw that enables remote OS command execution with SAP admin privileges.
The Hacker News | thehackernews.com • Sep 9, 2026
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft patches a record 974 vulnerabilities, including two Windows zero-days exploited in the wild.
The Hacker News | thehackernews.com • Sep 9, 2026
Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth.
Mayank Parmar | bleepingcomputer.com • Sep 9, 2026
DoppelCart fraud network uses 119,000 fake shops to steal credit cards
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details.
Bill Toulas | bleepingcomputer.com • Sep 8, 2026
