🛡Cybersecurity | Privacy | News 🛡
Open in Telegram
👨🏻💻Cybersecurity&Privacy News everyday👨🏻💻 ⚡️ Stay tuned with our channel
Show more9 858
Subscribers
No data24 hours
+207 days
+5030 days
Posts Archive
MFA's Weakest Link: Account Recovery Is the New Attack Path
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover.
@BleepinComputer | bleepingcomputer.com • Sep 9, 2026
Webinar: Learn How to Answer “Are We Exposed?” Faster After
Tines unifies SBOM, endpoint, cloud, and vulnerability data to speed exposure assessment with AI-assisted analysis and automation.
The Hacker News | thehackernews.com • Sep 9, 2026
DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
A DeepSeek Harness flaw let attacker-supplied text push AI agents to disable the file sandbox; fixed npm releases start at 0.1.2-alpha.2.
The Hacker News | thehackernews.com • Sep 9, 2026
Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
Alby warns a critical Hub flaw could let attackers take over internet-exposed wallets; versions 1.19.0 and later are not affected.
The Hacker News | thehackernews.com • Sep 9, 2026
Over 36,000 Plex servers unpatched against recently disclosed flaws
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks.
Sergiu Gatlan | bleepingcomputer.com • Sep 9, 2026
U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
U.S. agencies accuse six China-based AI firms of industrial-scale distillation to extract proprietary capabilities from frontier AI models.
The Hacker News | thehackernews.com • Sep 9, 2026
Man gets 15 years for extorting women with AI-generated porn videos
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content.
Sergiu Gatlan | bleepingcomputer.com • Sep 9, 2026
F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans
F5 BIG-IP malware injects a PHP web shell into memory, leaving targeted scripts unchanged on disk while commands run through web requests.
The Hacker News | thehackernews.com • Sep 9, 2026
Google warns of new Chrome zero-day bug exploited in attacks
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year.
Sergiu Gatlan | bleepingcomputer.com • Sep 9, 2026
SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution
SAP patches CVE-2026-44756, an unauthenticated EPP memory corruption flaw that enables remote OS command execution with SAP admin privileges.
The Hacker News | thehackernews.com • Sep 9, 2026
Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days
Microsoft patches a record 974 vulnerabilities, including two Windows zero-days exploited in the wild.
The Hacker News | thehackernews.com • Sep 9, 2026
Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults
Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth.
Mayank Parmar | bleepingcomputer.com • Sep 9, 2026
DoppelCart fraud network uses 119,000 fake shops to steal credit cards
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details.
Bill Toulas | bleepingcomputer.com • Sep 8, 2026
The EU CRA's Real Question: What Shipped, and When Did You Know?
The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements.
@BleepinComputer | bleepingcomputer.com • Sep 8, 2026
Microsoft releases Windows 10 KB5122878 extended security update
Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes.
Lawrence Abrams | bleepingcomputer.com • Sep 8, 2026
Microsoft September 2026 Patch Tuesday fixes 966 flaws,
Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities.
Lawrence Abrams | bleepingcomputer.com • Sep 8, 2026
ShinyHunters hackers claim breach of Florida "DAVID" DMV database
The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state.
Lawrence Abrams | bleepingcomputer.com • Sep 8, 2026
OpenAI says ChatGPT outage causes image generation errors
OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files.
Sergiu Gatlan | bleepingcomputer.com • Sep 8, 2026
August updates trigger 0xc0000409 errors on Windows Server 2016
Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled.
Sergiu Gatlan | bleepingcomputer.com • Sep 8, 2026
SAP warns of maximum severity 'OVERPASS' kernel vulnerability
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code.
Sergiu Gatlan | bleepingcomputer.com • Sep 8, 2026
