<?xml version="1.0" encoding="UTF-8" standalone="no"?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns="http://www.w3.org/2005/Atom" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:gd="http://schemas.google.com/g/2005" xmlns:georss="http://www.georss.org/georss" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:thr="http://purl.org/syndication/thread/1.0"><id>tag:blogger.com,1999:blog-4802841478634147276</id><updated>2026-09-12T21:24:45.724+05:30</updated><title type="text">The Hacker News</title><subtitle type="html">The Hacker News has been internationally recognized as a leading news source dedicated to promoting awareness for security experts and hackers</subtitle><link href="https://thehackernews.com/feeds/posts/default" rel="http://schemas.google.com/g/2005#feed" type="application/atom+xml"/><link href="https://thehackernews.com/feeds/posts/default?redirect=false" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/" rel="alternate" type="text/html"/><link href="http://pubsubhubbub.appspot.com/" rel="hub"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default?start-index=26&amp;max-results=25&amp;redirect=false" rel="next" type="application/atom+xml"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><generator uri="http://www.blogger.com" version="7.00">Blogger</generator><openSearch:totalResults>17251</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2162689053693183343</id><published>2026-09-12T21:24:45.724+05:30</published><updated>2026-09-12T21:24:45.724+05:30</updated><title type="text">CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV</title><summary type="html">
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild.

Details of the vulnerabilities are as follows -


  CVE-2026-42016 (CVSS score: 8.1) - An incorrect authorization </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2162689053693183343" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2162689053693183343" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/cisa-adds-5-actively-exploited.html" rel="alternate" title="CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhva55LDIsAmtR2cRnUJw2XZ3Rvo4YhdJe39cfng8EZ1oHjLevxwRcYoFdg-ydI2I7fdt9OxGj7aMcaHMekZmy9hwSlopIZ4_KQgRnmiSy0OfGh8zO26StiEeOsHaQ4fYed0dbEUCUcz4gJM9Lu6Wt7m-ppDmI7iMl52-cRfQfsu9d90Sp2ncuvbVpAPupe/s260-e100/jj.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-5551172337109220775</id><published>2026-09-12T15:54:44.780+05:30</published><updated>2026-09-12T15:54:44.780+05:30</updated><title type="text">When the Whole Company Adopts AI: What It Does to Your SOC</title><summary type="html">

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks against AI, but the ordinary, everyday footprint of an organization using it, from developers running coding agents and non-technical staff signing consumer AI tools into corporate </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5551172337109220775" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5551172337109220775" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/when-whole-company-adopts-ai-what-it.html" rel="alternate" title="When the Whole Company Adopts AI: What It Does to Your SOC" type="text/html"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhx03NP3tJYBFro8_pZ2g6irfvMJFy0HGYqvUu9kkRJZBnMJ-BcA9aWGZZ1vS4a71YOgpB5qLBDkoNnMyOBJXGhfsyQQMK0IgaGunMOUTLnFUSFddG_5NwlnXsUCWJpGh3bGOcWLHpxXTAqv0i4QAYyRZPXcm0Rcp5K9Yfc7o7SEeLZXNtGp3NZVMzlv1M/s260-e100/in.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-9009428608589687012</id><published>2026-09-12T14:37:56.004+05:30</published><updated>2026-09-12T15:07:09.453+05:30</updated><title type="text">OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers</title><summary type="html">

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx.

On May 12, Maciej Mensfeld, senior product manager for software supply chain security at Mend.io, disclosed details of a coordinated cyber attack that targeted the package manager for the </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/9009428608589687012" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/9009428608589687012" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/openai-agents-linked-to-rubygems.html" rel="alternate" title="OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiSyR4P1ZPtVeXKeb60Ut1xdO4OhRvHWFmoYNgM7SI3NEwfwcTi3Ut60xwcqIfP56OzGFtixKW4Aeo14cVZNE6TPmpC-x8qFgofgMToETQ82bp1aMIMBuaOER2Rq6PkhONMhZPGLFSKFfxVjY4_zDNJOXYHPbQaorfgr74o2PimTPeCf1hgZQ0spe-nJoiU/s260-e100/rubygems-openai.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-8207261269349575298</id><published>2026-09-11T22:00:18.938+05:30</published><updated>2026-09-12T15:07:28.335+05:30</updated><title type="text">GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure</title><summary type="html">
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.

The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8207261269349575298" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8207261269349575298" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html" rel="alternate" title="GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEioFH6aWhF9NgRW1O3yFExc7paTA9akN5-3IUQF8mvEiSTaFJjKvm6YQzFX6MP2uimYplHe1MJXz6eZtPtnxaLy25jJBhU6KuhsWFpIlnqhbn6OI6QTcfp6Olp1-VDUEF4KEYFF7hQDBdmgtxibsg9MkvbcOJIlR8Of2Flyw2m9zYfXC6gUm-TV8XA6vU43/s260-e100/gitlab-wild.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2629769390110221542</id><published>2026-09-11T21:45:29.532+05:30</published><updated>2026-09-12T14:23:38.384+05:30</updated><title type="text">Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks</title><summary type="html">
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax.

Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a "teacher" to </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2629769390110221542" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2629769390110221542" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html" rel="alternate" title="Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIEiaJBfFrHCrYlSFKWGSRYD6CW_EeKfmYWCZw4jm5c9hyphenhyphenDVbaSIhyphenhyphenXwFB0ncQOoB10crmwgJV9nsvhQzJNuVMsDh6jPVt2ep23r0A2PB7ZhLfTroa0Ff__kyjjX2MjP4ok4DtBwFEF1VZC7b5OOCkibJBbwECsR0Y_9S1-NpdEIw04J5FtY9OloB084t_/s260-e100/claude-china.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-7935738996509497363</id><published>2026-09-11T19:59:47.654+05:30</published><updated>2026-09-11T21:35:23.474+05:30</updated><title type="text">Claude Used to Automate Exploitation and Data Theft Across Multiple Victims</title><summary type="html">
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026.

The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7935738996509497363" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/7935738996509497363" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html" rel="alternate" title="Claude Used to Automate Exploitation and Data Theft Across Multiple Victims" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiG0iCBQ4Eqxn0QOtvYZSysksPzr5fT0m8aLqNTa0a7Gcz3A5ikRt1oAenJwzo8rxcLERq54SNLtRvkYXKMTo0nMOmV8pWh4It3T0vP7q4J5Z23tdDkbBf3j7v317S7sQbBBbN6j6MuHusofo3qcbm2Y3DWT76gHp4Z1_En2QnJMCyEpvCo1sCcXoRZVw5-/s260-e100/claudeai.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6565371554561542711</id><published>2026-09-11T19:40:20.708+05:30</published><updated>2026-09-11T21:35:40.525+05:30</updated><title type="text">Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection</title><summary type="html">
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.

The operation has been attributed to a cyber espionage group it calls GTG-20006 (where "GTG" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6565371554561542711" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6565371554561542711" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html" rel="alternate" title="Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtfzeoSe_6tXrJiKsyJfN4vYk6suLsJPF3-SOJWE8LAaZ6_WixrsJVjZ0T8O6jdtB1d08IR8swK6H0B4S_m7-0YfIiJlVPHuL7guxwC-4ANLXUyNsEWfIusPzvOMPOKSBmFcBT1NBBVWIglIRlT8fs6O9Uc6ZRBRgWZNPbvgAVIj8gIXfusRwZh0tndhni/s260-e100/claude-malware.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-217916837299982814</id><published>2026-09-11T17:00:00.000+05:30</published><updated>2026-09-11T17:00:00.317+05:30</updated><title type="text">Your Critical Vulnerabilities Might Not Be Your Biggest Risk</title><summary type="html">
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise.

A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/217916837299982814" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/217916837299982814" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/your-critical-vulnerabilities-might-not.html" rel="alternate" title="Your Critical Vulnerabilities Might Not Be Your Biggest Risk" type="text/html"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgPPe_ve3Cylrq2fJ8HTFPebWF7lR7tvzMvL3mwFcGZNF2KWesOGc66BfO7NbiPxmsiao8jcItyikguKNqsEGfpJEcAvacbP7rflAaAT-e0Y1IbsNCNvdqvXMbwERLlPpV0PMhk9c5esoEjCE97wglh8rU9xZ7eGz2N4BOpzFYTb9-Ln3FaBRQiscqzK7U/s260-e100/breachlock.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-561102034028206476</id><published>2026-09-11T13:01:05.301+05:30</published><updated>2026-09-11T13:01:05.301+05:30</updated><title type="text">Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors</title><summary type="html">
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz&amp;nbsp;said in a report.

Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.

</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/561102034028206476" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/561102034028206476" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html" rel="alternate" title="Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgX61WXln9MMGAzqzflpRDt_LZGfB7ZJ_u1fsQhr5FRnml48-E-V-uxtCIF-GERZlt-eBhw3MDT7_6jFgwEDF1ppC7YZlB_CZn-q4_nKD9S3fQTI3kDQFe2Izsq6_NoGnCRtRZckr8Irg9kOJ8Fwghl3qHqwg1zWoN6ff-VsmlCaojw2Divb6L00F34lJk/s260-e100/jfrog-art.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2669861340259544523</id><published>2026-09-11T12:44:09.735+05:30</published><updated>2026-09-11T12:44:09.735+05:30</updated><title type="text">China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor</title><summary type="html">
A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in&amp;nbsp;research published Thursday.

The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2669861340259544523" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2669861340259544523" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html" rel="alternate" title="China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjp8vDxYtUGwWuRZlSSBh2ghvSf6GTi_VlTQSQXTaIWSlQgHY_imEfl4hyAcrhPz9w3_ejmdAKK7ZeOt5gBsNZI7mhxJsnbyLT8Bo6O6HdM01yCNuDjuz-IU64LRuAuVDOzh2Z0vLhvzwP9PUUBKE_OLn0YD7m74-kZpo1dr5c0hzCMRHxrgfIzjk9MnR4/s260-e100/chinese.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6399687826174854081</id><published>2026-09-11T12:16:18.155+05:30</published><updated>2026-09-11T12:16:18.155+05:30</updated><title type="text">PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws</title><summary type="html">
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.

The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.

"These are Regular Maintenance Releases (MR) that </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6399687826174854081" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6399687826174854081" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html" rel="alternate" title="PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhT6b7k7Y60TgLLmuruqSocYNfZoYEmONgga8CidWSXIdOZLWlgCYLuXOe9bWQRi_3BRkOmJvPNANZAOS85Xx6RtuQTVCg2-QNi3dXfELQm8bglTMUK9rn54e-sLoslCkVYlPGiyGSnsu58yxo9EkC3PvXDWVTYhTRgDQqTDAQTs69vPBh7xjq0Fwm7bY40/s260-e100/papercut-flaws.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-5596500808131000044</id><published>2026-09-11T11:49:59.778+05:30</published><updated>2026-09-11T11:49:59.779+05:30</updated><title type="text">Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware</title><summary type="html">
Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities.

The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5596500808131000044" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5596500808131000044" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html" rel="alternate" title="Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgJizB5uHZncQAbfKm3-k256bJHufHNcClzKqXH2XK79HlAw8egcuz3abU_gxrTbR2zrWqpMmFcHApBqp5AvC2uox6vEeOlDt1JdRy-A6WAqpFPfVeZ4hM4gp-lCqqY_hIXMu2VVupFLGzbv1sBXLjQGSPlORsnaEdcOqjLJQKAKfDMHJqGY6KY1NZCLth0/s260-e100/cisco-ransomware.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2012166857913609249</id><published>2026-09-10T23:17:38.366+05:30</published><updated>2026-09-11T11:56:12.651+05:30</updated><title type="text">ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories</title><summary type="html">

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”

An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2012166857913609249" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2012166857913609249" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html" rel="alternate" title="ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFNPIVe_Yx__WtfjnMTnoJSKPMcGPiMCP5NxEyv1gRcGSlnozG41TeGldWhQi7Hsc0XgcmC9tfTEBS-CdLLAz8cOskVbBOsghdSM9kg_AhQmhfMada8rs4l7O7Py8YJErqK54BIt0r06Sm1l62fy8yv6H8PJrEXWxjnvyLkyFKzzXcGI_h00yeBqck5v9L/s260-e100/td-main.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6343613446889159909</id><published>2026-09-10T20:06:47.405+05:30</published><updated>2026-09-10T20:06:47.405+05:30</updated><title type="text">Google Play Early Access Abused to Push Thousands of Deceptive Android Apps</title><summary type="html">
Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content.

Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6343613446889159909" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6343613446889159909" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html" rel="alternate" title="Google Play Early Access Abused to Push Thousands of Deceptive Android Apps" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4vbRDTWaQnxiILexae9P_rAk0hzx-re0czK2tM_WNQcoVDPlKblD4M5qOy8FZ9hHJBDLGjHHAyYutmaiacI54o5q1SH5qSbsptviRF16T2r6i8Iywvzk4GJprCm60p12qrK7t3R8h_ZR7CUoG47YfdeOb0iKY0WRapDeObI8_poWklMtKXrmr421Scjzi/s260-e100/play.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-8385862754518897463</id><published>2026-09-10T17:15:05.997+05:30</published><updated>2026-09-10T17:15:05.997+05:30</updated><title type="text">Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE</title><summary type="html">
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only "under specific conditions" that it has not described.

One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8385862754518897463" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8385862754518897463" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html" rel="alternate" title="Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyc0Kqar7_6N4y9ymGxw8ukQCQbqQ_pGCfnoXYMBZoNZK1w3ljkO26S_rhVhJaIVcx8rcEK95njKyaYj5g63VByKh8ncf_s84nUBWoyEbWZH6uaLYjnu5fNt_TC9wz-r6P_RTJgZ83Z5wmurzSb9_lHVfV1t9STts4WCZr18AH-3XRHTn5pj15uURIM-0/s260-e100/checkpoint.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-3120241237279291508</id><published>2026-09-10T17:11:53.824+05:30</published><updated>2026-09-10T20:53:00.122+05:30</updated><title type="text">PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances</title><summary type="html">
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances.

According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from "45.142.193[.]132," an IP address that has been linked to </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3120241237279291508" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3120241237279291508" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html" rel="alternate" title="PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgkLW3i6mB4uE2g7Ze6CDAess3UTTeol7YmRP-N3uTkLJHPglZc0BHvTlESyulvcTp05ObPwuGY5XHqV9q599pqLmK-ypamAPNUdHa9y-34Q4IEE3EBId9UrN9L0J3zK1TTf1Atovhkz51Gk_2gul7DmjvLmJd7BbwgqMhmVODTiQUuqu_IdFFGJt0WAiC_/s260-e100/paper.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-2021291515673184679</id><published>2026-09-10T17:03:43.212+05:30</published><updated>2026-09-10T17:03:43.213+05:30</updated><title type="text">Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks</title><summary type="html">
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a&amp;nbsp;report published on September 9.

A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2021291515673184679" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/2021291515673184679" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html" rel="alternate" title="Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiJHT3nuLNpTkrzjiictjYuKsyepFXuDoZVUZB_Gz6yQFCP4CYdOIpSDon_tEsZ43eVe2_qiPXs7V9byKtyoYZ7HE7QltUfQgEUTnSSjmclQH27vVm5JjVIcrvANMIEOxUDmOWy0dPeHVOkiYoFZMgubtGqZJKfgft34Z-q5F7dyqPoJ6iInpgMwyIL3l8/s260-e100/android-work.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6208281038566137507</id><published>2026-09-10T16:06:46.954+05:30</published><updated>2026-09-11T11:26:26.816+05:30</updated><title type="text">CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline</title><summary type="html">
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.

The vulnerabilities are listed below -


  CVE-2026-20079 (CVSS score: 10.0) - An authentication </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6208281038566137507" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6208281038566137507" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html" rel="alternate" title="CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7j6Sm8OqDeYzrbb5faLBuDOc0zIMlvfjiKbn1aCMpx_2iBl6gb3HhJhpbqU8SPajHUClJEXUwnFbY1DcubmzWeVaWCyGcHkw45rCYqU_4IFO_g4OwdyNrTFFK3l3YsXwfOWQj2QtW3UTeglKmyRJ4GvbVKMxLTByMgeZ7E0WWpxpi50qie2lx9DbCY9rr/s260-e100/cisa-list.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-8246411968475905083</id><published>2026-09-10T12:42:55.229+05:30</published><updated>2026-09-10T12:43:24.880+05:30</updated><title type="text">Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key</title><summary type="html">
Nearly one in ten of the internet-facing LiteLLM servers that&amp;nbsp;Wiz Research&amp;nbsp;scanned in February accepted&amp;nbsp;sk-1234, the example admin key in LiteLLM's own setup guide.

LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential.

Anyone who holds it can read every </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8246411968475905083" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8246411968475905083" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html" rel="alternate" title="Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example &quot;sk-1234&quot; Admin Key" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfjbI1DXHJ4wQzSRFbddkmgQ9CTLSPPGP8fcQ6a37qbwKvgd4JxU51YhADR8S4IsWaiQ4fRApn-ih4m0AhsizM3wa6aJ3P8MlgBztNQm-oH4bE_TkPsmUZHhblcNMrQFxGdWnDHePCQDcSz-AJeWMoKH6YVcXXFCjK2ajZfbmObdeVkWmvv8O_fufqsl0/s260-e100/litellm.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-3123377199153559106</id><published>2026-09-10T12:34:01.972+05:30</published><updated>2026-09-10T20:53:36.540+05:30</updated><title type="text">Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6</title><summary type="html">
Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents.

The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached "</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3123377199153559106" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3123377199153559106" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html" rel="alternate" title="Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmMNfeF1h2D3MrUkoHWN2M9yhKD-FFQ6DgwixOflNATW2UA5b_6AsUjXLAjrn5c4hQWw0xueXTWDlbqKwS_gexDm0Yq8PB_B2LpXHaQiw7m7thOATlckixuA8VUIFDFERGBS8o1Kph93eYnDysXuRljKaXfe7813MwWKkBLex8BP3YL-fahCr4Xm3xMWZE/s260-e100/claude-hack.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-968403025024014018</id><published>2026-09-09T23:56:05.514+05:30</published><updated>2026-09-10T20:53:51.086+05:30</updated><title type="text">U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto</title><summary type="html">
The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/968403025024014018" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/968403025024014018" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html" rel="alternate" title="U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcQQNutHn5K2x_gd-2eyAP0wzneQ3mOSl3jaaRHGFDUY1O95tuckdjL_botXvrBlt_ts6Bjb91JU4Z-B74VAceL1cYa3oMlt91mHSxZP_FiiVTJLfL8UBUgoBIvjJCuI7Nma3dOxJ48n4wS5VvoBWRDNYqwlYIfStXIKTDBUrRXBIWITx_TprflrVXqjum/s260-e100/xinbi.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-8215137575346111595</id><published>2026-09-09T22:04:05.815+05:30</published><updated>2026-09-10T12:10:35.003+05:30</updated><title type="text">Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week</title><summary type="html">
Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.

The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo, </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8215137575346111595" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/8215137575346111595" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/four-spy-groups-used-same-chrome-and.html" rel="alternate" title="Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhxouoVfK0MjZpruL0J1chmWnC7avUov1fOLbgX-XyFGrTcXeOh08tVntBjzJ7wBMmOB3P-PpxMr6E868Wpsaky-b-Nrf1LajzoQFfmjnkI1KHQzGXrCcVnC57nF2ndYZHCLx5WA3dENCWmCbZlSAb5TC-p8DXCGWxWB7I3iRIsdMMk6SS6IV03722lZIS4/s260-e100/spy.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-5884972136506307938</id><published>2026-09-09T19:53:55.520+05:30</published><updated>2026-09-09T23:23:28.459+05:30</updated><title type="text">Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA</title><summary type="html">


Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.&amp;nbsp;

Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5884972136506307938" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/5884972136506307938" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html" rel="alternate" title="Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA" type="text/html"/><author><name>Ravie Lakshmanan</name><uri>http://www.blogger.com/profile/09767675513435997467</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiYP_zrhRTZRWnPPcDkUrE7dBh2Bf5eaQmlBxyl7euTRGjS0C8boQppnrmjY0CIVjGrS_PF13V1W3BPVI3RDPZY59s_7xIkI8LnFkg3Tn_Q0x7_tbCs_sMkvhZMREtFLW3IOJSNNmQrKCDI88FCWhfymdWkEWtdMMRzivv3lZXImjreAz0d74VXt2K80ipH/s260-e100/tokens.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-6984996824537517729</id><published>2026-09-09T17:27:36.604+05:30</published><updated>2026-09-09T17:27:36.605+05:30</updated><title type="text">Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE  </title><summary type="html">
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed?

For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act.

As AI accelerates vulnerability discovery and research, that delay matters more</summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6984996824537517729" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/6984996824537517729" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/webinar-learn-how-to-answer-are-we.html" rel="alternate" title="Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE  " type="text/html"/><author><name>Unknown</name><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6J-Pt0v8CDXEvzMCsK37Gumde1WYysaqiuzK3Rg_dGXBeFEhbxFpLRbwaFSMOVcAz5XsbJXD9977trBg0eHEY-x4mZiu9W4ASLWGnIIA4kWkTmtIF-uBYlQWfLhQjAUL0llbl1Jn2hKfz5Wr78TR4Retzt9PlGD4mEGifQCvrEfFfqMy5966fDGvFHgY/s260-e100/tines-webinar.jpg" width="72"/></entry><entry><id>tag:blogger.com,1999:blog-4802841478634147276.post-3525999956997343161</id><published>2026-09-09T16:47:07.239+05:30</published><updated>2026-09-09T16:47:07.240+05:30</updated><title type="text">DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval</title><summary type="html">
A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command.

The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web </summary><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3525999956997343161" rel="edit" type="application/atom+xml"/><link href="http://www.blogger.com/feeds/4802841478634147276/posts/default/3525999956997343161" rel="self" type="application/atom+xml"/><link href="https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html" rel="alternate" title="DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval" type="text/html"/><author><name>Swati Khandelwal</name><uri>http://www.blogger.com/profile/06009796704238391750</uri><email>noreply@blogger.com</email><gd:image height="16" rel="http://schemas.google.com/g/2005#thumbnail" src="https://img1.blogblog.com/img/b16-rounded.gif" width="16"/></author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" height="72" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi0fUTc6rz4ZeeaMmjDLOfb2qNhnJf_TdNHK3F3qbNCQLLJbaF-nbSw5YPdeSAwg1HjoGwfQJZaXBpwvEbasFDhQb5ZkUm158shateq7uubMyrlejW4SDZAAzNQGUYkYdsxHupipxzRA7dQwTwTt9ArVJgU-wA5bGxIXduJj3CdyBF69Ixp6_qAU1LGzfI/s260-e100/deepseek.jpg" width="72"/></entry></feed>