Microsoft released its September 2026 Patch Tuesday security updates on September 8, addressing 973 vulnerabilities, including two zero-days already…
Category: Cyber Security News
Phishing Powers 80% of Attacks on US Companies: How SOCs Can Detect It Early
Phishing remains one of the most effective ways for attackers to gain access to corporate environments. From 2013-2023, the FBI recorded 158,436 US…
ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channel
A covert cross-account communication channel inside ChatGPT let an attacker hijack a victim’s session and silently exfiltrate data from connected apps…
Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware
An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js…
Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks
Ivanti has disclosed a wave of security advisories affecting three flagship enterprise products, Endpoint Manager Mobile, Neurons for ITSM, and Sentry,…
FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack
Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an…
CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV)…
Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access
Dell has disclosed three critical vulnerabilities in its Secure Connect Gateway 5.0 platform that could allow attackers to gain unauthorized access,…
Mars Security Launches Real-Time Intel-to-Detection Engine That Turns Live Threat Intelligence Into Backtested Detections in Minutes
New York, NY, United States, September 8th, 2026, CyberNewswire Mars Security, the autonomous threat hunting and detection engineering platform founded by…
WeWorm – First 0-Click Worm Spreading Through WeChat Calls Across iOS and Android
A proof-of-concept zero-click worm dubbed “WeWorm” that it says can spread through WeChat voice calls on both iOS and Android, compromising a target’s…
Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain
A new intrusion campaign shows how quickly a Windows domain can be turned into a launchpad for deeper compromise. The operators used a Sliver…
Claude Mythos AI Autonomously Executes Full Cyber Kill Chain Without Human Guidance
Claude Mythos is the first model reported to complete a cyber kill chain without step-by-step human direction. The finding does not describe malware or a…
SAP Security Updates September 2026 – Critical Flaws Patched in SAP NetWeaver, Cloud and Extended Passport
SAP has released its September 2026 Security Patch Day updates, delivering 19 new security notes and one update to a previously issued note. The patches…
Top 10 Best Extended Detection & Response (XDR) Platforms in 2026
Palo Alto Cortex XDR scores highest in our 2026 evaluation, with CrowdStrike close behind on detection engineering and Microsoft Defender XDR leading on…
Top 10 Best Managed Detection & Response (MDR) Services in 2026
MDR gives you a 24/7 security operations team without hiring one. Modern Managed Detection and Response (MDR) services fuse advanced analytics with…
Top 10 Best Firewall-as-a-Service (FWaaS) Providers in 2026
Firewall-as-a-service moves inspection, IPS, and policy into the cloud, so every user and site gets the same protection without appliances to size, patch,…
Top 10 Best Web Application Firewall (WAF) Solutions in 2026
A web application firewall (WAF) filters malicious HTTP/S traffic SQL injection, cross-site scripting, credential stuffing, and API abuse before it…
BigBear 2.0 Evilginx2 Phishing Campaign Bypasses Microsoft 365 MFA With Session Cookie Theft
BigBear 2.0 is a phishing operation designed to steal proof that a user has already passed multi-factor authentication. It targets Microsoft 365 accounts…
Panzer Ransomware Targets Italian Manufacturers and Telecom Firms With ESXi-Ready RaaS
Panzer ransomware has entered Italy amid a sharp rise in attacks. The ransomware-as-a-service, or RaaS, operation surfaced on August 5 and listed a…
U.S. Offers $10 Million Reward for Iranian IRGC Cyber Chief Linked to Critical Infrastructure Attacks
The U.S. Department of State’s Rewards for Justice program has announced a reward of up to $10 million for information leading to the identification or…