Security researchers have proposed an open standard designed to make API keys self-destruct within 60 seconds of being detected as leaked.
Tag: CyberMaterial
Cyber Briefing: 2026.09.08
Attackers are exploiting critical identity flaws, automating credential theft with AI, compromising AI development ecosystems, and abusing…
AI Coding Tools Targeted by Threat Actors
Threat actors have shifted focus to exploiting AI-assisted coding tools and development environments, resulting in several major software supply chain…
LG TVs Spying on Users Even When Offline
LG smart television sets are actively monitoring users and their home networks even when the devices appear to be offline or in standby mode, according to…
Tenable Launches AI Inspector for Community AI Components
Tenable has introduced AI Inspector, a free security evaluation tool designed to help organizations assess risks in community-developed AI components.
Hackers deploy AI frameworks for mass credential theft
Cybercriminals have begun deploying autonomous AI frameworks that coordinate multi-stage attacks with little human intervention, dramatically compressing…
Grindr settles UK privacy class action for £26M
Dating app Grindr has agreed to pay £26 million to settle a UK class action lawsuit alleging it improperly shared sensitive user data with third parties.
36K Plex servers unpatched against recent flaws
More than 36,000 Plex Media Server installations accessible from the internet have not been patched against recently disclosed security vulnerabilities,…
Cyber Briefing: 2026.09.10
Internet-facing vulnerabilities, third-party compromises, and supply-chain controls remain central security concerns, while government agencies and…
Lumexa Imaging breach affects 5.8M individuals
Lumexa Imaging has notified federal regulators of a massive data breach affecting 5.8 million individuals after a vendor compromise allowed unauthorized…
CISA Flags Exploited Cisco, Citrix, Fortinet Flaws
The U.S.
FBI Publishes First Cyber Strategy
The FBI published its inaugural Cyber Strategy on September 9, marking a significant shift in how the agency approaches cyber threats.
WordPress Adds Automated Security Review for Plugins
WordPress has deployed an automated security review system that evaluates every plugin release before distribution through the WordPress.org update API.
VMware ends public VDDK downloads
VMware has quietly discontinued public downloads of its Virtual Disk Development Kit (VDDK), a software development kit that provides APIs for accessing…
Cyber Briefing: 2026.09.09
Authenticated sessions exploited, application security flaws, weak account-recovery mechanisms, and exposed credentials to gain unauthorized access, steal…
BigBear 2.0 phishing campaign hijacks M365 sessions
A large-scale phishing operation has compromised thousands of Microsoft 365 accounts by stealing authenticated session cookies that remain valid even…
Singapore man pleads guilty to $245M crypto theft
A 22-year-old Singapore national has admitted to leading a criminal operation that stole more than $245 million in cryptocurrency from victims’ digital…
Jellyfin 12.0 releases security fixes
Jellyfin has released version 12.0 of its media server platform with several critical security patches addressing vulnerabilities that could expose files…
Open Standard for Revocable API Keys Proposed
Security researchers have proposed an open standard designed to make API keys self-destruct within 60 seconds of being detected as leaked.
DeepSeek Harness Sandbox Bypass Flaw
Security researchers have identified a critical sandbox escape vulnerability in DeepSeek Harness, the open-source framework developed by DeepSeek for…
