<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Cybersecurity Alphabet Soup: Security News</title>
    <description>One feed for cybersecurity news: headlines from 8+ trusted newsrooms, research teams, and practitioner blogs, merged hourly. Full articles at the original publishers.</description>
    <link>https://www.cybersecurityalphabetsoup.com/news/</link>
    <atom:link href="https://thestateofcybersecurity.github.io/ransomwareRSS/cybersecurity-feed.xml" rel="self" type="application/rss+xml"/>
    <lastBuildDate>Wed, 09 Sep 2026 14:40:21 GMT</lastBuildDate>
    <ttl>60</ttl>
    <item>
      <title>Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension</title>
      <link>https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/</link>
      <guid isPermaLink="false">https://www.securityweek.com/fortinet-patches-critical-vulnerabilities-in-fortimonitoronsight-chrome-extension/</guid>
      <pubDate>Wed, 09 Sep 2026 14:33:52 GMT</pubDate>
      <source url="https://www.securityweek.com/">SecurityWeek</source>
      <description>The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek . (via SecurityWeek)</description>
    </item>
    <item>
      <title>Gigabud Uses Android App Cloning to Evade Fraud Detection</title>
      <link>https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/</link>
      <guid isPermaLink="false">https://www.infosecurity-magazine.com/news/gigabud-android-app-cloning-fraud/</guid>
      <pubDate>Wed, 09 Sep 2026 14:30:00 GMT</pubDate>
      <source url="https://www.infosecurity-magazine.com/">Infosecurity Magazine</source>
      <description>Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud (via Infosecurity Magazine)</description>
    </item>
    <item>
      <title>Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA</title>
      <link>https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html</link>
      <guid isPermaLink="false">https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html</guid>
      <pubDate>Wed, 09 Sep 2026 14:23:55 GMT</pubDate>
      <source url="https://thehackernews.com/">The Hacker News</source>
      <description>Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create &quot;stolen keys&quot; that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped… (via The Hacker News)</description>
    </item>
    <item>
      <title>MFA&#39;s Weakest Link: Account Recovery Is the New Attack Path</title>
      <link>https://www.bleepingcomputer.com/news/security/mfas-weakest-link-account-recovery-is-the-new-attack-path/</link>
      <guid isPermaLink="false">https://www.bleepingcomputer.com/news/security/mfas-weakest-link-account-recovery-is-the-new-attack-path/</guid>
      <pubDate>Wed, 09 Sep 2026 14:01:11 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/">BleepingComputer</source>
      <description>MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks… (via BleepingComputer)</description>
    </item>
    <item>
      <title>Akeyless adds real-time enforcement for AI agents in production</title>
      <link>https://www.helpnetsecurity.com/2026/09/09/akeyless-agentic-runtime-authority-identity-control-layer/</link>
      <guid isPermaLink="false">https://www.helpnetsecurity.com/2026/09/09/akeyless-agentic-runtime-authority-identity-control-layer/</guid>
      <pubDate>Wed, 09 Sep 2026 13:54:35 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/">Help Net Security</source>
      <description>Akeyless has announced the general availability of Akeyless Agentic Runtime Authority, the real-time identity control layer for AI agent actions. It works on top of Akeyless SecretlessAI, a credential protection layer that keeps credentials out of AI agents and brokers access to… (via Help Net Security)</description>
    </item>
    <item>
      <title>ClickFix Moves into the Browser to Steal Cryptocurrency</title>
      <link>https://www.infosecurity-magazine.com/news/clickfix-browser-cryptocurrency/</link>
      <guid isPermaLink="false">https://www.infosecurity-magazine.com/news/clickfix-browser-cryptocurrency/</guid>
      <pubDate>Wed, 09 Sep 2026 13:45:00 GMT</pubDate>
      <source url="https://www.infosecurity-magazine.com/">Infosecurity Magazine</source>
      <description>ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency (via Infosecurity Magazine)</description>
    </item>
    <item>
      <title>Orchid Security targets AI agent risk with drift detection and kill switches</title>
      <link>https://www.helpnetsecurity.com/2026/09/09/orchid-security-ai-agents-application-level-kill-switches/</link>
      <guid isPermaLink="false">https://www.helpnetsecurity.com/2026/09/09/orchid-security-ai-agents-application-level-kill-switches/</guid>
      <pubDate>Wed, 09 Sep 2026 13:29:17 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/">Help Net Security</source>
      <description>Orchid Security has announced identity drift detection and application-level kill switches for AI agents. They can complete authorized objectives beyond their initial privilege level within seconds. AI agents do not need to “break” security controls or workflow guardrails. AI… (via Help Net Security)</description>
    </item>
    <item>
      <title>FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching</title>
      <link>https://cyberscoop.com/fbi-cyber-strategy-ai-threats-patching/</link>
      <guid isPermaLink="false">https://cyberscoop.com/fbi-cyber-strategy-ai-threats-patching/</guid>
      <pubDate>Wed, 09 Sep 2026 13:00:00 GMT</pubDate>
      <source url="https://cyberscoop.com/">CyberScoop</source>
      <description>The remarks, to both CyberScoop and at the Billington CyberSecurity Summit, dovetail with the release of a new bureau cyber strategy. The post FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching appeared first on CyberScoop . (via CyberScoop)</description>
    </item>
    <item>
      <title>NHIs Now the Number One Corporate Entry Point for Hackers</title>
      <link>https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/</link>
      <guid isPermaLink="false">https://www.infosecurity-magazine.com/news/nhis-number-one-corporate-entry/</guid>
      <pubDate>Wed, 09 Sep 2026 13:00:00 GMT</pubDate>
      <source url="https://www.infosecurity-magazine.com/">Infosecurity Magazine</source>
      <description>SpyCloud claims non-human identities are the most likely route into the enterprise (via Infosecurity Magazine)</description>
    </item>
    <item>
      <title>US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities</title>
      <link>https://www.securityweek.com/us-agencies-warn-china-is-systematically-extracting-frontier-ai-capabilities/</link>
      <guid isPermaLink="false">https://www.securityweek.com/us-agencies-warn-china-is-systematically-extracting-frontier-ai-capabilities/</guid>
      <pubDate>Wed, 09 Sep 2026 12:32:13 GMT</pubDate>
      <source url="https://www.securityweek.com/">SecurityWeek</source>
      <description>Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek . (via SecurityWeek)</description>
    </item>
    <item>
      <title>Ukraine prosecutor general steps down amid scam call center bribery probe</title>
      <link>https://therecord.media/ukraine-prosecutor-general-scam-center</link>
      <guid isPermaLink="false">https://therecord.media/ukraine-prosecutor-general-scam-center</guid>
      <pubDate>Wed, 09 Sep 2026 12:15:00 GMT</pubDate>
      <source url="https://therecord.media/">The Record</source>
      <description>Ukraine’s prosecutor general, Ruslan Kravchenko, resigned this week over allegations that officials in his office took bribes to shield scam call centers from law enforcement. (via The Record)</description>
    </item>
    <item>
      <title>$245 million in stolen crypto funded racketeering crew’s lavish lifestyle</title>
      <link>https://www.helpnetsecurity.com/2026/09/09/singapore-man-pleads-guilty-245-million-crypto-theft/</link>
      <guid isPermaLink="false">https://www.helpnetsecurity.com/2026/09/09/singapore-man-pleads-guilty-245-million-crypto-theft/</guid>
      <pubDate>Wed, 09 Sep 2026 12:11:36 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/">Help Net Security</source>
      <description>A 22-year-old man built his fortune by breaking into strangers’ digital wallets, then spent it on nightclub tabs, private jets, and a fleet of cars worth millions. Malone Lam, a Singapore citizen, pleaded guilty this week in a Washington D.C. federal court to running a… (via Help Net Security)</description>
    </item>
    <item>
      <title>Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy</title>
      <link>https://www.securityweek.com/meta-launches-personal-ai-agent-muse-emphasizes-safety-and-privacy/</link>
      <guid isPermaLink="false">https://www.securityweek.com/meta-launches-personal-ai-agent-muse-emphasizes-safety-and-privacy/</guid>
      <pubDate>Wed, 09 Sep 2026 12:00:00 GMT</pubDate>
      <source url="https://www.securityweek.com/">SecurityWeek</source>
      <description>Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek . (via SecurityWeek)</description>
    </item>
    <item>
      <title>Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE</title>
      <link>https://thehackernews.com/2026/09/webinar-learn-how-to-answer-are-we.html</link>
      <guid isPermaLink="false">https://thehackernews.com/2026/09/webinar-learn-how-to-answer-are-we.html</guid>
      <pubDate>Wed, 09 Sep 2026 11:57:36 GMT</pubDate>
      <source url="https://thehackernews.com/">The Hacker News</source>
      <description>A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application… (via The Hacker News)</description>
    </item>
    <item>
      <title>DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval</title>
      <link>https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html</link>
      <guid isPermaLink="false">https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html</guid>
      <pubDate>Wed, 09 Sep 2026 11:17:07 GMT</pubDate>
      <source url="https://thehackernews.com/">The Hacker News</source>
      <description>A flaw in DeepSeek Harness, DeepSeek&#39;s open-source tool for running AI coding agents on a developer&#39;s machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent&#39;s commands inside an operating-system sandbox, so that an agent working on… (via The Hacker News)</description>
    </item>
    <item>
      <title>Claude Fable Solves a Historical Cipher</title>
      <link>https://www.schneier.com/blog/archives/2026/09/claude-fable-solves-a-historical-cipher.html</link>
      <guid isPermaLink="false">https://www.schneier.com/blog/archives/2026/09/claude-fable-solves-a-historical-cipher.html</guid>
      <pubDate>Wed, 09 Sep 2026 11:08:26 GMT</pubDate>
      <source url="https://www.schneier.com/">Schneier on Security</source>
      <description>Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing. (via Schneier on Security)</description>
    </item>
    <item>
      <title>Hackers deploy Linux rootkit on F5 BIG-IP APM devices, hiding web shell in memory</title>
      <link>https://www.helpnetsecurity.com/2026/09/09/f5-big-ip-apm-rootkit-hides-web-shell-in-memory/</link>
      <guid isPermaLink="false">https://www.helpnetsecurity.com/2026/09/09/f5-big-ip-apm-rootkit-hides-web-shell-in-memory/</guid>
      <pubDate>Wed, 09 Sep 2026 11:05:32 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/">Help Net Security</source>
      <description>A rootkit found on hacked F5 BIG-IP APM devices skips the usual step of writing a web shell to disk, hiding it in memory instead, according to Sophos. F5 BIG-IP APM provides access policy enforcement to secure access to apps, APIs, and data. It’s primarily used by enterprises,… (via Help Net Security)</description>
    </item>
    <item>
      <title>ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws</title>
      <link>https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/</link>
      <guid isPermaLink="false">https://www.securityweek.com/ics-patch-tuesday-schneider-electric-siemens-fix-critical-flaws/</guid>
      <pubDate>Wed, 09 Sep 2026 10:49:30 GMT</pubDate>
      <source url="https://www.securityweek.com/">SecurityWeek</source>
      <description>AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products. The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek . (via SecurityWeek)</description>
    </item>
    <item>
      <title>Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets</title>
      <link>https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html</link>
      <guid isPermaLink="false">https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html</guid>
      <pubDate>Wed, 09 Sep 2026 10:43:04 GMT</pubDate>
      <source url="https://thehackernews.com/">The Hacker News</source>
      <description>Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs… (via The Hacker News)</description>
    </item>
    <item>
      <title>Ivanti Patches Critical Flaws Across Enterprise Security Products</title>
      <link>https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-security-products/</link>
      <guid isPermaLink="false">https://www.securityweek.com/ivanti-patches-critical-flaws-across-enterprise-security-products/</guid>
      <pubDate>Wed, 09 Sep 2026 10:28:34 GMT</pubDate>
      <source url="https://www.securityweek.com/">SecurityWeek</source>
      <description>Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws. The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek . (via SecurityWeek)</description>
    </item>
    <item>
      <title>Over 36,000 exposed Plex servers vulnerable to recent flaws</title>
      <link>https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/</link>
      <guid isPermaLink="false">https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/</guid>
      <pubDate>Wed, 09 Sep 2026 10:11:29 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/">BleepingComputer</source>
      <description>Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...] (via BleepingComputer)</description>
    </item>
    <item>
      <title>Zscaler Agentic SOC combines AI agents with zero trust telemetry</title>
      <link>https://www.helpnetsecurity.com/2026/09/09/zscaler-agentic-soc-solution/</link>
      <guid isPermaLink="false">https://www.helpnetsecurity.com/2026/09/09/zscaler-agentic-soc-solution/</guid>
      <pubDate>Wed, 09 Sep 2026 10:09:49 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/">Help Net Security</source>
      <description>Zscaler has announced Zscaler Agentic SOC, a new approach to security operations built to proactively reduce exposures, scale human expertise and stop AI-driven attacks at machine speed. Simply layering in AI capabilities onto the existing security stack will not provide the… (via Help Net Security)</description>
    </item>
    <item>
      <title>Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure</title>
      <link>https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/</link>
      <guid isPermaLink="false">https://unit42.paloaltonetworks.com/ppi-network-malware-campaign-analysis/</guid>
      <pubDate>Wed, 09 Sep 2026 10:00:55 GMT</pubDate>
      <source url="https://unit42.paloaltonetworks.com/">Unit 42</source>
      <description>An investigation into how cybercriminals used YouTube gaming lures and SEO poisoning to deliver multi-payload malware to enterprise networks. The post Untracked Nightmares: The Threats Hiding Behind Commodity Infrastructure appeared first on Unit 42 . (via Unit 42)</description>
    </item>
    <item>
      <title>This Key Will Self-Destruct: An Open Standard for Revocable API Keys</title>
      <link>https://www.securityweek.com/this-key-will-self-destruct-an-open-standard-for-revocable-api-keys/</link>
      <guid isPermaLink="false">https://www.securityweek.com/this-key-will-self-destruct-an-open-standard-for-revocable-api-keys/</guid>
      <pubDate>Wed, 09 Sep 2026 10:00:00 GMT</pubDate>
      <source url="https://www.securityweek.com/">SecurityWeek</source>
      <description>Every leaked credential should be dead, or dying, within sixty seconds of being found. Here&#39;s a proposal to make that the default. The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek . (via SecurityWeek)</description>
    </item>
    <item>
      <title>New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser</title>
      <link>https://www.securityweek.com/new-phishing-attack-creates-malicious-pages-inside-the-victims-browser/</link>
      <guid isPermaLink="false">https://www.securityweek.com/new-phishing-attack-creates-malicious-pages-inside-the-victims-browser/</guid>
      <pubDate>Wed, 09 Sep 2026 10:00:00 GMT</pubDate>
      <source url="https://www.securityweek.com/">SecurityWeek</source>
      <description>Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block. The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek . (via SecurityWeek)</description>
    </item>
    <item>
      <title>Chinese AI firms are siphoning capabilities from American models, CISA warns</title>
      <link>https://www.helpnetsecurity.com/2026/09/09/china-malicious-ai-knowledge-distillation-against-us-companies/</link>
      <guid isPermaLink="false">https://www.helpnetsecurity.com/2026/09/09/china-malicious-ai-knowledge-distillation-against-us-companies/</guid>
      <pubDate>Wed, 09 Sep 2026 09:55:36 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/">Help Net Security</source>
      <description>China-based AI companies are using large-scale knowledge distillation campaigns to copy capabilities from leading U.S. AI models, according to a joint cybersecurity advisory from the CISA, NSA, and FBI. Knowledge distillation is a standard AI training technique that uses outputs… (via Help Net Security)</description>
    </item>
    <item>
      <title>Securin Platform helps security teams prove when attack paths are closed</title>
      <link>https://www.helpnetsecurity.com/2026/09/09/securin-exposure-management-platform/</link>
      <guid isPermaLink="false">https://www.helpnetsecurity.com/2026/09/09/securin-exposure-management-platform/</guid>
      <pubDate>Wed, 09 Sep 2026 09:52:55 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/">Help Net Security</source>
      <description>Securin has announced the general availability of the Securin Platform, an AI-native Preemptive Exposure Management platform designed to answer three questions security teams struggle with every day: What can attackers actually exploit? What should we fix first? And did the fix… (via Help Net Security)</description>
    </item>
    <item>
      <title>Chrome 153 Patches Seventh Zero-Day of 2026</title>
      <link>https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/</link>
      <guid isPermaLink="false">https://www.securityweek.com/chrome-153-patches-seventh-zero-day-of-2026/</guid>
      <pubDate>Wed, 09 Sep 2026 09:45:00 GMT</pubDate>
      <source url="https://www.securityweek.com/">SecurityWeek</source>
      <description>The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible. The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek . (via SecurityWeek)</description>
    </item>
    <item>
      <title>Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026</title>
      <link>https://www.infosecurity-magazine.com/news/microsoft-patch-tuesday-record/</link>
      <guid isPermaLink="false">https://www.infosecurity-magazine.com/news/microsoft-patch-tuesday-record/</guid>
      <pubDate>Wed, 09 Sep 2026 09:40:00 GMT</pubDate>
      <source url="https://www.infosecurity-magazine.com/">Infosecurity Magazine</source>
      <description>The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates (via Infosecurity Magazine)</description>
    </item>
    <item>
      <title>U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok</title>
      <link>https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html</link>
      <guid isPermaLink="false">https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html</guid>
      <pubDate>Wed, 09 Sep 2026 09:32:26 GMT</pubDate>
      <source url="https://thehackernews.com/">The Hacker News</source>
      <description>U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting &quot;systematic extraction&quot; of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been… (via The Hacker News)</description>
    </item>
    <item>
      <title>Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox</title>
      <link>https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html</link>
      <guid isPermaLink="false">https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html</guid>
      <pubDate>Wed, 09 Sep 2026 09:11:03 GMT</pubDate>
      <source url="https://thehackernews.com/">The Hacker News</source>
      <description>Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds… (via The Hacker News)</description>
    </item>
    <item>
      <title>September 2026 Patch Tuesday: Record patch count, 2 zero-days, and a SigRed successor</title>
      <link>https://www.helpnetsecurity.com/2026/09/09/september-2026-patch-tuesday-zero-days-sigred-successor/</link>
      <guid isPermaLink="false">https://www.helpnetsecurity.com/2026/09/09/september-2026-patch-tuesday-zero-days-sigred-successor/</guid>
      <pubDate>Wed, 09 Sep 2026 09:04:18 GMT</pubDate>
      <source url="https://www.helpnetsecurity.com/">Help Net Security</source>
      <description>September 2026 Patch Tuesday is here, with Microsoft delivering another record-breaking number of patches, including those for two vulnerabilities that have been exploited as zero-days. Another “new normal” is the anonymous security researcher Nightmare Eclipse publishing a… (via Help Net Security)</description>
    </item>
    <item>
      <title>Man gets 15 years for extorting women with AI-generated porn videos</title>
      <link>https://www.bleepingcomputer.com/news/security/man-gets-15-years-in-prison-for-cyberstalking-and-sextortion/</link>
      <guid isPermaLink="false">https://www.bleepingcomputer.com/news/security/man-gets-15-years-in-prison-for-cyberstalking-and-sextortion/</guid>
      <pubDate>Wed, 09 Sep 2026 08:44:22 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/">BleepingComputer</source>
      <description>An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...] (via BleepingComputer)</description>
    </item>
    <item>
      <title>CRPx0 ransomware: what you need to know</title>
      <link>https://www.fortra.com/blog/crpx0-ransomware-what-you-need-know</link>
      <guid isPermaLink="false">https://www.fortra.com/blog/crpx0-ransomware-what-you-need-know</guid>
      <pubDate>Wed, 09 Sep 2026 08:42:55 GMT</pubDate>
      <source url="https://grahamcluley.com/">Graham Cluley</source>
      <description>CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. Read more in my article on the Fortra blog. (via Graham Cluley)</description>
    </item>
    <item>
      <title>New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root</title>
      <link>https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html</link>
      <guid isPermaLink="false">https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html</guid>
      <pubDate>Wed, 09 Sep 2026 08:19:32 GMT</pubDate>
      <source url="https://thehackernews.com/">The Hacker News</source>
      <description>cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user.… (via The Hacker News)</description>
    </item>
    <item>
      <title>SAP Patches Maximum Severity “Overpass” Flaw</title>
      <link>https://www.infosecurity-magazine.com/news/sap-patches-maximum-severity/</link>
      <guid isPermaLink="false">https://www.infosecurity-magazine.com/news/sap-patches-maximum-severity/</guid>
      <pubDate>Wed, 09 Sep 2026 08:15:00 GMT</pubDate>
      <source url="https://www.infosecurity-magazine.com/">Infosecurity Magazine</source>
      <description>Onapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0 (via Infosecurity Magazine)</description>
    </item>
    <item>
      <title>F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans</title>
      <link>https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html</link>
      <guid isPermaLink="false">https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html</guid>
      <pubDate>Wed, 09 Sep 2026 07:36:49 GMT</pubDate>
      <source url="https://thehackernews.com/">The Hacker News</source>
      <description>Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances&#39; own PHP scripts, the malware adds the web… (via The Hacker News)</description>
    </item>
    <item>
      <title>New Microsoft Defender &#39;ShieldCrash&#39; zero-day grants SYSTEM access</title>
      <link>https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/</link>
      <guid isPermaLink="false">https://www.bleepingcomputer.com/news/security/new-microsoft-defender-shieldcrash-zero-day-grants-system-access/</guid>
      <pubDate>Wed, 09 Sep 2026 07:30:15 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/">BleepingComputer</source>
      <description>An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named &quot;ShieldCrash&quot; right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...] (via BleepingComputer)</description>
    </item>
    <item>
      <title>Google warns of new Chrome zero-day bug exploited in attacks</title>
      <link>https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/</link>
      <guid isPermaLink="false">https://www.bleepingcomputer.com/news/security/google-patches-seventh-chrome-zero-day-exploited-in-attacks-this-year/</guid>
      <pubDate>Wed, 09 Sep 2026 06:25:48 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/">BleepingComputer</source>
      <description>Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...] (via BleepingComputer)</description>
    </item>
    <item>
      <title>ISC Stormcast For Wednesday, September 9th, 2026 https://isc.sans.edu/podcastdetail/10086, (Wed, Sep 9th)</title>
      <link>https://isc.sans.edu/diary/rss/33322</link>
      <guid isPermaLink="false">https://isc.sans.edu/diary/rss/33322</guid>
      <pubDate>Wed, 09 Sep 2026 02:00:02 GMT</pubDate>
      <source url="https://isc.sans.edu/">SANS Internet Storm Center</source>
      <description>via SANS Internet Storm Center</description>
    </item>
    <item>
      <title>Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults</title>
      <link>https://www.bleepingcomputer.com/news/microsoft/microsoft-adds-age-awareness-apis-that-can-tell-if-users-are-children-teens-or-adults/</link>
      <guid isPermaLink="false">https://www.bleepingcomputer.com/news/microsoft/microsoft-adds-age-awareness-apis-that-can-tell-if-users-are-children-teens-or-adults/</guid>
      <pubDate>Wed, 09 Sep 2026 01:16:27 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/">BleepingComputer</source>
      <description>Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...] (via BleepingComputer)</description>
    </item>
    <item>
      <title>Microsoft discloses two actively exploited zero-days among 974 vulnerabilities</title>
      <link>https://cyberscoop.com/microsoft-patch-tuesday-september-2026/</link>
      <guid isPermaLink="false">https://cyberscoop.com/microsoft-patch-tuesday-september-2026/</guid>
      <pubDate>Tue, 08 Sep 2026 22:50:41 GMT</pubDate>
      <source url="https://cyberscoop.com/">CyberScoop</source>
      <description>While the vendor hit another monthly record, it hasn’t resulted in a flood of active exploits. Researchers encourage customers to focus on their specific areas of risk and exposure. The post Microsoft discloses two actively exploited zero-days among 974 vulnerabilities appeared… (via CyberScoop)</description>
    </item>
    <item>
      <title>Microsoft posts nearly 1,000 bugs for Patch Tuesday as CISA warns two being exploited</title>
      <link>https://therecord.media/microsoft-patch-tuesday-september-2026</link>
      <guid isPermaLink="false">https://therecord.media/microsoft-patch-tuesday-september-2026</guid>
      <pubDate>Tue, 08 Sep 2026 22:40:00 GMT</pubDate>
      <source url="https://therecord.media/">The Record</source>
      <description>The new record total for Patch Tuesday is 973 vulnerabilities. (via The Record)</description>
    </item>
    <item>
      <title>Microsoft Plugs Nearly 1,000 Security Holes</title>
      <link>https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/</link>
      <guid isPermaLink="false">https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/</guid>
      <pubDate>Tue, 08 Sep 2026 21:44:22 GMT</pubDate>
      <source url="https://krebsonsecurity.com/">Krebs on Security</source>
      <description>Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security… (via Krebs on Security)</description>
    </item>
    <item>
      <title>Patch Tuesday Sets Another Record With 974 CVEs</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/patch-tuesday-another-record-974-cves</link>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/patch-tuesday-another-record-974-cves</guid>
      <pubDate>Tue, 08 Sep 2026 21:26:02 GMT</pubDate>
      <source url="https://www.darkreading.com/">Dark Reading</source>
      <description>Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft. (via Dark Reading)</description>
    </item>
    <item>
      <title>Why this month&#39;s Microsoft patch release is a doozy</title>
      <link>https://arstechnica.com/security/2026/09/microsoft-patches-a-record-972-vulnerabilities-112-of-them-critical/</link>
      <guid isPermaLink="false">https://arstechnica.com/security/2026/09/microsoft-patches-a-record-972-vulnerabilities-112-of-them-critical/</guid>
      <pubDate>Tue, 08 Sep 2026 21:11:46 GMT</pubDate>
      <source url="https://arstechnica.com/security/">Ars Technica Security</source>
      <description>Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks. (via Ars Technica Security)</description>
    </item>
    <item>
      <title>Attackers Use Multi-Hop Google Redirects for Phishing Campaign</title>
      <link>https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign</link>
      <guid isPermaLink="false">https://www.darkreading.com/cyberattacks-data-breaches/attackers-multi-hop-google-redirects-phishing-campaign</guid>
      <pubDate>Tue, 08 Sep 2026 21:03:46 GMT</pubDate>
      <source url="https://www.darkreading.com/">Dark Reading</source>
      <description>Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access. (via Dark Reading)</description>
    </item>
    <item>
      <title>Scammer behind $245 million crypto heist pleads guilty to RICO charges</title>
      <link>https://therecord.media/scammer-behind-245-million-crypto-heist-pleads-guilty-rico</link>
      <guid isPermaLink="false">https://therecord.media/scammer-behind-245-million-crypto-heist-pleads-guilty-rico</guid>
      <pubDate>Tue, 08 Sep 2026 20:52:00 GMT</pubDate>
      <source url="https://therecord.media/">The Record</source>
      <description>Malone Lam was indicted on scamming charges in September 2024 after drawing law enforcement scrutiny for parlaying stolen crypto into lavish Hamptons vacations, cars and private jets. (via The Record)</description>
    </item>
    <item>
      <title>Feds accuse China of ‘systematic’ distillation of U.S. AI models</title>
      <link>https://cyberscoop.com/us-accuses-chinese-ai-companies-distillation/</link>
      <guid isPermaLink="false">https://cyberscoop.com/us-accuses-chinese-ai-companies-distillation/</guid>
      <pubDate>Tue, 08 Sep 2026 20:47:53 GMT</pubDate>
      <source url="https://cyberscoop.com/">CyberScoop</source>
      <description>A joint advisory alleges Chinese companies are using sophisticated systems to route millions of data requests to US AI models across different accounts and platforms. The post Feds accuse China of ‘systematic’ distillation of U.S. AI models appeared first on CyberScoop . (via CyberScoop)</description>
    </item>
    <item>
      <title>OpenAI Agents Took Over Wiki Site Before Hugging Face Attack</title>
      <link>https://www.darkreading.com/cyberattacks-data-breaches/openai-agents-wiki-site-hugging-face-attack</link>
      <guid isPermaLink="false">https://www.darkreading.com/cyberattacks-data-breaches/openai-agents-wiki-site-hugging-face-attack</guid>
      <pubDate>Tue, 08 Sep 2026 20:36:15 GMT</pubDate>
      <source url="https://www.darkreading.com/">Dark Reading</source>
      <description>Researchers and OpenAI disagree on whether the earlier incident involving DseWiki, which the company did not disclose, was a “hack.&quot; (via Dark Reading)</description>
    </item>
    <item>
      <title>DoppelCart fraud network uses 119,000 fake shops to steal credit cards</title>
      <link>https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/</link>
      <guid isPermaLink="false">https://www.bleepingcomputer.com/news/security/doppelcart-fraud-network-uses-119-000-fake-shops-to-steal-credit-cards/</guid>
      <pubDate>Tue, 08 Sep 2026 20:35:14 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/">BleepingComputer</source>
      <description>A massive operation dubbed &quot;DoppelCart&quot; uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...] (via BleepingComputer)</description>
    </item>
    <item>
      <title>Russian national extradited to US for alleged involvement in bank-account takeover scheme</title>
      <link>https://cyberscoop.com/russian-national-extradited-bank-account-takeover-sergei-filimonov/</link>
      <guid isPermaLink="false">https://cyberscoop.com/russian-national-extradited-bank-account-takeover-sergei-filimonov/</guid>
      <pubDate>Tue, 08 Sep 2026 20:32:03 GMT</pubDate>
      <source url="https://cyberscoop.com/">CyberScoop</source>
      <description>Authorities accuse the 36-year-old and co-conspirators of collecting more than 5,000 victim login credentials to various banks. The post Russian national extradited to US for alleged involvement in bank-account takeover scheme appeared first on CyberScoop . (via CyberScoop)</description>
    </item>
    <item>
      <title>The EU CRA&#39;s Real Question: What Shipped, and When Did You Know?</title>
      <link>https://www.bleepingcomputer.com/news/security/the-eu-cras-real-question-what-shipped-and-when-did-you-know/</link>
      <guid isPermaLink="false">https://www.bleepingcomputer.com/news/security/the-eu-cras-real-question-what-shipped-and-when-did-you-know/</guid>
      <pubDate>Tue, 08 Sep 2026 20:24:16 GMT</pubDate>
      <source url="https://www.bleepingcomputer.com/">BleepingComputer</source>
      <description>The EU Cyber Resilience Act&#39;s vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be… (via BleepingComputer)</description>
    </item>
    <item>
      <title>CIA’s Michael Ellis says cyber intelligence is changing how the agency operates</title>
      <link>https://cyberscoop.com/cia-cyber-operations-operation-absolute-resolve-michael-ellis-billington-cybersecurity/</link>
      <guid isPermaLink="false">https://cyberscoop.com/cia-cyber-operations-operation-absolute-resolve-michael-ellis-billington-cybersecurity/</guid>
      <pubDate>Tue, 08 Sep 2026 19:49:14 GMT</pubDate>
      <source url="https://cyberscoop.com/">CyberScoop</source>
      <description>The deputy director cited Operation Absolute Resolve as evidence that cyber teams have become central to CIA missions. The post CIA’s Michael Ellis says cyber intelligence is changing how the agency operates appeared first on CyberScoop . (via CyberScoop)</description>
    </item>
    <item>
      <title>CIA official touts agency’s Cyber Mission Center in capture of Venezuela’s Maduro</title>
      <link>https://therecord.media/cia-cyber-operations-maduro-capture-venezuela</link>
      <guid isPermaLink="false">https://therecord.media/cia-cyber-operations-maduro-capture-venezuela</guid>
      <pubDate>Tue, 08 Sep 2026 19:46:00 GMT</pubDate>
      <source url="https://therecord.media/">The Record</source>
      <description>A &quot;flawless&quot; performance by the CIA&#39;s Cyber Mission Center contributed to the capture of Venezuelan President Nicolás Maduro in January, agency Deputy Director Michael Ellis says. (via The Record)</description>
    </item>
    <item>
      <title>Russian suspect in bank account takeovers is extradited to US</title>
      <link>https://therecord.media/russian-cybercrime-bank-extradition</link>
      <guid isPermaLink="false">https://therecord.media/russian-cybercrime-bank-extradition</guid>
      <pubDate>Tue, 08 Sep 2026 19:37:42 GMT</pubDate>
      <source url="https://therecord.media/">The Record</source>
      <description>A Russian web developer who played a role in a multimillion-dollar bank account takeover scheme has been extradited to the U.S. to face an indictment. (via The Record)</description>
    </item>
    <item>
      <title>September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)</title>
      <link>https://isc.sans.edu/diary/rss/33320</link>
      <guid isPermaLink="false">https://isc.sans.edu/diary/rss/33320</guid>
      <pubDate>Tue, 08 Sep 2026 19:20:30 GMT</pubDate>
      <source url="https://isc.sans.edu/">SANS Internet Storm Center</source>
      <description>This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well ahead of the previous high of 664 set in July 2026. Two vulnerabilities are listed as exploited in the wild, while… (via SANS Internet Storm Center)</description>
    </item>
    <item>
      <title>The Socrates Agent</title>
      <link>https://danielmiessler.com/blog/the-socrates-agent?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</link>
      <guid isPermaLink="false">https://danielmiessler.com/blog/the-socrates-agent?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</guid>
      <pubDate>Tue, 08 Sep 2026 18:45:00 GMT</pubDate>
      <source url="https://danielmiessler.com/">Daniel Miessler</source>
      <description>A charcoal sketch of four slumped people being fed sheets of paper by a tall purple machine, while across the room one person writes at a wooden desk and a small purple Socrates leans in with open, empty hands/images/the-socrates-agent.webp/images/the-socrates-agent.webp… (via Daniel Miessler)</description>
    </item>
    <item>
      <title>Why federal cyber defense demands an offense-driven mindset</title>
      <link>https://cyberscoop.com/offense-driven-federal-cyber-defense/</link>
      <guid isPermaLink="false">https://cyberscoop.com/offense-driven-federal-cyber-defense/</guid>
      <pubDate>Tue, 08 Sep 2026 18:30:00 GMT</pubDate>
      <source url="https://cyberscoop.com/">CyberScoop</source>
      <description>Static checklists and annual penetration tests leave agencies with dangerous blind spots. True resilience requires moving from reactive attestation to continuous, automated validation. The post Why federal cyber defense demands an offense-driven mindset appeared first on… (via CyberScoop)</description>
    </item>
    <item>
      <title>ClickFix Campaigns Abuse Legitimate Services for Persistent Access</title>
      <link>https://www.darkreading.com/endpoint-security/clickfix-campaigns-legitimate-services-persistent-access</link>
      <guid isPermaLink="false">https://www.darkreading.com/endpoint-security/clickfix-campaigns-legitimate-services-persistent-access</guid>
      <pubDate>Tue, 08 Sep 2026 17:25:37 GMT</pubDate>
      <source url="https://www.darkreading.com/">Dark Reading</source>
      <description>Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic. (via Dark Reading)</description>
    </item>
    <item>
      <title>AIs as Modern Genies</title>
      <link>https://www.schneier.com/blog/archives/2026/09/ais-as-modern-genies.html</link>
      <guid isPermaLink="false">https://www.schneier.com/blog/archives/2026/09/ais-as-modern-genies.html</guid>
      <pubDate>Tue, 08 Sep 2026 17:12:42 GMT</pubDate>
      <source url="https://www.schneier.com/">Schneier on Security</source>
      <description>This essay was written with Barath Raghavan, and originally appeared in Lawfare . In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its… (via Schneier on Security)</description>
    </item>
    <item>
      <title>The US military just turned off ad tracking on its phones. Maybe you should too</title>
      <link>https://www.bitdefender.com/en-us/blog/hotforsecurity/us-military-turned-off-ad-tracking-phones</link>
      <guid isPermaLink="false">https://www.bitdefender.com/en-us/blog/hotforsecurity/us-military-turned-off-ad-tracking-phones</guid>
      <pubDate>Tue, 08 Sep 2026 15:33:07 GMT</pubDate>
      <source url="https://grahamcluley.com/">Graham Cluley</source>
      <description>Location data sold by the ad industry has reportedly helped adversaries target US troops. The Pentagon has responded by switching off ad tracking on its devices - and you can do the same on yours. Read more in my article on the Hot for Security blog. (via Graham Cluley)</description>
    </item>
    <item>
      <title>France Establishes New Government-Focused Cyber Incident Response Unit</title>
      <link>https://www.infosecurity-magazine.com/news/france-new-government-cyber/</link>
      <guid isPermaLink="false">https://www.infosecurity-magazine.com/news/france-new-government-cyber/</guid>
      <pubDate>Tue, 08 Sep 2026 14:30:00 GMT</pubDate>
      <source url="https://www.infosecurity-magazine.com/">Infosecurity Magazine</source>
      <description>After a major cyber-attack targeted France&#39;s national tax authority, the Prime Minister called for the establishment of a new dedicated cyber incident response capability (via Infosecurity Magazine)</description>
    </item>
    <item>
      <title>Grindr Settles UK Data Privacy Claims for £26m</title>
      <link>https://www.infosecurity-magazine.com/news/grindr-settles-uk-data-privacy/</link>
      <guid isPermaLink="false">https://www.infosecurity-magazine.com/news/grindr-settles-uk-data-privacy/</guid>
      <pubDate>Tue, 08 Sep 2026 13:00:00 GMT</pubDate>
      <source url="https://www.infosecurity-magazine.com/">Infosecurity Magazine</source>
      <description>Grindr settled UK claims over alleged unlawful processing of sensitive user data (via Infosecurity Magazine)</description>
    </item>
    <item>
      <title>AI Coding Tools Now a Prime Target for Threat Actors, Google Warns</title>
      <link>https://www.infosecurity-magazine.com/news/ai-coding-tools-threat-actors/</link>
      <guid isPermaLink="false">https://www.infosecurity-magazine.com/news/ai-coding-tools-threat-actors/</guid>
      <pubDate>Tue, 08 Sep 2026 12:02:00 GMT</pubDate>
      <source url="https://www.infosecurity-magazine.com/">Infosecurity Magazine</source>
      <description>Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks (via Infosecurity Magazine)</description>
    </item>
    <item>
      <title>Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites</title>
      <link>https://www.darkreading.com/threat-intelligence/cybercriminals-hack-brazilian-government-servers-host-phishing-sites</link>
      <guid isPermaLink="false">https://www.darkreading.com/threat-intelligence/cybercriminals-hack-brazilian-government-servers-host-phishing-sites</guid>
      <pubDate>Tue, 08 Sep 2026 12:00:00 GMT</pubDate>
      <source url="https://www.darkreading.com/">Dark Reading</source>
      <description>A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites. (via Dark Reading)</description>
    </item>
    <item>
      <title>Stealing AI Reasoning Traces</title>
      <link>https://www.schneier.com/blog/archives/2026/09/stealing-ai-reasoning-traces.html</link>
      <guid isPermaLink="false">https://www.schneier.com/blog/archives/2026/09/stealing-ai-reasoning-traces.html</guid>
      <pubDate>Tue, 08 Sep 2026 10:20:04 GMT</pubDate>
      <source url="https://www.schneier.com/">Schneier on Security</source>
      <description>Interesting research: “ Stealing Reasoning Traces from Proprietary LLM APIs “: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than… (via Schneier on Security)</description>
    </item>
    <item>
      <title>In most cities, nobody owns the whole network</title>
      <link>https://cyberscoop.com/water-utility-cybersecurity-network-segmentation-op-ed/</link>
      <guid isPermaLink="false">https://cyberscoop.com/water-utility-cybersecurity-network-segmentation-op-ed/</guid>
      <pubDate>Tue, 08 Sep 2026 10:00:00 GMT</pubDate>
      <source url="https://cyberscoop.com/">CyberScoop</source>
      <description>July’s intrusions reached water controllers that sat on a cellular link no city network scan would find. Naming an owner and paying for the fix are decisions a utility can make this fiscal year, out of money it already applies for. The post In most cities, nobody owns the whole… (via CyberScoop)</description>
    </item>
    <item>
      <title>Testing race conditions with memory access tracing and stack-based delay injection</title>
      <link>https://projectzero.google/2026/09/maccconc-race-condition.html</link>
      <guid isPermaLink="false">https://projectzero.google/2026/09/maccconc-race-condition.html</guid>
      <pubDate>Tue, 08 Sep 2026 07:00:00 GMT</pubDate>
      <source url="https://googleprojectzero.blogspot.com/">Google Project Zero</source>
      <description>Many security bugs are race conditions, where multi-threaded execution has to occur with the right interleaving for a negative effect to appear. This creates challenges for several use cases: Confirming bug candidates that have been discovered manually or through static… (via Google Project Zero)</description>
    </item>
    <item>
      <title>ISC Stormcast For Tuesday, September 8th, 2026 https://isc.sans.edu/podcastdetail/10084, (Tue, Sep 8th)</title>
      <link>https://isc.sans.edu/diary/rss/33316</link>
      <guid isPermaLink="false">https://isc.sans.edu/diary/rss/33316</guid>
      <pubDate>Tue, 08 Sep 2026 02:00:03 GMT</pubDate>
      <source url="https://isc.sans.edu/">SANS Internet Storm Center</source>
      <description>via SANS Internet Storm Center</description>
    </item>
    <item>
      <title>Watch the Plot</title>
      <link>https://danielmiessler.com/blog/watch-the-plot?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</link>
      <guid isPermaLink="false">https://danielmiessler.com/blog/watch-the-plot?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</guid>
      <pubDate>Tue, 08 Sep 2026 01:16:00 GMT</pubDate>
      <source url="https://danielmiessler.com/">Daniel Miessler</source>
      <description>Charcoal cutaway of a three-story building: a small purple glass lab on top where researchers admire a humanoid robot, and two much larger sienna floors below crowded with a family at a kitchen table, an old man in a sickbed, a child reading under a bare bulb, and a mother… (via Daniel Miessler)</description>
    </item>
    <item>
      <title>The Good Person Bank</title>
      <link>https://danielmiessler.com/blog/the-good-person-bank?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</link>
      <guid isPermaLink="false">https://danielmiessler.com/blog/the-good-person-bank?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</guid>
      <pubDate>Tue, 08 Sep 2026 00:30:00 GMT</pubDate>
      <source url="https://danielmiessler.com/">Daniel Miessler</source>
      <description>A charcoal sketch of a man whose head is an open purple ledger with a rubber stamp on it, dropping coins into a donation box held by a smiling person on his left while his other arm shoves a startled waiter away on his… (via Daniel Miessler)</description>
    </item>
    <item>
      <title>Humans Aren&#39;t Aligned Either</title>
      <link>https://danielmiessler.com/blog/humans-arent-aligned-either?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</link>
      <guid isPermaLink="false">https://danielmiessler.com/blog/humans-arent-aligned-either?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</guid>
      <pubDate>Tue, 08 Sep 2026 00:27:00 GMT</pubDate>
      <source url="https://danielmiessler.com/">Daniel Miessler</source>
      <description>Charcoal sketch of a man in a long coat holding a carpenter&#39;s level against an upright purple machine, while behind him a toppled column smokes and small figures huddle in the rubble/images/humans-arent-aligned-either-header.webp/images/humans-arent-aligned-either-header.webp… (via Daniel Miessler)</description>
    </item>
    <item>
      <title>Automobile Camouflage to Hide from Flock Cameras</title>
      <link>https://www.schneier.com/blog/archives/2026/09/automobile-camouflage-to-hide-from-flock-cameras.html</link>
      <guid isPermaLink="false">https://www.schneier.com/blog/archives/2026/09/automobile-camouflage-to-hide-from-flock-cameras.html</guid>
      <pubDate>Mon, 07 Sep 2026 11:06:40 GMT</pubDate>
      <source url="https://www.schneier.com/">Schneier on Security</source>
      <description>Not sure it’s practical, but it’s certainly striking . (via Schneier on Security)</description>
    </item>
    <item>
      <title>How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts</title>
      <link>https://www.bitdefender.com/en-us/blog/hotforsecurity/lenovo-login-system-hackers-dropbox</link>
      <guid isPermaLink="false">https://www.bitdefender.com/en-us/blog/hotforsecurity/lenovo-login-system-hackers-dropbox</guid>
      <pubDate>Mon, 07 Sep 2026 10:30:27 GMT</pubDate>
      <source url="https://grahamcluley.com/">Graham Cluley</source>
      <description>If you ever linked your Dropbox account to a Lenovo ID - perhaps to make life easier when logging in via a Lenovo laptop - you might want to take heed. Read more in my article on the Hot for Security blog. (via Graham Cluley)</description>
    </item>
    <item>
      <title>Dissecting a PHP web server rootkit</title>
      <link>https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit</link>
      <guid isPermaLink="false">https://www.sophos.com/en-us/blog/dissecting-a-php-web-server-rootkit</guid>
      <pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate>
      <source url="https://news.sophos.com/">Sophos News</source>
      <description>Sophos X-Ops takes a deep dive into an insidious piece of malware (via Sophos News)</description>
    </item>
    <item>
      <title>Weekly Update 520: The Unscripted Edition</title>
      <link>https://www.troyhunt.com/weekly-update-520/</link>
      <guid isPermaLink="false">https://www.troyhunt.com/weekly-update-520/</guid>
      <pubDate>Sun, 06 Sep 2026 23:31:36 GMT</pubDate>
      <source url="https://www.troyhunt.com/">Troy Hunt</source>
      <description>I&#39;ve started playing around with YouTube&#39;s &quot;create video thumbnail&quot;, which hopefully will give me back a bit of time in my day (it used to be a manual job in Photoshop) and be a bit more interesting. And on that note, the imagery it&amp; (via Troy Hunt)</description>
    </item>
    <item>
      <title>Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)</title>
      <link>https://isc.sans.edu/diary/rss/33314</link>
      <guid isPermaLink="false">https://isc.sans.edu/diary/rss/33314</guid>
      <pubDate>Sun, 06 Sep 2026 21:43:17 GMT</pubDate>
      <source url="https://isc.sans.edu/">SANS Internet Storm Center</source>
      <description>Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access… (via SANS Internet Storm Center)</description>
    </item>
    <item>
      <title>numbat - AI agent observability, (Fri, Sep 4th)</title>
      <link>https://isc.sans.edu/diary/rss/33312</link>
      <guid isPermaLink="false">https://isc.sans.edu/diary/rss/33312</guid>
      <pubDate>Sat, 05 Sep 2026 03:39:52 GMT</pubDate>
      <source url="https://isc.sans.edu/">SANS Internet Storm Center</source>
      <description>via SANS Internet Storm Center</description>
    </item>
    <item>
      <title>OpenAI agents discussed ways to escape their sandbox on public wiki</title>
      <link>https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/</link>
      <guid isPermaLink="false">https://arstechnica.com/security/2026/09/openai-agents-discussed-ways-to-escape-their-sandbox-on-public-wiki/</guid>
      <pubDate>Fri, 04 Sep 2026 22:17:36 GMT</pubDate>
      <source url="https://arstechnica.com/security/">Ars Technica Security</source>
      <description>In all, 3,700 internal agents posted 18,000 messages discussing cheating on a test. (via Ars Technica Security)</description>
    </item>
    <item>
      <title>European parliament members call for slowdown of Serbia’s EU entry over spyware use</title>
      <link>https://cyberscoop.com/eu-parliament-serbia-accession-spyware-demands/</link>
      <guid isPermaLink="false">https://cyberscoop.com/eu-parliament-serbia-accession-spyware-demands/</guid>
      <pubDate>Fri, 04 Sep 2026 21:02:39 GMT</pubDate>
      <source url="https://cyberscoop.com/">CyberScoop</source>
      <description>The letter follows revelations about Serbian student activists being infected with Pegasus and NoviSpy, and coincides with other pressures on Belgrade. The post European parliament members call for slowdown of Serbia’s EU entry over spyware use appeared first on CyberScoop . (via CyberScoop)</description>
    </item>
    <item>
      <title>Friday Squid Blogging: Squid on a Stick at the New York State Fair</title>
      <link>https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-squid-on-a-stick-at-the-new-york-state-fair.html</link>
      <guid isPermaLink="false">https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-squid-on-a-stick-at-the-new-york-state-fair.html</guid>
      <pubDate>Fri, 04 Sep 2026 21:01:35 GMT</pubDate>
      <source url="https://www.schneier.com/">Schneier on Security</source>
      <description>Looks tasty . As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy. (via Schneier on Security)</description>
    </item>
    <item>
      <title>How to secure edge AI in customer-owned environments</title>
      <link>https://www.microsoft.com/en-us/security/blog/2026/09/04/secure-edge-ai-customer-owned-environments/</link>
      <guid isPermaLink="false">https://www.microsoft.com/en-us/security/blog/2026/09/04/secure-edge-ai-customer-owned-environments/</guid>
      <pubDate>Fri, 04 Sep 2026 19:10:10 GMT</pubDate>
      <source url="https://www.microsoft.com/en-us/security/blog/">Microsoft Security Blog</source>
      <description>As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned environments appeared first on Microsoft… (via Microsoft Security Blog)</description>
    </item>
    <item>
      <title>Socratic AI</title>
      <link>https://danielmiessler.com/blog/socratic-ai?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</link>
      <guid isPermaLink="false">https://danielmiessler.com/blog/socratic-ai?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</guid>
      <pubDate>Fri, 04 Sep 2026 19:05:00 GMT</pubDate>
      <source url="https://danielmiessler.com/">Daniel Miessler</source>
      <description>A charcoal sketch of a student at a desk with a finished handwritten page in front of him while a purple AI figure across the desk hands his pencil back to him, its other palm open and empty/images/socratic-ai-pencil.webp/images/socratic-ai-pencil.webp I&#39;ve been thinking about… (via Daniel Miessler)</description>
    </item>
    <item>
      <title>Cliff&#39;s Notes for Everything</title>
      <link>https://danielmiessler.com/blog/cliffs-notes-for-everything?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</link>
      <guid isPermaLink="false">https://danielmiessler.com/blog/cliffs-notes-for-everything?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</guid>
      <pubDate>Fri, 04 Sep 2026 18:43:00 GMT</pubDate>
      <source url="https://danielmiessler.com/">Daniel Miessler</source>
      <description>A sienna sketch of a man squatting under a giant open book he is lifting overhead, while a purple robot arm on a desk hands a striped summary sheet to a faint gray figure/images/cliffs-notes-for-everything.webp/images/cliffs-notes-for-everything.webp There&#39;s something really… (via Daniel Miessler)</description>
    </item>
    <item>
      <title>Once popular for attacking AI, ASCII smuggling is embraced by spammers</title>
      <link>https://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/</link>
      <guid isPermaLink="false">https://arstechnica.com/security/2026/09/once-popular-for-attacking-ai-ascii-smuggling-is-embraced-by-spammers/</guid>
      <pubDate>Fri, 04 Sep 2026 17:18:12 GMT</pubDate>
      <source url="https://arstechnica.com/security/">Ars Technica Security</source>
      <description>A once-overlooked block of unicode that&#39;s invisible to humans is gaining ever wider use. (via Ars Technica Security)</description>
    </item>
    <item>
      <title>Using a VM to Contain an AI Agent</title>
      <link>https://www.schneier.com/blog/archives/2026/09/using-a-vm-to-contain-an-ai-agent.html</link>
      <guid isPermaLink="false">https://www.schneier.com/blog/archives/2026/09/using-a-vm-to-contain-an-ai-agent.html</guid>
      <pubDate>Fri, 04 Sep 2026 16:31:38 GMT</pubDate>
      <source url="https://www.schneier.com/">Schneier on Security</source>
      <description>It won’t work : My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which they interact. An off-the-shelf VM is not… (via Schneier on Security)</description>
    </item>
    <item>
      <title>Companies Have 6 Months to Prepare for Automated Attacks</title>
      <link>https://www.darkreading.com/cybersecurity-operations/companies-six-months-prepare-automated-attacks</link>
      <guid isPermaLink="false">https://www.darkreading.com/cybersecurity-operations/companies-six-months-prepare-automated-attacks</guid>
      <pubDate>Fri, 04 Sep 2026 15:57:31 GMT</pubDate>
      <source url="https://www.darkreading.com/">Dark Reading</source>
      <description>Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon. (via Dark Reading)</description>
    </item>
    <item>
      <title>AI Is Ending the Era of Hidden Vulnerabilities — Are Vendors Ready?</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/ai-ending-era-hidden-vulnerabilities-are-vendors-ready</link>
      <guid isPermaLink="false">https://www.darkreading.com/vulnerabilities-threats/ai-ending-era-hidden-vulnerabilities-are-vendors-ready</guid>
      <pubDate>Fri, 04 Sep 2026 13:00:00 GMT</pubDate>
      <source url="https://www.darkreading.com/">Dark Reading</source>
      <description>A tidal wave of bug reports is overwhelming software vendors, exposing secure-by-design failures and creating disclosure bottlenecks. (via Dark Reading)</description>
    </item>
    <item>
      <title>Insurers Search for Answers to Rein in Rogue AI</title>
      <link>https://www.darkreading.com/cyber-risk/insurers-search-answers-rogue-ai</link>
      <guid isPermaLink="false">https://www.darkreading.com/cyber-risk/insurers-search-answers-rogue-ai</guid>
      <pubDate>Fri, 04 Sep 2026 12:15:03 GMT</pubDate>
      <source url="https://www.darkreading.com/">Dark Reading</source>
      <description>As incidents of unintended harm caused by rogue AI agents mount, CISOs and insurance firms are figuring out how to handle the fallout. (via Dark Reading)</description>
    </item>
    <item>
      <title>Security Vulnerability in a Voting System</title>
      <link>https://www.schneier.com/blog/archives/2026/09/security-vulnerability-in-a-voting-system.html</link>
      <guid isPermaLink="false">https://www.schneier.com/blog/archives/2026/09/security-vulnerability-in-a-voting-system.html</guid>
      <pubDate>Fri, 04 Sep 2026 11:09:35 GMT</pubDate>
      <source url="https://www.schneier.com/">Schneier on Security</source>
      <description>It’s a vulnerability that allows someone to recover the order of ballots cast, newly exploited with AI tools. Nearly four years since the original vulnerability was disclosed, I was still able to use it to analyze voter behavior in Georgia (one of the 21 states that uses… (via Schneier on Security)</description>
    </item>
    <item>
      <title>AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks</title>
      <link>https://www.schneier.com/blog/archives/2026/09/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate-networks.html</link>
      <guid isPermaLink="false">https://www.schneier.com/blog/archives/2026/09/ai-coding-agents-are-installing-unknown-untrusted-code-on-corporate-networks.html</guid>
      <pubDate>Fri, 04 Sep 2026 10:35:17 GMT</pubDate>
      <source url="https://www.schneier.com/">Schneier on Security</source>
      <description>We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites… (via Schneier on Security)</description>
    </item>
    <item>
      <title>Angry Birds: Toy Ghouls’ new toys</title>
      <link>https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/</link>
      <guid isPermaLink="false">https://securelist.com/toy-ghouls-new-hivemq-and-element-backdoors/121270/</guid>
      <pubDate>Fri, 04 Sep 2026 10:00:05 GMT</pubDate>
      <source url="https://securelist.com/">Securelist</source>
      <description>Kaspersky GERT experts have discovered new backdoors used by the Toy Ghouls group. One version of the backdoor uses the HiveMQ MQTT broker as its command-and-control server; the other uses the Matrix-based Element messenger. (via Securelist)</description>
    </item>
    <item>
      <title>Peak Human Readership</title>
      <link>https://danielmiessler.com/blog/peak-human-readership?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</link>
      <guid isPermaLink="false">https://danielmiessler.com/blog/peak-human-readership?utm_source=rss&amp;utm_medium=feed&amp;utm_campaign=website</guid>
      <pubDate>Fri, 04 Sep 2026 03:47:00 GMT</pubDate>
      <source url="https://danielmiessler.com/">Daniel Miessler</source>
      <description>A lone writer in warm sienna works at a desk on top of a purple machine that crushes his pages into tiny slips for a crowd below staring at their phones, while one person in sienna stands apart reading a full… (via Daniel Miessler)</description>
    </item>
    <item>
      <title>ISC Stormcast For Friday, September 4th, 2026 https://isc.sans.edu/podcastdetail/10082, (Fri, Sep 4th)</title>
      <link>https://isc.sans.edu/diary/rss/33310</link>
      <guid isPermaLink="false">https://isc.sans.edu/diary/rss/33310</guid>
      <pubDate>Fri, 04 Sep 2026 02:00:02 GMT</pubDate>
      <source url="https://isc.sans.edu/">SANS Internet Storm Center</source>
      <description>via SANS Internet Storm Center</description>
    </item>
    <item>
      <title>Confused about which VPN is right, US senator asks the NSA for guidance</title>
      <link>https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns/</link>
      <guid isPermaLink="false">https://arstechnica.com/security/2026/09/us-senator-calls-on-the-nsa-to-give-guidance-for-use-of-vpns/</guid>
      <pubDate>Thu, 03 Sep 2026 19:52:06 GMT</pubDate>
      <source url="https://arstechnica.com/security/">Ars Technica Security</source>
      <description>Open source, commercial, single-hop, multi-hop, mixnet? The array of options is dizzying. (via Ars Technica Security)</description>
    </item>
    <item>
      <title>ASCII smuggling crosses over from AI prompt injection to phishing evasion</title>
      <link>https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/</link>
      <guid isPermaLink="false">https://www.microsoft.com/en-us/security/blog/2026/09/03/ascii-smuggling-crosses-over-from-ai-prompt-injection-to-phishing-evasion/</guid>
      <pubDate>Thu, 03 Sep 2026 16:00:00 GMT</pubDate>
      <source url="https://www.microsoft.com/en-us/security/blog/">Microsoft Security Blog</source>
      <description>Invisible Unicode characters popularized for hiding instructions from AI models are now being used to obfuscate words before email filters parse them. The post ASCII smuggling crosses over from AI prompt injection to phishing evasion appeared first on Microsoft Security Blog . (via Microsoft Security Blog)</description>
    </item>
    <item>
      <title>Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America</title>
      <link>https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/</link>
      <guid isPermaLink="false">https://unit42.paloaltonetworks.com/ai-tool-use-targeting-latam-orgs/</guid>
      <pubDate>Thu, 03 Sep 2026 10:00:58 GMT</pubDate>
      <source url="https://unit42.paloaltonetworks.com/">Unit 42</source>
      <description>Explore how attackers targeting Latin American entities use AI for data exfiltration and how basic OpSec errors allow defenders to disrupt operations. The post Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin America appeared first on Unit 42 . (via Unit 42)</description>
    </item>
    <item>
      <title>Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)</title>
      <link>https://isc.sans.edu/diary/rss/33306</link>
      <guid isPermaLink="false">https://isc.sans.edu/diary/rss/33306</guid>
      <pubDate>Thu, 03 Sep 2026 02:02:56 GMT</pubDate>
      <source url="https://isc.sans.edu/">SANS Internet Storm Center</source>
      <description>[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program] (via SANS Internet Storm Center)</description>
    </item>
    <item>
      <title>ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)</title>
      <link>https://isc.sans.edu/diary/rss/33308</link>
      <guid isPermaLink="false">https://isc.sans.edu/diary/rss/33308</guid>
      <pubDate>Thu, 03 Sep 2026 02:00:03 GMT</pubDate>
      <source url="https://isc.sans.edu/">SANS Internet Storm Center</source>
      <description>via SANS Internet Storm Center</description>
    </item>
  </channel>
</rss>
