Cybersecurity firms Check Point, Kaspersky, and Tanium have each patched severe vulnerabilities in their products, including ones that can be exploited for remote code execution. Check Point has informed customers about a critical vulnerability affecting Security Management and Log Server… Read More "Check Point, Kaspersky, Tanium Patch Product Vulnerabilities"
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost… Read More "An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It."
Researchers Link Suspected Chinese APT to Hack-for-Hire Operations
Security researchers from Broadcom’s Threat Hunter Team have revealed that Jewelbug, a threat group associated with Chinese-sponsored cyber-espionage operations, may be a hacker-for-hire group that also runs profitable crypto fraud campaigns. In a new report published on August 13, the… Read More "Researchers Link Suspected Chinese APT to Hack-for-Hire Operations"
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy… Read More "In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw"
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Ravie LakshmananSep 18, 2026Vulnerability / Cloud Security Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a… Read More "Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation"
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufa
A new ransomware variant named Settra has been deployed in incidents targeting the retail and manufacturing sectors, according to Huntress. The variant was first observed in June, and Huntress researchers highlighted notable post-compromise techniques used by threat actors deploying Settra… Read More "New Settra Ransomware Variant Deployed in Attacks on Retail and Manufa"
Meta’s Copyright System Is Being Weaponized Against Albanian Protesters
European lawmakers are calling for an investigation into Meta after the mass suspension of accounts posting about anti-government protests in Albania, in what observers believe is a coordinated brigading attack. “What happened in Albania is tantamount to censorship,” said MEP… Read More "Meta’s Copyright System Is Being Weaponized Against Albanian Protesters"
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Researchers at security firm Hacktron used Claude to build a working exploit for a vulnerability in an image-processing library, then chained it with a flaw in OpenAI’s sign-in system to take over employee ChatGPT and Codex accounts, and ultimately gained… Read More "AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code"
Novel macOS Infostealer AmnesiaStealer Spread via ClickFix
A new macOS infostealer is being distributed via ClickFix social engineering attacks, researchers from Jamf have warned. The Rust infostealer, dubbed AmnesiaStealer, has multiple stages and objectives once it has infected a victim device, including harvesting credentials, browser data and… Read More "Novel macOS Infostealer AmnesiaStealer Spread via ClickFix"
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into over 100,000 websites. Brevo was initially hacked on September 10, when a threat actor exploited a vulnerability in Brevo’s handling of… Read More "Brevo Supply Chain Attack Injects Malware Into 100,000 Websites"