Meta has confirmed that one of its AI models exploited a vulnerability in a third-party service during testing, joining OpenAI and Anthropic in reporting similar incidents. Meta said the incident occurred during testing by independent firm Irregular. A misconfiguration by… Read More "Meta Joins OpenAI and Anthropic in Reporting AI Exploit Incident"
Best Threat Intelligence Platforms and Vendors
A threat intelligence platform (TIP) is the software layer that bridges the gap between raw threat data and your team’s security decisions. It aggregates signals from open, deep, and dark web sources, normalizes indicators of compromise (IOCs), enriches them with… Read More "Best Threat Intelligence Platforms and Vendors"
Adobe Commerce Zero-Day Exploited to Backdoor Online Stores
Threat actors are exploiting a zero-day vulnerability in Adobe Commerce and Magento e-commerce platforms to backdoor online stores, cybersecurity firm Sansec reports. Dubbed StyleSmuggler, the security defect enables attackers to inject PHP code into Magento’s template system and evade detection… Read More "Adobe Commerce Zero-Day Exploited to Backdoor Online Stores"
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
Ravie LakshmananSep 07, 2026Phishing / Identity Security Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token… Read More "Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks"
Rhysida Publishes Berlin Government Data After €2m Extortion Demand Re
Berlin’s state government has confirmed that the Rhysida ransomware gang has published a stolen dataset on the dark web, after it refused to pay the threat actor’s extortion demand. The State of Berlin said Rhysida had demanded 30 bitcoins, equivalent… Read More "Rhysida Publishes Berlin Government Data After €2m Extortion Demand Re"
Best Shadow AI Governance Tools for Enterprises: Buyer’s Shortlist
Security teams already know employees use generative AI. The harder problem is buying the right platform before unsanctioned apps move sensitive data outside your visibility and control. UpGuard research found 81% of employees and 88% of security leaders use unapproved… Read More "Best Shadow AI Governance Tools for Enterprises: Buyer’s Shortlist"
OpenAI Agents Hijack Another Victim Website
OpenAI agents overwhelmed a small German Wikipedia-style website with thousands of posts that fought the moderator to avoid being removed. On September 4, 2026, Reuters reported that ‘a swarm’ of OpenAI agents ‘had hijacked a German wiki site’. Open AI… Read More "OpenAI Agents Hijack Another Victim Website"
Ransomware Attack Vectors: 5 Endpoint Blind Spots
Ransomware rarely appears out of nowhere. Before encryption, extortion, or data theft begins, attackers often spend time establishing access, stealing credentials, moving laterally, and identifying valuable systems. These activities occur during the ransomware pre-execution phase, when malicious activity may be… Read More "Ransomware Attack Vectors: 5 Endpoint Blind Spots"
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Ravie LakshmananSep 07, 2026Malware / Vulnerability Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found… Read More "Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts"
NCSC Warns Shadow AI Creates New Security Risks
The UK’s National Cyber Security Centre (NCSC) has warned that employees using unapproved AI tools can expose corporate data and create security risks that organizations may struggle to detect and manage. The NCSC blog post, published on September 7, said… Read More "NCSC Warns Shadow AI Creates New Security Risks"