A two-week focused sandbox bug-bounty program resulted in 1,285 filings, but none that could access customer data. The Vercel sandbox, a Firecracker‑based microVM environment, is an isolation tool for untrusted AI‑agent code. For two weeks (August 18 until September 1),… Read More "$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws"
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since… Read More "BambooToken Malware Uses MQTT to Control Windows and Linux Systems"
Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data
Texas utility CenterPoint Energy confirmed on Monday that a threat actor has obtained customers’ personal information. The disclosure comes just days after a hacker claimed to have stolen millions of records. CenterPoint Energy is a Houston-based public utility that delivers… Read More "Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data"
Most Fraudulent Hires Receive Credentials Before Detection
Most fraudulent hires receive corporate credentials and internal network access before being detected, according to a new report by HYPR. Fraudulent candidates successfully navigate pre-hire screening and take up their roles in 42% cases. Just 3% are subsequently detected as… Read More "Most Fraudulent Hires Receive Credentials Before Detection"
Exposed Vite servers are being probed for AWS and Azure credentials
Vite was part of a broader scanning pattern F5 also observed attackers combining CVE-2026-39364 with older Vite file access vulnerabilities, including CVE-2025-30208, CVE-2025-31125 and CVE-2024-45811. The same scanning infrastructure also probed for a Next.js middleware bypass, indicating that the activity… Read More "Exposed Vite servers are being probed for AWS and Azure credentials"
Most Firms Unable to Recover Quickly from Ransomware
Only four out of more than 800 clients (0.5%) assessed by Fenix24 came close to their own 24 to 48-hour ransomware recovery targets, and then only for partial business operations. None reached full operational capacity until several weeks after the… Read More "Most Firms Unable to Recover Quickly from Ransomware"
Black Axe Members Extradited to US Over Internet Fraud Claims
Five alleged leaders of the Black Axe criminal organization have been extradited from South Africa to the US to face charges over romance scams, advance-fee fraud and money laundering. The US Department of Justice (DoJ) said the five Nigerian nationals… Read More "Black Axe Members Extradited to US Over Internet Fraud Claims"
Thai Broadband Provider Hacked via Fortinet Vulnerability
A threat actor targeted multiple vulnerabilities in Fortinet and F5 products to gain access to Thai broadband provider 3BB’s systems, Hunt.io reports. The attack was discovered after the hackers left their intrusion arsenal in an open directory hosted on infrastructure… Read More "Thai Broadband Provider Hacked via Fortinet Vulnerability"
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
Ravie LakshmananSep 15, 2026Vulnerability / Cloud Security Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that’s designed to steal… Read More "Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers"
Exaforce extends its AI security tool to monitor more than just Claude
While most of these efforts focused on AI agent discovery, a recent study showed that this is only part of the puzzle that enterprises need to solve. A March 2026 survey by the Cloud Security Alliance found 68% of organizations… Read More "Exaforce extends its AI security tool to monitor more than just Claude"