Customer data relating to car park, lounge and Fast Track bookings, and in-airport Wi-Fi sign-ups at three UK airports has been obtained by an unauthorized third party. Manchester Airports Group (MAG), which operates Manchester, London Stansted and East Midlands airports,… Read More "Manchester Airports Group Hit by Cyber Incident"
New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the processor keeps reading old encrypted data as if it were… Read More "New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing"
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Aurora ransomware actors have been observed abusing SpaceX’s AI Cursor Agent as part of exploitation campaigns, according to a new study by Gambit Security’s Threat Intelligence team. The threat actors ran Claude Sonnet through Cursor Agent to assist with various… Read More "Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations"
New York Seizes a Dozen Celebrity Deepfake Websites
For the best part of a decade, abusive deepfake “pornography” websites have published thousands of nonconsensual videos depicting women, including high-profile celebrities, politicians, and public figures, into sexual situations. Now, in what is likely the largest takedown of explicit deepfake… Read More "New York Seizes a Dozen Celebrity Deepfake Websites"
Three JFrog Artifactory Flaws Exploited for Backdoor Deployment
Threat actors have been exploiting three high-severity vulnerabilities in JFrog Artifactory to compromise deployments and install backdoors, cybersecurity firm Wiz reports. Many organizations use Artifactory to manage software artifacts, binaries, AI models, containers, and packages. The three flaws, CVE-2026-42016, CVE-2026-42018,… Read More "Three JFrog Artifactory Flaws Exploited for Backdoor Deployment"
WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution
Ravie LakshmananSep 14, 2026Web Security / Vulnerability WordPress has announced it’s launching an automated security review for every release of a plugin before it’s distributed through the WordPress.org update API so as to analyze it for potential security issues and… Read More "WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution"
Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Gia
More than 100 tech and cybersecurity companies, including OpenAI, Anthropic, Google and Microsoft, have warned there is a “narrowing window” to act before AI-enabled attacks escalate to a level that puts critical public services at severe risk. “In the coming… Read More "Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Gia"
The Race to Control AI and Protect What Makes Us Human
A current debate is whether artificial intelligence (AI) is a force for good or bad; or perhaps both. What follows is the argued opinion of the author – it is not the inevitable outcome of current AI development. On August… Read More "The Race to Control AI and Protect What Makes Us Human"
⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits
Ravie LakshmananSep 14, 2026Cybersecurity / Hacking AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That… Read More "⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits"
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
A two-month phishing campaign used scalable vector graphics (SVG) attachments disguised as voicemail files to smuggle obfuscated JavaScript past email defenses, with 26,589 messages detected across 5527 organizations. Email security vendor INKY, which is part of Kaseya, detected and flagged… Read More "Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign"