CyberSecurity News

Source: SecurityWeek

PaperCut Flaws Exploited in AI-Powered Attacks

<p>A Russian threat actor used AI to build, test, and deploy exploits against hundreds of organizations worldwide.</p> <p>The post <a href="https://www.securityweek.com/papercut-flaws-exploited-in-ai-powered-attacks/">PaperCut Flaws Exploited in AI-Powered Attacks</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Source: The Hacker News

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz&nbsp;said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
Source: The Hacker News

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in&nbsp;research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns

Source: Security Affairs

UK Council Attack Linked to Mass Exploitation of SonicWall Flaw

A critical SonicWall flaw was rapidly weaponized, with a UK Council attack linked to a campaign that exposed credentials and enabled Active Directory theft. On July 17, 2026, the Borough Council of King&#8217;s Lynn and West Norfolk announced it had detected a cyberattack affecting council services. Hunt.io has since published a detailed technical analysis linking [&#8230;]

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
Source: The Hacker News

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. "These are Regular Maintenance Releases (MR) that

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Source: The Hacker News

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass

Source: SecurityWeek

Mandiant Founder Kevin Mandia Joins Amazon Board

<p>Mandiant founder and cybersecurity veteran brings more than 30 years of public and private sector experience to Amazon’s board.</p> <p>The post <a href="https://www.securityweek.com/mandiant-founder-kevin-mandia-joins-amazon-board/">Mandiant Founder Kevin Mandia Joins Amazon Board</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

Source: Security Affairs

U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog

U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-20079 (CVSS score of 10.0) is an authentication bypass issue. The flaw resides in Cisco Secure [&#8230;]

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
Source: The Hacker News

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already

Source: SecurityWeek

Cybersecurity M&A Roundup: 33 Deals Announced in August 2026

<p>Significant cybersecurity M&#038;A deals announced by Brinqa, Cribl, Echo, Fortinet, Kiteworks, Palo Alto Networks, and Visa.</p> <p>The post <a href="https://www.securityweek.com/cybersecurity-ma-roundup-33-deals-announced-in-august-2026/">Cybersecurity M&#038;A Roundup: 33 Deals Announced in August 2026</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

Source: Security Affairs

More Capable AI, Not Enough Guardrails

AI agents are gaining real-world access faster than safeguards can mature, making permissions, isolation and oversight critical to prevent harmful actions. Jacob Coxon, a researcher who spent three years working on model training at OpenAI and later Anthropic, left Anthropic this week with a blunt warning: AI companies are moving toward increasingly capable systems faster [&#8230;]

Source: SecurityWeek

Anthropic Researcher Resigns With Warning About the Dangers of AI Development

<p>Both Anthropic and OpenAI have seen high-profile resignations in recent years that were tied to safety concerns.</p> <p>The post <a href="https://www.securityweek.com/anthropic-researcher-resigns-with-warning-about-the-dangers-of-ai-development/">Anthropic Researcher Resigns With Warning About the Dangers of AI Development</a> appeared first on <a href="https://www.securityweek.com">SecurityWeek</a>.</p>

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
Source: The Hacker News

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their

Source: Check Point Research

PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector

<p>Executive Summary In this research we introduce a prompt-crafting technique for bypassing quick LLM-based policy checks — using plain English (no emojis, base64, invisible formatting, etc.) A policy-violating payload (e.g.&#160;”encrypt files in ~/Documents”, “give me a biohazard recipe”, “ignore all previous instructions and…”) is embedded in a specially crafted prose wrapper. An LLM with limited [&#8230;]</p> <p>The post <a href="https://research.checkpoint.com/2026/puzzlemask-abusing-plain-prose-as-a-covert-ai-attack-vector/">PuzzleMask: Abusing Plain Prose as a Covert AI Attack Vector</a> appeared first on <a href="https://research.checkpoint.com">Check Point Research</a>.</p>