Security (11)¶
Part of the Technology feed · AI-researched.
Latest¶
Microsoft September patch breaks record with 972 vulnerabilities, 112 critical
Microsoft's September security patch sets a new record by addressing approximately 972 vulnerabilities, including 112 rated as critical severity.
DDRop attack compromises Intel TDX and AMD SEV-SNP confidential computing
Researchers from KU Leuven, ETH Zurich, Durham University, and Google disclosed DDRop, a hardware attack that breaks Intel TDX, Intel Scalable SGX, and AMD SEV-SNP confidential computing by silently dropping memory writes. An attacker needs server software control and brief physical access to insert
Three JFrog Artifactory vulnerabilities actively exploited for backdoor deployment
Security researchers identified three JFrog Artifactory flaws being exploited in the wild to bypass authentication and gain administrator privileges.
ConnectWise patches critical ScreenConnect vulnerability exploited in attacks
ConnectWise has released a patch for a critical ScreenConnect flaw allowing unauthorized file execution and transfer in active remote sessions.
Malicious Twitch browser extension leaks OAuth tokens from 31,000 users
The Twitch Enhanced Viewer | JeetBot extension, installed by 30,000 users and available in Chrome and Firefox, leaked users' Twitch OAuth session tokens to a commercial service.
CISA warns of active GitLab maximum-severity vulnerability exploitation
The U.S. Cybersecurity and Infrastructure Security Agency reports that hackers are exploiting a maximum-severity GitLab vulnerability in live attacks.
Chinese threat actor Red Heron exploits Gitea RCE vulnerability across six countries
Red Heron, a suspected Chinese threat actor, exploited CVE-2026-60004, a critical Gitea RCE vulnerability, to compromise 13 organizations across Canada, Argentina, Taiwan, U.S., Qatar, and Sri Lanka. The group weaponized public exploit code into an automated framework within days of the July 2026 di
Microsoft releases emergency Windows updates for RDS failures
Microsoft issued out-of-band security updates to fix Remote Desktop Services failures, Hyper-V, and USB audio issues.
Hackers hijack HBO Max Reddit account to distribute ClickFix malware
Attackers compromised HBO Max's official Reddit account and used it to push malicious advertisements that deployed ClickFix malware to Windows and macOS systems.
Revolut data breach exposes financial information and passport documents
Fintech firm Revolut disclosed a significant data breach that compromised customer financial data and passport information after a threat actor impersonated a government agency.
CISOs grapple with securing AI agents
Security leaders face challenges modernizing cyber hygiene while preventing over-privileged AI agents from causing unintended harm.
Earlier¶
2026-09-13 (5 events) · 2026-09-12 (6 events) · 2026-09-11 (10 events) · 2026-09-10 (10 events) · 2026-09-09 (11 events) · 2026-09-08 (10 events) · 2026-09-07 (10 events) · 2026-09-06 (4 events) · 2026-09-05 (9 events) · 2026-09-04 (10 events) · 2026-09-03 (11 events) · 2026-09-02 (11 events) · 2026-09-01 (10 events) · 2026-08-31 (11 events) · 2026-08-30 (7 events) · 2026-08-29 (10 events) · 2026-08-28 (11 events) · 2026-08-27 (11 events) · 2026-08-26 (11 events) · 2026-08-25 (12 events) · 2026-08-24 (11 events) · 2026-08-23 (9 events) · 2026-08-22 (10 events) · 2026-08-21 (13 events) · 2026-08-20 (12 events) · 2026-08-19 (10 events) · 2026-08-18 (12 events) · 2026-08-17 (14 events) · 2026-08-16 (10 events) · 2026-08-15 (10 events) · 2026-08-14 (10 events) · 2026-08-13 (10 events) · 2026-08-12 (10 events) · 2026-08-11 (10 events) · 2026-08-10 (11 events)