Skip to content
Home

IT Security · Latest

IT Security News

Latest reports on IT security, cyber threats and data protection — automatically curated from leading sources.

BleepingComputer24 Sept 2026

MacSync malware uses public iCloud calendars to deliver new payloads

A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]

Read more
BleepingComputer24 Sept 2026

New Carbonato malware uses AI agents to hijack exposed Docker hosts

A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]

Read more
The Hacker News24 Sept 2026

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software 

Read more
The Hacker News24 Sept 2026

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pi

Read more
BleepingComputer24 Sept 2026

Exposed GitLab project email addresses let attackers push code

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]

Read more
Microsoft Security24 Sept 2026

Beyond the ransomware: Tracking Storm-2570’s consistent tradecraft across deployments

Storm-2570 is a ransomware affiliate that uses consistent post-compromise tools and techniques across deployments involving Qilin, DragonForce, Anubis, and BERT ransomware, and provides guidance to help defenders detect

Read more
Microsoft Security24 Sept 2026

​​​​​​​​What’s new in Microsoft Security: September 2026​​

This month's updates help you discover and control local AI agents, extend Zero Trust to agent traffic, and strengthen SOC foundations. The post ​​​​​​​​What’s new in Microsoft Security: September 2026​​ appeared first o

Read more
The Hacker News24 Sept 2026

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a

Read more
The Hacker News24 Sept 2026

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information ste

Read more
BleepingComputer24 Sept 2026

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadlin

Read more
Heise Security24 Sept 2026

DSGVO-Falle Smart Glasses: Datenschützer warnen Träger vor Rechtsverstößen

Die Datenschutzkonferenz (DSK) stellt klar: Beim Filmen Dritter haften Nutzer. Eine LED reicht als Information nicht aus. Die DSK sieht die Politik gefordert.

Read more
BleepingComputer24 Sept 2026

Hackers now exploit critical Roundcube flaw in code injection attacks

A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]

Read more
Heise Security24 Sept 2026

Angriff mit KI-Agenten auf hunderte Shops: 600.000 Kreditkartendaten geklaut

Ein Angreifer hat hunderte Online-Shops mit KI-Agenten angegriffen und dabei Daten von mehr als 600.000 Kreditkarten abgegriffen.

Read more
Fortinet FortiGuard24 Sept 2026

Uncovering a SectopRAT Variant Embedded in Legitimate Software

Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control           

Read more
Golem Security24 Sept 2026

Erpresser verlangen 3 Millionen Euro: Revolut will nach Cyberangriff kein Lösegeld zahlen

Eine umfangreiche Recherche mehrerer großer Medienhäuser macht Revolut zudem schwere Vorwürfe: Die Bank unternehme zu wenig gegen Geldwäsche. (<a href="https://www.golem.de/specials/revolut/">Revolut</a>, <a href="https:

Read more
BleepingComputer24 Sept 2026

Windows 11 KB5124010 update released with 46 changes and fixes

Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]

Read more
The Hacker News24 Sept 2026

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as

Read more
Golem Security24 Sept 2026

(g+) SAP-Patchtag: 19, 21, 22 oder 33 Sicherheitslücken?

SAP-Patchtage liefern widersprüchliche Listen. Für Admins entscheiden ohnehin andere Kriterien, was zuerst gepatcht wird. Ein Ratgebertext von Steffen Zahn (<a href="https://www.golem.de/specials/sap/">SAP</a>, <a href="

Read more
The Hacker News24 Sept 2026

Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified a

Read more
Golem Security24 Sept 2026

Meta-Ray-Ban-Display: Smarte Brille zeigt bei Anrufen Hologramm des Sprechers

Wer mit Trägern einer Meta-Ray-Ban-Display telefoniert, kann sich dabei ein Hologramm des Sprechenden anzeigen lassen. (<a href="https://www.golem.de/specials/meta/">Meta</a>, <a href="https://www.golem.de/specials/daten

Read more
BleepingComputer24 Sept 2026

CISA: Ransomware gangs now exploiting critical TeamCity flaw

​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]

Read more
Kaspersky SecureList24 Sept 2026

MacSync under the microscope: new delivery methods and a new payload

We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.

Read more
BleepingComputer24 Sept 2026

OpenAI hacked Australian Medicare govt site, probed data providers

OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as p

Read more
Heise Security24 Sept 2026

Speicherort von Microsoft-365-Daten für kurze Zeit wählbar

IT-Verantwortliche haben bis zum 14. Dezember Zeit, den Speicherort ihrer Microsoft-365-Daten auszuwählen: im eigenen Land oder EU.

Read more
The Hacker News24 Sept 2026

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in lat

Read more
Heise Security24 Sept 2026

Sicherheitspatch gegen Schadcode repariert SolarWinds Observability Self-Hosted

Die Monitoring-Lösung für IT-Infrastrukturen SolarWinds Observability Self-Hosted ist unter bestimmten Voraussetzungen verwundbar.

Read more
BleepingComputer24 Sept 2026

Microsoft fixes bug that broke Windows File History backup feature

Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. [...]

Read more
The Hacker News24 Sept 2026

OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister&nbsp;Anthony Albanese said. The portal publishes aggregate figures,

Read more
Heise Security24 Sept 2026

Cybergang ShinyHunters behauptet Einbruch in FBI-Jobportal

ShinyHunters behaupteten, in das Jobportal des FBI eingebrochen zu sein und dort Daten von Mitarbeitern erbeutet zu haben.

Read more
The Hacker News24 Sept 2026

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the act

Read more
SANS ISC24 Sept 2026

One URL, Three Different Tricks, (Thu, Sep 24th)

Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link: &#x

Read more
The Hacker News24 Sept 2026

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticate

Read more
Heise Security24 Sept 2026

OpenAI-Agent knackt australisches Regierungsportal

Eine KI sollte Gesundheitsstatistiken suchen – und knackte dabei ein australisches Regierungsportal. Die Empörung ist groß.

Read more
SANS ISC24 Sept 2026

ISC Stormcast For Thursday, September 24th, 2026 https://isc.sans.edu/podcastdetail/10108, (Thu, Sep 24th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Read more
BleepingComputer23 Sept 2026

Placeholder domain used in dev docs now serves ClickFix attacks

The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell com

Read more
BleepingComputer23 Sept 2026

New RemControl Android banking malware targets users in Europe and Canada

A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]

Read more
BleepingComputer23 Sept 2026

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway

Read more
BleepingComputer23 Sept 2026

Hackers start exploiting critical WordPress flaw for code execution

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]

Read more
The Hacker News23 Sept 2026

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a dis

Read more
The Hacker News23 Sept 2026

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start C

Read more

Updated every 30 minutes · CH/DE: BACS Switzerland, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky