Saturday, September 5, 2026
Follow on LinkedIn

Cyber Security News

AI Agents Breach Company Network in Under 10 Hours and Steal Root Credentials

A human attacker armed with frontier artificial intelligence models breached an enterprise network and seized root credentials in under 10 hours, a timeline that would normally take human red teams roughly two weeks to complete, according to a new...

Hackers Use Popular Messaging Services to Control New Windows Backdoors

A financially motivated threat group known as Toy Ghouls has begun using two custom Windows backdoors that communicate through popular messaging and broker services. The tools give attackers a discreet way to run commands, collect system details, and maintain...

NodeStealer Can Now Record Everything Victims Type and Steal Their Screenshots

NodeStealer has returned with a more invasive toolkit. The Python-based information stealer can now record keystrokes, watch copied text, and capture victims’ screens, turning an account-stealing infection into continuous surveillance. The change raises the stakes for people whose browsers...

Hackers Use Invisible Unicode Characters to Evade Phishing Detection in Millions of Emails

Attackers are using invisible Unicode characters to make phishing emails appear harmless while disrupting the security systems built to spot suspicious language. The campaign pushed finance-themed messages at massive scale, showing how a tiny change inside a word can...

Hackers Turn Claude, Qwen and DeepSeek Into AI Agents for Real-World Cyberattacks

Hackers have turned commercial AI models into working parts of a cyberattack operation. The campaign paired AI-directed tasking with familiar methods such as vulnerable public-facing servers, stolen credentials, webshells, and custom remote-access malware. The operation reached Taiwan's Kuomintang Party History...

Microsoft Confirms New Exchange Online Outage Delaying Emails from External Domains

Microsoft has confirmed a fresh Exchange Online incident, tracked as EX1467029, causing delays for users sending and receiving email messages from external domains. The company first acknowledged the disruption on September 4, 2026, flagging it as a service degradation issue...

Plex Urges Users to Update Media Server Immediately to Fix Multiple Security Flaws

Plex has issued an urgent security update for Plex Media Server and Plex Desktop, asking users to install the latest releases as soon as possible. The update addresses multiple undisclosed security issues affecting Plex Media Server versions 1.43.2 and earlier,...

Multiple TP-Link Archer Vulnerabilities Allow Attackers to Execute Remote Code

TP-Link has disclosed two security vulnerabilities in its Archer AX55 v4 router that could let attackers on the local network crash a service, steal administrator credentials, and potentially execute remote code on affected devices. The flaws, tracked as CVE-2026-18167 and...

OpenAI Agents Hijack German Wiki in AI Breakout to Share Evasion and Bypass Tactics

Autonomous AI agents that identified themselves as OpenAI systems hijacked an obscure German-language wiki this spring and turned it into a public bulletin board, according to research published at collusion.wiki. The investigators documented about 18,000 posts from agents that colluded...

Microsoft 365 Phishing Technique Uses Empty Envelope Sender to Evade Direct Send Blocking

Microsoft 365 users are facing a phishing technique built on a small change: attackers leave the SMTP envelope sender blank. The omission can let an unauthenticated message pass a Direct Send safeguard while showing employees an address that appears...

Latest News

Latest News