Wednesday, September 16, 2026
Follow on LinkedIn

Cyber Security

Hackers Pose as Domain Controllers to Steal Active Directory Password Hashes

Threat actors are increasingly abusing Active Directory replication to impersonate domain controllers and steal password hashes from enterprise networks. This technique, known as a DCSync attack, can let attackers obtain credential data for privileged accounts without deploying malware directly on...

OpenSSL 4.1.0 Alpha1 Released With DTLS 1.3 and Faster Post-Quantum Cryptography

The OpenSSL Project has released OpenSSL 4.1.0 Alpha1, an early preview of its forthcoming feature release. This update adds support for Datagram Transport Layer Security (DTLS) 1.3, GREASE for more resilient TLS deployments, and architecture-specific performance enhancements for post-quantum...

Claude AI Models Gained Unauthorized Access to Real Systems During Cybersecurity Tests

Anthropic has disclosed that four separate versions of its Claude AI models breached real-world third-party systems while running what were supposed to be sandboxed cybersecurity evaluations, exposing a gap between how the models reasoned about their environment and the...

Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks

Multiple espionage-motivated threat actors have rapidly adopted a newly discovered exploit kit that chains Chrome browser and Microsoft Windows vulnerabilities to deploy backdoors and surveillance tools against government, defense, and commercial targets worldwide. Security researchers at Proofpoint have named the...

Microsoft Expands Windows Family Safety With Built-In Age Verification and Parental Controls

Microsoft is expanding Windows Family Safety with account-based age verification, privacy-focused age signals, and improved parental controls. The company said the updates are designed to help Windows apps, games, services, and AI experiences provide protections that match a user’s age. The...

Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild

Google has rolled out Chrome 153 to the stable channel for Windows, Mac, and Linux, shipping as version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac. The update will reach users over the coming days and weeks and includes...

Massive Microsoft Patch Tuesday September 2026 – 973 Vulnerabilities Fixed, Including 2 Zero-Days

Microsoft released its September 2026 Patch Tuesday security updates on September 8, addressing 973 vulnerabilities, including two zero-days already exploited in attacks. This massive patch follows the recent Microsoft update on artificial intelligence in vulnerability discovery, deploying a proprietary multi-model agentic...

FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack

Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an unauthenticated remote attacker intercept traffic flowing between the ZTNA portal and the backend destination website. Tracked as CVE-2026-84393 and...

Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware

An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js remote access trojan (RAT) that turns compromised perimeter devices into long-term footholds for espionage and data theft. The SOCRadar Threat Research...

ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channel

A covert cross-account communication channel inside ChatGPT let an attacker hijack a victim's session and silently exfiltrate data from connected apps like Gmail, all while the victim saw nothing unusual in their conversation. The vulnerability exploited ChatGPT's code-execution containers, isolated...

Latest News

Latest News