Cybersecurity
Breaches, vulnerabilities, security companies
OpenAI pledges $1 billion for AI cyber defense program
OpenAI has pledged $1 billion in credits to help organizations defending critical U.S. infrastructure—including water utilities, electric grids, local governments, banks, and nonprofits—access its AI-powered cybersecurity tools, training, and support. The "Daybreak for Frontline Defenders" initiative aims to help these sectors strengthen their defenses as AI-driven cyberattacks become more advanced. OpenAI says it will expand the program to partner countries in the coming weeks.
More in Cybersecurity
Breeze Comet targets Brazilian financial firms with fraud
A group known as Breeze Comet has targeted Brazilian banks, retailers, and e-commerce companies through sophisticated attacks since early 2024, according to Google Cloud and Mandiant. The organization uses malware and voice phishing to access internal payment systems and carry out fraudulent transfers. Google states that Breeze Comet is also using generative AI to develop new malware and may expand operations to parts of Latin America and Africa.
Phishing Campaign Poses as IT Staff on Microsoft Teams
A coordinated phishing operation dubbed 'Spring Ring' targeted more than 150 employees at at least 10 companies between January and April 2026, according to Palo Alto Networks' Unit 42. Attackers used external Microsoft Teams accounts to impersonate IT support, aiming to trick victims into installing remote monitoring or malicious software. Some attacks escalated to attempted NTLM relay attacks against company domain controllers. No successful compromises or losses were reported in the source.
Google fixes Chrome zero-day exploited in the wild
Google released an update to Chrome addressing a critical security flaw, CVE-2026-85046, that has been actively exploited. The vulnerability, found in the V8 JavaScript engine, could let attackers run code by luring users to malicious web pages. The bug was reported by Salvatore Gulizia, who received a $1,000 bounty. Updates are available for Windows, macOS, and Linux. U.S. agencies are required to patch by September 18.
SonicWall SMA1000 flaws exploited before disclosure
SonicWall has confirmed two critical vulnerabilities in its SMA1000 remote access appliances, identified as CVE-2026-83548 and CVE-2026-83549, are being exploited in the wild. These flaws can be chained to let attackers run code on affected systems without authentication. Patches are now available, and security agencies have flagged the issues as known exploited vulnerabilities. There is no information about the number of affected customers.
FBI Investigates Dark Web Sale of 153 Million Licenses
The FBI's New Orleans office has opened an investigation into a dark web service selling over 153 million U.S. and Canadian drivers license scans. Interviews and forum posts suggest these records, including those of senior U.S. officials, may stem from a breach at a Louisiana-based identity verification company. The service claims to have accumulated data for more than a year, exposing identities of millions across North America.
Microsoft detects mass phishing using hidden Unicode tags
Microsoft identified a large phishing campaign that uses hidden Unicode tag characters to disguise key words in emails, enabling attackers to evade spam filters and machine learning-based detection. Microsoft tracked this method, known as ASCII smuggling, in more than 2.3 million messages over two days. While invisible to recipients, these tags break up high-risk words like “credit” or “loan,” allowing them to slip past automated screening systems.
Serbian activists hit by largest known spyware attack
Researchers have identified at least 14 Serbian civil society members, including student activists, as victims of advanced spyware earlier this year. Forensic analysis confirmed Pegasus spyware was used on at least one target, with a NoviSpy variant also detected. This is the largest documented wave of spyware attacks in Serbia, occurring around the March local elections. There is no evidence on who conducted the attacks, and the Serbian government has denied involvement.
CrowdStrike and Nvidia unveil new AI cybersecurity platform
CrowdStrike, in partnership with Nvidia, announced a new AI-powered cybersecurity system called SafeMind at CrowdStrike’s annual Fal.Con event in Las Vegas. The platform uses Nvidia's Nemotron models, trained on CrowdStrike's threat data, to create a continuously evolving defense mechanism against automated cyber attacks. CrowdStrike also introduced new products for automated cyber workload management and advanced safety solutions. Both companies say this approach aims to close the gap with attackers using frontier AI tools.
Cloudflare launches AI-driven vulnerability detection service
Cloudflare has launched early access to a new service for customers called Vulnerability Discovery and Remediation, part of its Managed Defense offering. The invite-only tool uses OpenAI's Daybreak models to scan approved codebases for potential security issues, validate them, and suggest fixes. The service prioritizes vulnerabilities by analyzing production traffic and existing protections, aiming to help organizations address the most critical risks first.
Researcher Publishes CrowdStrike Falcon Privilege Escalation PoC
A security researcher identified as Chaotic Eclipse has released a proof-of-concept exploit for a previously unknown privilege escalation vulnerability in CrowdStrike's Falcon security software. The exploit, called FalconFlank, targets the product's handling of Microsoft Office macro remediation on current Windows 11 and Windows Server 2025 systems. CrowdStrike says it is investigating the claim and is advising customers to adjust certain policy settings while the review is ongoing.
Pegasus spyware infects Serbian student activist's iPhone
Citizen Lab and the SHARE Foundation have confirmed that Pegasus spyware, developed by NSO Group, infected the iPhone of a Serbian student protest movement member through a zero-click iMessage exploit. Forensic evidence showed signs of infection between December 2025 and January 2026. At least 14 members of Serbia's student movement, civil society, and opposition politicians have been targeted with advanced spyware, coinciding with the country's local elections.
Broadcom fixes critical flaws in VMware Workstation and Fusion
Broadcom has released updates for two security vulnerabilities in VMware Workstation and Fusion, including a critical bug that allows users with local administrative rights in a virtual machine to execute code on the host system. Both flaws require local admin access to exploit. Broadcom says there is no evidence these vulnerabilities have been used in real attacks. The company has released patches and says no workarounds are available.
Unpatched Magento flaw lets attackers backdoor online stores
Attackers are exploiting an unpatched vulnerability in all current versions of Magento Open Source and possibly Adobe Commerce, allowing them to install a persistent backdoor on online stores without logging in, according to security firm Sansec. Attacks began September 4. Adobe has not yet released a patch or issued a public advisory as of September 6. The number of affected stores is not publicly known.
Hackers exploit WordPress plugin flaws for remote code execution
Hackers are actively exploiting two major vulnerabilities in the Super Forms and Elementor Pro WordPress plugins, both of which allow attackers to upload malicious files that grant remote control over sites. Security firm Wordfence reports blocking over 440,000 such attempts. The Super Forms flaw and Elementor Pro flaw have both been patched, but sites running outdated versions remain at risk of takeover or data theft.
N-able issues urgent patch for critical N-central flaw
N-able has released a fourth emergency hotfix for its N-central remote monitoring software, addressing a critical vulnerability that could allow remote code execution without authentication. The patch, released hours after the previous fix, affects all on-premises N-central builds before version 2026.3.1.14. N-able's notices are inconsistent on whether the flaw has been exploited: some communications say there are confirmed attacks, others say exploitation is unconfirmed.
Red Hat urges automated response to rising AI-era cyber threats
Red Hat says security and IT teams face rising risks as attackers use AI to identify software vulnerabilities faster than manual defenses can respond. According to Red Hat, organizations need to accelerate software patching, automate responses to threats, and adopt multi-layered security strategies to contain and limit the impact of vulnerabilities. Red Hat highlights the importance of automation in maintaining effective cyber defenses as threat landscapes evolve rapidly.
Red Hat CEO says AI changes open source security
Red Hat CEO Matt Hicks said artificial intelligence is transforming open source security, increasing the need for transparent processes and faster patching. Red Hat introduced Lightwell as a tool to help organizations counter AI-enabled exploitation of vulnerabilities by accelerating the patching of open source software. Hicks emphasized the importance of these measures for enterprises facing AI-related threats and discussed evolving security strategies in the context of modern, AI-driven workloads.
Attackers exploit critical bug in Sangoma Switchvox
Attackers are exploiting a critical vulnerability (CVE-2026-9586) in Sangoma Switchvox SMB Edition 8.3 that allows unauthenticated remote code execution without credentials. The flaw is actively being used to deploy reverse shells and access sensitive data on exposed systems. Sangoma released a patch on July 14. Security researchers report about 4,000 internet-facing systems are at risk, most in the U.S. Exploitation has been observed since August 30.
North Korean hackers target South Korean firms with Linux backdoor
Researchers at Rapid7 have discovered a new Linux-based toolkit, dubbed the 'ted backdoor,' embedded within HAProxy servers at two South Korean companies in the automotive and media sectors. The toolkit lets attackers remotely control the servers, intercept and alter web traffic, steal credentials, and monitor systems unnoticed. Rapid7 attributes the campaign to North Korean state-backed groups with moderate confidence. The toolkit went undetected for months and does not exploit a HAProxy vulnerability.
Smashing Security discusses AI aiding iPhone theft
A recent Smashing Security podcast episode discussed how artificial intelligence is being used to help criminals steal Apple iPhones. The hosts explored current cybersecurity issues involving AI, including methods that reportedly assist thieves in bypassing device security. Details about the specific AI tools or techniques involved were not disclosed in the segment. The discussion signals concern about evolving digital threats targeting personal electronics.
Berlin state data stolen in ransomware attack published online
A ransomware group called Rhysida published over 1.4 million files stolen from Berlin's state government after officials refused to pay a demand for 30 bitcoins. Authorities confirmed the exposure, which includes sensitive emergency plans and personal data of state employees and citizens. Berlin's government stated there's no current sign that its network remains compromised and is reviewing the leaked files to identify those affected.
Attackers use ScreenConnect for four-stage VBScript malware
Researchers have found that attackers are leveraging ConnectWise ScreenConnect to install and execute a sequence of malicious VBScript files on new hosts. The incidents, observed in August 2026, began through social engineering or phishing, resulting in rogue ScreenConnect clients repeatedly running a four-stage VBScript chain. These scripts profile the system, check for security tools, and attempt to download additional payloads. Multiple unrelated attacks have used this method.
G7 urges urgent shift to quantum-safe encryption
The G7 Cyber Security Working Group has called on governments and businesses to speed up efforts to switch their computer systems and encrypted data to quantum-resistant technology, warning that quantum computers could someday break current methods of encryption. In a new advisory, officials said the threat is already present, as attackers may be storing data now to decrypt later with quantum tools. They recommend starting migration now and prioritizing sensitive systems.
METR discloses API key theft used for $600,000 in AI credits
METR, an AI safety research organization, reported that attackers stole an API key from its systems and used it over three weeks to consume AI model credits worth about $600,000. The organization says no sensitive information appears to have been accessed in this or a separate probing attack. The stolen credits were provided free by a model developer, representing potential rather than actual financial loss.
Email spammers use AI attack trick to dodge filters
Email spammers have started using a tactic from AI attacks called ASCII smuggling to sneak messages past spam filters. Microsoft reports that starting in February, it saw daily detections go from 21,000 to 2.5 million within four days—a spike that lasted months. The trick? Hackers hide keywords inside special invisible characters, so filters miss them but computers still read them. The surge dropped sharply mid-May.
Zscaler surpasses quarterly forecasts but shares decline
Zscaler reported fiscal fourth-quarter results that beat Wall Street expectations on both earnings and revenue, with adjusted earnings at $1.19 per share and revenue reaching $898 million, both up 25% from a year ago. Despite this performance and issuing guidance above estimates, Zscaler shares dropped following the report. The company also reduced its net loss and recorded annual recurring revenue of $3.77 billion, partially boosted by the recent Red Canary acquisition.
Google donates ZKP cryptography library to Linux Foundation Europe
Google just handed off its open-source Longfellow cryptography tool to the Linux Foundation Europe. This library helps apps confirm details like your age without exposing other personal info—think proving you're over 18 without giving your birthdate. The move aims to make the tool a vetted standard worldwide, especially for digital IDs. Google says it'll keep developing the code, but now everyone can audit or use it.
Google DeepMind launches Fairwind cyber defense program
Google DeepMind has launched the Fairwind Program, giving select government agencies, critical infrastructure providers, and trusted partners access to its advanced AI cyber defense tools. The initiative offers early use of Gemini 3.8 Flash Cyber and the CodeMender harness to rapidly detect and autonomously fix software vulnerabilities. Access will be limited to vetted organizations, with operational safeguards in place for responsible use.
BGP hijack used to deliver malicious Virtualizor updates
Attackers used a Border Gateway Protocol hijack to reroute traffic from Virtualizor's software update service and deliver malicious updates to some servers. At least one hosting provider reported five of its 34 Virtualizor hypervisors were compromised, resulting in root account access for attackers. The incident occurred between August 28 and August 30. Virtualizor urged all operators to review their systems, as no complete list of affected installations exists.