ConciseSignal

Cybersecurity

Breaches, vulnerabilities, security companies

OpenAI pledges $1 billion for AI cyber defense program

OpenAI has pledged $1 billion in credits to help organizations defending critical U.S. infrastructure—including water utilities, electric grids, local governments, banks, and nonprofits—access its AI-powered cybersecurity tools, training, and support. The "Daybreak for Frontline Defenders" initiative aims to help these sectors strengthen their defenses as AI-driven cyberattacks become more advanced. OpenAI says it will expand the program to partner countries in the coming weeks.

Why it mattersCritical infrastructure operators face increasing cyber threats but often lack advanced security resources. By subsidizing AI cybersecurity access, OpenAI aims to narrow this defense gap as AI-enabled attacks escalate.

More in Cybersecurity

3 sources · 14h ago

Breeze Comet targets Brazilian financial firms with fraud

A group known as Breeze Comet has targeted Brazilian banks, retailers, and e-commerce companies through sophisticated attacks since early 2024, according to Google Cloud and Mandiant. The organization uses malware and voice phishing to access internal payment systems and carry out fraudulent transfers. Google states that Breeze Comet is also using generative AI to develop new malware and may expand operations to parts of Latin America and Africa.

2 sources · 14h ago

Phishing Campaign Poses as IT Staff on Microsoft Teams

A coordinated phishing operation dubbed 'Spring Ring' targeted more than 150 employees at at least 10 companies between January and April 2026, according to Palo Alto Networks' Unit 42. Attackers used external Microsoft Teams accounts to impersonate IT support, aiming to trick victims into installing remote monitoring or malicious software. Some attacks escalated to attempted NTLM relay attacks against company domain controllers. No successful compromises or losses were reported in the source.

3 sources · 14h ago

Google fixes Chrome zero-day exploited in the wild

Google released an update to Chrome addressing a critical security flaw, CVE-2026-85046, that has been actively exploited. The vulnerability, found in the V8 JavaScript engine, could let attackers run code by luring users to malicious web pages. The bug was reported by Salvatore Gulizia, who received a $1,000 bounty. Updates are available for Windows, macOS, and Linux. U.S. agencies are required to patch by September 18.

5 sources · 14h ago

SonicWall SMA1000 flaws exploited before disclosure

SonicWall has confirmed two critical vulnerabilities in its SMA1000 remote access appliances, identified as CVE-2026-83548 and CVE-2026-83549, are being exploited in the wild. These flaws can be chained to let attackers run code on affected systems without authentication. Patches are now available, and security agencies have flagged the issues as known exploited vulnerabilities. There is no information about the number of affected customers.

5 sources · 14h ago

FBI Investigates Dark Web Sale of 153 Million Licenses

The FBI's New Orleans office has opened an investigation into a dark web service selling over 153 million U.S. and Canadian drivers license scans. Interviews and forum posts suggest these records, including those of senior U.S. officials, may stem from a breach at a Louisiana-based identity verification company. The service claims to have accumulated data for more than a year, exposing identities of millions across North America.

3 sources · 14h ago

Microsoft detects mass phishing using hidden Unicode tags

Microsoft identified a large phishing campaign that uses hidden Unicode tag characters to disguise key words in emails, enabling attackers to evade spam filters and machine learning-based detection. Microsoft tracked this method, known as ASCII smuggling, in more than 2.3 million messages over two days. While invisible to recipients, these tags break up high-risk words like “credit” or “loan,” allowing them to slip past automated screening systems.

2 sources · 14h ago

Serbian activists hit by largest known spyware attack

Researchers have identified at least 14 Serbian civil society members, including student activists, as victims of advanced spyware earlier this year. Forensic analysis confirmed Pegasus spyware was used on at least one target, with a NoviSpy variant also detected. This is the largest documented wave of spyware attacks in Serbia, occurring around the March local elections. There is no evidence on who conducted the attacks, and the Serbian government has denied involvement.

1 sources · 14h ago

CrowdStrike and Nvidia unveil new AI cybersecurity platform

CrowdStrike, in partnership with Nvidia, announced a new AI-powered cybersecurity system called SafeMind at CrowdStrike’s annual Fal.Con event in Las Vegas. The platform uses Nvidia's Nemotron models, trained on CrowdStrike's threat data, to create a continuously evolving defense mechanism against automated cyber attacks. CrowdStrike also introduced new products for automated cyber workload management and advanced safety solutions. Both companies say this approach aims to close the gap with attackers using frontier AI tools.

1 sources · 14h ago

Cloudflare launches AI-driven vulnerability detection service

Cloudflare has launched early access to a new service for customers called Vulnerability Discovery and Remediation, part of its Managed Defense offering. The invite-only tool uses OpenAI's Daybreak models to scan approved codebases for potential security issues, validate them, and suggest fixes. The service prioritizes vulnerabilities by analyzing production traffic and existing protections, aiming to help organizations address the most critical risks first.

2 sources · 14h ago

Researcher Publishes CrowdStrike Falcon Privilege Escalation PoC

A security researcher identified as Chaotic Eclipse has released a proof-of-concept exploit for a previously unknown privilege escalation vulnerability in CrowdStrike's Falcon security software. The exploit, called FalconFlank, targets the product's handling of Microsoft Office macro remediation on current Windows 11 and Windows Server 2025 systems. CrowdStrike says it is investigating the claim and is advising customers to adjust certain policy settings while the review is ongoing.

2 sources · 14h ago

Pegasus spyware infects Serbian student activist's iPhone

Citizen Lab and the SHARE Foundation have confirmed that Pegasus spyware, developed by NSO Group, infected the iPhone of a Serbian student protest movement member through a zero-click iMessage exploit. Forensic evidence showed signs of infection between December 2025 and January 2026. At least 14 members of Serbia's student movement, civil society, and opposition politicians have been targeted with advanced spyware, coinciding with the country's local elections.

2 sources · 14h ago

Broadcom fixes critical flaws in VMware Workstation and Fusion

Broadcom has released updates for two security vulnerabilities in VMware Workstation and Fusion, including a critical bug that allows users with local administrative rights in a virtual machine to execute code on the host system. Both flaws require local admin access to exploit. Broadcom says there is no evidence these vulnerabilities have been used in real attacks. The company has released patches and says no workarounds are available.

2 sources · 7h ago

Unpatched Magento flaw lets attackers backdoor online stores

Attackers are exploiting an unpatched vulnerability in all current versions of Magento Open Source and possibly Adobe Commerce, allowing them to install a persistent backdoor on online stores without logging in, according to security firm Sansec. Attacks began September 4. Adobe has not yet released a patch or issued a public advisory as of September 6. The number of affected stores is not publicly known.

3 sources · 14h ago

Hackers exploit WordPress plugin flaws for remote code execution

Hackers are actively exploiting two major vulnerabilities in the Super Forms and Elementor Pro WordPress plugins, both of which allow attackers to upload malicious files that grant remote control over sites. Security firm Wordfence reports blocking over 440,000 such attempts. The Super Forms flaw and Elementor Pro flaw have both been patched, but sites running outdated versions remain at risk of takeover or data theft.

3 sources · 6h ago

N-able issues urgent patch for critical N-central flaw

N-able has released a fourth emergency hotfix for its N-central remote monitoring software, addressing a critical vulnerability that could allow remote code execution without authentication. The patch, released hours after the previous fix, affects all on-premises N-central builds before version 2026.3.1.14. N-able's notices are inconsistent on whether the flaw has been exploited: some communications say there are confirmed attacks, others say exploitation is unconfirmed.

1 sources · 13h ago

Red Hat urges automated response to rising AI-era cyber threats

Red Hat says security and IT teams face rising risks as attackers use AI to identify software vulnerabilities faster than manual defenses can respond. According to Red Hat, organizations need to accelerate software patching, automate responses to threats, and adopt multi-layered security strategies to contain and limit the impact of vulnerabilities. Red Hat highlights the importance of automation in maintaining effective cyber defenses as threat landscapes evolve rapidly.

1 sources · 13h ago

Red Hat CEO says AI changes open source security

Red Hat CEO Matt Hicks said artificial intelligence is transforming open source security, increasing the need for transparent processes and faster patching. Red Hat introduced Lightwell as a tool to help organizations counter AI-enabled exploitation of vulnerabilities by accelerating the patching of open source software. Hicks emphasized the importance of these measures for enterprises facing AI-related threats and discussed evolving security strategies in the context of modern, AI-driven workloads.

2 sources · 14h ago

Attackers exploit critical bug in Sangoma Switchvox

Attackers are exploiting a critical vulnerability (CVE-2026-9586) in Sangoma Switchvox SMB Edition 8.3 that allows unauthenticated remote code execution without credentials. The flaw is actively being used to deploy reverse shells and access sensitive data on exposed systems. Sangoma released a patch on July 14. Security researchers report about 4,000 internet-facing systems are at risk, most in the U.S. Exploitation has been observed since August 30.

3 sources · 14h ago

North Korean hackers target South Korean firms with Linux backdoor

Researchers at Rapid7 have discovered a new Linux-based toolkit, dubbed the 'ted backdoor,' embedded within HAProxy servers at two South Korean companies in the automotive and media sectors. The toolkit lets attackers remotely control the servers, intercept and alter web traffic, steal credentials, and monitor systems unnoticed. Rapid7 attributes the campaign to North Korean state-backed groups with moderate confidence. The toolkit went undetected for months and does not exploit a HAProxy vulnerability.

1 sources · 13h ago

Smashing Security discusses AI aiding iPhone theft

A recent Smashing Security podcast episode discussed how artificial intelligence is being used to help criminals steal Apple iPhones. The hosts explored current cybersecurity issues involving AI, including methods that reportedly assist thieves in bypassing device security. Details about the specific AI tools or techniques involved were not disclosed in the segment. The discussion signals concern about evolving digital threats targeting personal electronics.

2 sources · 5h ago

Berlin state data stolen in ransomware attack published online

A ransomware group called Rhysida published over 1.4 million files stolen from Berlin's state government after officials refused to pay a demand for 30 bitcoins. Authorities confirmed the exposure, which includes sensitive emergency plans and personal data of state employees and citizens. Berlin's government stated there's no current sign that its network remains compromised and is reviewing the leaked files to identify those affected.

2 sources · 6h ago

Attackers use ScreenConnect for four-stage VBScript malware

Researchers have found that attackers are leveraging ConnectWise ScreenConnect to install and execute a sequence of malicious VBScript files on new hosts. The incidents, observed in August 2026, began through social engineering or phishing, resulting in rogue ScreenConnect clients repeatedly running a four-stage VBScript chain. These scripts profile the system, check for security tools, and attempt to download additional payloads. Multiple unrelated attacks have used this method.

3 sources · 14h ago

G7 urges urgent shift to quantum-safe encryption

The G7 Cyber Security Working Group has called on governments and businesses to speed up efforts to switch their computer systems and encrypted data to quantum-resistant technology, warning that quantum computers could someday break current methods of encryption. In a new advisory, officials said the threat is already present, as attackers may be storing data now to decrypt later with quantum tools. They recommend starting migration now and prioritizing sensitive systems.

3 sources · 14h ago

METR discloses API key theft used for $600,000 in AI credits

METR, an AI safety research organization, reported that attackers stole an API key from its systems and used it over three weeks to consume AI model credits worth about $600,000. The organization says no sensitive information appears to have been accessed in this or a separate probing attack. The stolen credits were provided free by a model developer, representing potential rather than actual financial loss.

2 sources · 14h ago

Email spammers use AI attack trick to dodge filters

Email spammers have started using a tactic from AI attacks called ASCII smuggling to sneak messages past spam filters. Microsoft reports that starting in February, it saw daily detections go from 21,000 to 2.5 million within four days—a spike that lasted months. The trick? Hackers hide keywords inside special invisible characters, so filters miss them but computers still read them. The surge dropped sharply mid-May.

2 sources · 14h ago

Zscaler surpasses quarterly forecasts but shares decline

Zscaler reported fiscal fourth-quarter results that beat Wall Street expectations on both earnings and revenue, with adjusted earnings at $1.19 per share and revenue reaching $898 million, both up 25% from a year ago. Despite this performance and issuing guidance above estimates, Zscaler shares dropped following the report. The company also reduced its net loss and recorded annual recurring revenue of $3.77 billion, partially boosted by the recent Red Canary acquisition.

1 sources · 14h ago

Google donates ZKP cryptography library to Linux Foundation Europe

Google just handed off its open-source Longfellow cryptography tool to the Linux Foundation Europe. This library helps apps confirm details like your age without exposing other personal info—think proving you're over 18 without giving your birthdate. The move aims to make the tool a vetted standard worldwide, especially for digital IDs. Google says it'll keep developing the code, but now everyone can audit or use it.

1 sources · 14h ago

Google DeepMind launches Fairwind cyber defense program

Google DeepMind has launched the Fairwind Program, giving select government agencies, critical infrastructure providers, and trusted partners access to its advanced AI cyber defense tools. The initiative offers early use of Gemini 3.8 Flash Cyber and the CodeMender harness to rapidly detect and autonomously fix software vulnerabilities. Access will be limited to vetted organizations, with operational safeguards in place for responsible use.

2 sources · 14h ago

BGP hijack used to deliver malicious Virtualizor updates

Attackers used a Border Gateway Protocol hijack to reroute traffic from Virtualizor's software update service and deliver malicious updates to some servers. At least one hosting provider reported five of its 34 Virtualizor hypervisors were compromised, resulting in root account access for attackers. The incident occurred between August 28 and August 30. Virtualizor urged all operators to review their systems, as no complete list of affected installations exists.