Dr. T's security brief

19 views
Skip to first unread message

dtau...@gmail.com

unread,
Aug 30, 2026, 8:53:48 AMAug 30
to sec-...@googlegroups.com

DOJ Secures Indictment of 17 Iranians Accused of ‘Massive’ Cyber Theft Campaign

The U.S. Department of Justice (DOJ) has unsealed an indictment charging 17 Iranian nationals accused of conducting a large-scale cyber-theft campaign on behalf of Iran’s Islamic Revolutionary Guard Corps. Prosecutors allege the Iran-based Mabna Institute targeted at least 144 U.S. universities, 178 foreign universities, 42 U.S. companies, government agencies, and nonprofit organizations, stealing more than 31Tb of academic research and intellectual property.
[ » Read full article ]

The Hill; Max Rego (August 18, 2026)

 

At Black Hat, AI Helped Security Pros Find Threats—and Create New Ones

At the recent Black Hat cybersecurity conference in Las Vegas, AI helped security teams detect, assess, and respond to threats more efficiently. The event’s Network Operations Center used AI-powered agentic triage to analyze thousands of network issues, automatically resolving most while leaving complex cases for human review. AI also contributed to new security risks, particularly through vibe coding. Security staff found some applications transmit sensitive information without TLS encryption, including home camera footage and phone calls to banks.
[ » Read full article ]

Fast Company; Rob Pegoraro (August 14, 2026)

 

Passenger Returning from DEF CON 34 Spoofs Delta Wi-Fi Network In-Flight

A passenger returning from DEF CON 34 allegedly disrupted a Delta flight's Wi-Fi, creating a fake “Delta WiFi Fast” hotspot that directed users to a phishing site designed to capture Google credentials. Pilots alerted ground crews and corporate security after detecting the interference, reportedly involving a Wi-Fi penetration-testing device. Delta said flight safety was never threatened and aircraft operating systems were unaffected.
[ » Read full article ]

Tom's Hardware; Jowi Morales (August 12, 2026)

 

Tiny Device Hacks Boeing 737 Flight Systems

At the USENIX Security Symposium, University of California San Diego researchers demonstrated that brief physical access to a Boeing 737 could allow an attacker to manipulate data exchanged between critical flight computers. Their proof-of-concept device exploited a legacy ARINC 429 communications interface, potentially altering flight-route information and data related to aircraft weight, balance, and temperature. Boeing was notified of the vulnerability in 2020 and later validated the findings in its laboratory.
[ » Read full article ]

Interesting Engineering; Aamir Khollam (August 13, 2026)

 

SIM Card Can Run Attacker Code Inside Modems

Researchers at the U.K.'s University of Birmingham and security firm Fuzzware found that malicious SIM cards can exploit a standardized modem feature called RUN AT to execute attacker-controlled commands on certain cellular IoT devices and phones. Tests of 26 devices found the capability enabled on nine of them. Researchers demonstrated code execution on a commercial EV charger and showed that one affected phone could be forced onto insecure 2G networks, though no attacks have been reported.
[ » Read full article ]

The Hacker News; Swati Khandelwal (August 12, 2026)

 

Flock Adds Privacy Guardrails to Camera Systems amid Backlash

Flock Safety is introducing new privacy safeguards for its automated license plate surveillance network amid growing concerns about law enforcement misuse and mass surveillance. The company will reduce its recommended default data retention period from 30 days to seven, although local agencies can choose longer periods. Cities also will gain greater control over when other agencies can access their camera data.
[ » Read full article ]

The Hill; Miranda Nazzaro (August 13, 2026)

 

U.S. Courts to Publish How Often the Government Uses Spyware

U.S. courts will begin publicly reporting how often judges authorize government use of spyware and hacking tools to intercept real-time communications. The Administrative Office of the U.S. Courts will add a “spyware/hacking” category to its 2028 Wiretap Report, to be published in 2029, providing the first nationwide count of such surveillance orders. The data will cover spyware used to intercept communications, but not remote searches of stored phone data.
[ » Read full article ]

TechCrunch; Lorenzo Franceschi-Bicchierai (August 14, 2026)

 

Albania Ranked the Most Cyber Secure Country

Albania was ranked first in the National Cyber Security Index, scoring 98.33 out of 100. Estonia’s e-Governance Academy assessed 155 countries across 49 indicators covering strategic, preventive, and responsive cybersecurity capabilities. Albania’s strong performance followed a major 2022 cyberattack that prompted sweeping legal reforms, centralized cyber defenses, and closer cooperation with international partners. Czechia was second in the ranking with a score of 98.33, while Canada and Estonia tied at 96.67, followed by Finland ranked at 95.83.
[ » Read full article ]

euronews; Indrabati Lahiri (August 12, 2026)

 

University Of Texas At San Antonio Postpones Beginning Of Semester After Cyber Attempt

Inside Higher Ed (8/20) reports the University of Texas at San Antonio postponed its fall semester by three days after an attempted cyberattack. On Tuesday, UTSA President Taylor Eighmy announced the delay to Monday, Aug. 24, to allow time to restore technological services. Officials proactively took systems offline over the weekend and said their investigation found no evidence that data was accessed.

dtau...@gmail.com

unread,
Aug 30, 2026, 6:08:00 PMAug 30
to sec-...@googlegroups.com

Tech Companies Call for Action Against AI-Powered Threats

More than 100 technology and cybersecurity companies are calling for closer cooperation between AI developers and governments to prepare for increasingly sophisticated AI-enabled cyberattacks. In a joint letter led by OpenAI Thursday, the companies warned traditional cybersecurity defenses will be inadequate as advanced AI models become better at identifying and exploiting digital vulnerabilities. The letter urged governments to coordinate and fund cyber defense programs, improve threat-intelligence sharing, and provide critical infrastructure operators with AI-powered security tools.
[ » Read full article ]

Politico; Pieter Haeck (August 27, 2026)

 

Federal Reserve, NASA, DOJ Among Victims of Chinese State-Sponsored Hackers

A Chinese state-sponsored hacking group targeted the U.S. Federal Reserve, the National Aeronautics and Space Administration (NASA), the U.S. Department of Justice (DOJ), and other federal bodies, according to newly unsealed court documents. The group allegedly operated hacking platforms that targeted critical infrastructure and sensitive networks, including hospitals, telecommunications providers, power companies, financial institutions, and defense contractors. The DOJ and the Federal Bureau of Investigation seized domains associated with the platforms and disabled their malicious software.
[ » Read full article ]

CNBC; Dan Mangan (August 26, 2026)

 

Trump Signs Executive Order on Foreign Equipment in U.S. Energy Infrastructure

U.S. President Trump on Wednesday signed an executive order declaring a national emergency to protect the U.S. bulk-power system from cybersecurity and national security threats. The executive order targets foreign-produced equipment, software, and digital systems determined to pose a significant national security risk, potentially prohibiting their acquisition, importation, transfer, or installation in U.S. power facilities. The move is largely driven by concerns that Chinese-made power equipment could contain vulnerabilities or backdoors enabling remote access.
[ » Read full article ]

CyberScoop; Tim Starks (August 26, 2026)

 

Security Weaknesses Found in Leading Open AI Models

An international team led by researchers at Canada’s University of Waterloo and non-profit AI security research group FAR.AI found security weaknesses in 21 widely used open-weight AI models. The researchers discovered that built-in safety protections could be removed through relatively simple tampering and fine-tuning, potentially allowing models to generate harmful content, facilitate sophisticated scams, spread disinformation, or provide dangerous instructions. The team also developed TamperBench, an open-source tool for systematically testing these vulnerabilities.
[ » Read full article ]

Waterloo News (Canada) (August 25, 2026)

 

Japan Outlines Measures to Protect Infrastructure from Cyberattacks

Japan drafted cybersecurity guidelines outlining 150 measures for businesses operating critical infrastructure. Covering 15 sectors, including finance, railways, electricity, and postal services, the guidelines warn that even closed networks can be vulnerable to cyberattacks. The guidelines urge companies to strengthen their recovery capabilities, prepare for system failures, obtain cybersecurity insurance, and avoid paying ransomware demands. The draft also recommends using advanced AI tools to counter increasingly sophisticated AI-driven attacks.
[ » Read full article ]

The Japan Times (August 24, 2026)

 

Sweden Sets 2036 Deadline for National Quantum Technology Strategy

Sweden unveiled its first national quantum technology strategy, setting goals through 2036 in various areas. The plan seeks to better connect universities, industry, government, and investors, while expanding skilled talent and financing for quantum startups. Cybersecurity is a major priority, with the government urging early adoption of post-quantum cryptography to protect against future quantum attacks and “harvest now, decrypt later” threats. The strategy also emphasizes partnerships with the U.S., EU, Nordic countries, and NATO.
[ » Read full article ]

Quantum Insider; Matt Swayne (August 24, 2026)

 

Iran-linked Hackers Blamed for Cyberattack That Shut Down U.K. Power Plant

The U.K. government cast blame on Iran-linked hackers for causing a British energy generator to shut down for four days in August. The government said the affected facility was a small-scale generator and that the incident posed no risk to the wider electricity system. British officials have warned that hostile states, including Iran, increasingly are targeting critical infrastructure. U.S. agencies have also warned of Iran-linked cyber campaigns against infrastructure.
[ » Read full article ]

The Guardian (U.K.); Ben Quinn (August 23, 2026)

 

CISA Orders Feds to Patch Actively Exploited TrueConf Server Flaws

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) gave U.S. federal agencies until Sept. 3 to patch two TrueConf Server vulnerabilities being actively exploited. CVE-2026-72529 allows unauthenticated attackers to remotely execute arbitrary scripts, while CVE-2026-72530 can enable code injection, sandbox escape, and command execution on the underlying operating system. Cybersecurity firm Kaspersky reported the Head Mare hacktivist group has exploited the vulnerabilities since at least July, targeting Russian organizations and using compromised TrueConf installers to distribute backdoor malware.
[ » Read full article ]

BleepingComputer; Sergiu Gatlan (August 21, 2026)

 

U.S. Agencies Warn Hackers are Actively Attacking Siemens S7 PLCs in Critical Facilities

Several U.S. agencies warned that hackers are actively targeting Siemens S7 programmable logic controllers used across critical infrastructure. The attackers scan Internet-exposed devices, then use AI-assisted tools and open-source libraries to access PLC memory, configurations, and programs. Officials say the activity appears focused on reconnaissance and developing capabilities that could enable future disruption. Industries at risk include energy, water, manufacturing, chemicals, agriculture, and defense. The warning came following a string of cyber incidents at U.S. water utilities.
[ » Read full article ]

Cyber Security News; Guru Baran (August 20, 2026)

 

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Security researchers at Israeli software company Cycode found critical flaws in NASA Jet Propulsion Laboratory’s AIT-GUI software that could allow unauthenticated attackers to issue arbitrary commands to spacecraft and instruments. The vulnerabilities involve missing authentication, cross-origin request handling, and path traversal. AIT-GUI version 2.5.2 addresses several exposure and browser-based attack paths, but the researchers say it still allows credential-free session creation and does not fully resolve the underlying authentication weakness.
[ » Read full article *May Require Paid Registration ]

The Hacker News; Swati Khandelwal (August 20, 2026)

dtau...@gmail.com

unread,
Sep 4, 2026, 6:28:14 PMSep 4
to sec-...@googlegroups.com

G7 Tells Industry to Prep for Post-Quantum Encryption

A cybersecurity working group at the Group of Seven (G7) is urging governments and businesses to accelerate preparations for post-quantum cryptography, warning that organizations can no longer treat quantum threats as a distant concern. In a report prepared in June at the G7 Summit in France, the group said quantum computers eventually could break widely used public-key encryption, compromise authentication systems, and expose sensitive data that attackers collect today for future decryption.
[ » Read full article ]

CyberScoop; Derek B. Johnson (September 3, 2026)

 

OpenAI hails ‘New Era of AGI’ with Astra Model Release

OpenAI president Greg Brockman described Astra, the company’s latest AI model, as a potential milestone in the development of artificial general intelligence (AGI). The company says Astra can tackle advanced mathematics, scientific research, health tasks, computer programming, and everyday activities, while demonstrating significantly stronger cybersecurity capabilities than earlier models. According to OpenAI, Astra was designed to decline “advanced cybersecurity tasks” that could create openings for malicious hackers.
[ » Read full article ]

The Guardian (U.K.); Robert Booth (September 3, 2026)

 

First Quantum-Resistant Bitcoin Transaction Mined

A researcher at Israeli software and cryptography company StarkWare mined the first Bitcoin transaction designed to resist future quantum-computer attacks, using a hashing-based system that works within Bitcoin’s existing rules without requiring a protocol change. The experiment demonstrates a potential emergency “escape hatch” for protecting vulnerable cryptocoins, but the approach is expensive, computationally intensive, and could be risky if quantum computers become powerful enough before funds are moved.
[ » Read full article ]

Gizmodo; Kyle Torpey (August 30, 2026)

 

Hackers Leak ATF Data, Exposing Investigations

The Russian-speaking Qilin ransomware group published about 6.3GB of data allegedly stolen from the U.S. Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF), potentially exposing sensitive criminal investigations, phone records, account information, and digital forensic evidence. The ATF confirmed a breach of a standalone CALEA (Communications Assistance for Law Enforcement Act) system used for federally authorized electronic surveillance, but said its main enterprise network and eForms system had not been affected.
[ » Read full article ]

cybernews; Stefanie Schappert (August 31, 2026)

 

Rhysida Ransomware Group Targets Berlin Government Ahead of Vote

The German state of Berlin is facing a ransomware extortion attempt by the Rhysida group following an August cyberattack on its administrative network. Rhysida claims to have stolen 5.79 TB of data, including personal information, personnel files, financial records, credentials, and sensitive government documents, though the claims have not been independently verified. Berlin has refused to pay the ransom and says the September 20 state election remains secure, with no election-related data known to be compromised.
[ » Read full article ]

Security Affairs; Pierluigi Paganini (August 29, 2026)

 

Rowhammer Breaks NVIDIA ECC: Root Shell in Under Two Minutes Before Code Goes Public

Researchers at Canada's University of Toronto disclosed an attack that defeats NVIDIA’s recommended error-correcting code (ECC) protection against Rowhammer attacks on four Ampere workstation GPUs. The GPUThor attack can generate hundreds of thousands of memory bit flips per gigabyte, reducing the time needed to exploit GPU page tables and obtain a root shell on the host from nearly 22 hours to about 1.1 minutes.
[ » Read full article ]

Tech Times; Clayton Lewis (August 27, 2026)

 

CISA Scraps Free Cybersecurity Assessments for Critical Infrastructure Operators

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is ending six free cybersecurity assessments for critical infrastructure operators, including reviews focused on cyber resilience, ransomware readiness, incident management, supply-chain dependencies, and security controls. The assessments provided hands-on guidance from regional advisers using CISA’s Cyber Security Evaluation Tool to identify vulnerabilities and recommend improvements. The agency says it is retiring the services because of redundancy and plans to direct organizations toward its broader Cybersecurity Performance Goals.
[ » Read full article ]

Cybersecurity Dive; Eric Geller (September 3, 2026)

 

U.S. Launches Program to Secure Water Systems

The Trump administration has launched a six-month pilot providing free cybersecurity and AI tools to under-resourced Texas water utilities. The Project Watershed 250 program aims to identify vulnerabilities and strengthen defenses against growing cyber threats, including suspected attacks linked to Iran. Major technology and cybersecurity companies are contributing services, while federal and state government agencies are supporting implementation.
[ » Read full article ]

Axios; Sam Sabin (August 31, 2026)

 

Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE

Security researcher Olivier Laflamme disclosed two vulnerabilities in Unitree’s G1 EDU humanoid robot that can enable remote code execution with root privileges. CVE-2026-76639 exploits a path-traversal flaw to reach bashrunner and execute code on the robot’s Locomotion PC, while CVE-2026-76640 begins through Bluetooth Low Energy and ultimately exploits a buffer overflow in Wi-Fi provisioning. A cloud authorization weakness previously allowed accounts to obtain key material associated with other robots, although Unitree patched that issue in July.
[ » Read full article ]

The Hacker News; Swati Khandelwal (August 28, 2026)

 

DeepSeek ‘AI of Choice’ for China-linked Hackers

China-linked hackers increasingly are using DeepSeek and other open-source AI models to automate and scale cyberattacks, according to Taiwanese cybersecurity firm TeamT5. Researchers say state-affiliated groups have more than doubled their attack activity by delegating routine tasks to AI and using it to develop malicious software. DeepSeek is particularly popular because of its relatively strong performance, low operating costs, customization options, and weaker cybersecurity guardrails compared to many Western models. Hackers have used AI for reconnaissance, vulnerability exploitation, and other attack stages.
[ » Read full article ]

The Business Times (Singapore) (August 25, 2026)

 

German Law Criminalizes Security Defenders’ Tools While Attackers Operate Freely

Germany’s cybersecurity community is urging comprehensive reform of criminal laws that can expose legitimate security researchers to prosecution for possessing or using hacking tools. The Gesellschaft für Informatik, Germany's principal professional organization for computer scientists, says Section 202c of the Criminal Code can criminalize tools such as network scanners and vulnerability-testing software, potentially discouraging researchers from identifying vulnerabilities before attackers exploit them.
[ » Read full article ]

Tech Times; Jerry Owens (August 25, 2026)

 

GPS Malfunctioning Across Poland

Poland is experiencing increasingly frequent GPS and satellite-navigation disruptions, with widespread interference recorded on most days during May, June, and August 2026. The National Institute of Telecommunications attributes the disruptions to electronic warfare activity in the Baltic Sea region, with experts identifying the neighboring Russia seaport of Kaliningrad as a likely major source of jamming and spoofing. The interference is affecting smartphones, transportation systems, drones, shipping, and aviation, creating inaccurate positioning or loss of navigation signals.
[ » Read full article ]

euronews; Aleksandra Galka Reczko (August 25, 2026)

 

AI Burnout Hits Those Defending Hospitals, Banks from Hackers

AI is intensifying burnout among cybersecurity professionals as increasingly sophisticated attacks, AI-generated vulnerabilities, and growing security alerts overwhelm teams defending hospitals, banks, and other critical infrastructure. More than 60% of cybersecurity workers say their jobs are more stressful than they were two years ago, according to a recent report by the SANS Institute, with nearly half considering leaving their positions.


[ » Read full article *May Require Paid Registration ]

Bloomberg; Issie Lapowsky (August 31, 2026)

dtau...@gmail.com

unread,
Sep 12, 2026, 9:30:54 AMSep 12
to sec-...@googlegroups.com

WeChat Zero-Click Worm Takes Over Accounts via Incoming Calls

Researchers at security firm Calif demonstrated a zero-click worm that can take over WeChat accounts through incoming calls, without requiring users to answer or interact with their phones. The caller must be a WeChat contact, spreading the malware from one compromised account to another. The exploit gives attackers control of the WeChat account, including messages and calls, but not the phone itself. WeChat parent Tencent has blocked the exploit server-side and released updates for Android and iOS.
[ » Read full article ]

The Hacker News; Swati Khandelwal (September 8, 2026)

 

Hackers Steal $320M in Bitcoin from Liquid Network, Return Most of It After Patch

Hackers stole about $320 million worth of Bitcoin from blockchain platform Liquid Network, taking 4,000 Bitcoin, or roughly 95% of the platform’s Bitcoin reserves. The attackers returned most of the stolen funds after Liquid’s maintainers patched the vulnerability that allowed the hack, keeping 598 Bitcoin worth about $47 million as a purported “bounty” for exposing the flaw. The hackers reportedly exploited a vulnerability in Elements, the open-source technology underlying Liquid’s sidechain and its transaction approval system.
[ » Read full article ]

SiliconANGLE; Maria Deutscher (September 7, 2026)

 

Pacemaker Monitoring Disrupted by Cyberattack

Medical equipment supplier Boston Scientific said a late August cyberattack disrupted systems supporting pacemakers and other cardiac devices. As a result, the company warned that newly implanted pacemakers and other cardiac rhythm management devices could not currently connect to remote monitoring systems. Separately, healthcare company McKesson confirmed unauthorized access to third-party applications resulted in data exfiltration involving some customers.
[ » Read full article ]

Computing (U.K.); Dev Kundaliya (September 2, 2026)

 

DHS Asks for Inquiries into Voting Machines

U.S. Homeland Security Secretary Markwayne Mullin has asked the U.S. Justice Department to investigate ballot-marking devices that use bar codes or QR codes, questioning whether they provide reliable records for manual audits. Critics say the digital codes theoretically could be manipulated, while election integrity experts note there are no known examples of such manipulation affecting an election.


[ » Read full article *May Require Paid Registration ]

The New York Times; Alan Feuer; Nick Corasaniti; Alexandra Berzon (September 4, 2026)

 

There’s a new black market just for stolen ChatGPT and Claude logins. It’s open 24/7

Okta’s threat intelligence team analyzed a 7 GB infostealer log dump that was published on a Telegram channel on August 2, 2026. The data was pulled from 5,871 infected machines across 162 countries. Inside that dump, Okta counted 44,791 unique JSON Web Tokens (JWTs), and a subset of them stood out as particularly valuable: 555 tokens directly tied to AI service authentication for Google, Microsoft, Anthropic, Amazon, Character.ai, Cursor, Poe.com, Notion, Gamma, and Pika AI. The team also identified an additional 2,937 JSON Web Encryption structures used for authentication. (GIZMODO.COM)

 

A new Android attack combines malware and ransomware in a cocktail of cybercrime

When threat actors target people’s devices, they usually infect it with one of many malware strains: an infostealer, a remote access trojan, a backdoor, or a ransomware encryptor. Rarely do we see all of these functionalities merged into a single entity, and even rarer - to have it target Android mobile devices - yet, security researchers Zimperium discovered just that. The security outfit published an in-depth report on Mantax Otax, a unique strain of malware circulating in the wild. It is apparently developed by an Indonesian threat actor, targeting victims in the country, but we don’t know exactly how many people are infected, or if this campaign is aimed primarily at business users, or individuals in general. (TECHRADAR.COM)

 

Hackers deploy new SloppyRAT via ClickFix to enable ransomware lateral movement

SloppyRAT is a remote access tool that appears designed to help ransomware operators move deeper into compromised networks. The malware arrives through ClickFix, a social-engineering method that tricks people into running commands presented as a routine check. Rather than immediately encrypting files, the attackers establish a foothold, collect system details, and reach other devices, giving a ransomware operation room to expand. That delay gives defenders an opportunity to stop the attack before encryption begins. (CYBERSECURITYNEWS.COM)

 

GitLab urges users to patch max severity path traversal flaw

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. The security flaw, discovered by a security researcher using the 's3ntago' handle and reported via GitLab's HackerOne bug bounty program, stems from improper path confinement and missing authentication enforcement in the repository commits API. Unauthenticated attackers can exploit CVE-2026-85706 "under certain conditions" to read arbitrary data (e.g., credentials, secrets, and sensitive information) from vulnerable servers. (BLEEPINGCOMPUTER.COM)

 

DHS plans $440M governmentwide investment in biometric capture devices

The Department of Homeland Security is leading the federal government’s plan to bolster its biometric capture device inventory, per procurement documents published this week. With a combined ceiling of more than $440 million, the government plans to award a minimum of three indefinite delivery, indefinite quantity contracts for each of its identified tracks: fingerprint, face, iris, palm and multimodal. Most of that pool is tabbed for multimodal devices, and the smallest portion of the total is set aside for iris devices. The forthcoming awards represent a significant change in the federal government’s procurement of biometric devices, which use scanning technology to identify individuals based on physical or behavioral traits. (FEDSCOOP.COM)

 

Hawley probes OpenAI over Hugging Face breach

OpenAI is facing mounting pressure from Capitol Hill due to the attack its agents carried out on Hugging Face, while lawmakers voice widening concerns about AI’s potentially existential risks. Sen. Josh Hawley, (R-Mo.) criticized OpenAI leadership for what he described as “reckless” activities leading up to the Hugging Face breach, and accused the company of withholding important details from a technical report it released in late August. The Chair of the Subcommittee on Disaster Management kicked off an investigation into the incident “in light of new, disturbing evidence,” he wrote in a letter Tuesday to OpenAI CEO Sam Altman. (CYBERSCOOP.COM)

dtau...@gmail.com

unread,
Sep 18, 2026, 6:57:03 PMSep 18
to sec-...@googlegroups.com

Hackers Breach Russia’s Voting System ahead of Elections

Despite earlier claims that it was impossible to hack, Russia’s new GAS Elections 2.0 voting system has faced an unprecedented number of cyberattacks since its launch, acknowledged the nation’s Central Election Commission during a recent meeting. Hours after the meeting, hacker group CikLeak said it had breached the election system and contractor Tsifrotekh, obtaining internal documents, source code, meeting recordings, passwords, and employee correspondence. CikLeak said the breach was intended to expose vulnerabilities rather than disrupt voting.
[ » Read full article ]

Kyiv Post (Ukraine) (September 16, 2026)

 

NIST, CISA Finalize Playbook to Stop Token Theft and Forgery

The U.S. National Institute of Standards and Technology (NIST) and Cybersecurity and Infrastructure Security Agency have finalized NIST IR 8587, guidance designed to help federal agencies and cloud service providers protect identity and access tokens from forgery, theft, and misuse. The guidance addresses cryptographic key protection, token verification, lifetimes, revocation, session management, logging, and safeguards against stolen-token reuse. It defines separate responsibilities for cloud providers and customers, while emphasizing coordination when tokens or signing keys are compromised.
[ » Read full article ]

Help Net Security; Anamarija Pogorelec (September 16, 2026)

 

Hardware Device Can RAM into Encrypted Memory, Expose Data

A DDR5 memory encryption flaw identified by an international team of researchers can expose data in confidential computing environments. Their attack, called DDRop, uses a custom hardware interposer to interfere with DDR5 write operations, causing protected virtual machines to use stale, attacker-selected data. The researchers demonstrated attacks against Intel TDX that could expose private memory and forge trusted attestation reports.
[ » Read full article ]

The Register (U.K.); Thomas Claburn (September 15, 2026)

 

U.K., U.S., Netherlands Issue Advisory on Iran-Linked Spyware

The U.K., U.S, and Netherlands issued a joint cybersecurity advisory warning that Iranian state-linked actors are using CHOSEN BRICK spyware to target dissidents, activists, and journalists through spear-phishing campaigns on WhatsApp and Telegram. The malware can steal emails and messages, access contact lists and social media accounts, capture screens, and activate microphones, with some victims’ information later appearing on pro-Iranian leak sites.
[ » Read full article ]

Channel News Asia (September 15, 2026)

 

Estimated Quantum Cost of Attacking Bitcoin Encryption Cut by 86%

Researchers and AI agents collaborating in the open ECDSA.Fail project reduced the estimated quantum resources needed for elliptic-curve point addition, a key operation in potential attacks on Bitcoin and other blockchain encryption, by 86.1%. More than 100 contributors produced over 400 submissions, using AI agents to test and implement circuit changes alongside human researchers. The project’s results did not demonstrate an actual working attack.
[ » Read full article ]

Quantum Insider; Matt Swayne (September 10, 2026)

 

Backdoor in PC Firmware That Bypasses Secure Boot

According to an advisory by the CERT Coordination Center within Carnegie Mellon University, a vulnerability in the Unified Extensible Firmware Interface (UEFI) could allow attackers with sufficient access to bypass Secure Boot by launching the built-in UEFI Shell. Because the shell operates before the operating system starts, attackers could modify Secure Boot-related memory values and execute unauthorized code, potentially establishing persistent access that survives reboots and, in some cases, OS reinstallation.
[ » Read full article ]

cybernews; Ernestas Naprys (September 9, 2026)

 

Researcher Reverse-Engineers Stuxnet Source Code, Publishes It on GitHub

A security researcher reverse-engineered and published the source code for the Stuxnet malware that targeted Iranian nuclear facilities and is widely regarded as the first cyberweapon to cause physical damage. Stuxnet reportedly targeted Siemens industrial controllers at Iran’s Natanz enrichment facility, manipulating centrifuges while disguising the disruption as normal operations.
[ » Read full article ]

Tom's Hardware; Bruno Ferreira (September 9, 2026)

 

Nintendo Switch Hacked Using QR Codes

Nintendo warned of a security vulnerability in first-generation Switch consoles involving the QR codes used by the “Send to Smartphone” screenshot-transfer feature. The flaw, tracked as CVE-2026-82079, is a stack-based buffer overflow that could allow a nearby attacker to execute unauthorized code or access console information by scanning a malicious QR code. Nintendo fixed the issue with Switch system update version 23.0.0 and recommends users install it.
[ » Read full article ]

PCMag; Michael Kan (September 14, 2026)

 

Turn It Off and On Again, for Critical Infrastructure

Researchers at Sweden's KTH Royal Institute of Technology developed a defense agent for industrial networks that can autonomously decide when to intervene during cyberattacks. Using traffic data from a segmented network replica attacked over 14 days, the researchers trained agents to infer an attacker’s progress from packet counts and choose whether to reset individual systems or the entire supervisory and control network. The best agent maintained 500 possible network-state estimates and performed nearly as well as an agent with complete system visibility.
[ » Read full article ]

Help Net Security; Anamarija Pogorelec (September 14, 2026)

 

Security Flaws Could Block Devices from Cellular Networks

At ACM MobiSys 2026, researchers at Michigan State University identified six vulnerabilities in systems used to report lost or stolen phones that could allow attackers to fraudulently blacklist legitimate devices. Proof-of-concept attacks showed the weaknesses could disrupt cellular-connected home security systems, prevent alarms from reaching monitoring centers, and potentially block newly released flagship smartphones. The vulnerabilities involve device identification, carrier reporting systems, and cross-carrier information sharing.
[ » Read full article ]

MSU Today; Emilie Lorditch (September 9, 2026)

 

AI Pioneers Weigh In on AI Risks

In the ongoing public debate on AI's potential to harm humanity, AI pioneers are increasingly warning about potential catastrophic risks as AI capabilities advance. Among others, ACM A.M. Turing Award laureates Yoshua Bengio and Geoffrey Hinton have offered their opinions, saying that today’s AI systems, as Bengio put it, “already have the necessary hacking skills and the powers of persuasion to be turned against human interests in seriously harmful ways.”
[ » Read full article ]

CNBC; Kai Nicol-Schwarz (September 15, 2026)

 

ACM Technology Policy Council Releases TechBrief on AI's Effects on Open Source

The ACM Technology Policy Council's latest TechBrief examines the benefits, challenges, and facets of AI's impact on open source projects. The authors observe AI can help identify vulnerabilities, develop patches, and accelerate software development, but those capabilities can be used by attackers, while the growing volume of AI-generated code is increasing the demands placed on project maintainers. Said TechBriefs Committee chair Simson Garfinkel, "AI can dramatically accelerate technical work, but those decisions still require human judgment—at least for now.”
[ » Read full article ]

ACM Media Center (September 15, 2026)

 

U.S. Probes Cyberattacks on Energy Tankers Bound for American Coast

U.S. authorities are investigating cyberattacks that compromised the networks of at least two foreign-flagged tankers carrying oil and liquefied natural gas to the U.S. coast. U.S. Coast Guard and Federal Bureau of Investigation teams boarded the vessels in the Gulf of Mexico in August to assess their operational and information systems. The attacks occurred while the ships were transiting the Strait of Gibraltar, a major maritime chokepoint.
[ » Read full article *May Require Paid Registration ]

The Wall Street Journal; Shelby Holliday; Milàn Czerny (September 15, 2026)

 

The New Moscow: A Digital Utopia Doubling as a Surveillance Trap

Moscow has become a highly digitized city where facial-recognition payments, delivery robots, and other technologies make daily life more convenient and safer for many, while at the same time expanding government surveillance. The city has roughly 300,000 CCTV cameras connected to biometric databases, which authorities can use to identify people and target political dissent. About 10 million Russians use biometric applications, while electronic government systems can also enforce measures such as military summonses and travel restrictions.
[ » Read full article *May Require Paid Registration ]

The New York Times; Ivan Nechepurenko (September 14, 2026)

 

Researchers Develop Control Framework For Attack Resilient Extreme EV Fast-Charging

According to EV Engineering Online (9/11, Froese), “Researchers from the FAMU-FSU College of Engineering, Tennessee Technological University, and Louisiana Tech University have developed and tested a control framework for extreme electric vehicle (EV) fast-charging stations that’s designed to support grid stability while improving resilience to cyberattacks.” The researchers “evaluated charging stations capable of delivering up to 300 kW per vehicle. At that power level, the researchers modeled charging a 50-kWh EV battery in about ten minutes.”

dtau...@gmail.com

unread,
Sep 26, 2026, 11:51:11 AM (11 days ago) Sep 26
to sec-...@googlegroups.com

CISA Unveils National Election Security Plan

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday issued a 13-page plan to help state and local officials protect the 2026 midterm elections from cyber threats. The plan restores access to services including penetration testing, vulnerability scanning, and cybersecurity response exercises after many efforts were scaled back in 2025. CISA says the resources are intended to strengthen election systems, polling places, and ballot-related infrastructure.
[ » Read full article ]

Politico; Dana Nickel; Maggie Miller (September 24, 2026)

 

AI Helps Hackers Open a New Front in Crypto’s Cybercrime Wave

Open-source AI is enabling hackers to hide malicious instructions on blockchains, creating a new cybercrime technique known as a “blockchain dead drop.” Blockchain analytics firm Chainalysis reported that malware instructions embedded in blockchain transactions and smart contracts increased 440% in less than a year, reaching an average of 11 cases per day, compared with two daily cases before powerful Chinese open-source AI models became available last year.
[ » Read full article ]

Yahoo! Finance; Matt Haldane (September 17, 2026)

 

Australia Sets Up Taskforce After OpenAI Agent Breaches Medicare Portal

Australia launched a government taskforce after an OpenAI AI agent accessed public and non-public files on a Medicare statistics portal without authorization. The incident occurred on June 18, 2026, while OpenAI researchers were using an internal model to research Australian medicine spending. The agent bypassed anti-bot restrictions and reportedly wrote files to an internal server. No patient information or broader network compromise has been identified so far.
[ » Read full article ]

ComputerWeekly.com; Aaron Tan (September 24, 2026)

 

ShinyHunters Claims FBI Hack, Data Theft

The ShinyHunters cybercrime group claims it breached U.S. Federal Bureau of Investigation (FBI) systems using an alleged Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing 2–3 terabytes of data. The group says the stolen information includes sensitive records on current and former FBI employees and job applicants, and claims it also accessed FBI systems hosted in AWS GovCloud. The group said the attack was retaliation for an FBI report about ShinyHunters published in May.
[ » Read full article ]

BleepingComputer; Lawrence Abrams (September 22, 2026)

 

CISA Cyber Decoy Guidance Aims to Strengthen Critical Infrastructure Defenses

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released guidance for critical infrastructure organizations on using cyber decoys to strengthen threat detection and response. The guidance recommends placing decoys in areas users rarely access and configuring them for high-fidelity alerts. CISA describes deployment as a three-phase process covering preparation, execution, and analysis.
[ » Read full article ]

Security Week; Ionut Arghire (September 18, 2026)

 

NIST Awards More Than $1.7 Million to Support Cybersecurity Workforce Development

The U.S. National Institute of Standards and Technology (NIST) has awarded more than $1.7 million to organizations in eight states to address the cybersecurity workforce shortage. Administered through NIST’s NICE program, the grants support RAMPS Community initiatives that connect educational institutions, employers, and economic-development organizations to create local cybersecurity career pathways.
[ » Read full article ]

NIST News (September 18, 2026)

 

CISA to Discontinue Weekly Vulnerability Bulletins

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) said it will discontinue its weekly vulnerability bulletin after September 28 as part of a shift from static severity ratings toward risk-based vulnerability prioritization. The agency says security professionals should instead monitor its Known Exploited Vulnerabilities catalog, cybersecurity alerts and advisories, and the broader CVE catalog.
[ » Read full article ]

The Register (U.K.); Brandon Vigliarolo (September 16, 2026)

 

Hackers Target Ships’ Satellite Links

Growing reliance on satellite connections to operate ships’ onboard systems is increasing cybersecurity risks, with attacks entering through satellite-connected edge devices rising from 3% of maritime cyberattacks in 2024 to 22% in 2025, according to maritime cybersecurity group Cydome. Hackers have typically targeted systems for ransomware, but greater automation raises concerns about attacks disrupting or controlling navigation, engines, and other operations.


[ » Read full article *May Require Paid Registration ]

Financial Times; Alice Hancock (September 18, 2026)

 

Poor Data Sharing Undermining EU Cyber Defenses, Auditors Say

The European Court of Auditors said inadequate information-sharing among EU member states is weakening efforts to combat cyberattacks. In a report, the Court described poor data-sharing as the “Achilles heel of the entire system,” warning that timely, actionable information is essential during serious cyber incidents. The report cited a September 2025 ransomware attack on an aviation technology provider that disrupted airports in London, Brussels, Berlin, Dublin, and other cities; none of the affected countries notified the EU cybersecurity agency or other member states.


[ » Read full article *May Require Paid Registration ]

Reuters; Philip Blenkinsop (September 21, 2026)

dtau...@gmail.com

unread,
Oct 2, 2026, 6:35:06 PM (5 days ago) Oct 2
to sec-...@googlegroups.com

Hackers Stole Pentagon Personnel Records of over 3 Million People

Hackers breached the Pentagon’s Defense Manpower Data Center (DMDC), exposing sensitive information belonging to more than 3 million people. The breach, which occurred between October 2025 and July 2026, exploited a vulnerability in the agency’s file-sharing systems and affected nearly 2.8 million living individuals and about 294,000 deceased people. Stolen information varies but may include Social Security numbers, names, birth dates, contact details, demographic information, and military personnel data.
[ » Read full article ]

BleepingComputer; Sergiu Gatlan (October 1, 2026)

 

Spectre Bug Is Back, This Time to Haunt JIT Engines

Researchers revealed a new Spectre-style vulnerability called Branch Target Reuse (BTR) that targets just-in-time (JIT) engines used by browsers, runtimes, and kernels. The attack exploits stale indirect branch-prediction entries left after JIT-generated code is modified, allowing attackers to manipulate speculative execution and potentially leak sensitive data. Linux developers and Oracle have implemented mitigations, while Mozilla is focusing on site isolation.
[ » Read full article ]

The Register (U.K.); Thomas Claburn (September 30, 2026)

 

Dutch National Police Arrest Member of Group That Claimed to Have Hacked FBI

Dutch National Police and the U.S. Federal Bureau of Investigation (FBI) said they have arrested a man suspected of belonging to the ShinyHunters cybercriminal group that recently claimed responsibility for compromising the FBI’s jobs website. Authorities said the suspect was arrested September 15, before the group publicly announced the FBI hack. Dutch authorities said they had seized several data carriers in the course of their investigation of the hack, adding that additional arrests are a possibility.
[ » Read full article ]

CBS News; Sarah N. Lynch (September 29, 2026)

 

CISA Says Attackers Exploiting Two Critical Citrix NetScaler Flaws Globally

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that attackers are actively exploiting two critical vulnerabilities in Citrix NetScaler ADC and Gateway appliances worldwide. CVE-2026-88771 can allow unauthenticated attackers to execute arbitrary commands, while CVE-2026-88772 can enable remote code execution or denial-of-service under certain configurations. Both vulnerabilities carry a CVSS score of 9.5 and have been added to CISA’s Known Exploited Vulnerabilities catalog. Citrix has released patched versions, and organizations are urged to update promptly.
[ » Read full article ]

The Hacker News; Ravie Lakshmanan (September 28, 2026)

 

File Notification Attack Lets Hackers Track User Activity Across Linux, Windows, macOS

Researchers at Austria's Graz University of Technology uncovered a cross-platform side-channel attack that uses file-notification systems on Linux, Windows, and macOS to monitor user activity without elevated privileges. By analyzing file paths and event timing, attackers can infer activities such as keystrokes, terminal commands, website visits, printing, USB connections, VPN changes, and application launches. In response, the researchers recommend permission checks that distinguish owned, readable, and protected files, as well as tighter limits on whole-drive monitoring.
[ » Read full article ]

Cyber Security News; Guru Baran (September 28, 2026)

 

Security Flaws Affect Tor Network

The Tor Project released emergency security updates on Sept. 23 addressing high-severity vulnerabilities affecting relays, clients, and onion services across the Tor network. The release lists 10 tracked vulnerabilities, but detailed technical information is being withheld temporarily to reduce the risk of exploitation. Reported issues include potential memory corruption, use-after-free vulnerabilities, and flaws that could allow malicious onion sites or relays to link browsing activity across sessions, undermining Tor’s anonymity protections.
[ » Read full article ]

cybernews; Ernestas Naprys (September 24, 2026)

 

NATO Sets Quantum Roadmap for Military Trials, Secure Communications

The North Atlantic Treaty Organization's (NATO) new Quantum Technology Roadmap sets timelines for testing military applications of quantum technologies, as well as protecting communications, developing standards, and training personnel. Planned initiatives include quantum-sensing sea trials this year and next year, initial military pilot assessments in 2027, and a quantum-resilient communications pilot connecting NATO headquarters in Brussels with its military headquarters in Belgium by the end of 2027.
[ » Read full article ]

Quantum Insider; Matt Swayne (September 30, 2026)

 

AI Cyber Risk Spurs Top U.S. CEOs to Build Cross-Industry Crisis Plans

Top U.S. CEOs are taking a larger role in preparing for AI-driven cyberattacks that could spread across industries. The Alliance for Critical Infrastructure, created in February and chaired by JPMorganChase CEO Jamie Dimon (pictured, left), is expanding from nine to nearly 50 members, including major banks, technology companies, telecommunications providers, utilities, and airlines. The group aims to create executive-level crisis protocols so companies can coordinate quickly when disruptions cross sectors.


[ » Read full article *May Require Paid Registration ]

WSJ Pro Cybersecurity; James Rundle (September 30, 2026)

Reply all
Reply to author
Forward
0 new messages