
IGN / GameSpot / PC Gamer / Kotaku
Steam Hit Gets Attacked By Malware Twice In One Year: ‘It’s Not Looking Good’
The malicious code can apparently wipe people's personal data
Stories tagged security.

IGN / GameSpot / PC Gamer / Kotaku
The malicious code can apparently wipe people's personal data
BleepingComputer
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]
CyberScoop
A key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators — separate from another administration-proposed pilot program. The post After water attacks, Capitol Hill offers its own proposal for an AI-cyber test program…

Dark Reading
More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.
Huntress
DarkMe, an APT-linked VB6 RAT known for using zero day exploits, turned up in two Huntress incidents stripped down to a plain .pif infostealer malware.

Dark Reading
Cybersecurity and brand reputation are inextricably linked. Security and marketing leaders who establish regular touchpoints, develop joint crisis communications plans, and translate security risks into their brand impact position their organizations to significantly outperform those treating…
Canadian Centre for Cyber Security
Serial Number: AV26-902 Date: September 9, 2026 Updated: September 22, 2026 As of September 9, 2026, Check Point is affected by vulnerabilities in the following products: Security Gateway Multiple versions Check Point Spark Firewall using Site to Site VPN or Remote Access VPN Multiple versions…
Canadian Centre for Cyber Security
Serial number: AV26-949 Date: September 22, 2026 As of September 22, 2026, F5 is affected by a vulnerability in the following product: BIG-IP APM Versions 21.1.0 prior to Hotfix-BIGIP-21.1.0.2.0.30.22-ENG Versions 17.5.0 prior to Hotfix-BIGIP-17.5.1.9.0.160.12-ENG Versions 17.1.0 prior to…
Canadian Centre for Cyber Security
Serial number: AV26-947 Date: September 22, 2026 As of September 22, 2026, Arista Networks is affected by a vulnerability in the following product: VeloCloud Orchestrator (VCO) On-Prem Versions 5.2.0 to 5.2.3.15 Versions 6.1.0 to 6.1.3.7 Versions 6.4.0 to 6.4.2.7 Versions 7.0.0 to 7.0.0.2 Update 1…

Dark Reading
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.

Dark Reading
The Cybersecurity and Infrastructure Security Agency (CISA) is going old school to help organizations with limited resources set traps for hackers.


ransomware.live
[AI generated] N/A

ransomware.live
[AI generated] Cozen O'Connor is an American full-service law firm headquartered in Philadelphia, Pennsylvania. Founded in 1970, it operates in the legal services industry, providing counsel across practice areas including litigation, corporate law, insurance, real estate, labor and employment…
Actively exploitedCritical 85Canadian Centre for Cyber Security
Number: AL26-022 Date: September 22, 2026 Audience This Alert is intended for IT professionals and managers. Purpose An Alert is used to raise awareness of a recently identified cyber threat that may impact cyber information assets, and to provide additional detection and mitigation advice to…

FedScoop / StateScoop / Nextgov
The hacking group says it obtained sensitive employee and applicant records. The full scope of the claimed breach remains unclear.

ransomware.live
Dear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI, During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended. We were…
CyberScoop
The threat group Volexity tracks as UTA0565 showcased a variance in tactics, but it used the same exploit kit as multiple Chinese threat groups. The post Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects appeared first on CyberScoop.

Actively exploitedCritical 100The Hacker News
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released…
Google Chrome Releases
Hi, everyone! We've just released Chrome 154 (154.0.8037.57) for Android. It'll become available on Google Play over the next few days. This release includes stability and performance improvements. You can see a full list of the changes in the Git log. If you find a new issue, please let us know by…
Google Chrome Releases
The Extended Stable channel has been updated to 152.0.7977.140 for Windows and Mac which will roll out over the coming days/weeks. A full list of changes in this build is available in the log. Interested in switching release channels? Find out how here. If you find a new issue, please let us know…
Google Chrome Releases
The Chrome team is delighted to announce the promotion of Chrome 154 to the stable channel for Windows, Mac and Linux. This will roll out over the coming days/weeks. Chrome 154.0.8037.57 (Linux) 154.0.8037.57/.58 Windows/Mac contains a number of fixes and improvements -- a list of changes is…
CERT/CC
Overview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash in the UEFI Authorized Signature Database…

The Hacker News
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with…

The Hacker News
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-pkgprobe-7731," was…

ransomware.live
IT services / document services · Mali | Client documents: scans, attestations, insurance and embassy files, shared business folders | Operations are fully stopped. Nothing restores without settlement — all backups and shadow copies are encrypted or destroyed. | [ACTIVE: deadline 2026-09-25 16:00…

Dark Reading
As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.
SD Times
When this AI security researcher confirmed an unauthenticated remote code execution vulnerability in OpenMed, the finding was not just another security bug. It showed how AI can help vulnerability researchers move from scattered code signals to a real, reproducible attack path. Software teams…

The Hacker News
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the…

ransomware.live
Universal Auto Group PROLOGUE We obtained thousands of documents belonging to two Washington State c...