Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM).
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded JSON Web Token (JWT) signing key that is identical across every installation.
A website used around the world for reporting meteors faces weeks of downtime as the organization moves away from systems that were hacked recently.
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle , Hacking Cat , and Toy Ghouls , according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
ASEC Blog publishes Ransom & Dark Web Issues Week 3, September 2026           Internal Data of a Japanese Pharmaceutical and Healthcare Company Offered for Sale Following a Cyber Incident Customer Data of a South Korean E-Commerce and Retail Company Offered for Sale AUDIT TEAM Ransomware Attacks on Two South Korean Organizations.