Curated news, CVE analysis, and threat reports from the world's top cybersecurity sources.
This article from Cisco Talos details active exploitation of two vulnerabilities in Cisco Secure FMC: a critical authentication bypass and a static credential issue. The flaws can be chained to elevate privileges, and Cisco has released patches.
Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at a third-party vendor. The breach exposed patient data including Social Security numbers, medical records, and personal health information.
Researchers at German cybersecurity company Nebty have identified “DoppelCart,” a cluster of almost 119,000 domains linked to copied online stores. The researchers describe it as the largest publicly documented fake-shop network by associated domain count.
ASEC Blog publishes Ransom & Dark Web Issues Week 2, September 2026           The Gentlemen Ransomware Attack on a Canadian Airline LAPSUS$ Group Resumes Chapter II and Teases New Victim Disclosure AUDIT TEAM Data Extortion Attacks on Four Organizations in South Korea, Germany, and Argentina
A new class of attack dubbed "Workflow Identity Hijacking" targets AI agent workflows by exploiting how identity and access management systems authenticate API calls between AI services. Researchers warn that standard security controls like MFA and network segmentation can be bypassed when AI agents reuse identity tokens across multiple services.
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API keys.