On the heels of a record-breaking Patch Tuesday, the disgruntled security researcher known as Nightmare-Eclipse dropped yet another Windows zero-day exploit, which enables privilege escalation and bypasses the fix for a previous Windows exploit released last month. The latest from the researcher - who also goes by Chaotic Eclipse, MSNightmare, and their X handle, Infinite Nightmare - is the "ShieldCrash" exploit, which they claim is a patch bypass for CVE-2026-69414, or "ShieldBreak." READ MORE...
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans. IDScan disclosed the incident in a September 4 security notice, saying it learned on or around September 1 that certain data may have been accessed without authorization. READ MORE...
Initial access brokers (IABs) are phishing employees by calling or texting their personal devices, then exploiting the Microsoft Graph API to perform large-scale corporate data exfiltration. It's almost unavoidable that, in general corporate settings, employees will use personal devices to access company resources. Only the most careful government, research, and other high-value organizations ban it entirely. READ MORE...
Cybersecurity firm Check Point this week announced patches for two critical-severity vulnerabilities in its gateway and firewall products using VPN functionality. Tracked as CVE-2026-85102 and CVE-2026-85103 (CVSS score of 9.8), both security defects could be exploited without authentication for remote code execution (RCE), Check Point warns. The former is described as an improper validation of certificate data during VPN negotiation. READ MORE...
A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. Indonesian operators distribute the malware through malicious APKs hosted outside Google Play, targeting users with phishing and social engineering messages. After installation, the malware requests permission to use the Accessibility service, which gives it extensive control over compromised devices. READ MORE...
A threat actor built a working exploit for PaperCut print management software, then handed the job of breaking into hundreds of organizations to AI agents that did most of the work on their own, according to GreyNoise. The result was at least 440 compromised PaperCut instances across 395 identified organizations in 48 countries. Attacker first built a private lab environment with a vulnerable copy of PaperCut NG/MF and an Active Directory server to develop and test exploits. READ MORE...
A44-year-old Ukrainian national was sentenced to four years in prison for his long-running participation in Conti, a ransomware group that attacked more than 1,000 organizations globally before it disbanded in 2022, the Justice Department said Thursday. Oleksii Oleksiyovych Lytvynenko, also known as Alexsey Alexseevich Litvinenko, pleaded guilty in June to conspiracy to commit wire fraud as a result of some of those attacks. READ MORE...
Anthropic said it stopped multiple attempts by scientists this year to use its technology for research that could help develop biological weapons, as experts increasingly fear the threat that AI poses to public safety. The startup gave five examples of times actors "circumvented controls" and made other efforts to "obfuscate" the purpose of their research to dodge safeguards. The cases involved some users in nations that it prohibits from accessing its models. READ MORE...
With the release of Apple Watch Series 12, Apple has decided that it's ok to capture people's conversations without their consent. The latest Apple Watch comes with Audio Intelligence, a set of AI audio processing capabilities tuned for the company's S11 chip. Its features include: Sound Recognition, Music Recognition with Shazam, Live Rewind, and Siri Recap. "Live Rewind lets you instantly see the last 15 seconds of a conversation as text," Apple explains in its technical summary. READ MORE...