Spain's data protection agency (AEPD) has reported the country's first-ever personal data breach caused by the actions of an autonomous AI agent. Francisco Pérez Bes, president and deputy of the AEPD, said in a Monday blog post that an individual deployed an AI agent that used a "known large language model (LLM)" to carry out the attack on an organization. The agent scanned "generic files" before accessing the organization's system, then ran vulnerability scans to find flaws. READ MORE...
Stealthy attacks on South Korean automotive and media firms have given an espionage group access to victims' networks - operating, in some cases, since early 2025. In an analysis this week, Rapid7 attributed the attack to North Korean advanced persistent threat (APT) groups - although only with medium confidence - because of the targets of the attacks, the use of simple obfuscation, and a list of command-and-control (C2) servers that matches those used by APT37. READ MORE...
Microsoft on Monday issued out-of-band updates to address several issues caused by this month's massive, record-setting Patch Tuesday. The emergency patches fix problems with Remote Desktop Services (RDS) that came to light last week, as well as unintended side effects for Hyper-V virtual machines and USB audio devices following the historic update last week. September's Patch Tuesday addressed a whopping 974 unique CVEs, smashing the previous record set earlier this year. READ MORE...
Google has released its September 2026 Pixel Update Bulletin, fixing 110 vulnerabilities, including one that it says "may be under limited, targeted exploitation." The bug is not described as a simple remote takeover, but as a vulnerability that could give an attacker who already has a foothold on a phone more power than they should have. Although Pixel devices also run Android, they receive separate security updates and bug fixes from the standard monthly patches. READ MORE...
Iranian state cyber actors are targeting individuals using social messaging apps to deploy surveillance and data-stealing malware on their Windows machines, three Western governments warned. In all observed cases, Chosen Brick has infected Windows systems exclusively. Iran has used it since at least 2025 to take over individuals' devices, stealing their contacts, emails, and social media messages, which allows the spies to track people's movements. READ MORE...
A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed "ParaShells," can allow any local user on a Mac to gain root privileges on the host system. The danger is highest on developer laptops, where a single poisoned Homebrew formula or malicious npm preinstall script can go from local user to full control, and on shared university and corporate machines that have many local accounts, JFrog vulnerability research team lead Yuval Moravchick noted. READ MORE...
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. The flaw is tracked as CVE-2026-27540 and impacts plugin versions 2.0.3.1 and older. It is an unauthenticated arbitrary file-upload vulnerability discovered by security researcher Teemu Saarentaus. An attacker can exploit it to upload PHP webshells and execute code, potentially leading to a complete site compromise. READ MORE...