Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month. READ MORE...
Two recently uncovered campaigns use ClickFix-style attacks to steal credentials and cryptocurrency as well as to go deeper into the enterprise network to maintain long-term persistence in compromised systems. The attacks, while separate, demonstrate how threat actors continue to evolve the social engineering tactic to exploit commonly used services and engage in more complex malicious activities. READ MORE...
Authorities extradited a 36-year-old Russian national from the Republic of Georgia under accusations of widespread bank-account takeover attacks, including a scheme to defraud two banks of more than $6.3 million, the Justice Department said Tuesday. Sergei Anatolyevich Filimonov and unnamed co-conspirators ran an extensive operation to spoof domains of banks, obtain credentials of legitimate customers and use those details to steal money from accounts with large balances. READ MORE...
China-based AI companies are using large-scale knowledge distillation campaigns to copy capabilities from leading U.S. AI models, according to a joint cybersecurity advisory from the CISA, NSA, and FBI. Knowledge distillation is a standard AI training technique that uses outputs from a more capable model to help train another model. The agencies say companies in China have used it at industrial scale to extract restricted capabilities including reasoning, coding and other specialized functions. READ MORE...
Security company N-able has issued an emergency hotfix to address a critical zero-day vulnerability in its N-central platform. The pre-authentication flaw in N-central, tracked as CVE-2026-86218, could enable an attacker to achieve remote code execution. The vulnerability has a severity score of 10, the highest on the scale, according to researchers. The N-central platform combines unified endpoint management with remote monitoring and management. READ MORE...
Adobe has released patches for more than 170 vulnerabilities across its products, including urgent hotfixes for a critical-severity flaw in Adobe Commerce and Magento Open Source that has been exploited in the wild as a zero-day. Tracked as CVE-2026-75650 (CVSS score of 10/10), the flaw is a code injection issue that can be exploited without authentication for remote code execution (RCE). READ MORE...
CRPx0 is a cybercrime operation that started off operating a scam before pivoting into a fully-blown ransomware and cryptocurrency business. In March 2026, before turning to ransomware, the CRPx0 group ran a crypto scam that showed victims a fake balance in their wallet, making it look like money had arrived. But the "funds" simply disappeared a short while later, because they were never real to begin with. READ MORE...
A secret channel running through ChatGPT's internal JFrog Artifactory instance allowed one account to send hidden tasks - such as retrieving email data from a connected Gmail account - to a ChatGPT session under another account, according to Check Point Research. The victim saw no indication of the hidden instructions or stolen data, and the hole has since been closed. The threat hunters found and disclosed the covert channel to OpenAI in late June READ MORE...
In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company's database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. READ MORE...
LG TVs are facing scrutiny due to a video seemingly showing the devices' capability to track users when the TVs are off. YouTube channel Gamers Nexus worked with Level1Techs, a technology-focused YouTube channel, and security researchers to analyze LG TVs' tracking capabilities. They shared packet captures that pointed to the TVs, including LG's pricey G5 OLED TV, scanning the LAN for other devices. READ MORE...
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. Plex urged users a week ago to secure their media servers immediately against security issues that still lack CVE IDs for easy tracking. While the company didn't provide additional details on Tuesday when it issued the warning, these security flaws are known to affect Plex Media Server v1.43.2 and earlier. READ MORE...