SecurityWeek

US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

Security Week - Wed, 09/09/2026 - 8:32am

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.

The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.

Categories: SecurityWeek

Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy

Security Week - Wed, 09/09/2026 - 8:00am

Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data.

The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek.

Categories: SecurityWeek

ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws

Security Week - Wed, 09/09/2026 - 6:49am

AVEVA and Rockwell Automation also released patches for vulnerabilities affecting industrial control system products.

The post ICS Patch Tuesday: Schneider Electric, Siemens Fix Critical Flaws appeared first on SecurityWeek.

Categories: SecurityWeek

Ivanti Patches Critical Flaws Across Enterprise Security Products

Security Week - Wed, 09/09/2026 - 6:28am

Six critical vulnerabilities in Neurons for ITSM could enable remote code execution, while Sentry and EPMM received patches for authentication bypass flaws.

The post Ivanti Patches Critical Flaws Across Enterprise Security Products appeared first on SecurityWeek.

Categories: SecurityWeek

This Key Will Self-Destruct: An Open Standard for Revocable API Keys

Security Week - Wed, 09/09/2026 - 6:00am

Every leaked credential should be dead, or dying, within sixty seconds of being found. Here's a proposal to make that the default.

The post This Key Will Self-Destruct: An Open Standard for Revocable API Keys appeared first on SecurityWeek.

Categories: SecurityWeek

New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser

Security Week - Wed, 09/09/2026 - 6:00am

Attackers are using trusted Microsoft services and blob URLs to generate stealthy phishing pages that leave defenders with no static website to detect or block.

The post New Phishing Attack Creates Malicious Pages Inside the Victim’s Browser appeared first on SecurityWeek.

Categories: SecurityWeek

Chrome 153 Patches Seventh Zero-Day of 2026

Security Week - Wed, 09/09/2026 - 5:45am

The Chrome update includes 230 security fixes, and users are advised to update their browsers as soon as possible.

The post Chrome 153 Patches Seventh Zero-Day of 2026 appeared first on SecurityWeek.

Categories: SecurityWeek

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Security Week - Tue, 09/08/2026 - 3:20pm

The record-breaking September security update fixes two exploited privilege-escalation zero-days and 20 potentially wormable vulnerabilities.

The post Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days appeared first on SecurityWeek.

Categories: SecurityWeek

Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day

Security Week - Tue, 09/08/2026 - 2:37pm

Tracked as CVE-2026-75650, the exploited defect allows unauthenticated attackers to execute arbitrary code.

The post Adobe Patches Over 170 Vulnerabilities, Including Commerce Zero-Day appeared first on SecurityWeek.

Categories: SecurityWeek

The Hidden Instructions That Can Hijack AI Agents

Security Week - Tue, 09/08/2026 - 1:00pm

Malicious prompts concealed in documents, metadata, emails, images and code can manipulate autonomous agents into taking dangerous actions.

The post The Hidden Instructions That Can Hijack AI Agents appeared first on SecurityWeek.

Categories: SecurityWeek

Hackers Return $263 Million Stolen From Liquid Network

Security Week - Tue, 09/08/2026 - 12:35pm

Alleged ‘white-hat’ hackers drained $320 million from Liquid’s federation wallet, demanding a bug fix.

The post Hackers Return $263 Million Stolen From Liquid Network appeared first on SecurityWeek.

Categories: SecurityWeek

Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta

Security Week - Tue, 09/08/2026 - 11:21am

The startup founded by Palo Alto Networks’ Nir Zuk has raised $290 million to build an AI-native security platform for highly regulated organizations that cannot rely on the public cloud.

The post Cylake Raises $245 Million Ahead of Cybersecurity Platform Beta appeared first on SecurityWeek.

Categories: SecurityWeek

SAP Patches Critical Extended Passport Processing Vulnerability

Security Week - Tue, 09/08/2026 - 10:55am

Affecting the SAP kernel code, the flaw allows unauthenticated, remote attackers to run arbitrary commands, recover secrets, and modify data.

The post SAP Patches Critical Extended Passport Processing Vulnerability appeared first on SecurityWeek.

Categories: SecurityWeek

Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft

Security Week - Tue, 09/08/2026 - 9:00am

The scammers purchased fleets of sports cars, flew on private jets, hired security guards and rented mansions in Miami and the Hamptons.

The post Party’s Over for Crypto Scammers Who Went on a Spending Spree After a $240 Million Bitcoin Theft appeared first on SecurityWeek.

Categories: SecurityWeek

MikroTik Patches Critical Flaws Chained to Hack Routers

Security Week - Tue, 09/08/2026 - 7:15am

Dubbed MikroTrick, the bugs allow attackers to bypass authentication, overwrite configuration files, and take over devices.

The post MikroTik Patches Critical Flaws Chained to Hack Routers appeared first on SecurityWeek.

Categories: SecurityWeek

Mathspace Data Breach Exposes Over 1 Million People

Security Week - Tue, 09/08/2026 - 6:47am

Hackers stole the information of students, teachers, staff, and parents/guardians from a self-hosted Metabase instance.

The post Mathspace Data Breach Exposes Over 1 Million People appeared first on SecurityWeek.

Categories: SecurityWeek

N-able Patches Critical Zero-Day in N-central

Security Week - Tue, 09/08/2026 - 6:37am

Administrators are advised to check their deployments for newly created user accounts they don’t recognize.

The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek.

Categories: SecurityWeek

Pages