LIVE · cybersecurity feed
Live wire

News Archive

1917 stories · page 1 of 80

Every story we've published, newest first. Vulnerability records live in the CVE Tracker.

vulnerability

The vulnpocalypse rains iBugs down on Apple with record-setting number of patches

September Patch Tuesday part 2?

vulnerabilityhigh

Acronis warns of actively exploited flaw in its cPanel backup plugin

Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]

vulnerabilitycritical

Oracle September 2026 Critical Security Patch Update addresses 672 CVEs

Oracle addresses 672 CVEs in its September 2026 Critical Security Patch Update with 673 patches, including 104 critical updates. Key Takeaways The September 2026 Critical Security Patch Update (CSPU) contains fixes for 672 unique CVEs in 673 security updates 104 issues (15.5% of all patches) were assigned a critical severity rating Oracle E-Business Suite received the highest number of patches at

malware

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

malware

Iranian spies hit Windows machines with Chosen Brick data-stealing malware

'Enemies of the regime' on notice

patch

Before You Patch. Why Patch Reliability Matters for Confident Deployment

Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security patching. Qualys TruRisk Eliminate classified both updates as Low Reliability, signaling the need for additional validation before production deployment. Patch Reliability helps IT and s

vulnerabilitycritical

Hackers target WordPress sites via third-party WooCommerce plugin

Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. [...]

ransomware

Most Firms Unable to Recover Quickly from Ransomware

Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours

breach

Electric and gas utility CenterPoint Energy warns of data breach after dark web post

Houston-based CenterPoint Energy notified federal regulators about an incident that exposed some customer data on the dark web.

finance

Suspected Black Axe gang leaders face cybercrime charges in the US

Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. [...]

ai

Meta AI builds detailed profiles of children from years of family posts

A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.

security

Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man

44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison. That should be plenty of time for him to rue the day he agreed to increase his monthly income by helping a SIM swap gang in their attempt to steal over half a million dollars. Read more in my article on the Hot for Security blog.

ai

Most chief audit executives can’t tell you what AI is worth yet

Auditors are using AI in their daily work, and their departments have mostly left them to figure it out alone. 93% of audit leaders and auditors report some level of AI use, while 15% say their department has deployed formal use cases and runs them routinely in audits, according to Gartner. Chief audit executives (CAE) have to defend that arrangement to stakeholders, and most of them cannot say wh

security

Supreme Court denies Trump request to allow USPS mail ballot changes

One justice said the attempt to change the rules ahead of the 2026 elections would be "arbitrary and capricious” and violated the Administrative Procedures Act. The post Supreme Court denies Trump request to allow USPS mail ballot changes appeared first on CyberScoop.

malware

HBO Max Reddit account compromised to serve ClickFix attacks

Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware

security

Apple parental controls in iOS 27 let kids ask before opening new websites

Apple has overhauled the child-safety tools that ship across iPhone, iPad, and Mac. One idea runs through the redesign. Give a child a device that does very little, then open it up as they’re ready. The tools went live on September 14, after a preview in June, and they require iOS 27, iPadOS 27, or macOS 27. The Child Account is the foundation Everything hangs off the Child Account, set up through

ai

Cybersecurity jobs available right now: September 15, 2026

AI & Security Architect SecNinjaz Technologies | India | On-site – View job details As an AI & Security Architect, you will design secure and reliable AI agent platforms, including tools, memory, models, evaluations, and backend services. You will define controls for sensitive data, access, credentials, sandboxing, human approvals, and agent actions. CISO Texas Health and Human Services | USA | On

patch

Microsoft releases emergency Windows updates to fix RDS failures

Microsoft has released emergency out-of-band Windows updates to fix Remote Desktop Services failures caused by this month's security updates, along with Hyper-V and USB audio problems on some Windows versions. [...]

breach

Japan's Digital Agency says VPN flaw exposed 246,000 personnel records

Japan's Digital Agency has discovered a data breach that may have exposed around 246,000 record rows containing personal information of government employees. [...]

CVE-2026-85706

Maximum Severity GitLab Flaw Puts Supply Chains at Risk

CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.

security

New York Seizes a Dozen Celebrity Deepfake Websites

In the biggest-ever legal action against harmful deepfake websites, the Manhattan District Attorney’s Office has seized 12 sites that collectively targeted around 1,200 victims.

breach

Hackers target exposed Vite dev servers to steal AWS, Azure secrets

A mass-scanning campaign targeting internet-exposed Vite development servers is attempting to steal cloud credentials and configurations from AWS and Azure deployments. [...]

breach

Pro-Ukraine Hacking Cat group deploying new malware against Russian targets

The pro-Ukraine hacktivist group Hacking Cat has evolved from carrying out website defacements and data leaks to more sophisticated and destructive attacks on Russian targets, researchers said.

ai

CISOs Race to Control AI Agents Without Destroying Their Value

Security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. The post CISOs Race to Control AI Agents Without Destroying Their Value appeared first on SecurityWeek.