The release of The Odyssey has already sparked a wave of piracy scams, from fake browser errors to malware masquerading as movie files.

Within hours of the theatrical release of Christopher Nolan's film *The Odyssey*, cybersecurity researchers observed a rapid proliferation of scams designed to exploit public interest in pirated copies of the movie. These campaigns did not target the film's distribution directly but rather individuals searching for illicit downloads, leveraging social engineering tactics rather than software vulnerabilities.
Two primary scam methods were identified. The first involved fake browser warnings displayed on cloned piracy websites. These sites, designed to mimic legitimate torrent trackers, featured authentic-looking listings, artwork, and cast information for *The Odyssey*. Upon visiting, users were presented with a pop-up warning, "Browser Issue Detected," claiming a missing component prevented full access. A prominent "Fix It Now" button was offered, with a smaller "Close and Continue Browsing" option. Clicking "Fix It Now" did not resolve any browser issue but instead redirected users through malvertising networks. The ultimate destination of these redirects varied, potentially leading to fake browser extension installations, scareware prompting calls to fraudulent technical support, or attempts to deliver other malware. The consistent appearance and identical layout of these pop-ups across multiple cloned sites, with only branding colors altered, suggested a coordinated campaign rather than compromised legitimate sites.
The second scam involved malicious files disguised as movie downloads. Researchers found a listing advertised as "The Odyssey 2026 1080p WEBRip-LAMA," which, despite its name, was a Windows executable (.exe) file rather than a standard video file format like .mkv, .mp4, or .avi. The file displayed the familiar orange traffic cone icon of VLC Media Player, a common social engineering tactic to make it appear as a harmless video file. However, Windows correctly identified it as an "Application." Further inconsistencies included a file description of "wireless bus Business Controller," which is unrelated to video playback and likely leftover metadata.
Executing such a file would launch an unknown program with user permissions. The payload could vary, potentially installing Trojans to create backdoors, information stealers to pilfer passwords and browser sessions, loaders for additional malware, or even ransomware. The presence of a high number of "seeders" for these malicious files was noted as an unreliable indicator of safety, as many users unknowingly distribute infected content.
These scams do not rely on exploiting software vulnerabilities but rather on tricking users into taking specific actions, such as clicking a fake warning or running a disguised executable. While security software can block known malicious sites and detect identified malware, it is less effective at preventing these initial social engineering steps. Browsers struggle to distinguish between genuine system messages and those rendered within a webpage's HTML, and antivirus software cannot flag every executable with misleading icons or unusual metadata, as some legitimate applications may also exhibit these characteristics.
Users are advised that legitimate movie downloads will never be Windows executables. If a supposed movie download ends in ".exe" or prompts for browser fixes or software installation, it is almost certainly malicious. If a user has clicked a "Fix It Now" button and experienced unexpected downloads or openings, or if they have executed a suspicious ".exe" file, immediate action is recommended. This includes disconnecting the affected computer from the network, performing a full malware scan, and refraining from using the device for sensitive activities like banking or email until it is confirmed clean. Additionally, users should check their browsers for unfamiliar extensions and remove them, and if an unknown program was executed, change passwords for important accounts from a separate, trusted device.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed