Over 36,000 exposed Plex servers vulnerable to recent flaws
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]
Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider The HIPAA Journal
Two ransomware groups have claimed attacks on the home health care provider Interim Healthcare. Data breaches have been announced by […] The post Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider appeared first on The HIPAA Journal.
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been desc…
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds b…
An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]
cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPa…
Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web s…
An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]
The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which t…
Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by Se…
Ameaças cibernéticas estão migrando de interações simples com modelos de linguagem para frameworks de IA multiagentes, capazes de automatizar ataques complexos em velocidade sem precedentes. A constatação é do Google Threat Intelligence Group (GTIG), que publicou ontem um relatór…
Uma pequena equipe de pesquisadores da Calif, empresa de segurança sediada em Palo Alto, construiu em pouco mais de uma semana uma ferramenta de hacking alimentada por inteligência artificial capaz de se espalhar pelo WeChat, a popular plataforma de mensagens da China, sem que as…
Um programa malicioso que tem como alvo dispositivos F5 BIG-IP APM está interceptando o carregamento de arquivos para injetar um código diretamente na memória, sem escrever conteúdo malicioso em disco. De acordo com análise da Sophos publicada esta semana, o malware é uma etapa s…
A Adobe publicou hoje uma correção emergencial para a vulnerabilidade CVE-2026-75650, um zero-day de gravidade máxima que afeta múltiplas versões do Magento e do Adobe Commerce. A falha, batizada de “StyleSmuggler” pela empresa de segurança Sansec, está sendo explorada ativamente…
Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks.
Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.
A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]
A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]