ESET researchers document SparroWocky, the new flagship backdoor of the FamousSparrow APT group
Spain’s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a company’s network, found a way to alter personal records, and pulled invoice data. “Before drawing any conclusions, it should be noted that t...
Every DevOps team member knows that dealing with an AI is like being a circus lion tamer. The boss and the audience are happy when the lions sit on the pedestal and roar on cue, but there’s always the danger that they’ll go rogue and bring the whole show to a quick and disastr...
Spanish data protection agency AEPD reveals the country’s first AI-powered data breach
Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]
The Internet Systems Consortium (ISC) has released BIND 9.20.29 and 9.21.26 to fix fourteen security flaws it disclosed on 16 September in BIND 9, its open-source DNS server software. One of them affects any BIND server that answers DNS-over-HTTPS (DoH).
A sender with no credentials can crash the s...
Attackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle campaign targets people who d...
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.
The post CISA Releases Guidance on Deploying Cyber Decoys appeared first on SecurityWeek.
New research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks.
The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek.
A security breach at Gyazo, Helpfeel's image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday.
It also exposed about 490 million image metadata records, mostly for images from Janua...
UK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran’s intelligence services...
Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]
Microsoft confirme que la KB5124008 peut casser la relation d'approbation des PC Windows 11 avec l'AD. En cause : Machine Identity Isolation. Voici la solution.
Le post KB5124008 : Microsoft confirme le bug de relation d’approbation et pointe Machine Identity Isolation a été publié sur IT-Connect.
Several security issues were fixed in Valkey.
Cisco has warned of a fresh maximum-severity security flaw impacting Identity Services Engine (ISE) that has come under active exploitation.
The vulnerability, tracked as CVE-2026-76460 (CVSS score: 10.0), could allow an unauthenticated, remote attacker to bypass authentication.
"This vulnerabilit...
Remote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests.
The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek.
Riverbed has announced new Riverbed intelligent network observability solutions that combine 360-degree network visibility with agentic AI to help network operations teams accelerate troubleshooting, identify root causes, predict emerging issues and increasingly prevent disruptions before they impac...
Tuskira has announced Vector, its autonomous red teaming agentic capability, which identifies an organization’s exploitable attack surface by simulating what an attacker can do from outside it. Tuskira validates every external finding against the organization’s deployed compensating controls, the in...
ESET PSA plugin Service Release 2.6 is now available after logging into the ESET PSA plugin portal.
En Allemagne, police et douanes lient un appareil au compte WhatsApp, Signal ou Telegram de leurs cibles pour lire leurs messages. Une méthode contestée.
Le post Ni spyware ni faille : comment la police allemande lit les messages WhatsApp, Signal et Telegram ? a été publié sur IT-Connect.