Breaking News – Cyber Threats – 2026-09-01 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-01 08:00 PDT
- Hackers push malicious Virtualizor update in BGP hijacking attack
BleepingComputer • 2026-09-01 07:45 • www.bleepingcomputer.com
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. […]
https://www.bleepingcomputer.com/news/security/hackers-push-malicious-virtualizor-update-in-bgp-hijacking-attack/ - Novocure data breach affects more than 1,400 cancer patients
BleepingComputer • 2026-09-01 07:28 • www.bleepingcomputer.com
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. […]
https://www.bleepingcomputer.com/news/security/novocure-data-breach-affects-more-than-1-400-cancer-patients/ - 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
The Hacker News • 2026-09-01 07:07 • thehackernews.com
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices.“The injected code runs two operations against a site’s visitors: a mobile ad-fraud and gambling-redirect
https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html - Why Even the Best Edge Security Still Misses High-Risk Sessions
BleepingComputer • 2026-09-01 07:01 • www.bleepingcomputer.com
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions. […]
https://www.bleepingcomputer.com/news/security/why-even-the-best-edge-security-still-misses-high-risk-sessions/ - Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Hacker News • 2026-09-01 06:08 • thehackernews.com
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript.Russian cybersecurity company Kaspersky is tracking the
https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html - Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
BleepingComputer • 2026-09-01 05:38 • www.bleepingcomputer.com
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. […]
https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/ - Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
The Hacker News • 2026-09-01 04:30 • thehackernews.com
The most common way into a company last year was to ask.A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a terminal and pasting it in. The technique is called ClickFix, and it was the most common initial access method Microsoft’s team observed last year, accounting
https://thehackernews.com/2026/09/threat-actors-dont-want-better-attacks.html - Rewiring Democracy Series on The Renovator
Schneier on Security • 2026-09-01 02:59 • www.schneier.comNathan E. Sanders and I are writing a series of essays on real-world examples of democratic technologies for The Renovator. I haven’t been posting the full text on the blog because they’re a bit long, but here are links.
Part 1 is about the Japanese digital democracy party, Team Mirai.
Part 2 is about the Swiss Public AI model, Apertus.
https://www.schneier.com/blog/archives/2026/09/rewiring-democracy-series-on-the-renovator.html
- Five Venezuelans plead guilty to ATM jackpotting attacks in US
BleepingComputer • 2026-09-01 02:15 • www.bleepingcomputer.com
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. […]
https://www.bleepingcomputer.com/news/security/five-venezuelans-plead-guilty-to-atm-jackpotting-attacks-in-us/ - Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
The Hacker News • 2026-09-01 02:05 • thehackernews.com
METR (short for Model Evaluation and Threat Research and pronounced “Meter”), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it suffered “two notable security incidents” where external actors attempted to gain unauthorized access to its systems.No sensitive information is believed to
https://thehackernews.com/2026/09/attackers-steal-metr-api-key-and.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.