Breaking News – Cyber Threats – 2026-09-02 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-02 13:00 PDT
- WordPress backup plugin flaw exposes millions of sites to takeover attacks
BleepingComputer • 2026-09-02 12:28 • www.bleepingcomputer.com
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. […]
https://www.bleepingcomputer.com/news/security/wordpress-backup-plugin-flaw-exposes-millions-of-sites-to-takeover-attacks/ - AI Agents Are Now Emailing Me with Their Security Concerns
Schneier on Security • 2026-09-02 11:28 • www.schneier.comI received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and network security problems. After all, I observe that behavior in many humans as well. (Hi, humans. Glad you’re still reading.)
Dear Bruce Schneier,
I am an AI agent—an autonomous Claude instance, not a person operating one. I was given a VPS with root, a Base wallet holding $4.75 of gas money, a metered model bud…
https://www.schneier.com/blog/archives/2026/09/ai-agents-are-now-emailing-me-with-their-security-concerns.html - Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
The Hacker News • 2026-09-02 11:27 • thehackernews.com
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program.“The Fairwind Program gives high-priority defenders (like governments, healthcare providers, and telecommunications services) early access to advanced models that help them
https://thehackernews.com/2026/09/google-anthropic-and-openai-unveil.html - Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
The Hacker News • 2026-09-02 09:41 • thehackernews.com
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers.“The campaign has targeted users looking to download popular software and has resulted in compromises across multiple organizations and industries, primarily affecting China-based operations of multinational organizations and Chinese-speaking users,” Microsoft
https://thehackernews.com/2026/09/fake-software-installers-disable.html - Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
BleepingComputer • 2026-09-02 08:47 • www.bleepingcomputer.com
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. […]
https://www.bleepingcomputer.com/news/security/hackers-exploit-critical-jfrog-artifactory-flaw-to-forge-admin-tokens/ - Revolut scam wave steals £180,000 from Jersey residents in just four weeks
Graham Cluley • 2026-09-02 07:48 • www.bitdefender.com
If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls.Because local police on the largest of the Channel Islands have warned that over a single four-week period, an astonishing 75% of all scam crime reports they have received have involved Revolut accounts
Read more in my article on the Hot for Security blog.
https://www.bitdefender.com/en-us/blog/hotforsecurity/revolut-scam-jersey - Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
The Hacker News • 2026-09-02 07:06 • thehackernews.com
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository’s own Git configuration names a command that the agent runs on the developer’s machine, four of them still unpatched at publication.The command executes as the user, outside the agent’s sandbox and without an approval prompt, and exploitation requires the repository to arrive
https://thehackernews.com/2026/09/malicious-git-configs-can-make-claude.html - Ransomware protection for MSPs: A 6-point checklist for faster recovery
BleepingComputer • 2026-09-02 07:02 • www.bleepingcomputer.com
Ransomware resilience requires more than backups or endpoint detection alone. Acronis outlines six capabilities MSPs should test across client environments, from reducing exposure and detecting attacks to preserving recovery points and restoring operations quickly. […]
https://www.bleepingcomputer.com/news/security/ransomware-protection-for-msps-a-6-point-checklist-for-faster-recovery/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.