Breaking News – Cyber Threats – 2026-09-07 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-07 08:00 PDT
- Mathspace discloses data breach affecting over 1 million people
BleepingComputer • 2026-09-07 06:05 • www.bleepingcomputer.com
Online maths learning platform Mathspace disclosed over the weekend that attackers stole data from more than 1 million students, staff, and parents after breaching its Metabase internal reporting system. […]
https://www.bleepingcomputer.com/news/security/mathspace-discloses-data-breach-affecting-over-1-million-people/ - Trezor data breach impact now reaches 81,000 customers
BleepingComputer • 2026-09-07 05:16 • www.bleepingcomputer.com
Cryptocurrency hardware wallet maker Trezor says an August data breach at its shipping and logistics provider, ShipMonk, affects an additional 67,000 U.S. customers. […]
https://www.bleepingcomputer.com/news/security/trezor-data-breach-impact-now-reaches-81-000-customers/ - Your Cloud Security Checklist Doesn't Work the Way You Think It Does
The Hacker News • 2026-09-07 04:45 • thehackernews.com
If managing security across multiple cloud providers wasn’t hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like.How risk differs across cloud providers
https://thehackernews.com/2026/09/your-cloud-security-checklist-doesnt.html - Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
The Hacker News • 2026-09-07 04:36 • thehackernews.com
Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems.According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake
https://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html - Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
The Hacker News • 2026-09-07 04:20 • thehackernews.com
A TantoSec proof-of-concept turns an AES-CBC “padding oracle” in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild.Security firm TantoSec has published a working exploit chain targeting vulnerabilities
https://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html - Automobile Camouflage to Hide from Flock Cameras
Schneier on Security • 2026-09-07 04:06 • www.schneier.comNot sure it’s practical, but it’s certainly striking.
https://www.schneier.com/blog/archives/2026/09/automobile-camouflage-to-hide-from-flock-cameras.html
- ChatGPT can now connect to your personal apps to mimic writing style
BleepingComputer • 2026-09-07 03:36 • www.bleepingcomputer.com
OpenAI appears to be testing a new “Writing Style” feature for ChatGPT that can learn how you write by looking at examples from your connected apps. […]
https://www.bleepingcomputer.com/news/artificial-intelligence/chatgpt-can-now-connect-to-your-personal-apps-to-mimic-writing-style/ - Hackers exploit new MikroTik RouterOS flaws to hijack routers
BleepingComputer • 2026-09-07 03:32 • www.bleepingcomputer.com
Hackers are exploiting a chain of two recently disclosed vulnerabilities in MikroTik routers to take control of devices with SSH services exposed to the internet. […]
https://www.bleepingcomputer.com/news/security/hackers-exploit-new-mikrotik-routeros-flaws-to-hijack-routers/ - How a hole in Lenovo’s login system let hackers walk into 5,000 Dropbox accounts
Graham Cluley • 2026-09-07 03:30 • www.bitdefender.com
If you ever linked your Dropbox account to a Lenovo ID – perhaps to make life easier when logging in via a Lenovo laptop – you might want to take heed.Read more in my article on the Hot for Security blog.
https://www.bitdefender.com/en-us/blog/hotforsecurity/lenovo-login-system-hackers-dropbox - ConnectWise warns of new ScreenConnect flaw without patch
BleepingComputer • 2026-09-07 03:06 • www.bleepingcomputer.com
ConnectWise has shared temporary mitigation measures for a new ScreenConnect Remote Access vulnerability that it plans to patch later this week. […]
https://www.bleepingcomputer.com/news/security/connectwise-warns-of-new-screenconnect-flaw-without-patch/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.