Breaking News – Cyber Threats – 2026-09-10 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-10 08:00 PDT
- IDScan confirms breach tied to 153 million stolen driver’s licenses
BleepingComputer • 2026-09-10 07:55 • www.bleepingcomputer.com
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver’s license scans. […]
https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/ - Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
The Hacker News • 2026-09-10 07:36 • thehackernews.com
Bad actors are misusing Google Play’s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content.Early Access apps are apps that haven’t been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their
https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html - New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
BleepingComputer • 2026-09-10 07:11 • www.bleepingcomputer.com
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. […]
https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/ - The Top 4 Threats We Found by Investigating Every Alert for a Quarter
BleepingComputer • 2026-09-10 07:00 • www.bleepingcomputer.com
Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. […]
https://www.bleepingcomputer.com/news/security/the-top-4-threats-we-found-by-investigating-every-alert-for-a-quarter/ - ‘Anne Hathaway’ admits leading $245 million crypto theft gang that spent a fortune on nightclubs, watches, and luxury cars
Graham Cluley • 2026-09-10 06:32 • www.bitdefender.com
Here’s a tip for any budding cybercriminals out there.If you’re going to steal a quarter of a billion dollars worth of cryptocurrency, maybe don’t broadcast on a group chat every time you buy a Lamborghini, or blow half a million dollars on a single night out at a nightclub.
Read more in my article on the Hot for Security blog.
https://www.bitdefender.com/en-us/blog/hotforsecurity/anne-hathaway-245-million-crypto-theft-nightclubs-watches-luxury-cars - Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)
SANS ISC Diary (full) • 2026-09-10 05:58 • isc.sans.edu[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]
- Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE
The Hacker News • 2026-09-10 04:45 • thehackernews.com
Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only “under specific conditions” that it has not described.One flaw affects Check Point’s Security Gateways, its firewall appliances. The other affects those gateways and the Security
https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html - PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances
The Hacker News • 2026-09-10 04:41 • thehackernews.com
A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances.According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from “45.142.193[.]132,” an IP address that has been linked to
https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html - Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Hacker News • 2026-09-10 04:33 • thehackernews.com
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9.A work profile is a separate space that Android typically reserves for employer apps, and what’s inside it is kept separate from everything in the personal space. That
https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html - Microsoft says September updates fix mouse settings reset issues
BleepingComputer • 2026-09-10 04:14 • www.bleepingcomputer.com
Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-resolves-mouse-settings-reset-bug-windows-11-update/ - AIs Compress Exploit Timeline
Schneier on Security • 2026-09-10 03:40 • www.schneier.comGive an AI agent a mere rumor of an exploit, and it’s enough for them to find it.
What’s worse, I found I could use my own agents to find the exploit just by knowing roughly what it was about and so could have been exploiting it well before the public patch was available! Given that just the rumour of a security issue seems enough to give attackers enough info to find new exploits, we’re going to need to change the way we deal with security responses in open source.
https://www.schneier.com/blog/archives/2026/09/ais-compress-exploit-timeline.html
- CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline
The Hacker News • 2026-09-10 03:36 • thehackernews.com
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026.The vulnerabilities are listed below –
CVE-2026-20079 (CVSS score: 10.0) – An authentication
https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html - ISC Stormcast For Thursday, September 10th, 2026 https://isc.sans.edu/podcastdetail/10088, (Thu, Sep 10th)
SANS ISC Diary (full) • 2026-09-10 03:10 • isc.sans.edu
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
https://isc.sans.edu/diary/rss/33328 - CISA: WatchGuard RCE flaw now exploited in ransomware attacks
BleepingComputer • 2026-09-10 02:10 • www.bleepingcomputer.com
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December. […]
https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.