Breaking News – Cyber Threats – 2026-09-10 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-10 13:00 PDT
- Surfshark VPN says hackers breached internal testing, proxy servers
BleepingComputer • 2026-09-10 12:15 • www.bleepingcomputer.com
Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet. […]
https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/ - Microsoft Excel KB5002914 update breaks copy and paste for some users
BleepingComputer • 2026-09-10 12:07 • www.bleepingcomputer.com
Microsoft Excel users report that this week’s KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-excel-kb5002914-update-breaks-copy-and-paste-for-some-users/ - ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories
The Hacker News • 2026-09-10 10:47 • thehackernews.com
A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?”An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already
https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html - AI-powered attack exploited PaperCut flaws to hack 395 organizations
BleepingComputer • 2026-09-10 08:55 • www.bleepingcomputer.com
A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers. […]
https://www.bleepingcomputer.com/news/security/ai-powered-attack-exploited-papercut-flaws-to-hack-395-organizations/ - Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers
BleepingComputer • 2026-09-10 08:43 • www.bleepingcomputer.com
Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks. […]
https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/ - IDScan confirms breach tied to 153 million stolen driver’s licenses
BleepingComputer • 2026-09-10 07:55 • www.bleepingcomputer.com
Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver’s license scans. […]
https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/ - Google Play Early Access Abused to Push Thousands of Deceptive Android Apps
The Hacker News • 2026-09-10 07:36 • thehackernews.com
Bad actors are misusing Google Play’s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content.Early Access apps are apps that haven’t been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their
https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html - New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws
BleepingComputer • 2026-09-10 07:11 • www.bleepingcomputer.com
Multiple cyber-espionage groups deployed an exploit kit dubbed “BlueMoon” that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome. […]
https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/ - The Top 4 Threats We Found by Investigating Every Alert for a Quarter
BleepingComputer • 2026-09-10 07:00 • www.bleepingcomputer.com
Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked. […]
https://www.bleepingcomputer.com/news/security/the-top-4-threats-we-found-by-investigating-every-alert-for-a-quarter/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.