Breaking News – Cyber Threats – 2026-09-11 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-11 08:00 PDT
- The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)
SANS ISC Diary (full) • 2026-09-11 07:40 • isc.sans.eduI identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own.
- How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
BleepingComputer • 2026-09-11 07:01 • www.bleepingcomputer.com
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. […]
https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/ - Your Critical Vulnerabilities Might Not Be Your Biggest Risk
The Hacker News • 2026-09-11 04:30 • thehackernews.com
Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise.A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker
https://thehackernews.com/2026/09/your-critical-vulnerabilities-might-not.html - GitLab urges users to patch max severity path traversal flaw
BleepingComputer • 2026-09-11 04:15 • www.bleepingcomputer.com
GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. […]
https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/ - Cliff Stoll’s DEF CON Talk
Schneier on Security • 2026-09-11 04:09 • www.schneier.comIn August, Cliff Stoll gave a talk at DEF CON, remembering the wily hacker he stalked forty years ago.
Great fun.
https://www.schneier.com/blog/archives/2026/09/cliff-stolls-def-con-talk.html
- Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs
BleepingComputer • 2026-09-11 02:39 • www.bleepingcomputer.com
Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-teams-outlook-launch-failures-on-arm-windows-pcs/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.