Breaking News – Cyber Threats – 2026-09-11 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-11 13:00 PDT
- Florida confirms DMV database breached via stolen police account
BleepingComputer • 2026-09-11 12:00 • www.bleepingcomputer.com
The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee. […]
https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/ - My Talk at DEF CON
Schneier on Security • 2026-09-11 11:06 • www.schneier.comLast month, I gave a talk at DEF CON on AI hacking: what happens when AIs become hackers. It’s a combination of the potentialities I raised in my 2022 book A Hacker’s Mind and the lessons we’re learning from current AI models engaging in hacking behavior. I’m really proud of the talk, and the fact that it gained over 100K views on YouTube in just a few days.
Also online is an inte…
https://www.schneier.com/blog/archives/2026/09/my-talk-at-def-con.html - Passkey-themed phishing attacks lead to Microsoft 365 data theft
BleepingComputer • 2026-09-11 10:26 • www.bleepingcomputer.com
Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services. […]
https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/ - GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
The Hacker News • 2026-09-11 09:30 • thehackernews.com
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html - Artifactory flaws chained in attacks deploying backdoor malware
BleepingComputer • 2026-09-11 09:29 • www.bleepingcomputer.com
Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. […]
https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/ - Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks
The Hacker News • 2026-09-11 09:15 • thehackernews.com
Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax.Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a “teacher” to
https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html - The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)
SANS ISC Diary (full) • 2026-09-11 07:40 • isc.sans.eduI identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the resulting inference capacity, and aggregating it behind a single gateway of their own.
- Claude Used to Automate Exploitation and Data Theft Across Multiple Victims
The Hacker News • 2026-09-11 07:29 • thehackernews.com
Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026.The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial
https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html - Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
The Hacker News • 2026-09-11 07:10 • thehackernews.com
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve.The operation has been attributed to a cyber espionage group it calls GTG-20006 (where “GTG” stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight
https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html - How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
BleepingComputer • 2026-09-11 07:01 • www.bleepingcomputer.com
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures. […]
https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.