Breaking News – Cyber Threats – 2026-09-09 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-09 08:00 PDT
- Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA
The Hacker News • 2026-09-09 07:23 • thehackernews.com
Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create “stolen keys” that grant illicit access to tools from model providers like Google, Anthropic, and others.Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API
https://thehackernews.com/2026/09/infostealer-logs-expose-replayable-ai.html - MFA's Weakest Link: Account Recovery Is the New Attack Path
BleepingComputer • 2026-09-09 07:01 • www.bleepingcomputer.com
MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. […]
https://www.bleepingcomputer.com/news/security/mfas-weakest-link-account-recovery-is-the-new-attack-path/ - Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE
The Hacker News • 2026-09-09 04:57 • thehackernews.com
A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed?For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act.
As AI accelerates vulnerability discovery and research, that delay matters more
https://thehackernews.com/2026/09/webinar-learn-how-to-answer-are-we.html - DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval
The Hacker News • 2026-09-09 04:17 • thehackernews.com
A flaw in DeepSeek Harness, DeepSeek’s open-source tool for running AI coding agents on a developer’s machine, let a sandboxed agent turn off its own sandbox with a single command.The tool runs an agent’s commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool’s own web
https://thehackernews.com/2026/09/deepseek-harness-flaw-let-ai-agents.html - Claude Fable Solves a Historical Cipher
Schneier on Security • 2026-09-09 04:08 • www.schneier.comClaude Fable 5.1 solved a 370-year-old cipher in forty-four minutes.
This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.
https://www.schneier.com/blog/archives/2026/09/claude-fable-solves-a-historical-cipher.html
- Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets
The Hacker News • 2026-09-09 03:43 • thehackernews.com
Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet.Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through
https://thehackernews.com/2026/09/alby-hub-critical-flaw-could-let.html - Over 36,000 exposed Plex servers vulnerable to recent flaws
BleepingComputer • 2026-09-09 03:11 • www.bleepingcomputer.com
Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. […]
https://www.bleepingcomputer.com/news/security/over-36-000-plex-servers-unpatched-against-recently-disclosed-flaws/ - U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok
The Hacker News • 2026-09-09 02:32 • thehackernews.com
U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting “systematic extraction” of proprietary functionalities and capabilities of American frontier models through distillation attacks.The activity has been described as occurring at an industrial-scale and one that forms the “core” of their AI development strategy, according to
https://thehackernews.com/2026/09/us-agencies-accuse-china-ai-firms-of.html - Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox
The Hacker News • 2026-09-09 02:11 • thehackernews.com
Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild.The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome’s JavaScript and WebAssembly engine.
“Out-of-bounds write in V8 in Google Chrome prior to
https://thehackernews.com/2026/09/chrome-v8-zero-day-exploited-in-wild.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.