Breaking News – Cyber Threats – 2026-09-17 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-17 08:00 PDT
- LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)
SANS ISC Diary (full) • 2026-09-17 07:54 • isc.sans.eduAt the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company.
- What Recent AI-Powered Attacks Mean for Your Identity Security
BleepingComputer • 2026-09-17 07:01 • www.bleepingcomputer.com
AI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted. […]
https://www.bleepingcomputer.com/news/security/what-recent-ai-powered-attacks-mean-for-your-identity-security/ - Windows 11 24H2 Home and Pro reach end of support in October
BleepingComputer • 2026-09-17 06:09 • www.bleepingcomputer.com
Microsoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. […]
https://www.bleepingcomputer.com/news/microsoft/windows-11-24h2-home-and-pro-reach-end-of-support-in-october/ - The Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrents
Securelist • 2026-09-17 06:00 • securelist.com
Kaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as “The Odyssey,” and uses the Solana blockchain to hide its C2 infrastructure.
https://securelist.com/moviereaper-malware-torrent-odyssey-solana/121344/ - Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
The Hacker News • 2026-09-17 05:30 • thehackernews.com
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday.An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code execution.
Unbound 1.26.1, released the same day, fixes the bug, tracked as CVE-2026-81642, along with
https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html - Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
The Hacker News • 2026-09-17 04:50 • thehackernews.com
A new CVE drops. Your scanner finds it. The severity score looks ugly.But that still does not answer the question that matters: Can it actually be exploited in your environment?
Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is
https://thehackernews.com/2026/09/can-you-prove-new-cve-is-exploitable.html - US takes down NightmareStresser DDoS-for-hire platform
BleepingComputer • 2026-09-17 04:33 • www.bleepingcomputer.com
The U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world’s longest-running distributed denial-of-service (DDoS) platforms. […]
https://www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-thousands-of-ddos-attacks/ - How Candidates Could Use AI for Good
Schneier on Security • 2026-09-17 04:06 • www.schneier.comThis essay was written with Nathan E. Sanders, and originally appeared in The Guardian.
There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to https://www.schneier.com/blog/archives/2026/09/how-candidates-could-use-ai-for-good.html
- CISO's Expert Guide to Agentic Pentesting for Websites
The Hacker News • 2026-09-17 03:50 • thehackernews.com
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand before pointing one at production.TL;DR
Exploitation is now the front door. It starts 31% of breaches (Verizon DBIR
https://thehackernews.com/2026/09/cisos-expert-guide-to-agentic.html - China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
The Hacker News • 2026-09-17 03:05 • thehackernews.com
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025.“SparroWocky is a modular, C++ backdoor,” ESET security researchers Alexandre Côté Cyr and Romain Dumont said in a technical report shared with The Hacker News
https://thehackernews.com/2026/09/china-aligned-famoussparrow-deploys.html - OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
The Hacker News • 2026-09-17 02:53 • thehackernews.com
OpenAI on Wednesday disclosed six new instances of “unexpected or concerning model behavior” that took place over the past six months, while sharing a new framework for reporting, tracking, investigating, and disclosing model misalignment in a bid to improve transparency.“As AI systems grow more advanced and more widely deployed, we need to build a broader and better-informed consensus on the
https://thehackernews.com/2026/09/openai-reveals-six-model-incidents.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.