πŸ” Search
Sign in to post
The domestic armed threat facing Iranhttps://www.aljazeera.com/news/2026/9/7/the-domestic-armed-threat-facing-iran

External support for ethnic armed groups poses an escalating security threat to Iran, experts and state officials warn.

β†—
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Executionhttps://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium's own Secure Preferences

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attackshttps://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff

⚑ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and Morehttps://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on. Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management

Your Cloud Security Checklist Doesn't Work the Way You Think It Doeshttps://thehackernews.com/2026/09/your-cloud-security-checklist-doesnt.html

If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud Security Index, Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud and found that risk profiles across providers have almost nothing in common. Here’s what the data looks like. How risk differs across cloud providers

Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hostshttps://thehackernews.com/2026/09/rogue-screenconnect-clients-spread-four.html

Cybersecurity researchers have disclosed details of worm-like activity that abuses ConnectWise ScreenConnect to distribute a malicious Visual Basic Script (VBScript) payload to newly connected systems. According to Huntress, three unrelated incidents have been found to use diverse initial access methods, namely a Quick Assist tech-support scam, a phishing-delivered MSI installer, and a fake

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE β€” Public Exploit Releasedhttps://thehackernews.com/2026/09/telerik-ui-padding-oracle-bug-chained.html

A TantoSec proof-of-concept turns an AES-CBC "padding oracle" in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution β€” but only against applications in a specific non-default configuration, and Progress patched the chain in July. There are no confirmed reports of exploitation in the wild. Security firm TantoSec has published a working exploit chain targeting vulnerabilities

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flawhttps://thehackernews.com/2026/09/n-able-issues-fourth-n-central-hotfix.html

Every on-premises N-central build below 2026.3.1.14 β€” including servers updated to Hotfix 3 a day earlier β€” needs Hotfix 4. N-able's incident notice says the flaw has been exploited in the wild; its release notes say that is unconfirmed. N-able has released itsΒ fourth hotfixΒ in five weeks for the N-central remote monitoring and management (RMM) platform, this time for a

JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookieshttps://thehackernews.com/2026/09/jsceal-malware-can-bypass-google.html

Cybersecurity researchers have unpacked JSCeal, a sophisticated compiled V8 JavaScript (JSC) malware with credential harvesting, surveillance, and traffic-interception capabilities. "The payloads are protected with javascript-obfuscator, using multiple techniques including RC4-protected strings, control-flow flattening, proxy functions, and operation wrappers," Check Point Research said in a

0trust.social media

Loading your media...

Pick a GIF β€” Giphy

Loading GIFs...