Intelligence Feed // Live

Cyber Newsroom

Aggregated intelligence from HIPAA Journal, CISA, NIST, BleepingComputer, MIT AI, and more — categorised for LinkedIn storytelling.

Cyber Intel
CyberPulse
Cyber
Sep 9

Driver’s License Data for Sale

A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.

Schneier on Security
Read
AI
Sep 9

US says Chinese firms extracted billions of tokens from frontier AI models

U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]

BleepingComputer
Read
Cyber
Sep 9

Veradigm warns of patient data breach after ransomware gang claims attack

Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]

BleepingComputer
Read
HIPAA
Sep 9

FBI Raises Alarm About OAuth Consent Phishing Activity

The Federal Bureau of Investigation (FBI) has issued a warning about ongoing phishing activity involving a sophisticated technique known as […] The post FBI Raises Alarm About OAuth Consent Phishing Activity appeared first on The HIPAA Journal.

HIPAA Journal
Read
AI
Sep 9

Identity-Based AI Attack Threatens Security of Enterprise Data

"Workflow identity hijacking" can bypass standard security controls and hijack an organization's data by sending a basic request through an unauthenticated entry point.

Dark Reading
Read
AI
Sep 9

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.  Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API

The Hacker News
Read
Cyber
Sep 9

MFA's Weakest Link: Account Recovery Is the New Attack Path

MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service desk is critical to preventing social engineering attacks from turning account recovery into account takeover. [...]

BleepingComputer
Read
Cyber Intel
CyberPulse
Cyber
Sep 9

Claude Fable Solves a Historical Cipher

Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that involve lots of searching and testing.

Schneier on Security
Read
AI
Sep 9

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more

The Hacker News
Read
AI
Sep 9

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands inside an operating-system sandbox, so that an agent working on untrusted files cannot write outside its workspace. The agent could remove that limit by calling the tool's own web

The Hacker News
Read
Cyber
Sep 9

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet. Alby Hub is a self-hosted Lightning wallet, meaning the owner runs it on their own computer or server, and it holds their bitcoin. The flaw affects versions v1.7.0 through

The Hacker News
Read
Cyber
Sep 9

Over 36,000 exposed Plex servers vulnerable to recent flaws

Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]

BleepingComputer
Read
HIPAA
Sep 9

Wellstar Health System & Cone Health Settle Pixel Lawsuits

Settlements have been agreed to resolve class action lawsuits against Wellstar Health System and Moses H. Cone Memorial Hospital Operating […] The post Wellstar Health System & Cone Health Settle Pixel Lawsuits appeared first on The HIPAA Journal.

HIPAA Journal
Read
HIPAA
Sep 9

Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider

Two ransomware groups have claimed attacks on the home health care provider Interim Healthcare. Data breaches have been announced by […] The post Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider appeared first on The HIPAA Journal.

HIPAA Journal
Read
AI
Sep 9

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier models through distillation attacks. The activity has been described as occurring at an industrial-scale and one that forms the "core" of their AI development strategy, according to

The Hacker News
Read
Cyber
Sep 9

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome's JavaScript and WebAssembly engine. "Out-of-bounds write in V8 in Google Chrome prior to

The Hacker News
Read
Cyber Intel
CyberPulse
Cyber
Sep 9

Man gets 15 years for extorting women with AI-generated porn videos

An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]

BleepingComputer
Read
Cyber
Sep 9

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user. cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected.

The Hacker News
Read
Cyber
Sep 9

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an analysis published on September 7. When Apache loads any of the three appliances' own PHP scripts, the malware adds the web shell to the copy held in memory, so a check of the file on disk can come back clean. Those three scripts are

The Hacker News
Read
Cyber Intel
CyberPulse
Cyber
Sep 9

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [...]

BleepingComputer
Read
HIPAA
Sep 9

Boston Scientific Unlikely to Meet 2026 Sales and Profit Forecast Due to Cyberattack

It has been two weeks since a cyberattack on the Massachusetts-based medical device manufacturer Boston Scientific prevented access to critical […] The post Boston Scientific Unlikely to Meet 2026 Sales and Profit Forecast Due to Cyberattack appeared first on The HIPAA Journal.

HIPAA Journal
Read
Cyber
Sep 9

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-2026-69414 (CVSS score: 7.8), also called ShieldBreak, which the researcher reported last month. "Microsoft has failed to properly patch ShieldBreak CVE-2026-69414," Chaotic

The Hacker News
Read
Cyber Intel
CyberPulse
Cyber
Sep 9

Google warns of new Chrome zero-day bug exploited in attacks

Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]

BleepingComputer
Read
Cyber
Sep 9

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and availability of the application The vulnerability, tracked as CVE-2026-44756 (CVSS score: 10.0), has been described as a case of memory corruption. Discovered and reported by SAP

The Hacker News
Read
Cyber
Sep 9

Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days

Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Windows, 111 in Office and Office 2016, 62 in SQL, and 22 in Developer Tools. Of these, over 110 shortcomings have been assigned a critical severity rating.

The Hacker News
Read
Cyber
Sep 9

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the fixes by September 11, 2026. The vulnerability in question is CVE-2026-86218 (CVSS score: 10.0), which has been described as a

The Hacker News
Read
Cyber
Sep 9

Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults

Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. [...]

BleepingComputer
Read
Cyber
Sep 8

Patch Tuesday Sets Another Record With 974 CVEs

Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.

Dark Reading
Read
Cyber
Sep 8

Attackers Use Multi-Hop Google Redirects for Phishing Campaign

Threat actors are abusing multiple Google services to evade detection, ultimately harvesting credentials or installing ScreenConnect remote access.

Dark Reading
Read
Cyber
Sep 8

OpenAI Agents Took Over Wiki Site Before Hugging Face Attack

Researchers and OpenAI disagree on whether the earlier incident involving DseWiki was a “hack” that the company did not disclose.

Dark Reading
Read
Cyber
Sep 8

DoppelCart fraud network uses 119,000 fake shops to steal credit cards

A massive operation dubbed "DoppelCart" uses more than 119,000 domains to run a network of fake e-shops that steal payment card details. [...]

BleepingComputer
Read
Cyber
Sep 8

The EU CRA's Real Question: What Shipped, and When Did You Know?

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]

BleepingComputer
Read
Cyber
Sep 8

Hackers breach F5 BIG-IP APM devices to deploy Linux rootkit

A Linux rootkit targeting devices in F5 BIG-IP APM environments can intercept PHP file loading and inject a fileless web shell directly into memory, avoiding the need to write malicious code to disk. [...]

BleepingComputer
Read
Cyber
Sep 8

Microsoft releases Windows 10 KB5122878 extended security update

Microsoft has released the Windows 10 KB5122878 extended security update, which includes this month's record-breaking September 2026 Patch Tuesday fixes, along with a few bug fixes. [...]

BleepingComputer
Read
Cyber
Sep 8

Microsoft September 2026 Patch Tuesday fixes 966 flaws, 2 zero-days

Today is Microsoft's September 2026 Patch Tuesday, with security updates released for a record-breaking 966 flaws, including two actively exploited zero-day vulnerabilities. [...]

BleepingComputer
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

Windows 11 cumulative updates KB5124008 & KB5122880 released

Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]

BleepingComputer
Read
AI Security
CyberPulse
AI
Sep 8

AIs as Modern Genies

This essay was written with Barath Raghavan, and originally appeared in Lawfare. In April, an artificial intelligence (AI) agent conducting a routine task at a company hit a snag, tried to solve it, and soon ended up deleting the company’s database along with all of its backups. In July, OpenAI asked an unreleased AI model to attempt a hacking test. Instead of staying in the isolated box the developers had put it in, the model hacked onto the open internet and into another company to steal the answers. And as reported in August, an AI agent booked someone into a full gym class by ...

Schneier on Security
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

ClickFix Campaigns Abuse Legitimate Services for Persistent Access

Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.

Dark Reading
Read
AI Security
CyberPulse
AI
Sep 8

Stealing AI Reasoning Traces

Interesting research: “Stealing Reasoning Traces from Proprietary LLM APIs“: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which the client passes back with each subsequent request. Building on prior research, we identify an architectural vulnerability: these encrypted blocks are fully compatible and interchangeable across different sessions, users, and models within a provider’s ecosystem. We exploit this compatibility to develop a scalable decryption jailbreak. By injecting an encrypted reasoning trace from a given mode

Schneier on Security
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

ShinyHunters hackers claim breach of Florida "DAVID" DMV database

The ShinyHunters extortion gang claims it breached an online platform for the Florida Department of Motor Vehicles database known as "DAVID" and stole over 200,000 records about drivers in the state. [...]

BleepingComputer
Read
AI Security
CyberPulse
AI
Sep 8

OpenAI says ChatGPT outage causes image generation errors

OpenAI is investigating an ongoing incident causing ChatGPT image generation failures and delays when uploading files. [...]

BleepingComputer
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment

The Hacker News
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

August updates trigger 0xc0000409 errors on Windows Server 2016

Microsoft says the August 2026 security update may trigger 0xc0000409 errors on Windows Server 2016 systems where the Compatibility Appraiser diagnostic service is enabled. [...]

BleepingComputer
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

SAP warns of maximum severity 'OVERPASS' kernel vulnerability

SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]

BleepingComputer
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

Liquid Hackers Return 3,400 Bitcoin Taken via Elements Bug, Still Holding $47M in BTC

Whoever took nearly 4,000 bitcoin from the Liquid Network on Sunday, September 6, returned 3,400 of it the next day, Bitcoin's public record shows. About 598.5 bitcoin has not come back. Liquid is a Bitcoin sidechain that holds real bitcoin to back a token called L-BTC. The network is still paused, so holders cannot turn that token back into bitcoin. The 3,400 bitcoin was sent to a&

The Hacker News
Read
AI Security
CyberPulse
AI
Sep 8

OpenAI says GPT-6 Astra can find zero-days, but is also harder to monitor

OpenAI confirmed that GPT-6 Astra is the first model it has broadly deployed to reach the "Critical level" for cybersecurity capabilities. [...]

BleepingComputer
Read
AI Security
CyberPulse
AI
Sep 8

ChatGPT Flaw Let a Planted Prompt Send a Victim's Gmail Data to Another Account

Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from the user's connected Gmail account and passed it to a second ChatGPT account through a hidden channel

The Hacker News
Read
AI Security
CyberPulse
AI
Sep 8

Autonomous AI Agents Compromise Thousands of Credentials in Under Six Hours

Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Google Threat Intelligence Group (GTIG) said it has observed attackers with diverse motivations targeting proprietary AI

The Hacker News
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

Adobe fixes critical Magento zero-day exploited to backdoor servers

Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]

BleepingComputer
Read
HIPAA
CyberPulse
HIPAA
Sep 8

OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement

The Wisconsin mailing and printing vendor OneTouchPoint Corp. has agreed to settle class action litigation over a 2022 ransomware attack […] The post OneTouchPoint Agrees to Multi-Million Dollar Data Breach Settlement appeared first on The HIPAA Journal.

HIPAA Journal
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

Webinar: The forgotten Google Workspace access that can lead to a breach

Third-party applications connected to Google Workspace can retain access long after their original purpose is forgotten. This webinar examines how overly permissive integrations contribute to breaches and which security controls can help fast-growing companies reduce their exposure. [...]

BleepingComputer
Read
AI Security
CyberPulse
AI
Sep 8

Hackers build AI frameworks for widescale credential theft

Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]

BleepingComputer
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

CareCam Pro IP Cameras

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take full control of the device. The following versions of CareCam Pro IP Cameras are affected: ANJIA AJL33PC0801 Firmware linux_linux_202008261138_svn13796_/_Bootloader_U-Boot_2010.06_compiled_2020-08-26 (CVE-2026-85083) CVSS Vendor Equipment Vulnerabilities v3 6.8 CareCam CareCam Pro IP Cameras Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Commercial Facilities Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-85083 The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for bootloader authentication. An attacker with physical access to the device may leverage this weakness to gain priv

CISA Alerts
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

CISA Adds Four Known Exploited Vulnerabilities to Catalog

CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation.   CVE-2026-75650 Adobe Commerce and Magento Improper Neutralization of Special Elements Used in a Template Engine Vulnerability CVE-2026-81963 Microsoft Windows Link Following Vulnerability   CVE-2026-85880 Microsoft Windows Heap-Based Buffer Overflow Vulnerability  CVE-2026-86218 N-able N-central Static Code Injection Vulnerability  These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executi

CISA Alerts
Read
AI Security
CyberPulse
AI
Sep 8

China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies

Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation activities at an industrial scale that extract restricted proprietary functionalities and capabilities of U.S. frontier AI models. The National Security Agency (NSA), Cybersecurity and Infrastructure Security Agency (CISA), and Federal Bureau of Investigation (FBI) (hereafter referred to as the authorin

CISA Alerts
Read
Cyber
Sep 8

Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.

Dark Reading
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

Microsoft: Windows Server 2025 changes causing app crashes

Microsoft warned customers last week that they may experience application crashes on some Windows Server 2025 due to recent memory management changes. [...]

BleepingComputer
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

WeChat Zero-Click Worm Took Over Accounts on iPhone and Android via Incoming Calls

Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already be one of their WeChat contacts. Calif reported the flaw to Tencent in July and says the company has since

The Hacker News
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

What It Took to Reach 1 Billion Build Manifests

In the last six months, Chainguard doubled its output from 500 million to more than 1 billion container build manifests. We also surpassed 3,000 unique container images and 675,000 image versions in our catalog. Those are the headline numbers, but I want to share what's actually behind them. The number itself is less interesting than the system that produced it, and why we had to fundamentally

The Hacker News
Read
Cyber Intel
CyberPulse
Cyber
Sep 8

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities in a 389 Directory Server database accessed via LDAP. The attack needs a second flaw in that database software. The

The Hacker News
Read

© 2026 CyberPulse AI™. All rights reserved.

CyberPulse AI™ and the CyberPulse logo are trademarks of CyberPulse AI. All other product names, logos, and brands — including HIPAA Journal®, The Hacker News®, BleepingComputer®, NIST®, ISO®, and LinkedIn® — are property of their respective owners and used for identification purposes only.