Latest security news
- CISA Upgrades Vulnerability Reporting Platform with More Automation
- Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
- Android apps can now check security patches down to individual device components
- Manufacturing Accounts for 22% of all Ransomware Victims
- Abandoned IoT apps keep sending sensitive data to broken servers
- Hardcoded MCP credentials found in public GitHub files
- 98% of fraudulent hires have company credentials by the time they’re caught
- Most WordPress pros still lack a breach recovery plan
- New infosec products of the week: September 18, 2026
- FamousSparrow Swaps SparrowDoor For New SparroWocky Backdoor
- CISA Urges Critical Infrastructure to Plant Decoys Inside Networks
- Iranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAE
- A fake ChatGPT billing email is after your OpenAI password
- New Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial Data
- Cyber Essentials Has Record Year but Takeup Remains Low
- Cisco Warns of Active Exploitation of Critical ISE Flaw
- AI Agent Carries Out Multi-Stage Data Theft Attack
- PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug
- CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
- Cyber-Attacks Cost Organizations $52,000 on Average
- Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
- Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
- NCSC and Allies Warn of Iranian Spyware Campaign
- Most Fraudulent Hires Receive Credentials Before Detection
The US cybersecurity agency is moving to a new vulnerability coordination platform called VINCE-NT
(C) Do-Know.com (http://do-know.com/). Do not copy without permission from info at do-know.com.