Latest security news
- Hackers Favor US Eastern Business Hours in M365 Phishing Campaign
- AI agents exploited PaperCut flaws to breach 395 organizations
- Most Organizations Skip Permissions Reviews Before Deploying AI Tools
- IDScan confirms breach after 153 million driver’s licenses leak on dark web
- Getting a stranger’s phone kicked off the cellular network costs a few dollars
- Companies may be measuring phishing resilience the wrong way
- AI is changing what Salesforce security needs to govern
- Ubuntu 24.04.5 LTS release patches security bugs across ten flavors
- New infosec products of the week: September 11, 2026
- CISA Updates Insider Threat Guide With New Mitigation Advice
- MantaxOtax Android Malware Combines Ransomware With Spyware
- FBI Publishes First-Ever Cyber Strategy, With Focus on Disrupting Threat Actors
- Anthropic Reveals Yet Another Cybersecurity Incident
- OFAC Sanctions Chinese Scam Platform Xinbi Guarantee
- Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
- Gigabud Uses Android App Cloning to Evade Fraud Detection
- ClickFix Moves into the Browser to Steal Cryptocurrency
- NHIs Now the Number One Corporate Entry Point for Hackers
- Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
- SAP Patches Maximum Severity “Overpass” Flaw
- France Establishes New Government-Focused Cyber Incident Response Unit
- Grindr Settles UK Data Privacy Claims for £26m
KnowBe4 researchers observed a new phishing campaign leveraging Microsoft 365’s Direct Send to send malicious emails
(C) Do-Know.com (http://do-know.com/). Do not copy without permission from info at do-know.com.