Security News
Latest Updates

Stay informed with the latest security trends and insights...

Latest Articles

Explore the most recent articles on security topics.

1. Security News – 2026-09-01

Tue Sep 01 2026 00:00:00 GMT+0000 (Coordinated Universal Time)

SecurityWeek

Latest cybersecurity news

9.5 Million Impacted by Aesto Health Data Breach - September 01, 2026

Hackers stole personal and health information from the healthcare technology company’s AWS infrastructure.

The post 9.5 Million Impacted by Aesto Health Data Breach appeared first on SecurityWeek.

WatchGuard Patches Critical Vulnerabilities - September 01, 2026

Three critical issues in the Fireware OS iked process could allow unauthenticated attackers to execute arbitrary code remotely.

The post WatchGuard Patches Critical Vulnerabilities appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity - September 01, 2026

Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck.

The vulnerabilities in question are listed below -

CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the context of the root user. CVE-2026-66066 aka

SecurityWeek

Latest cybersecurity news

PaperCut Exploitation Escalates to Active Intrusions - September 01, 2026

CISA has added the vulnerabilities tracked as CVE-2026-82078 and CVE-2026-81578 to its KEV catalog.

The post PaperCut Exploitation Escalates to Active Intrusions appeared first on SecurityWeek.

Schneier on Security

Security news and analysis by Bruce Schneier

Is Someone Hacking DoD Refrigerators? - August 31, 2026

It sure seems like it.

The stores confirmed to be affected include Fort Irwin, Calif.; F.E. Warren Air Force Base, Wyo.; Fort Huachuca, Ariz.; Naval Station Newport, R.I.; Columbus Air Force Base, Miss.; and Travis Air Force Base, Calif., according to announcements made online by each installation.

Naval Air Station Lemoore, Calif., also experienced an outage, according to M. Elizabeth, writer of the Substack newsletter Signal and Silence.

Each service declined to answer questions about how many bases are affected by the outages, referring all questions to the Defense Department. Pentagon officials did not respond to questions...

SecurityWeek

Latest cybersecurity news

Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit - August 31, 2026

Kaspersky told SecurityWeek that it patched the vulnerability affecting its Endpoint Security product.

The post Nightmare Eclipse Drops ‘HardBreacher’ Kaspersky Product Exploit appeared first on SecurityWeek.

ServiceNow Patches 3 Critical Code Injection Vulnerabilities - August 31, 2026

Attackers could exploit the security defects to execute arbitrary code and access or tamper with data.

The post ServiceNow Patches 3 Critical Code Injection Vulnerabilities appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and More - August 31, 2026

The boring parts caused most of the trouble.

A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional.

Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept

SecurityWeek

Latest cybersecurity news

McKesson Confirms Data Breach as Attacker Deadline Looms - August 31, 2026

The ShinyHunters extortion group has claimed the theft of 284 million records from the company’s systems.

The post McKesson Confirms Data Breach as Attacker Deadline Looms appeared first on SecurityWeek.

What the Hugging Face Incident Teaches Security Leaders About AI Agent Access - August 31, 2026

Security teams must treat autonomous agents as highly privileged identities.

The post What the Hugging Face Incident Teaches Security Leaders About AI Agent Access appeared first on SecurityWeek.

Anthropic Warns Claude Users of Infostealer Malware Infections - August 31, 2026

The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.

The post Anthropic Warns Claude Users of Infostealer Malware Infections appeared first on SecurityWeek.

The Hacker News

Cybersecurity news and insights

Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance - August 31, 2026

Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate.

AI has moved from the browser tab to the

SecurityWeek

Latest cybersecurity news

Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs - August 31, 2026

Named KindaRails2Shell, the arbitrary file read flaw allows attackers to extract secrets and execute arbitrary code remotely.

The post Critical Ruby on Rails Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.

View All Security News

Upcoming Events

Check out the upcoming security conferences and webinars.

Security Tools

Discover the latest tools and resources for enhancing security.