Search the Portal

Recent Articles

SEP10
Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example "sk-1234" Admin Key

Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every

The Hacker News by info@thehackernews.com (The Hacker News)
SEP10
New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

The exploit provides full System privileges on Windows machines running the September 2026 patches. The post New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender appeared first on SecurityWeek.

Security Week by Ionut Arghire
SEP10
Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached "

The Hacker News by info@thehackernews.com (The Hacker News)
SEP10
Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks

The high-severity, unauthenticated vulnerability tracked as CVE-2025-25249 was patched in January 2026. The post Fortinet Code Execution Flaw Exploited in PivotC2 RAT Attacks appeared first on SecurityWeek.

Security Week by Ionut Arghire
SEP9
U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime

The Hacker News by info@thehackernews.com (The Hacker News)
SEP9
HelmGuard Raises $7.3 Million for Agentic GRC and Security

The company will increase its US market presence and will expand its engineering and go-to-market teams. The post HelmGuard Raises $7.3 Million for Agentic GRC and Security appeared first on SecurityWeek.

Security Week by Ionut Arghire
SEP9
AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG. The post AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns appeared first on SecurityWeek.

Security Week by Kevin Townsend
SEP9
Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wild use of BlueMoon has been attributed to the China-aligned state-sponsored group tracked as APT31 (aka Bronze Vinewood, Judgement Panda, JungleBamboo,

The Hacker News by info@thehackernews.com (The Hacker News)
SEP9
Android’s September 2026 Updates Patch 180 Vulnerabilities

The security updates resolve critical flaws across Android’s Framework, System, and Kernel components. The post Android’s September 2026 Updates Patch 180 Vulnerabilities appeared first on SecurityWeek.

Security Week by Ionut Arghire
SEP9
Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories

Major chipmakers announced patches for vulnerabilities recently discovered in their products. The post Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories appeared first on SecurityWeek.

Security Week by Ionut Arghire
SEP9
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension

The critical, unauthenticated bugs allow attackers to bypass authentication and proxy a user’s browser traffic. The post Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension appeared first on SecurityWeek.

Security Week by Ionut Arghire
SEP9
Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers like Lumma Stealer or Vidar are equipped to harvest a wide range of data from compromised systems. This can include credential, session tokens, and API

The Hacker News by info@thehackernews.com (The Hacker News)
SEP9
US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model. The post US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities appeared first on SecurityWeek.

Security Week by Kevin Townsend
SEP9
Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy

Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data. The post Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy appeared first on SecurityWeek.

Security Week by Associated Press
SEP9
Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint tools, cloud inventories, SBOMs, repositories, and application data to build enough context to act. As AI accelerates vulnerability discovery and research, that delay matters more

The Hacker News by info@thehackernews.com (The Hacker News)