20 Sep, 2026

Chinese hackers use SparroWocky malware in govt espionage attacks

The China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. The operations have been ongoing for more than a year, with the new malware replacing the previously used SparrowDoor custom backdoor. ESET researchers observed SparroWocky in attacks targeting organizations in Argentina, Ecuador, Guatemala, Honduras, […]

3 mins read

Microsoft shares workaround for Windows domain login issues

Microsoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. According to widespread reports from users and IT administrators on Microsoft’s Q&A forums, Reddit, and other online platforms, this bug breaks domain trust relationships on […]

3 mins read

Cisco warns of max severity ISE zero-day exploited in attacks

Cisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. Cisco ISE is a centralized policy platform that IT administrators use to manage endpoints, users, and device access to network resources, often while enforcing Zero Trust security models. The security flaw (tracked as CVE-2026-76460) […]

2 mins read

Anthropic wants Claude to analyze your bank account and financial data

Anthropic is testing a new personal finance feature called “Claude Money” that will allow you to connect your bank accounts directly to Claude and “understand your money.” AI companies coming after your finances is not a new thing, as OpenAI has a similar feature, and Anthropic appears to be catching up. As spotted by TestingCatalog on […]

2 mins read

Windows 11 KB5124008 update breaks domain trust for some users

Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. Administrators report on Reddit and Microsoft’s Q&A forums that affected computers lose their secure channel with Active Directory after the Windows 11 update is installed and […]

4 mins read

Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. The malware features data theft and espionage capabilities that collect email, Telegram, and WhatsApp communications, take screenshots, and record audio. The threat actor primarily targeted individuals in the U.S., U.K., and […]

2 mins read

Malware bypasses browser checks to force install Chrome, Edge extensions

A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. Researchers at Elastic Security Labs found that the malicious extensions bypass Chromium’s integrity mechanisms and load in browsers as if they had been approved by the user. […]

3 mins read

Spain’s data agency gets first report of AI-powered data breach

The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). The organization reporting the incident said that the AI agent searched for flaws, logged into their systems, and then probed apps for additional security issues. In the final stages […]

2 mins read

Microsoft says Copilot buttons still missing in classic Outlook

Microsoft says it’s still investigating a known issue that causes the Copilot and Copilot Chat buttons in classic Outlook to disappear for some Windows users. As it acknowledged when it announced a fix via a service change in June, this affects only customers with the Copilot Chat (Basic) license or a paid M365 Copilot (Premium) […]

2 mins read

Critical ScreenConnect flaw now actively exploited in attacks

Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). ConnectWise shared temporary mitigation measures for this missing-authorization flaw on September 7, advising security teams to disable TransferFiles permissions to block potential attacks. The vulnerability (now tracked as CVE-2026-84869 and patched in ScreenConnect 26.6.5 and […]

2 mins read