IT News Analysis

// AI-powered news analysis

Latest Top 10 Articles

1
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN . Elastic Security Labs is tracking the activity under the moniker REF9334 . Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and Microsoft Edge. "The KREMLIN malware ecosystem employs multi-stage JavaScript loaders, custom C++ installers, and malicious browser extensions to steal credentials, session tokens, and sensitive data," security researchers Cyril François and Andrew Pease said in a technical report shared with The Hacker News. "Malicious browser extensions bypass Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs, and App-Bound encrypted hashes." A defining aspect of the operation is the use of blockchain to conceal the threat actor-controlled...

Sep 15, 2026
2
AI Security's Greatest Hits

AI Security's Greatest Hits

Get 7 of the most widely used AI security resources in one pack. Each asset provides practical tools for securing AI apps, models, and agents.

3
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record audio. The FBI calls it HEAVYGRAM , and the U.K.'s National Cyber Security Center (NCSC) calls it CHOSEN BRICK . The  joint advisory  was published on September 15 by the NCSC , the FBI, and the Netherlands' intelligence service, the AIVD. The FBI also released an  updated analysis  of the malware that expands on a  March 2026 alert , the first to describe the campaign, with more technical detail and new indicators of compromise. The FBI attributes the malware to Iran's Ministry of Intelligence and Security (MOIS), the country's main intelligence agency, and dates th...

Sep 15, 2026
4
BambooToken Malware Uses MQTT to Control Windows and Linux Systems

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport ( MQTT ) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken , is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America. Activity linked to the malware has been detected as recently as July 2026. Lumen Black Lotus Labs said it discovered the previously undocumented malware on VirusTotal in early 2026, with evidence pointing to a skilled threat actor that has managed to stay undetected until now. The initial access vector used to deliver BambooToken remains undetermined. "The actor used Tendyron's 'OnKey' software to sideload agents into targeted machines," Black Lotus Labs said in a report shared with The Hacker News. "Tendyron creates hardware-based tokens employed in high-se...

Sep 15, 2026
5
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH bastion host in eight seconds using a custom Python toolkit they "wrote and debugged by hand" without any AI agent in the loop. "Eight seconds is the kind of speed we expect to see in AI-assisted attacks," the Sysdig Threat Research Team said . "This operator got there on skill alone, and along the way walked straight past a trap that every agentic threat actor (ATA) we've profiled against this same CVE fell into. Not only can skilled human attackers move at machine speed, but they can also often better evade defenders' detections." The attack chain ha...

Sep 15, 2026
6
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise. But no matter how much you validate against these exposures, it doesn't fix the main problem the industry is facing: these are isolated, disconnected testing.  And real attackers, increasingly AI Powered ones, don't test techniques one at a time. They chain them. A phishing email leads to a credential harvest. That harvest leads to an initial foothold. The foothold leads to privilege escalation, then lateral movement, then data staging, then exfiltration… until the damage is irreversibly done.  Any one of those individual steps might be something a security control is theoretically capable of catching - but there's just too many po...

Sep 15, 2026
8
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that's designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs . The credential harvesting activity, observed in August 2026, has been found to leverage an exploit for CVE-2026-39364 (CVSS score: 8.2), a high-severity security flaw in Vite that could permit an unauthenticated attacker to bypass security restrictions via query parameter manipulation and leak sensitive data, including files specified by server.fs.deny. "On the Vite dev server, files that should be blocked by server.fs.deny (e.g., .env, *.crt) can be retrieved with HTTP 200 responses when query parameters such as ?raw, ?import&raw, or ?import&url&inline are appended," Vite s...

Sep 15, 2026
9
LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an  advisory published on September 14 . On such servers, many customers' sites run on a single machine, and an attacker with one of those hosting accounts could exploit the flaw to access or alter other sites and the server itself, according to the advisory. cPanel said it had received notice of the flaw, which affects versions before 6.3.7, and urged administrators to update to that release, which LiteSpeed  published on September 11 . The flaw can bypass the controls that keep hosting accounts apart, including  CageFS , cPanel said. CageFS is a CloudLinux tool that gives each hosting account a restricted view of the file system, so it cannot see other accounts or the server's configuration files. Neither cPanel's advisory nor LiteSpeed's release notes describe how the flaw works. LiteSpeed's an...

Sep 15, 2026
10
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461 , carries a CVSS score of 9.8 out of a maximum of 10.0. It has been described as a case of insufficient validation in the email parsing logic that could allow an unauthenticated, remote attacker to run arbitrary commands with root privileges on the underlying operating system. "An attacker could exploit this vulnerability by sending a crafted email message that contains malicious SQL statements through an affected device," Cisco said in a Monday advisory. "A successful exploit could allow the attacker to execute arbitrary SQL statements, leading to command execution with root privileges on the underlying operating system." The shortcoming affects Cisco Secure Email Gateway, both physical and virtual, regardless of device configuration. However, the networkin...

Sep 15, 2026

Get a summary by Chaplin or Kilmister Get a summary