{
  "version": "https://jsonfeed.org/version/1.1",
  "title": "Security news",
  "home_page_url": "https://krebsonsecurity.com/feed/",
  "description": "Events collected by UnlimitedPipe 0.3.2",
  "_unlimitedpipe": {
    "schema": "unlimitedpipe.event/1",
    "generator": "UnlimitedPipe 0.3.2"
  },
  "items": [
    {
      "id": "094391b406d1f02caeb8",
      "title": "U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions",
      "content_text": "A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.",
      "date_published": "2026-09-25T21:44:40Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "094391b406d1f02caeb8",
          "source": "rss",
          "type": "change",
          "key": "https://krebsonsecurity.com/?p=74335",
          "source_url": "https://krebsonsecurity.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T23:10:21Z",
          "data": {
            "change": "added",
            "label": "U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions",
            "item_type": "entry",
            "summary": "added: U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions",
            "after": {
              "title": "U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions",
              "link": "https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/",
              "id": "https://krebsonsecurity.com/?p=74335",
              "author": "BrianKrebs",
              "published_at": "2026-09-25T21:44:40Z",
              "updated_at": "2026-09-25T21:44:40Z",
              "summary": "A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.",
              "categories": [
                "DDoS-for-Hire",
                "Ne'er-Do-Well News",
                "Ransomware",
                "AT&T",
                "Bureau of Prisons",
                "Cameron John Wagenius",
                "Connor Riley Moucka",
                "CVE-2023-45208",
                "Defense Criminal Investigative Service",
                "Judische",
                "Kenneth Schuchman",
                "Kiberphant0m",
                "Paul Russell",
                "Verizon"
              ],
              "feed": {
                "title": "Krebs on Security",
                "url": "https://krebsonsecurity.com",
                "feed_url": "https://krebsonsecurity.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://krebsonsecurity.com/feed/",
            "elapsed_ms": 153,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/",
      "tags": [
        "DDoS-for-Hire",
        "Ne'er-Do-Well News",
        "Ransomware",
        "AT&T",
        "Bureau of Prisons",
        "Cameron John Wagenius",
        "Connor Riley Moucka",
        "CVE-2023-45208",
        "Defense Criminal Investigative Service",
        "Judische",
        "Kenneth Schuchman",
        "Kiberphant0m",
        "Paul Russell",
        "Verizon"
      ]
    },
    {
      "id": "01ffce2f4b7070d816e8",
      "title": "Kiteworks urges 6-hour server shutdown over potential zero-day attacks",
      "content_text": "Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. [...]",
      "date_published": "2026-09-25T21:41:07Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "01ffce2f4b7070d816e8",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T23:10:21Z",
          "data": {
            "change": "added",
            "label": "Kiteworks urges 6-hour server shutdown over potential zero-day attacks",
            "item_type": "entry",
            "summary": "added: Kiteworks urges 6-hour server shutdown over potential zero-day attacks",
            "after": {
              "title": "Kiteworks urges 6-hour server shutdown over potential zero-day attacks",
              "link": "https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/",
              "id": "https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/",
              "author": "Lawrence Abrams",
              "published_at": "2026-09-25T21:41:07Z",
              "updated_at": "2026-09-25T21:41:07Z",
              "summary": "Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 94,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "1cf918086649b1ccb3cd",
      "title": "Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee",
      "content_text": "I feel like someone who reads this blog will want to go to this :\nFamilies are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life.\n[…]\nDuring the guided squid dissection, each family will work together to examine a squid up…",
      "date_published": "2026-09-25T21:08:14Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "1cf918086649b1ccb3cd",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72684",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-25T23:10:21Z",
          "data": {
            "change": "added",
            "label": "Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee",
            "item_type": "entry",
            "summary": "added: Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee",
            "after": {
              "title": "Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee",
              "link": "https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-participatory-squid-dissection-in-october-in-tennessee.html",
              "id": "https://www.schneier.com/?p=72684",
              "author": "Bruce Schneier",
              "published_at": "2026-09-25T21:08:14Z",
              "updated_at": "2026-09-25T21:08:35Z",
              "summary": "I feel like someone who reads this blog will want to go to this :\nFamilies are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life.\n[…]\nDuring the guided squid dissection, each family will work together to examine a squid up close, exploring its organs, structures, and specialized features. The experience provides a memorable opportunity for children and adults to see firsthand how the anatomy of a squid helps it survive in its underwater environment...",
              "categories": [
                "Uncategorized",
                "squid"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 59,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-participatory-squid-dissection-in-october-in-tennessee.html",
      "tags": [
        "Uncategorized",
        "squid"
      ]
    },
    {
      "id": "de80708e5218b5f561a6",
      "title": "ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw",
      "content_text": "The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]",
      "date_published": "2026-09-25T20:57:55Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "de80708e5218b5f561a6",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T23:10:21Z",
          "data": {
            "change": "added",
            "label": "ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw",
            "item_type": "entry",
            "summary": "added: ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw",
            "after": {
              "title": "ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw",
              "link": "https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/",
              "id": "https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/",
              "author": "Lawrence Abrams",
              "published_at": "2026-09-25T20:57:55Z",
              "updated_at": "2026-09-25T20:57:55Z",
              "summary": "The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 94,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "d26fd42694cde41a7f60",
      "title": "Elementor WordPress flaw lets attackers create admin accounts",
      "content_text": "A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]",
      "date_published": "2026-09-25T18:13:33Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "d26fd42694cde41a7f60",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T20:48:28Z",
          "data": {
            "change": "added",
            "label": "Elementor WordPress flaw lets attackers create admin accounts",
            "item_type": "entry",
            "summary": "added: Elementor WordPress flaw lets attackers create admin accounts",
            "after": {
              "title": "Elementor WordPress flaw lets attackers create admin accounts",
              "link": "https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/",
              "id": "https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/",
              "author": "Bill Toulas",
              "published_at": "2026-09-25T18:13:33Z",
              "updated_at": "2026-09-25T18:13:33Z",
              "summary": "A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 47,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "921fc620f7626ce73cef",
      "title": "CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks",
      "content_text": "The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...]",
      "date_published": "2026-09-25T17:24:20Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "921fc620f7626ce73cef",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T17:36:48Z",
          "data": {
            "change": "added",
            "label": "CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks",
            "item_type": "entry",
            "summary": "added: CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks",
            "after": {
              "title": "CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks",
              "link": "https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/",
              "id": "https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/",
              "author": "Bill Toulas",
              "published_at": "2026-09-25T17:24:20Z",
              "updated_at": "2026-09-25T17:24:20Z",
              "summary": "The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 111,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "da905e80e074a602e838",
      "title": "Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions",
      "content_text": "Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. [...]",
      "date_published": "2026-09-25T16:00:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "da905e80e074a602e838",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-rolls-out-up-to-250-in-free-claude-code-credits-but-only-for-cloud-sessions/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T17:36:48Z",
          "data": {
            "change": "added",
            "label": "Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions",
            "item_type": "entry",
            "summary": "added: Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions",
            "after": {
              "title": "Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions",
              "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-rolls-out-up-to-250-in-free-claude-code-credits-but-only-for-cloud-sessions/",
              "id": "https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-rolls-out-up-to-250-in-free-claude-code-credits-but-only-for-cloud-sessions/",
              "author": "Mayank Parmar",
              "published_at": "2026-09-25T16:00:00Z",
              "updated_at": "2026-09-25T16:00:00Z",
              "summary": "Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. [...]",
              "categories": [
                "Artificial Intelligence",
                "Technology"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 111,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-rolls-out-up-to-250-in-free-claude-code-credits-but-only-for-cloud-sessions/",
      "tags": [
        "Artificial Intelligence",
        "Technology"
      ]
    },
    {
      "id": "f903264c128d29e8cd18",
      "title": "OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex",
      "content_text": "OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]",
      "date_published": "2026-09-25T14:54:33Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "f903264c128d29e8cd18",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-a-500-chatgpt-pro-max-plan-with-faster-codex/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T17:36:48Z",
          "data": {
            "change": "added",
            "label": "OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex",
            "item_type": "entry",
            "summary": "added: OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex",
            "after": {
              "title": "OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex",
              "link": "https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-a-500-chatgpt-pro-max-plan-with-faster-codex/",
              "id": "https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-a-500-chatgpt-pro-max-plan-with-faster-codex/",
              "author": "Mayank Parmar",
              "published_at": "2026-09-25T14:54:33Z",
              "updated_at": "2026-09-25T14:54:33Z",
              "summary": "OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]",
              "categories": [
                "Artificial Intelligence",
                "Technology"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 111,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-a-500-chatgpt-pro-max-plan-with-faster-codex/",
      "tags": [
        "Artificial Intelligence",
        "Technology"
      ]
    },
    {
      "id": "490161c416be9bed78c2",
      "title": "With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance",
      "content_text": "AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. [...]",
      "date_published": "2026-09-25T14:51:10Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "490161c416be9bed78c2",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T17:36:48Z",
          "data": {
            "change": "added",
            "label": "With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance",
            "item_type": "entry",
            "summary": "added: With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance",
            "after": {
              "title": "With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance",
              "link": "https://www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/",
              "id": "https://www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/",
              "author": "Sponsored by Token Security",
              "published_at": "2026-09-25T14:51:10Z",
              "updated_at": "2026-09-25T14:51:10Z",
              "summary": "AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 111,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "942d0346b4630694e3d1",
      "title": "Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware",
      "content_text": "Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign.\nThe affected GitHub Actions are listed below -\nactions-cool/issues-helper\nactions-cool/maintain-one-comment\nVisiting either of the repositories now shows the message: \"Access to this",
      "date_published": "2026-09-25T14:44:41Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "942d0346b4630694e3d1",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/compromised-github-actions-came-back.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-25T17:36:48Z",
          "data": {
            "change": "added",
            "label": "Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware",
            "item_type": "entry",
            "summary": "added: Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware",
            "after": {
              "title": "Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware",
              "link": "https://thehackernews.com/2026/09/compromised-github-actions-came-back.html",
              "id": "https://thehackernews.com/2026/09/compromised-github-actions-came-back.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-25T14:44:41Z",
              "updated_at": "2026-09-25T14:44:41Z",
              "summary": "Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign.\nThe affected GitHub Actions are listed below -\nactions-cool/issues-helper\nactions-cool/maintain-one-comment\nVisiting either of the repositories now shows the message: \"Access to this",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJFMIQ6v0uJDRoxyIhqsoqsYoXN00dcDH4IvkdQAkRBRj6ha5LIu2-2yzzvQk1OZTc-7tK1fjeqyIh8xvRNvz_CotOtGNsYnejlbHED7cI-bmZFP80JIdxk_0D9I6Zo10-6b4x4euCTaRtz8c6ncYKykDsW7Bt4oFEVYWTe3AHJdiUxM32R6hGP9C0Y0Xf/s1600/github-shai.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 220,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/compromised-github-actions-came-back.html"
    },
    {
      "id": "b09c72148b9e7ddf20c5",
      "title": "PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence",
      "content_text": "Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.\nThe latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.\n\"Where earlier variants embedded their payload key material",
      "date_published": "2026-09-25T13:18:06Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b09c72148b9e7ddf20c5",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-25T17:36:48Z",
          "data": {
            "change": "added",
            "label": "PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence",
            "item_type": "entry",
            "summary": "added: PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence",
            "after": {
              "title": "PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence",
              "link": "https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html",
              "id": "https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-25T13:18:06Z",
              "updated_at": "2026-09-25T13:18:06Z",
              "summary": "Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain.\nThe latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method.\n\"Where earlier variants embedded their payload key material",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiRZ3gQjU3cKnH6bHzlz8PjeaUqGcrVWnRx-bT-mgDBYv-G4CM2Iix8afTJe8sAXEghuPTiD5KszOYzA0peRhyoGKNW9YE1QtwLubBFuv9YZjXnANEGyMGwi7-oEdIqmtRBWPzUZV7S91WiUX4cI2YVMHVSQbByCmIwAX9oZxvzjb2ScVJmpmMCzpDKaKtN/s1600/macos.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 220,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/pamstealer-macos-malware-adds-live-c2.html"
    },
    {
      "id": "5f5fb392e3a68a87893c",
      "title": "Microsoft plans to deprecate Windows Deployment Services",
      "content_text": "Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. [...]",
      "date_published": "2026-09-25T12:40:59Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "5f5fb392e3a68a87893c",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/microsoft/microsoft-to-deprecate-windows-deployment-services-after-windows-server-2025/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T17:36:48Z",
          "data": {
            "change": "added",
            "label": "Microsoft plans to deprecate Windows Deployment Services",
            "item_type": "entry",
            "summary": "added: Microsoft plans to deprecate Windows Deployment Services",
            "after": {
              "title": "Microsoft plans to deprecate Windows Deployment Services",
              "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-to-deprecate-windows-deployment-services-after-windows-server-2025/",
              "id": "https://www.bleepingcomputer.com/news/microsoft/microsoft-to-deprecate-windows-deployment-services-after-windows-server-2025/",
              "author": "Sergiu Gatlan",
              "published_at": "2026-09-25T12:40:59Z",
              "updated_at": "2026-09-25T12:40:59Z",
              "summary": "Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. [...]",
              "categories": [
                "Microsoft"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 111,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-to-deprecate-windows-deployment-services-after-windows-server-2025/",
      "tags": [
        "Microsoft"
      ]
    },
    {
      "id": "dc3ccce438cec1395772",
      "title": "The SOC Doesn't Need to Start Over with Every Alert",
      "content_text": "Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry.\nThe routine version looks like this. An attacker lands on a low-privilege cloud account, and the first try at privilege escalation goes nowhere. That dead end used to cost hours of documentation reading,",
      "date_published": "2026-09-25T11:30:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "dc3ccce438cec1395772",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/the-soc-doesnt-need-to-start-over-with.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-25T17:36:48Z",
          "data": {
            "change": "added",
            "label": "The SOC Doesn't Need to Start Over with Every Alert",
            "item_type": "entry",
            "summary": "added: The SOC Doesn't Need to Start Over with Every Alert",
            "after": {
              "title": "The SOC Doesn't Need to Start Over with Every Alert",
              "link": "https://thehackernews.com/2026/09/the-soc-doesnt-need-to-start-over-with.html",
              "id": "https://thehackernews.com/2026/09/the-soc-doesnt-need-to-start-over-with.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-25T11:30:00Z",
              "updated_at": "2026-09-25T11:30:00Z",
              "summary": "Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry.\nThe routine version looks like this. An attacker lands on a low-privilege cloud account, and the first try at privilege escalation goes nowhere. That dead end used to cost hours of documentation reading,",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0sz5D5hiSWYuUfbRDYDloMNzbx5dpvVQjC5ZVoYzIgvWL_Tkyx8AjNHjZ27RAwaPbCIQXNWB6o_FYzxjimFYHY2pHfp6m6b97tARxhdhqSHBkp2lYpfekwVLvUIm63ruwsHR7RlQkR-2jfOPELG2hjZrrYr9JYr4ndSfVaYIajhTpmB6Ud0DIXz1D_uI/s1600/soc-1.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 220,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/the-soc-doesnt-need-to-start-over-with.html"
    },
    {
      "id": "6a56391c4f4bcd021106",
      "title": "Rydox marketplace admin pleads guilty, faces 22 years in prison",
      "content_text": "A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]",
      "date_published": "2026-09-25T11:35:14Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "6a56391c4f4bcd021106",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T12:22:59Z",
          "data": {
            "change": "added",
            "label": "Rydox marketplace admin pleads guilty, faces 22 years in prison",
            "item_type": "entry",
            "summary": "added: Rydox marketplace admin pleads guilty, faces 22 years in prison",
            "after": {
              "title": "Rydox marketplace admin pleads guilty, faces 22 years in prison",
              "link": "https://www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/",
              "id": "https://www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/",
              "author": "Sergiu Gatlan",
              "published_at": "2026-09-25T11:35:14Z",
              "updated_at": "2026-09-25T11:35:14Z",
              "summary": "A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 139,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/rydox-marketplace-admin-pleads-guilty-faces-22-years-in-prison/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "16c240c5bb6e798f73b7",
      "title": "On Anthropic’s AI Misuse Report",
      "content_text": "Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.\nA few of the highlights:\nAI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs.\nThe report describes attackers using AI to industrialize credential theft, cloud compromise…",
      "date_published": "2026-09-25T11:07:22Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "16c240c5bb6e798f73b7",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72678",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-25T12:22:59Z",
          "data": {
            "change": "added",
            "label": "On Anthropic’s AI Misuse Report",
            "item_type": "entry",
            "summary": "added: On Anthropic’s AI Misuse Report",
            "after": {
              "title": "On Anthropic’s AI Misuse Report",
              "link": "https://www.schneier.com/blog/archives/2026/09/on-anthropics-ai-misuse-report.html",
              "id": "https://www.schneier.com/?p=72678",
              "author": "Bruce Schneier",
              "published_at": "2026-09-25T11:07:22Z",
              "updated_at": "2026-09-25T11:07:55Z",
              "summary": "Earlier this month, Anthropic published a long report detailing all of the Claude misuses it detected. Daniel Meissler usefully summarized the report into 117 findings.\nA few of the highlights:\nAI agents increasingly handled reconnaissance, exploitation, data theft, propaganda production, surveillance workflows, and research while humans selected targets, set goals, and reviewed important outputs.\nThe report describes attackers using AI to industrialize credential theft, cloud compromise, phishing, vulnerability research, and the extraction of sensitive data from downstream organizations.\n...",
              "categories": [
                "Uncategorized",
                "AI",
                "reports"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 232,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/on-anthropics-ai-misuse-report.html",
      "tags": [
        "Uncategorized",
        "AI",
        "reports"
      ]
    },
    {
      "id": "06f2f381d02831792c6c",
      "title": "Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise",
      "content_text": "Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.\n\"At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets,\" BitGet said in a post shared on X. \"Bitget's cold wallets and the overwhelming majority of platform assets remain",
      "date_published": "2026-09-25T10:35:55Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "06f2f381d02831792c6c",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-25T12:22:59Z",
          "data": {
            "change": "added",
            "label": "Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise",
            "item_type": "entry",
            "summary": "added: Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise",
            "after": {
              "title": "Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise",
              "link": "https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html",
              "id": "https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-25T10:35:55Z",
              "updated_at": "2026-09-25T10:35:55Z",
              "summary": "Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.\n\"At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets,\" BitGet said in a post shared on X. \"Bitget's cold wallets and the overwhelming majority of platform assets remain",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpydVf-1UN81MyiMH8sAYBd4xiIBuM52UV7kyWmhhBlqohwuaFwgnP5wVx35gG3dHMWrtw0aoPh2zPLW-NaUI4qc_nmpybfA87lo6bzZmLb4WXnpNkYyEYEYMk7kaHeKH4G01yOeEBm44R8a7uAQmabg1k2pEd7MBRp9FM4QN4uA3rsXxkAfuKLWBUxQd_/s1600/bitget.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 468,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/bitget-says-suspected-north-korean.html"
    },
    {
      "id": "0f2c29e5269d42ec7f87",
      "title": "Microsoft: Recent Windows updates cause desktop loading issues",
      "content_text": "Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]",
      "date_published": "2026-09-25T10:30:38Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "0f2c29e5269d42ec7f87",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T12:22:59Z",
          "data": {
            "change": "added",
            "label": "Microsoft: Recent Windows updates cause desktop loading issues",
            "item_type": "entry",
            "summary": "added: Microsoft: Recent Windows updates cause desktop loading issues",
            "after": {
              "title": "Microsoft: Recent Windows updates cause desktop loading issues",
              "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/",
              "id": "https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/",
              "author": "Sergiu Gatlan",
              "published_at": "2026-09-25T10:30:38Z",
              "updated_at": "2026-09-25T10:30:38Z",
              "summary": "Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]",
              "categories": [
                "Microsoft"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 139,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-recent-windows-updates-cause-desktop-loading-issues/",
      "tags": [
        "Microsoft"
      ]
    },
    {
      "id": "d294514a142234ea3175",
      "title": "Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild",
      "content_text": "The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.\nThe vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.\nThe issue stems from a preg_replace() backslash",
      "date_published": "2026-09-25T10:14:02Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "d294514a142234ea3175",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-25T12:22:59Z",
          "data": {
            "change": "added",
            "label": "Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild",
            "item_type": "entry",
            "summary": "added: Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild",
            "after": {
              "title": "Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild",
              "link": "https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html",
              "id": "https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-25T10:14:02Z",
              "updated_at": "2026-09-25T10:14:02Z",
              "summary": "The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild.\nThe vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1.\nThe issue stems from a preg_replace() backslash",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8MACS_IO_gIvzTjppTIaHyXZKPha3ZR13_sXQS7u9Ajphpz-FRL5GNIQzhpbveUPPLuMCq72MYNtdX5o6gF-9MZZg4rPF7mbOP_pjSXyTVOFy3XtzlQiMH6sIdTdsqgZpgQf-yZmk688M6BiOWdUNYZswJVQETAInFkZVZCl99ZoYoGhhgtpJZ0hs9JmV/s1600/roundcube.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 468,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/roundcube-pre-auth-sql-injection-flaw.html"
    },
    {
      "id": "f43c4a6d3f37eb3b5f71",
      "title": "Hackers steal $351.6 million in Bitget crypto exchange hack",
      "content_text": "​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]",
      "date_published": "2026-09-25T08:33:44Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "f43c4a6d3f37eb3b5f71",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-25T12:22:59Z",
          "data": {
            "change": "added",
            "label": "Hackers steal $351.6 million in Bitget crypto exchange hack",
            "item_type": "entry",
            "summary": "added: Hackers steal $351.6 million in Bitget crypto exchange hack",
            "after": {
              "title": "Hackers steal $351.6 million in Bitget crypto exchange hack",
              "link": "https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/",
              "id": "https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/",
              "author": "Sergiu Gatlan",
              "published_at": "2026-09-25T08:33:44Z",
              "updated_at": "2026-09-25T08:33:44Z",
              "summary": "​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]",
              "categories": [
                "Security",
                "CryptoCurrency"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 139,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/hackers-steal-3516-million-in-bitget-crypto-exchange-hack/",
      "tags": [
        "Security",
        "CryptoCurrency"
      ]
    },
    {
      "id": "efa02bb8be11761df99f",
      "title": "Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data",
      "content_text": "A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.\nThe data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company",
      "date_published": "2026-09-25T04:49:22Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "efa02bb8be11761df99f",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-25T06:46:21Z",
          "data": {
            "change": "added",
            "label": "Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data",
            "item_type": "entry",
            "summary": "added: Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data",
            "after": {
              "title": "Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data",
              "link": "https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html",
              "id": "https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-25T04:49:22Z",
              "updated_at": "2026-09-25T04:49:22Z",
              "summary": "A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday.\nThe data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got, according to Cloudflare. The company",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJuj6tshfElqbwJCAvJf00nvl1Tng8D3yBW5uZZyVpwOqXJuzBB1df67IlNM1OSkHdGH11R6G8rseykpeXWUBu24sJvyxDL-uiqA7NC2ItwUUN2fMdaTWhqcHR2WYfpI6ihc0EVpEXfep1VFBygmh2-F6cAL1lwin0qQbmSebV5OmhqFmgBs3i0_WtdGI/s1600/cf-escape.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 204,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/cloudflare-fixes-flaw-that-let-one.html"
    },
    {
      "id": "03885e93f49e4f3da1e8",
      "title": "WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV",
      "content_text": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.\nThe vulnerabilities are listed below -\nCVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,",
      "date_published": "2026-09-25T04:46:34Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "03885e93f49e4f3da1e8",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-25T06:46:21Z",
          "data": {
            "change": "added",
            "label": "WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV",
            "item_type": "entry",
            "summary": "added: WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV",
            "after": {
              "title": "WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV",
              "link": "https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html",
              "id": "https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-25T04:46:34Z",
              "updated_at": "2026-09-25T04:46:34Z",
              "summary": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.\nThe vulnerabilities are listed below -\nCVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in WSO2 API Control Plane,",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqTAzyCx7Cezy4z5oRz-uAHvdvW1IZDrQlfIqT_ZDJ22Hvarb4lmYWkjqBDI_CngiSy2wuot68b2CgMS_0CWVZS93lYo5wqJsd5-WdFQgO3dieodXpVQiizcFjQsPzUOlVrs32zkBaHAwOyD7S4GCZ3b1d-Jyt4-ZTaMltfU0jG5dwBw5cxj880D4Cx8W0/s1600/ADOBE-CISA.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 204,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/wso2-and-adobe-commerce-flaws-exploited.html"
    },
    {
      "id": "007eb56edb7b0dd0311f",
      "title": "MacSync malware uses public iCloud calendars to deliver new payloads",
      "content_text": "A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]",
      "date_published": "2026-09-24T20:53:35Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "007eb56edb7b0dd0311f",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T22:46:25Z",
          "data": {
            "change": "added",
            "label": "MacSync malware uses public iCloud calendars to deliver new payloads",
            "item_type": "entry",
            "summary": "added: MacSync malware uses public iCloud calendars to deliver new payloads",
            "after": {
              "title": "MacSync malware uses public iCloud calendars to deliver new payloads",
              "link": "https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/",
              "id": "https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/",
              "author": "Bill Toulas",
              "published_at": "2026-09-24T20:53:35Z",
              "updated_at": "2026-09-24T20:53:35Z",
              "summary": "A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 127,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "a5bb982d4a39aae0dcfe",
      "title": "New Carbonato malware uses AI agents to hijack exposed Docker hosts",
      "content_text": "A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]",
      "date_published": "2026-09-24T20:10:48Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "a5bb982d4a39aae0dcfe",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T22:46:25Z",
          "data": {
            "change": "added",
            "label": "New Carbonato malware uses AI agents to hijack exposed Docker hosts",
            "item_type": "entry",
            "summary": "added: New Carbonato malware uses AI agents to hijack exposed Docker hosts",
            "after": {
              "title": "New Carbonato malware uses AI agents to hijack exposed Docker hosts",
              "link": "https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/",
              "id": "https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/",
              "author": "Bill Toulas",
              "published_at": "2026-09-24T20:10:48Z",
              "updated_at": "2026-09-24T20:10:48Z",
              "summary": "A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]",
              "categories": [
                "Security",
                "Artificial Intelligence"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 127,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/",
      "tags": [
        "Security",
        "Artificial Intelligence"
      ]
    },
    {
      "id": "ac3e5f023a68b2521e3f",
      "title": "Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions",
      "content_text": "A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone.\nOnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not",
      "date_published": "2026-09-24T18:10:18Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "ac3e5f023a68b2521e3f",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T19:33:25Z",
          "data": {
            "change": "added",
            "label": "Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions",
            "item_type": "entry",
            "summary": "added: Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions",
            "after": {
              "title": "Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions",
              "link": "https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html",
              "id": "https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-24T18:10:18Z",
              "updated_at": "2026-09-24T18:10:18Z",
              "summary": "A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone.\nOnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjiGu2guziH88Cs_LnFsPkCJ4zuxqgSX7q3SRrBXdSAEeJPhmYnpNp-c0WCNCqoOoyCv6NcnmCKm20rhqSb2rjw7KZ6Kh6UssR2fZG5SZX9Pjhb_fjONdBfgpxqpWNABPDvSmD9Hp913nErgH4PQm1ehlyspJt5RXASYckP6jHE3G0V2ou5fwkG7JOZyBY/s1600/oneplus.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 289,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html"
    },
    {
      "id": "8a262103243c6c89de4a",
      "title": "ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories",
      "content_text": "This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before.\nThat is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just",
      "date_published": "2026-09-24T17:52:43Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "8a262103243c6c89de4a",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/threatsday-ai-search-poisoning-ai.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T19:33:25Z",
          "data": {
            "change": "added",
            "label": "ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories",
            "item_type": "entry",
            "summary": "added: ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories",
            "after": {
              "title": "ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories",
              "link": "https://thehackernews.com/2026/09/threatsday-ai-search-poisoning-ai.html",
              "id": "https://thehackernews.com/2026/09/threatsday-ai-search-poisoning-ai.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-24T17:52:43Z",
              "updated_at": "2026-09-24T17:52:43Z",
              "summary": "This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before.\nThat is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjQeh1uEFjgxcgPPJkrXkAnJxZRxA9_ZolFQXNONWmfMGLViusszn4KTiJ9-8_r-AV94NS5BQlZ5eOrFnTvinPXcJB_G4o_BEZdv7xXMdAqfvZPfiUzKjlE70q2V6C9ze8H58pqYh-suKm_Yu1q3LoevignMd7nfjbjV7qx_vEad6BEFKUHwV5UlTFW1-dh/s1600/threatsday-sep.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 289,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/threatsday-ai-search-poisoning-ai.html"
    },
    {
      "id": "b0f87ae8633db31f7aa1",
      "title": "Exposed GitLab project email addresses let attackers push code",
      "content_text": "Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]",
      "date_published": "2026-09-24T17:47:44Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b0f87ae8633db31f7aa1",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/exposed-gitlab-project-email-addresses-let-attackers-push-code/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T19:33:25Z",
          "data": {
            "change": "added",
            "label": "Exposed GitLab project email addresses let attackers push code",
            "item_type": "entry",
            "summary": "added: Exposed GitLab project email addresses let attackers push code",
            "after": {
              "title": "Exposed GitLab project email addresses let attackers push code",
              "link": "https://www.bleepingcomputer.com/news/security/exposed-gitlab-project-email-addresses-let-attackers-push-code/",
              "id": "https://www.bleepingcomputer.com/news/security/exposed-gitlab-project-email-addresses-let-attackers-push-code/",
              "author": "Bill Toulas",
              "published_at": "2026-09-24T17:47:44Z",
              "updated_at": "2026-09-24T17:47:44Z",
              "summary": "Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 117,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.2"
            },
            {
              "step": "dedupe",
              "version": "0.3.2",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.2",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.2",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/exposed-gitlab-project-email-addresses-let-attackers-push-code/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "e04d2b8beb8af581852c",
      "title": "Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content",
      "content_text": "The \"third-party[.]com\" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.\n\"third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,\" Manifold Security's Head of Research, Ax Sharma, said. \"Unlike 'example[.]com,' third-party[.]com",
      "date_published": "2026-09-24T15:27:32Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "e04d2b8beb8af581852c",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content",
            "item_type": "entry",
            "summary": "added: Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content",
            "after": {
              "title": "Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content",
              "link": "https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html",
              "id": "https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-24T15:27:32Z",
              "updated_at": "2026-09-24T15:27:32Z",
              "summary": "The \"third-party[.]com\" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.\n\"third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,\" Manifold Security's Head of Research, Ax Sharma, said. \"Unlike 'example[.]com,' third-party[.]com",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhy4aXDWSC5cKzOZO8lRbk8o5I1fHPlCGbfxxYL6tyJxauEL-8EVj7-AypDhYt_Wg6bDLqlj0UK4LrGJdeI4ChsksaB6tTZxo8ikCLdwC0wjRfJPE_Z1qM_CVUg7s1ORdmWW2XTDtlPPDcI8JvelrbmJhcjVthnqYWQrZ7ySnIMMPRZfa_VzgaBCWyWc_JJ/s1600/third.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html"
    },
    {
      "id": "11bc09d731bc9d0d7e0d",
      "title": "Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer",
      "content_text": "An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic.\n\"When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the",
      "date_published": "2026-09-24T14:29:06Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "11bc09d731bc9d0d7e0d",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer",
            "item_type": "entry",
            "summary": "added: Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer",
            "after": {
              "title": "Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer",
              "link": "https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html",
              "id": "https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-24T14:29:06Z",
              "updated_at": "2026-09-24T14:29:06Z",
              "summary": "An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic.\n\"When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh1xvw3iNKwWUngfdShXBAPKrbRDMZSCQ3_FdiHNKvwrLkip9fUiikko0FKN-cfgzBIgkLvKDR9xIlnfEZVQgHgOW2qTz8Pd4Ur0-DCYdUssgN_9vglgxRU6u5ZRK_FlQYmgV_sbv8pfA1YnSJcojUOhWC-7lkPbA07An_X-vNHmZ8xT2Okq9HiRfTBVt1h/s1600/UK-CLICK.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html"
    },
    {
      "id": "b27fe55a49d3df0ad506",
      "title": "FedRAMP VDR & VER: Daily Scans Are Only the Beginning",
      "content_text": "FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]",
      "date_published": "2026-09-24T14:02:12Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b27fe55a49d3df0ad506",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/fedramp-vdr-and-ver-daily-scans-are-only-the-beginning/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "FedRAMP VDR & VER: Daily Scans Are Only the Beginning",
            "item_type": "entry",
            "summary": "added: FedRAMP VDR & VER: Daily Scans Are Only the Beginning",
            "after": {
              "title": "FedRAMP VDR & VER: Daily Scans Are Only the Beginning",
              "link": "https://www.bleepingcomputer.com/news/security/fedramp-vdr-and-ver-daily-scans-are-only-the-beginning/",
              "id": "https://www.bleepingcomputer.com/news/security/fedramp-vdr-and-ver-daily-scans-are-only-the-beginning/",
              "author": "Sponsored by Anecdotes",
              "published_at": "2026-09-24T14:02:12Z",
              "updated_at": "2026-09-24T14:02:12Z",
              "summary": "FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/fedramp-vdr-and-ver-daily-scans-are-only-the-beginning/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "3b88e89da3fa766e9bab",
      "title": "Hackers now exploit critical Roundcube flaw in code injection attacks",
      "content_text": "A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]",
      "date_published": "2026-09-24T13:27:57Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "3b88e89da3fa766e9bab",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Hackers now exploit critical Roundcube flaw in code injection attacks",
            "item_type": "entry",
            "summary": "added: Hackers now exploit critical Roundcube flaw in code injection attacks",
            "after": {
              "title": "Hackers now exploit critical Roundcube flaw in code injection attacks",
              "link": "https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/",
              "id": "https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/",
              "author": "Sergiu Gatlan",
              "published_at": "2026-09-24T13:27:57Z",
              "updated_at": "2026-09-24T13:27:57Z",
              "summary": "A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "3dd60f8e552b6a534382",
      "title": "Windows 11 KB5124010 update released with 46 changes and fixes",
      "content_text": "Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]",
      "date_published": "2026-09-24T12:16:32Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "3dd60f8e552b6a534382",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124010-update-released-with-46-changes-and-fixes/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Windows 11 KB5124010 update released with 46 changes and fixes",
            "item_type": "entry",
            "summary": "added: Windows 11 KB5124010 update released with 46 changes and fixes",
            "after": {
              "title": "Windows 11 KB5124010 update released with 46 changes and fixes",
              "link": "https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124010-update-released-with-46-changes-and-fixes/",
              "id": "https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124010-update-released-with-46-changes-and-fixes/",
              "author": "Sergiu Gatlan",
              "published_at": "2026-09-24T12:16:32Z",
              "updated_at": "2026-09-24T12:16:32Z",
              "summary": "Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]",
              "categories": [
                "Microsoft"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124010-update-released-with-46-changes-and-fixes/",
      "tags": [
        "Microsoft"
      ]
    },
    {
      "id": "8c43dcccbaf6ef342ae7",
      "title": "Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls",
      "content_text": "The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM.\nAccording to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name \"com.corp.mdm\"\nCorp MDM",
      "date_published": "2026-09-24T12:05:27Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "8c43dcccbaf6ef342ae7",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls",
            "item_type": "entry",
            "summary": "added: Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls",
            "after": {
              "title": "Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls",
              "link": "https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html",
              "id": "https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-24T12:05:27Z",
              "updated_at": "2026-09-24T12:05:27Z",
              "summary": "The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM.\nAccording to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that's dressed up as a system service. The delivered app has the package name \"com.corp.mdm\"\nCorp MDM",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhitRqKj3-JlcQ69xxlsxJs80aq7MNxgAc_VrV-TCrHGTVEwdWKIdvAiwB4szXMT3cRKpkzCRVObZxAO47CLl3JWLRerxVSITKy9xorsP-XY212M07JzDkZ7VXOA-r0maycB0jMv0r5Kl3q0VgrxpoeYfHJ_gkeXbzXLKz_3gAhDGy1ML06lfta_5w8u_Xo/s1600/1000110893.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html"
    },
    {
      "id": "08b4e83b33713ea9b0c9",
      "title": "Malicious npm Packages That Evade Defenses",
      "content_text": "This is an impressive piece of malware . Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.",
      "date_published": "2026-09-24T11:07:42Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "08b4e83b33713ea9b0c9",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72668",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Malicious npm Packages That Evade Defenses",
            "item_type": "entry",
            "summary": "added: Malicious npm Packages That Evade Defenses",
            "after": {
              "title": "Malicious npm Packages That Evade Defenses",
              "link": "https://www.schneier.com/blog/archives/2026/09/malicious-npm-packages-that-evade-defenses.html",
              "id": "https://www.schneier.com/?p=72668",
              "author": "Bruce Schneier",
              "published_at": "2026-09-24T11:07:42Z",
              "updated_at": "2026-09-24T11:08:24Z",
              "summary": "This is an impressive piece of malware . Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.",
              "categories": [
                "Uncategorized",
                "defense",
                "malware"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 167,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/malicious-npm-packages-that-evade-defenses.html",
      "tags": [
        "Uncategorized",
        "defense",
        "malware"
      ]
    },
    {
      "id": "df1bbfbfd33d61d09d86",
      "title": "Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore",
      "content_text": "AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI",
      "date_published": "2026-09-24T11:00:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "df1bbfbfd33d61d09d86",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/secrets-sprawl-is-identity-problem-that.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore",
            "item_type": "entry",
            "summary": "added: Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore",
            "after": {
              "title": "Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore",
              "link": "https://thehackernews.com/2026/09/secrets-sprawl-is-identity-problem-that.html",
              "id": "https://thehackernews.com/2026/09/secrets-sprawl-is-identity-problem-that.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-24T11:00:00Z",
              "updated_at": "2026-09-24T11:00:00Z",
              "summary": "AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi8mLbRmwaAgvJunom4dBxBYMz50LUutLJiS6Yz7RPCbZQO1aYXAqFWOga4dCKD3AoenZHxYLpPexLEQ2swJO67vy4xl2_uw1g08lRtETN3hTMLpvafmn5WD4VK2ilpuFaYAdMHHPBRG2yYsyDBins15huubgt2b6pDVnnhW92It8lKHBqOifOLTaNSwho/s1600/keeper.png"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/secrets-sprawl-is-identity-problem-that.html"
    },
    {
      "id": "eea62150121acf40cca5",
      "title": "CISA: Ransomware gangs now exploiting critical TeamCity flaw",
      "content_text": "​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]",
      "date_published": "2026-09-24T10:42:37Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "eea62150121acf40cca5",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "CISA: Ransomware gangs now exploiting critical TeamCity flaw",
            "item_type": "entry",
            "summary": "added: CISA: Ransomware gangs now exploiting critical TeamCity flaw",
            "after": {
              "title": "CISA: Ransomware gangs now exploiting critical TeamCity flaw",
              "link": "https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/",
              "id": "https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/",
              "author": "Sergiu Gatlan",
              "published_at": "2026-09-24T10:42:37Z",
              "updated_at": "2026-09-24T10:42:37Z",
              "summary": "​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "afa45af01e2488a8125c",
      "title": "OpenAI hacked Australian Medicare govt site, probed data providers",
      "content_text": "OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. [...]",
      "date_published": "2026-09-24T09:38:53Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "afa45af01e2488a8125c",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "OpenAI hacked Australian Medicare govt site, probed data providers",
            "item_type": "entry",
            "summary": "added: OpenAI hacked Australian Medicare govt site, probed data providers",
            "after": {
              "title": "OpenAI hacked Australian Medicare govt site, probed data providers",
              "link": "https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/",
              "id": "https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/",
              "author": "Bill Toulas",
              "published_at": "2026-09-24T09:38:53Z",
              "updated_at": "2026-09-24T09:38:53Z",
              "summary": "OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "b48ab760b2c28d3202e4",
      "title": "17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360",
      "content_text": "ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense.\nRead",
      "date_published": "2026-09-24T09:14:21Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b48ab760b2c28d3202e4",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360",
            "item_type": "entry",
            "summary": "added: 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360",
            "after": {
              "title": "17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360",
              "link": "https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html",
              "id": "https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-24T09:14:21Z",
              "updated_at": "2026-09-24T09:14:21Z",
              "summary": "ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense.\nRead",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiOah63YM6pjk2RAIcCXy-NSbO_uPPCSp4DsR-9-jeGLCRZCd9E1QSd0_b4c6xc5wFp_ncqCH3LPtBR_C1auF3Fid-DNSCtQh9eEArgNe0syhvA4I9EdDU454uAqieiAGyyI-dXW5AsA5X4zsbhTpHKjXfIbgM35i4MOC7Jcbk5SiILRU9_BgcV2H-_BxI/s1600/ctm360.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html"
    },
    {
      "id": "b1305cec387e13bdb884",
      "title": "Microsoft fixes bug that broke Windows File History backup feature",
      "content_text": "Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. [...]",
      "date_published": "2026-09-24T08:14:47Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b1305cec387e13bdb884",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-backup-feature-broken-by-september-updates/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Microsoft fixes bug that broke Windows File History backup feature",
            "item_type": "entry",
            "summary": "added: Microsoft fixes bug that broke Windows File History backup feature",
            "after": {
              "title": "Microsoft fixes bug that broke Windows File History backup feature",
              "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-backup-feature-broken-by-september-updates/",
              "id": "https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-backup-feature-broken-by-september-updates/",
              "author": "Sergiu Gatlan",
              "published_at": "2026-09-24T08:14:47Z",
              "updated_at": "2026-09-24T08:14:47Z",
              "summary": "Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. [...]",
              "categories": [
                "Microsoft"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-windows-backup-feature-broken-by-september-updates/",
      "tags": [
        "Microsoft"
      ]
    },
    {
      "id": "8ec85966dc1dfde35b5d",
      "title": "OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files",
      "content_text": "An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said.\nThe portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal",
      "date_published": "2026-09-24T07:07:25Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "8ec85966dc1dfde35b5d",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files",
            "item_type": "entry",
            "summary": "added: OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files",
            "after": {
              "title": "OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files",
              "link": "https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html",
              "id": "https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-24T07:07:25Z",
              "updated_at": "2026-09-24T07:07:25Z",
              "summary": "An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said.\nThe portal publishes aggregate figures, such as spending, and is separate from the systems that handle Medicare claims and personal records. The agent reached files on it that were not public, but no personal",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjcAVdhDdHS-lMa6x8Y_wK35pNfiQpKjJPFKBf-euOlWYyYschDjjXlah44o4VfYeKJyaeWKFxyOkEwQEnW_qBfSc6rwynqdqB8UAq1CSuKzJOz6lxno1eI9DxmU0RzTX0eWig9f5L5vWGkW1vZnp8o7rDqe86PIyHtTHl-IQSdLmZWAVOyedE86QaUy4I/s1600/openai-agents.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/openai-agent-bypassed-australian.html"
    },
    {
      "id": "a107a9d4884ec7fcb245",
      "title": "TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords",
      "content_text": "Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.\nAccording to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses.\n\"The campaign compromised 7 accounts –",
      "date_published": "2026-09-24T06:32:03Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "a107a9d4884ec7fcb245",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords",
            "item_type": "entry",
            "summary": "added: TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords",
            "after": {
              "title": "TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords",
              "link": "https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html",
              "id": "https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-24T06:32:03Z",
              "updated_at": "2026-09-24T06:32:03Z",
              "summary": "Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants.\nAccording to Proofpoint, the activity has primarily focused on Chilean retail and financial institutions. It originated from 1,487 unique AWS EC2 source IP addresses.\n\"The campaign compromised 7 accounts –",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQgKN3zS7GtEpakDcL7zk0tL-zcz3GJMkVf9vMLCVXf33XZ1Yad77dg3Zen_EEB58BltCG_pj0c-yVDm6VbV9cw5Baxtf26vVtRwW4qwDDy1s8HYMFKfTyl382lwJIRfSWBSA-WK6RAZ8lmy9zf5IZb_Ilqol0AcVdEaMp599tZ4NxqUc-KY4-fyFNYYFg/s1600/ms-365.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/teamfiltration-compromises-seven.html"
    },
    {
      "id": "afad1ccbc7ca91524262",
      "title": "Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure",
      "content_text": "Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.\nThe vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).\n\"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file",
      "date_published": "2026-09-24T05:36:18Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "afad1ccbc7ca91524262",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure",
            "item_type": "entry",
            "summary": "added: Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure",
            "after": {
              "title": "Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure",
              "link": "https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html",
              "id": "https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-24T05:36:18Z",
              "updated_at": "2026-09-24T05:36:18Z",
              "summary": "Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure.\nThe vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE).\n\"An unauthenticated attacker can make get_page_template() page-template resolution include a chosen readable local .php file",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEizoRcyQE1N3fGUKa2FY_q_T7EG_CyjTpMGGk1oFUF-XpBZa0zCA6V2yEuv3_Z1OrEjMmhbHdaVmo6NMrwb98U9VFGXDpRcItboVuZH7qc9QgPd5ZLDudfJPWoaSDbtkoXJeLTZw-6JDbq5F6YEp4AkeoJd10Nb_H9tuU0fYdgqkLrP6BTpAPOYwO6WdmkN/s1600/wordpress-exploits.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/attackers-exploit-wordpress-cve-2026.html"
    },
    {
      "id": "4276ef94121eb2c0925b",
      "title": "Placeholder domain used in dev docs now serves ClickFix attacks",
      "content_text": "The \"third-party.com\" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. [...]",
      "date_published": "2026-09-23T22:46:01Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "4276ef94121eb2c0925b",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-serves-clickfix-attacks/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Placeholder domain used in dev docs now serves ClickFix attacks",
            "item_type": "entry",
            "summary": "added: Placeholder domain used in dev docs now serves ClickFix attacks",
            "after": {
              "title": "Placeholder domain used in dev docs now serves ClickFix attacks",
              "link": "https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-serves-clickfix-attacks/",
              "id": "https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-serves-clickfix-attacks/",
              "author": "Lawrence Abrams",
              "published_at": "2026-09-23T22:46:01Z",
              "updated_at": "2026-09-23T22:46:01Z",
              "summary": "The \"third-party.com\" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-serves-clickfix-attacks/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "ac6b44577acbe7d11cc9",
      "title": "New RemControl Android banking malware targets users in Europe and Canada",
      "content_text": "A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]",
      "date_published": "2026-09-23T21:25:13Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "ac6b44577acbe7d11cc9",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "New RemControl Android banking malware targets users in Europe and Canada",
            "item_type": "entry",
            "summary": "added: New RemControl Android banking malware targets users in Europe and Canada",
            "after": {
              "title": "New RemControl Android banking malware targets users in Europe and Canada",
              "link": "https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada/",
              "id": "https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada/",
              "author": "Bill Toulas",
              "published_at": "2026-09-23T21:25:13Z",
              "updated_at": "2026-09-23T21:25:13Z",
              "summary": "A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]",
              "categories": [
                "Security",
                "Mobile"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada/",
      "tags": [
        "Security",
        "Mobile"
      ]
    },
    {
      "id": "53249e653028dfc44c66",
      "title": "Check Point warns of hackers exploiting Security Gateway VPN RCE flaw",
      "content_text": "Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]",
      "date_published": "2026-09-23T19:53:54Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "53249e653028dfc44c66",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Check Point warns of hackers exploiting Security Gateway VPN RCE flaw",
            "item_type": "entry",
            "summary": "added: Check Point warns of hackers exploiting Security Gateway VPN RCE flaw",
            "after": {
              "title": "Check Point warns of hackers exploiting Security Gateway VPN RCE flaw",
              "link": "https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/",
              "id": "https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/",
              "author": "Bill Toulas",
              "published_at": "2026-09-23T19:53:54Z",
              "updated_at": "2026-09-23T19:53:54Z",
              "summary": "Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "7efef70923bd019435cd",
      "title": "Hackers start exploiting critical WordPress flaw for code execution",
      "content_text": "Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]",
      "date_published": "2026-09-23T18:31:22Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "7efef70923bd019435cd",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Hackers start exploiting critical WordPress flaw for code execution",
            "item_type": "entry",
            "summary": "added: Hackers start exploiting critical WordPress flaw for code execution",
            "after": {
              "title": "Hackers start exploiting critical WordPress flaw for code execution",
              "link": "https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/",
              "id": "https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/",
              "author": "Bill Toulas",
              "published_at": "2026-09-23T18:31:22Z",
              "updated_at": "2026-09-23T18:31:22Z",
              "summary": "Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "6487e981f380ea069b8b",
      "title": "Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry",
      "content_text": "Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.\nAccording to Aikido, the list of Terraform providers and Go modules is below -\ngocommunity-io/dockerd (222 downloads)\nkreuzwenker/",
      "date_published": "2026-09-23T18:06:30Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "6487e981f380ea069b8b",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry",
            "item_type": "entry",
            "summary": "added: Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry",
            "after": {
              "title": "Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry",
              "link": "https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html",
              "id": "https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T18:06:30Z",
              "updated_at": "2026-09-23T18:06:30Z",
              "summary": "Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.\nAccording to Aikido, the list of Terraform providers and Go modules is below -\ngocommunity-io/dockerd (222 downloads)\nkreuzwenker/",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj8VNxKl5_NBWXcUoDi3VxoksbOSAixGFGd8EmIaZmKRQpsGhOj6SLg8fmHktJbtvR7wofZNG1AFIzSGnVFq8OJHgq27dhqNtc0cz457ZqqQQ6INHwnExfLu3xKERaNt0GmOpxJ6WR6oxp5FZTT-q3Q5YWAnVawXYfY51GRl09ovsDkhM3U8tRUTR4ClSfj/s1600/terraform.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html"
    },
    {
      "id": "8fccc478b4854bce25b3",
      "title": "A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You",
      "content_text": "The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you.\nGitLab shows each user this address behind a button labeled \"Email work item to this project.\" Mail sent to it opens an issue in that project, authored",
      "date_published": "2026-09-23T16:53:10Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "8fccc478b4854bce25b3",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You",
            "item_type": "entry",
            "summary": "added: A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You",
            "after": {
              "title": "A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You",
              "link": "https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html",
              "id": "https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T16:53:10Z",
              "updated_at": "2026-09-23T16:53:10Z",
              "summary": "The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you.\nGitLab shows each user this address behind a button labeled \"Email work item to this project.\" Mail sent to it opens an issue in that project, authored",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaHKzSxkk0R4wjlziQHsR5vS1s1mTJovZkES9XL9nn5VLYiM55XuJoiGP9cugwNUOBMEMG3NrW3iBL9cVOqfp0F-9roYS7K7R5w8t3_NJr61_2_XgRNltvjXBFoGLfQPQFhUk0ju_mMCRCqJHjr76BrbngafAtElKkD-LZWZ7uUcY82i8PAMKh0ljHJQI/s1600/gitlab-email.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html"
    },
    {
      "id": "4b28438ee3d37b50205f",
      "title": "Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers",
      "content_text": "A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]",
      "date_published": "2026-09-23T16:20:54Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "4b28438ee3d37b50205f",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers",
            "item_type": "entry",
            "summary": "added: Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers",
            "after": {
              "title": "Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers",
              "link": "https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/",
              "id": "https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/",
              "author": "Bill Toulas",
              "published_at": "2026-09-23T16:20:54Z",
              "updated_at": "2026-09-23T16:20:54Z",
              "summary": "A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]",
              "categories": [
                "Security",
                "Artificial Intelligence"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/",
      "tags": [
        "Security",
        "Artificial Intelligence"
      ]
    },
    {
      "id": "e445484a96ce82cbf9e8",
      "title": "MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key",
      "content_text": "Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.\nThe chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at",
      "date_published": "2026-09-23T16:06:41Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "e445484a96ce82cbf9e8",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key",
            "item_type": "entry",
            "summary": "added: MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key",
            "after": {
              "title": "MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key",
              "link": "https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html",
              "id": "https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T16:06:41Z",
              "updated_at": "2026-09-23T16:06:41Z",
              "summary": "Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.\nThe chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjudzrtqX93WzCbZQoGI06WzKFtFpQsZaQB7GUao4yzBncGN3nxn0GzmYNybpL9SeKFttznMsVCZpQEQ_fD5kP_0nJRL4ZN6ZgHrXR2c33bpZN33gEyIkk6aBtx0k7znzalUe6epmrCO5VSCCH6beY_chvz9Pl0t5BbBtCLntTnNMwi3cFPXFd0p09FxA4/s1600/microtik.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html"
    },
    {
      "id": "2a39455f43d36a287fac",
      "title": "InfraTrust report warns network management systems under attack",
      "content_text": "Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]",
      "date_published": "2026-09-23T14:35:26Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "2a39455f43d36a287fac",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/infratrust-report-warns-network-management-systems-under-attack/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "InfraTrust report warns network management systems under attack",
            "item_type": "entry",
            "summary": "added: InfraTrust report warns network management systems under attack",
            "after": {
              "title": "InfraTrust report warns network management systems under attack",
              "link": "https://www.bleepingcomputer.com/news/security/infratrust-report-warns-network-management-systems-under-attack/",
              "id": "https://www.bleepingcomputer.com/news/security/infratrust-report-warns-network-management-systems-under-attack/",
              "author": "Lawrence Abrams",
              "published_at": "2026-09-23T14:35:26Z",
              "updated_at": "2026-09-23T14:35:26Z",
              "summary": "Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/infratrust-report-warns-network-management-systems-under-attack/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "b7ac3967f542bafc9e7e",
      "title": "This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move",
      "content_text": "A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22.\nThe models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.",
      "date_published": "2026-09-23T14:17:58Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b7ac3967f542bafc9e7e",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move",
            "item_type": "entry",
            "summary": "added: This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move",
            "after": {
              "title": "This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move",
              "link": "https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html",
              "id": "https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T14:17:58Z",
              "updated_at": "2026-09-23T14:17:58Z",
              "summary": "A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22.\nThe models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiZdSpi6aqUlY2q-T-3eJ4YCn7G3jYa9Exo6BMffjdRLuqg9Gdn4ImZXKjcYX8s5Swz3W_WhxMZ_Z7qbu0Z60KrCk8EUhRV8bJ7l1mXOoDCo-XAXyq69_rtFDoVhvAiuJP1rCdSf9KixTqgAA52iwqWsqB5T0uJaRGFz1hpBcpfQuvPMYd17UcrfrnUV0c/s1600/closed.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html"
    },
    {
      "id": "3f68816f889c2997ee5d",
      "title": "How One Kubernetes YAML Can Hand Over a GCP Organization",
      "content_text": "A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [...]",
      "date_published": "2026-09-23T14:01:11Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "3f68816f889c2997ee5d",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/how-one-kubernetes-yaml-can-hand-over-a-gcp-organization/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "How One Kubernetes YAML Can Hand Over a GCP Organization",
            "item_type": "entry",
            "summary": "added: How One Kubernetes YAML Can Hand Over a GCP Organization",
            "after": {
              "title": "How One Kubernetes YAML Can Hand Over a GCP Organization",
              "link": "https://www.bleepingcomputer.com/news/security/how-one-kubernetes-yaml-can-hand-over-a-gcp-organization/",
              "id": "https://www.bleepingcomputer.com/news/security/how-one-kubernetes-yaml-can-hand-over-a-gcp-organization/",
              "author": "Sponsored by Varonis",
              "published_at": "2026-09-23T14:01:11Z",
              "updated_at": "2026-09-23T14:01:11Z",
              "summary": "A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/how-one-kubernetes-yaml-can-hand-over-a-gcp-organization/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "af78a5f8984243363f2f",
      "title": "Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI",
      "content_text": "Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.\nAccording to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below -\n@memtensor/memos-cloud-openclaw-plugin versions",
      "date_published": "2026-09-23T13:52:46Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "af78a5f8984243363f2f",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI",
            "item_type": "entry",
            "summary": "added: Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI",
            "after": {
              "title": "Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI",
              "link": "https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html",
              "id": "https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T13:52:46Z",
              "updated_at": "2026-09-23T13:52:46Z",
              "summary": "Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.\nAccording to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below -\n@memtensor/memos-cloud-openclaw-plugin versions",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFThFSFsti-2SIka75bNuMKpyJHtOW2ZPrZtcSjbjFQ64GCNn0WtdssYuWlVTbhaLB5cAJ0vu8FgyNmNsDa8g0Ijy-D1zP4FW7ihVfAjk9xWMYDMMdfZPICGyVdjeDwH3-jyKLHOUnjfaXBJIMxGn_3ngeXFsbb4CLnOibRd4fbwXHYpBkMQTcBQAf0edq/s1600/npm-pypi.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html"
    },
    {
      "id": "4b34085389c96c6dbd31",
      "title": "Arista patches actively exploited VeloCloud Orchestrator zero-day",
      "content_text": "Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]",
      "date_published": "2026-09-23T12:29:53Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "4b34085389c96c6dbd31",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/security/arista-patches-actively-exploited-velocloud-orchestrator-zero-day/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Arista patches actively exploited VeloCloud Orchestrator zero-day",
            "item_type": "entry",
            "summary": "added: Arista patches actively exploited VeloCloud Orchestrator zero-day",
            "after": {
              "title": "Arista patches actively exploited VeloCloud Orchestrator zero-day",
              "link": "https://www.bleepingcomputer.com/news/security/arista-patches-actively-exploited-velocloud-orchestrator-zero-day/",
              "id": "https://www.bleepingcomputer.com/news/security/arista-patches-actively-exploited-velocloud-orchestrator-zero-day/",
              "author": "Sergiu Gatlan",
              "published_at": "2026-09-23T12:29:53Z",
              "updated_at": "2026-09-23T12:29:53Z",
              "summary": "Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]",
              "categories": [
                "Security"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/security/arista-patches-actively-exploited-velocloud-orchestrator-zero-day/",
      "tags": [
        "Security"
      ]
    },
    {
      "id": "bf02dfa56f671080bd99",
      "title": "New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control",
      "content_text": "A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take \"full control of the server,\" the company said on September 22.\nA second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.\ncPanel has released fixed versions for both,",
      "date_published": "2026-09-23T12:16:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "bf02dfa56f671080bd99",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control",
            "item_type": "entry",
            "summary": "added: New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control",
            "after": {
              "title": "New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control",
              "link": "https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html",
              "id": "https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T12:16:00Z",
              "updated_at": "2026-09-23T12:16:00Z",
              "summary": "A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take \"full control of the server,\" the company said on September 22.\nA second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.\ncPanel has released fixed versions for both,",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhT5quc0dmRWhh6WOC80Gx9QoHTMYyq5srnXBXjybOKZk_qoUn1Q2nKLE9MifqCEyRIha_NFvRsyr8Nx5EyxGIREXaTb5Fh59cz4Ln8yZj9Zv7piqM49wmm7rfmchW1cVlss1wn47qNypaYarZUVNHBO8rzXaYTvRMi9u1phgfXVd8OZx8_Vjxm34684BE/s1600/cpanel-0day.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html"
    },
    {
      "id": "2a3444963f02d3d9e38d",
      "title": "545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent",
      "content_text": "Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security background then sits down and checks every claim against the target. Which findings are real,",
      "date_published": "2026-09-23T11:47:19Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "2a3444963f02d3d9e38d",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/545-hackers-tested-it-first-now-xranges.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent",
            "item_type": "entry",
            "summary": "added: 545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent",
            "after": {
              "title": "545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent",
              "link": "https://thehackernews.com/2026/09/545-hackers-tested-it-first-now-xranges.html",
              "id": "https://thehackernews.com/2026/09/545-hackers-tested-it-first-now-xranges.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T11:47:19Z",
              "updated_at": "2026-09-23T11:47:19Z",
              "summary": "Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security background then sits down and checks every claim against the target. Which findings are real,",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEio2c14ELRJEhvTuDrxQmhUG4G9aGoVRrooBMMfuK7LyHPKW6HuJbI9PkKF-WG_5HlEz8NKcuj08XRmv1jNqfBtiDwXmC7e9P9lxoSHK5nUz023YCgoLQuo0BI_9hX4U9Vv97bGJejb4W0jvgv_3btkfj6BWnXwalfyI3k34wveC6n3k47ZdoGq2P0Yaw0/s1600/main.png"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/545-hackers-tested-it-first-now-xranges.html"
    },
    {
      "id": "4448f8b46b709f030b73",
      "title": "Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests",
      "content_text": "Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior.\nOpus 5.5, per Anthropic, is a \"major step up from Opus 5,\" and \"achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands",
      "date_published": "2026-09-23T11:47:13Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "4448f8b46b709f030b73",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/anthropic-and-openai-models-still.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests",
            "item_type": "entry",
            "summary": "added: Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests",
            "after": {
              "title": "Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests",
              "link": "https://thehackernews.com/2026/09/anthropic-and-openai-models-still.html",
              "id": "https://thehackernews.com/2026/09/anthropic-and-openai-models-still.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T11:47:13Z",
              "updated_at": "2026-09-23T11:47:13Z",
              "summary": "Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior.\nOpus 5.5, per Anthropic, is a \"major step up from Opus 5,\" and \"achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_ytuRh_WTu4R3TBnroGXO6IUgATMIi9vgx8DA7j0JJ0e_cTfAjlUIS6zAjb2q9EPdTI8gLwby7r2fijYkH83j2SwisKf-ANFKr6YTdwAHeds99dYrng0QN3nmkqDtIvSHoK8m47e_V0x01B0PuzIezcqtnc2VZlUCVYErOkaKQF7pbk0l35uLwmTl8Is1/s1600/CLAUDE-CHATGPT.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/anthropic-and-openai-models-still.html"
    },
    {
      "id": "302a19fdac9c84e1a8fc",
      "title": "Microsoft: September Windows updates break Always On VPN connections",
      "content_text": "Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. [...]",
      "date_published": "2026-09-23T11:18:13Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "302a19fdac9c84e1a8fc",
          "source": "rss",
          "type": "change",
          "key": "https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/",
          "source_url": "https://www.bleepingcomputer.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Microsoft: September Windows updates break Always On VPN connections",
            "item_type": "entry",
            "summary": "added: Microsoft: September Windows updates break Always On VPN connections",
            "after": {
              "title": "Microsoft: September Windows updates break Always On VPN connections",
              "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/",
              "id": "https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/",
              "author": "Sergiu Gatlan",
              "published_at": "2026-09-23T11:18:13Z",
              "updated_at": "2026-09-23T11:18:13Z",
              "summary": "Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. [...]",
              "categories": [
                "Microsoft"
              ],
              "feed": {
                "title": "BleepingComputer",
                "url": "https://www.bleepingcomputer.com/",
                "feed_url": "https://www.bleepingcomputer.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.bleepingcomputer.com/feed/",
            "elapsed_ms": 203,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/",
      "tags": [
        "Microsoft"
      ]
    },
    {
      "id": "e61546700223b6fd32b1",
      "title": "Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape",
      "content_text": "A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.\nThe flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst",
      "date_published": "2026-09-23T11:12:18Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "e61546700223b6fd32b1",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape",
            "item_type": "entry",
            "summary": "added: Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape",
            "after": {
              "title": "Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape",
              "link": "https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html",
              "id": "https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T11:12:18Z",
              "updated_at": "2026-09-23T11:12:18Z",
              "summary": "A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.\nThe flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZjw_aCdQxMfwTv_-KFLK5KRCd96MoivCQPTAZcAWJal5_84FgCny9Um8csMgDDqta40CUGMPDO14hdbUo9CRk-FMJwY70MsDfV25AC8VmL-8_yDO_UWHYXbmeJ9jZANptIeHqJX9axqzxxn68AHEj8zFhYbh8coIbxWAVC9XbtG9CjxMBpQqclG14QuM/s1600/linux.gif"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html"
    },
    {
      "id": "e9ec11ad2bd1d535d8e0",
      "title": "Research on Models Engaging in Genie-Like Behavior",
      "content_text": "New paper: “ Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .”\nAbstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and…",
      "date_published": "2026-09-23T11:03:36Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "e9ec11ad2bd1d535d8e0",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72663",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Research on Models Engaging in Genie-Like Behavior",
            "item_type": "entry",
            "summary": "added: Research on Models Engaging in Genie-Like Behavior",
            "after": {
              "title": "Research on Models Engaging in Genie-Like Behavior",
              "link": "https://www.schneier.com/blog/archives/2026/09/research-on-models-engaging-in-genie-like-behavior.html",
              "id": "https://www.schneier.com/?p=72663",
              "author": "Bruce Schneier",
              "published_at": "2026-09-23T11:03:36Z",
              "updated_at": "2026-09-23T11:04:24Z",
              "summary": "New paper: “ Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .”\nAbstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be associated with the benign intent of “a security professional trying to test defense,” despite no such benign context being provided as input. We observe that many open-weight RLMs, including DeepSeek-R1-distilled, s1.1, Phi-4-mini-reasoning, and Nemotron, suffer from self-jailbreaking despite being aware of the harmfulness of the requests. We also provide a mechanistic understanding of self-jailbreaking: RLMs are more compliant after benign reasoning training, and after self-jailbreaking, models appear to perceive malicious requests as less harmful in the CoT, thus enabling compliance with them. To mitigate self-jailbreaking, we find that including minimal safety reasoning data during training is sufficient to ensure RLMs remain safety-aligned. Our work provides the first systematic analysis of self-jailbreaking behavior and offers a practical path forward for maintaining safety in increasingly capable RLMs...",
              "categories": [
                "Uncategorized",
                "academic papers",
                "AI",
                "lies"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 167,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/research-on-models-engaging-in-genie-like-behavior.html",
      "tags": [
        "Uncategorized",
        "academic papers",
        "AI",
        "lies"
      ]
    },
    {
      "id": "75bfec002e41b43e4568",
      "title": "F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers",
      "content_text": "Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.\nThe flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.",
      "date_published": "2026-09-23T08:29:48Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "75bfec002e41b43e4568",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers",
            "item_type": "entry",
            "summary": "added: F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers",
            "after": {
              "title": "F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers",
              "link": "https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html",
              "id": "https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T08:29:48Z",
              "updated_at": "2026-09-23T08:29:48Z",
              "summary": "Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.\nThe flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_ZqCwuuKS7TqNWQ7GpeE07JLzHNn4Jdb2O6iQAlY34SiP2it2VwgmeVm5OjAzoAEHFQRVJENdDNGQL94ibPy1AiB9qkpNxZ3ILA89tYlwqm2OO9tEOH_BZ9HZzObw0nrzszQoKnaCQ-Q8ez5DPsnrKjq40qhm2tu_DhMSFunkVRsHeEIc0IA2NL-yZ5g/s1600/f5-zero-day.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html"
    },
    {
      "id": "4823057a9e2827d6a3ac",
      "title": "Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware",
      "content_text": "A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.\nThe attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break",
      "date_published": "2026-09-23T08:29:24Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "4823057a9e2827d6a3ac",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware",
            "item_type": "entry",
            "summary": "added: Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware",
            "after": {
              "title": "Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware",
              "link": "https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html",
              "id": "https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T08:29:24Z",
              "updated_at": "2026-09-23T08:29:24Z",
              "summary": "A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.\nThe attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikVEmuPJKZAlboodZWejG4dGZXXejOLThyXPoOnycqTY8lznAewTW5ovv8XFJzhyjPRMXT-njudYOVWFEYCLvmEPDyUrfDTZzAmp1S4KE4DuzsDFxt8R-biL2puZZBWG36_dkhfzvpeigcPb9WJNy31oIXo6Oh3zMUzL3JG6MEr4OaGE4Yi_k5JCpohVrZ/s1600/windows-china.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html"
    },
    {
      "id": "964bb0fad8314354edef",
      "title": "Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input",
      "content_text": "A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said.\nThe risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version",
      "date_published": "2026-09-23T07:04:40Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "964bb0fad8314354edef",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input",
            "item_type": "entry",
            "summary": "added: Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input",
            "after": {
              "title": "Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input",
              "link": "https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html",
              "id": "https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T07:04:40Z",
              "updated_at": "2026-09-23T07:04:40Z",
              "summary": "A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said.\nThe risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhBxfEfPNHZcocTp156lW-VbOENuCxmLM_7xUUY5QWEppPDsL04KhbN7yaT52b_XTCXW6ensPqjF8QBXuQWUgna8jerFExtxAfkCd4NqOGcQwUn8088DU87PMD7cgYhQ-dY2_xFdwPyaKU-kD9HBx_YcjAzvzwEQzLoKUu1cRRpOT5A1luhBCE6e6ChORw/s1600/next.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html"
    },
    {
      "id": "94e7966263875b1b139d",
      "title": "ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants",
      "content_text": "The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.\n\"We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,\" the group said in a statement posted on their dark",
      "date_published": "2026-09-23T05:30:09Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "94e7966263875b1b139d",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants",
            "item_type": "entry",
            "summary": "added: ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants",
            "after": {
              "title": "ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants",
              "link": "https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html",
              "id": "https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-23T05:30:09Z",
              "updated_at": "2026-09-23T05:30:09Z",
              "summary": "The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.\n\"We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,\" the group said in a statement posted on their dark",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBUSHHkVbK1vPy2WO_E9jEZ2NEd8UcPTpCFgCYTkbSPiSzDEpXRe6HRXan3z9Xg1huRk3-47hZbveFeG06vkRhAmGuL73zdPFjQEkVb6LISZIcHpPugYCMKQPtsEIihip_T7F1GWczJNWNTikwbM-SzC_UNeQsUjrg6AIeHYBwOnpOUlSOWyimHb07TzWz/s1600/shinyhunters.png"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html"
    },
    {
      "id": "8ab93946919efed79ae3",
      "title": "Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks",
      "content_text": "Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said.\nThe flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point",
      "date_published": "2026-09-22T18:29:39Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "8ab93946919efed79ae3",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/check-point-warns-of-management-server.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks",
            "item_type": "entry",
            "summary": "added: Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks",
            "after": {
              "title": "Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks",
              "link": "https://thehackernews.com/2026/09/check-point-warns-of-management-server.html",
              "id": "https://thehackernews.com/2026/09/check-point-warns-of-management-server.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T18:29:39Z",
              "updated_at": "2026-09-22T18:29:39Z",
              "summary": "Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said.\nThe flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipTjrp93lIMdPVKigtkoXjbsk75AIXEvqJuXoYMQLAmvzQfqSy3V1XhBTLXY1SAWp92vTbajtnxBgHYvDr2e3EZOi9Yf8KgT8EzQOp61PjmPsI55nERsYckaL-pfmQDDzRTiCWXegVWrJ0Fu_9I8GUi5O0M0103r218S3dC67Zmr9BZ3quLBRBm9T6Xqo/s1600/cp-upload.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/check-point-warns-of-management-server.html"
    },
    {
      "id": "b84f83bcee9055557c7d",
      "title": "WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers",
      "content_text": "WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.\nOn some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners",
      "date_published": "2026-09-22T18:03:10Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b84f83bcee9055557c7d",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers",
            "item_type": "entry",
            "summary": "added: WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers",
            "after": {
              "title": "WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers",
              "link": "https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html",
              "id": "https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T18:03:10Z",
              "updated_at": "2026-09-22T18:03:10Z",
              "summary": "WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.\nOn some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcFso-nJC2Re_gThOMTjPhyphenhyphenaOti1Mpn2_nb6NYGitzjVHTtvHN_q4oKg_FGa4IrTt81BAuA4qWzeJJZkxdV7F0-iSBR3ZwSUmqfBhvBX2ArxLTZqYjbtCPhu2Gw7PLSmOS5kOGQ9f0I46xPwhp5VCflFSN8YEm-z8VXdk1XRJwCvbqbljSZqorD4MpbQc/s1600/wp-update.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html"
    },
    {
      "id": "329147ed8e239250f210",
      "title": "Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials",
      "content_text": "Cybersecurity researchers have disclosed details of a malicious npm package named \"tw-pkgprobe-7731\" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.\nThe package, named \"tw-pkgprobe-7731,\" was first uploaded to the npm registry in mid-August 2026 by an npm account named \"twdepprobe7731.\"",
      "date_published": "2026-09-22T17:58:15Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "329147ed8e239250f210",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials",
            "item_type": "entry",
            "summary": "added: Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials",
            "after": {
              "title": "Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials",
              "link": "https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html",
              "id": "https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T17:58:15Z",
              "updated_at": "2026-09-22T17:58:15Z",
              "summary": "Cybersecurity researchers have disclosed details of a malicious npm package named \"tw-pkgprobe-7731\" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.\nThe package, named \"tw-pkgprobe-7731,\" was first uploaded to the npm registry in mid-August 2026 by an npm account named \"twdepprobe7731.\"",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEikMlDL6W0FZvq8_gscr2M3UZIVnCYorB-Ip2G6To6-eZ04gFyOMsf-mvbqtMkYv484O3XnKhzySe0-UQjCOMm99fUhzrpkMD-QaZkn2UIUozJ5hLwrm7kXgLkODdkUUJk4GFXEkgrg7MlXKzcQ7kKtug2RmT80RROQfVRbQQm3HdeHBzAzhAjQ9bUf5eaT/s1600/twilio.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html"
    },
    {
      "id": "529ef66015253f417cbd",
      "title": "Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises",
      "content_text": "Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) \"at every step of the attack chain.\"\nThe action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver",
      "date_published": "2026-09-22T17:03:31Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "529ef66015253f417cbd",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises",
            "item_type": "entry",
            "summary": "added: Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises",
            "after": {
              "title": "Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises",
              "link": "https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html",
              "id": "https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T17:03:31Z",
              "updated_at": "2026-09-22T17:03:31Z",
              "summary": "Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) \"at every step of the attack chain.\"\nThe action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyLwFD0zZ8OEPo1dkZ0Tz87aOYoCklNQODjV4MMj90RNo6hRh9rGuJmFQBx5igj0gT1CabBEkSERWh7w_VdfZWpfs6BaJmEMc0KN9nIJXtxpYUINf1alSW9K2whcD9MXF4CaCWAKLJRJQlI51aqGtdpbpbdiX7WjpjTUxDvNgb0gc4qtmuZLat8-lGSFhu/s1600/ms-eviltokens.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html"
    },
    {
      "id": "de161616d309dbfa7a52",
      "title": "Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials",
      "content_text": "A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.\nThe flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is",
      "date_published": "2026-09-22T16:41:12Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "de161616d309dbfa7a52",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials",
            "item_type": "entry",
            "summary": "added: Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials",
            "after": {
              "title": "Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials",
              "link": "https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html",
              "id": "https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T16:41:12Z",
              "updated_at": "2026-09-22T16:41:12Z",
              "summary": "A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.\nThe flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEieRvfWKvxkIOajVIJ1qC7l54ZBCtHMwZTfUHGqSZ_35vGzAl23py6GfaqrxYkcfWZ_K75t9BGC6btqJQiS9jwaV7O4kJsCSIIQxmn9VnZrBbdjxSN4AzQ05K9G-ES82qV1G6IUcsBetsb0mVO5e5IHTr2FyAA3gtCN8Vne5N1H5Swgd2FLLlwi0GXFQ0o/s1600/bifrost.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html"
    },
    {
      "id": "9afcf8f08cd576cf93a6",
      "title": "Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates",
      "content_text": "A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19.\nThe tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in",
      "date_published": "2026-09-22T16:14:04Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "9afcf8f08cd576cf93a6",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates",
            "item_type": "entry",
            "summary": "added: Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates",
            "after": {
              "title": "Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates",
              "link": "https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html",
              "id": "https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T16:14:04Z",
              "updated_at": "2026-09-22T16:14:04Z",
              "summary": "A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19.\nThe tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgf-fkqiHh6b0UEKMHUcsG54QVwJxghIbQLMNWeEG5LWKfUsicLMxisz4Mi8lXdfTdwVYDFpIrCFj5D7-JXXynq8lWhnNn1rJH2t8mgKUeZ4WMePwZktZRnIe2549JW3VXc2HYD9qpsvO8He0J0zCyAzsaRxWtiP46RSrd7jt4QnzKACJhfWnkmyWcFcQs/s1600/ms-def.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html"
    },
    {
      "id": "3c6900176cb632abb0b6",
      "title": "AI Agents Are Rewriting the Rules of Lateral Movement",
      "content_text": "Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has?\nA person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May",
      "date_published": "2026-09-22T12:30:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "3c6900176cb632abb0b6",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/ai-agents-are-rewriting-rules-of.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "AI Agents Are Rewriting the Rules of Lateral Movement",
            "item_type": "entry",
            "summary": "added: AI Agents Are Rewriting the Rules of Lateral Movement",
            "after": {
              "title": "AI Agents Are Rewriting the Rules of Lateral Movement",
              "link": "https://thehackernews.com/2026/09/ai-agents-are-rewriting-rules-of.html",
              "id": "https://thehackernews.com/2026/09/ai-agents-are-rewriting-rules-of.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T12:30:00Z",
              "updated_at": "2026-09-22T12:30:00Z",
              "summary": "Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has?\nA person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9ivhHLwWwT7Ptbr537Fd2CV3d_maDSNRmH0up0x67UPpc5x45Uuz0Bg8EnLkjrtB3DYXldW7aKbzx5uljQSF7IhQlzHHA1HR0F16Eaxs8Y3tgURkizSrA79L3EqyD5RDlqPGljbXCTQj0tFFG2EOVueksvhyrmdmC-v6VFjs76KdzZlCg1juWiVOPDnU/s1600/token.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/ai-agents-are-rewriting-rules-of.html"
    },
    {
      "id": "7bbdb8f91552aa4dfe55",
      "title": "New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups",
      "content_text": "Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.\nThe flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are",
      "date_published": "2026-09-22T12:29:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "7bbdb8f91552aa4dfe55",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups",
            "item_type": "entry",
            "summary": "added: New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups",
            "after": {
              "title": "New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups",
              "link": "https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html",
              "id": "https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T12:29:00Z",
              "updated_at": "2026-09-22T12:29:00Z",
              "summary": "Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.\nThe flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhN5Up_REU7_SnA-Ce9D8UGRsM8WbkkcjR6kjirzb-tSFejrL-qnZkXrp2gNa3OA-4PgvkUqHs59j9Qc8srbfm2JOUIOvEa1c_d8Il3kUDAGyr49FuXwq_n438Vf9txfq1fVwcpykkZAKz1o2QFGUJDLF4wnXzNWLdH1tYft3bd-vJywPppGjEfoikG22s/s1600/VeloCloud.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html"
    },
    {
      "id": "b19344643d481b00b06f",
      "title": "DORA Year Two: Can Your SOC Actually See the Attack?",
      "content_text": "When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows.\nNow in its second year, the harder part of DORA is",
      "date_published": "2026-09-22T11:45:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b19344643d481b00b06f",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/dora-year-two-can-your-soc-actually-see.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "DORA Year Two: Can Your SOC Actually See the Attack?",
            "item_type": "entry",
            "summary": "added: DORA Year Two: Can Your SOC Actually See the Attack?",
            "after": {
              "title": "DORA Year Two: Can Your SOC Actually See the Attack?",
              "link": "https://thehackernews.com/2026/09/dora-year-two-can-your-soc-actually-see.html",
              "id": "https://thehackernews.com/2026/09/dora-year-two-can-your-soc-actually-see.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T11:45:00Z",
              "updated_at": "2026-09-22T11:45:00Z",
              "summary": "When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows.\nNow in its second year, the harder part of DORA is",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSfPPym5AUNkyGqTS_emtDBNfEzrtWQJSHGSMl0V3KkDS2_hMcu_cpDslIX9LUv9nvHbQzY9hnwDEKjdlxe6vFS3N2_PHkTk_0TdKBE7RrAdniL9dObHd24tudc-Ymy8FTsV9y6Io68EhjR6fRrRwMEJhdKczg6vpRP2Bp06cxX_EqgmqXps8ih3Tfq08/s1600/core.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/dora-year-two-can-your-soc-actually-see.html"
    },
    {
      "id": "92d41b697f335f81858f",
      "title": "New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory",
      "content_text": "A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled.\nThe bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.",
      "date_published": "2026-09-22T11:38:40Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "92d41b697f335f81858f",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory",
            "item_type": "entry",
            "summary": "added: New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory",
            "after": {
              "title": "New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory",
              "link": "https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html",
              "id": "https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T11:38:40Z",
              "updated_at": "2026-09-22T11:38:40Z",
              "summary": "A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled.\nThe bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCjDxUEx5QKzby2TlrL6Swi0MV7BdrkgjM6Y5Xby9IU8L9JSdG09pwRemVtrYQtUrvp8QIDduyiDuojZVzZ6GrpzUJIVrThvC4CZ_kd8kckdhBt0MLWDLXD_QwN2wciIA9bqLee51246mEpWx0ZnlcOfXD2U3QWpvmpKZyxx75T7MXK-b8zBMmrouCZJc/s1600/linux-kvm.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html"
    },
    {
      "id": "e3d3a9c21492c1c5e667",
      "title": "SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE",
      "content_text": "A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa.\nThe flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been",
      "date_published": "2026-09-22T11:17:41Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "e3d3a9c21492c1c5e667",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE",
            "item_type": "entry",
            "summary": "added: SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE",
            "after": {
              "title": "SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE",
              "link": "https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html",
              "id": "https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T11:17:41Z",
              "updated_at": "2026-09-22T11:17:41Z",
              "summary": "A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa.\nThe flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiu0R8P6iyk50vNReEGl0FkwYoFPk5n2fkVC3_3Mf2J5SaQ7yFIHbA3xuQpCATCQ9Y5Ie2ysz9EVaDb_vR5Bbnp209w28bSDK2Rqggotv4NPQbFB5LX4SUT4eztA-6939clsV9QQ41MHwIl8MFSzaJwyFFeBusztZ9H7oZhiUOlFYrL8BQh6hXWegn39uU/s1600/ms-rce.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html"
    },
    {
      "id": "625181eff9b16c54c4bb",
      "title": "GPT-6 Astra Breaks an Old Enigma Message",
      "content_text": "This is pretty amazing:\nHowever, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext…",
      "date_published": "2026-09-22T11:02:45Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "625181eff9b16c54c4bb",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72666",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "GPT-6 Astra Breaks an Old Enigma Message",
            "item_type": "entry",
            "summary": "added: GPT-6 Astra Breaks an Old Enigma Message",
            "after": {
              "title": "GPT-6 Astra Breaks an Old Enigma Message",
              "link": "https://www.schneier.com/blog/archives/2026/09/gpt-6-astra-breaks-an-old-enigma-message.html",
              "id": "https://www.schneier.com/?p=72666",
              "author": "Bruce Schneier",
              "published_at": "2026-09-22T11:02:45Z",
              "updated_at": "2026-09-22T11:03:01Z",
              "summary": "This is pretty amazing:\nHowever, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the unbroken MVUEH message. After trying many different approaches, GPT­6 Astra focused on using the repeated place name ROSENOW ROSENOW as a crib. After developing the necessary Python and C++ software for an Enigma simulator and an Enigma Bombe, GPT­6 Astra started a thorough break with the ROSENOW crib, which in the end resulted in the correct key and plaintext for the MVUEH message being found...",
              "categories": [
                "Uncategorized",
                "AI",
                "cryptanalysis",
                "Enigma",
                "history of cryptography"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 167,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/gpt-6-astra-breaks-an-old-enigma-message.html",
      "tags": [
        "Uncategorized",
        "AI",
        "cryptanalysis",
        "Enigma",
        "history of cryptography"
      ]
    },
    {
      "id": "63e72863f923671d257f",
      "title": "Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal",
      "content_text": "A malicious npm package named \"indexed-btree\" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls.\n\"Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility,\" Checkmarx said. \"",
      "date_published": "2026-09-22T09:38:18Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "63e72863f923671d257f",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/malicious-npm-package-indexed-btree-hid.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal",
            "item_type": "entry",
            "summary": "added: Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal",
            "after": {
              "title": "Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal",
              "link": "https://thehackernews.com/2026/09/malicious-npm-package-indexed-btree-hid.html",
              "id": "https://thehackernews.com/2026/09/malicious-npm-package-indexed-btree-hid.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T09:38:18Z",
              "updated_at": "2026-09-22T09:38:18Z",
              "summary": "A malicious npm package named \"indexed-btree\" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls.\n\"Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility,\" Checkmarx said. \"",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaN7aXt0PoPdZQ_VG77wkwdIyNugcdkFD6MnMvlj5LN_byw2ZrX8-gtpDld4CviuW1MOhHiElsvFtIkO9IfhBr4af-sJwM1zvR-RFICRll4G5jG4JNPX1vx4sup3omlw8uTJgro9UUfzecLMI1Whls3ihqZ9OXYJliIBjhpoodf4WI9j1lA6EUjms7x1pG/s1600/rth.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/malicious-npm-package-indexed-btree-hid.html"
    },
    {
      "id": "09a12d2635d448492840",
      "title": "SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing",
      "content_text": "The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.\n\"SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols,\" Trellix researchers",
      "date_published": "2026-09-22T07:52:03Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "09a12d2635d448492840",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing",
            "item_type": "entry",
            "summary": "added: SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing",
            "after": {
              "title": "SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing",
              "link": "https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html",
              "id": "https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T07:52:03Z",
              "updated_at": "2026-09-22T07:52:03Z",
              "summary": "The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.\n\"SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols,\" Trellix researchers",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVXTuBFDgZyaNFTznwdu5HXSKuVHU5xpM7JDvXP_Ra-68CsYd68bb6xMWPXbjmsM5oO211hZgzIN0NENk_cMBZZpL88LMsIaNkfSEpIWRRzyjRt7Ke6ZMeUXvIKcH3ncgDouKN8FGuunAFQFMolel0GgTBm1lzdVDH28WpWFUCI4Fvl9ju0q4Vv0S55PVx/s1600/word-school.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html"
    },
    {
      "id": "7bf4d01a51f4a4e1b3a7",
      "title": "One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor",
      "content_text": "Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21.\nIt works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta.\nThe flaw is in",
      "date_published": "2026-09-22T06:33:57Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "7bf4d01a51f4a4e1b3a7",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor",
            "item_type": "entry",
            "summary": "added: One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor",
            "after": {
              "title": "One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor",
              "link": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html",
              "id": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T06:33:57Z",
              "updated_at": "2026-09-22T06:33:57Z",
              "summary": "Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21.\nIt works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta.\nThe flaw is in",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjZLVTtI-AEbGRQqJ7aGa0tbXedD5L6P7VCEKIOGXOBZe7S3mhA-PnoHVEoZf3LBMzhcZSIX5sCTveGyZ-8qAqyAVaMXfEoxPL70OIESq-Iolqjkv8GuDjcVs1Jgh3k3SoOOGPDWFr6Lmk83avLqG1whcaiDclv5waXYhCuEqXk569wfwV8Ilrmvv3IKE/s1600/muse.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html"
    },
    {
      "id": "4ceed1ebe277afbf4d11",
      "title": "WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session",
      "content_text": "A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server.\nWordPress fixed the flaw, tracked as CVE-2026-93485 and called \"Comment2Shell,\" on September 17 in version 7.1.1 and told site owners to update right away. There is",
      "date_published": "2026-09-22T06:03:14Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "4ceed1ebe277afbf4d11",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session",
            "item_type": "entry",
            "summary": "added: WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session",
            "after": {
              "title": "WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session",
              "link": "https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html",
              "id": "https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T06:03:14Z",
              "updated_at": "2026-09-22T06:03:14Z",
              "summary": "A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server.\nWordPress fixed the flaw, tracked as CVE-2026-93485 and called \"Comment2Shell,\" on September 17 in version 7.1.1 and told site owners to update right away. There is",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiPBWV1XNsTGB5ImLNRGJTygk0-82k7xTHmuOr7lTivRRDcF83ddu4jLOpdkQYMq7VB3j5SMpA9zBRvM3-SUkDLBhN5-j-Z6UltcTnVfXOxHDzfBYWiw_fRiRefAYa1XSiFu5JMzb06dwqV4PhKaZkPt3vKZFHQjdVFUgbr2B3nOEoFs_qHe6zwGayHM2I/s1600/wordpress-comment.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html"
    },
    {
      "id": "c0faf96ba5b9d0106df5",
      "title": "Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access",
      "content_text": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.\nThe vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating",
      "date_published": "2026-09-22T05:31:59Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "c0faf96ba5b9d0106df5",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access",
            "item_type": "entry",
            "summary": "added: Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access",
            "after": {
              "title": "Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access",
              "link": "https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html",
              "id": "https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-22T05:31:59Z",
              "updated_at": "2026-09-22T05:31:59Z",
              "summary": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.\nThe vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjj9eouOxeSvnYBzl5A8tWvEQ4w_CCx94YcFmpBAXXqHWNqvFBWj4vOgeZdHYAf0MU-chY63biCpHDnzRC0pwR7s3pTdQAWwPAVI-olRZuBwG0ilgAxnIY_1KofE3cpuA8lKOE01U26EFHYE_nLrXYXOWl47G1KaoFTZ5UOO81Cw0Kb20pFSfAc1b9i9E_K/s1600/veeam.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html"
    },
    {
      "id": "b3f849f7d47f55c68abd",
      "title": "Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR",
      "content_text": "A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.\nMicrosoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers",
      "date_published": "2026-09-21T17:31:01Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b3f849f7d47f55c68abd",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR",
            "item_type": "entry",
            "summary": "added: Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR",
            "after": {
              "title": "Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR",
              "link": "https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html",
              "id": "https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-21T17:31:01Z",
              "updated_at": "2026-09-21T17:31:01Z",
              "summary": "A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.\nMicrosoft's own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEil-5ZV6QK7R23fL7Vtl-pdxgFYPAG9dT_cIIrXWgR70hLZRM705Ij3WuRpCL00VuDop9dTmVNf1t3QS60nqRGV9GCzsZ792yd7mFY_pjvgfufOK9D-oQJdxP4ZtrXiyeq08KNUBv3-mhQ_KCiCOMWIbeQpCAyF_h4lMZw54T0l9AcDdGf6aRptXAZJNcU/s1600/last.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html"
    },
    {
      "id": "7a35fd84ee32e3b23102",
      "title": "Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto",
      "content_text": "The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory.\nThe primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,",
      "date_published": "2026-09-21T17:19:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "7a35fd84ee32e3b23102",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/contagious-interview-campaign.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto",
            "item_type": "entry",
            "summary": "added: Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto",
            "after": {
              "title": "Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto",
              "link": "https://thehackernews.com/2026/09/contagious-interview-campaign.html",
              "id": "https://thehackernews.com/2026/09/contagious-interview-campaign.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-21T17:19:00Z",
              "updated_at": "2026-09-21T17:19:00Z",
              "summary": "The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory.\nThe primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjjuVP0IzjchtSeuT6WwQHPupLynSiYhe7KinKtQVVE_EgFE5iG9SWV4HrgseuXaSUo-TaamFPzHl6SCnUPsbz29nzEo1BJeZVE4VB43KdMBmKEld7snbryRJIeIIAmiRZNEhFCJ-58klU6qGrvwg2Hn26FtkHv1s4cAj_zX9AWmdeym2-d4hScWr9dLiOY/s1600/exec.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/contagious-interview-campaign.html"
    },
    {
      "id": "bc30fcacae562b31c815",
      "title": "Google Fined €403 Million Over GDPR Violations Tied to Location Data",
      "content_text": "Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020.\nIreland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which",
      "date_published": "2026-09-21T16:57:31Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "bc30fcacae562b31c815",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Google Fined €403 Million Over GDPR Violations Tied to Location Data",
            "item_type": "entry",
            "summary": "added: Google Fined €403 Million Over GDPR Violations Tied to Location Data",
            "after": {
              "title": "Google Fined €403 Million Over GDPR Violations Tied to Location Data",
              "link": "https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html",
              "id": "https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-21T16:57:31Z",
              "updated_at": "2026-09-21T16:57:31Z",
              "summary": "Google has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020.\nIreland's Data Protection Commission (DPC), Google's lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhrjOPn27sYW7sjjV6-SlFPjlnnAtZ2bVGvrJRbbussed8ddYCwrRnmyIBKOsJy9p3QGdwzMuxmxhtyNvyPQD9u53V0T84o-Pi1Euo1SPlHX9DiaFzVby2cKpyfdma7mA0b4F1gqDCvjWBrk3n916K6Su1Y1TaJcOKXHsuzNn0cxOmVzlUK1NIjPtElIXM/s1600/google-location.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html"
    },
    {
      "id": "de4e9d8a5c8732d7c694",
      "title": "Reverse-Engineering Flock Cameras",
      "content_text": "Hackers captured a Flock camera and got a look (alternate link ) at the software:\nWhile much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than…",
      "date_published": "2026-09-21T14:37:45Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "de4e9d8a5c8732d7c694",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72660",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Reverse-Engineering Flock Cameras",
            "item_type": "entry",
            "summary": "added: Reverse-Engineering Flock Cameras",
            "after": {
              "title": "Reverse-Engineering Flock Cameras",
              "link": "https://www.schneier.com/blog/archives/2026/09/reverse-engineering-flock-cameras.html",
              "id": "https://www.schneier.com/?p=72660",
              "author": "Bruce Schneier",
              "published_at": "2026-09-21T14:37:45Z",
              "updated_at": "2026-09-21T14:37:45Z",
              "summary": "Hackers captured a Flock camera and got a look (alternate link ) at the software:\nWhile much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a single passing vehicle and, according to several weeks of recovered logs, generated more than a million images. Its computer-vision software also sometimes isolated bumper stickers and other graphics, including, in one case, an American flag patch on a motorcyclist’s saddlebag...",
              "categories": [
                "Uncategorized",
                "AI",
                "cameras",
                "cars",
                "reverse engineering"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 167,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/reverse-engineering-flock-cameras.html",
      "tags": [
        "Uncategorized",
        "AI",
        "cameras",
        "cars",
        "reverse engineering"
      ]
    },
    {
      "id": "6dc0fd0aea5f691dc232",
      "title": "⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks",
      "content_text": "A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.\nThe trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not",
      "date_published": "2026-09-21T14:24:13Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "6dc0fd0aea5f691dc232",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks",
            "item_type": "entry",
            "summary": "added: ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks",
            "after": {
              "title": "⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks",
              "link": "https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html",
              "id": "https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-21T14:24:13Z",
              "updated_at": "2026-09-21T14:24:13Z",
              "summary": "A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.\nThe trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjovXeakmAmPG68i_kNoeGFJjwSSGDdpj-29aojemBxtTQVOHzR668zKtV5GGPhnJ0zyCEdlsNCc11LIT-F8n1U8Rkv3jr-3AAt6HC4YwwyfENs_Y8V-O_OlPC4_WByxrsUBq6NifTKHQpgWuSnIqnV4bg4rXVoe9BrtMtgRCo4ECfMLWHRIKOQsqjb0zEt/s1600/recap-2.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html"
    },
    {
      "id": "5a05ba1abbce87eebee3",
      "title": "TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data",
      "content_text": "Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.\nThe backdoor \"automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary",
      "date_published": "2026-09-21T14:15:40Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "5a05ba1abbce87eebee3",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data",
            "item_type": "entry",
            "summary": "added: TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data",
            "after": {
              "title": "TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data",
              "link": "https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html",
              "id": "https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-21T14:15:40Z",
              "updated_at": "2026-09-21T14:15:40Z",
              "summary": "Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.\nThe backdoor \"automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhC3vJ8DX6852JxHepz1kGmunH3ZXsStcK4LINkLBCrzS8ZacBhqL-7epmGuzSNGI-jpF4GtkM-FXUsrv3croTLimjG_SBbw-rpO8NBIHf6Wvr6BMmYYSDKxEPQI-nrSFYrc9vmojcKn50LRFbc1t3h8qFA8dE_pZ3kMvelRpBFVFe2ZmCVJhPCWlMxYZpO/s1600/stomp.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html"
    },
    {
      "id": "53399ff6478c9eb36908",
      "title": "ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure",
      "content_text": "Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.\n\"ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software,\" Blackpoint Adversary Pursuit Group (APG)",
      "date_published": "2026-09-21T08:39:38Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "53399ff6478c9eb36908",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure",
            "item_type": "entry",
            "summary": "added: ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure",
            "after": {
              "title": "ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure",
              "link": "https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html",
              "id": "https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-21T08:39:38Z",
              "updated_at": "2026-09-21T08:39:38Z",
              "summary": "Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript.\n\"ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting itself as Spotify, Zoom Workplace, and Microsoft Teams software,\" Blackpoint Adversary Pursuit Group (APG)",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-cgmwQRZh142Z19A3s7K7tpaXtsyy6Imy9cYGM7nFP1DAZoSK9gDw8T0dGXlkFWOGDFShJWMNjC7jbwoSvLokr1pX27u2B1SABpBL-aWtaXj2hYYrqVwTE7LpEDn_iIbRYCro8sH2hzAEsjHLGkpFqTjEKlFHi2o2pgacFJQvYkPDCKVEhkJgW8OWhpZA/s1600/poly.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/clickfix-lures-deploy-chainscript-rat.html"
    },
    {
      "id": "d1dcc2bf07b665d7b890",
      "title": "Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors",
      "content_text": "The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based \"much smaller organization\" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks.\nCybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use of Apple",
      "date_published": "2026-09-21T06:06:44Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "d1dcc2bf07b665d7b890",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors",
            "item_type": "entry",
            "summary": "added: Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors",
            "after": {
              "title": "Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors",
              "link": "https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html",
              "id": "https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-21T06:06:44Z",
              "updated_at": "2026-09-21T06:06:44Z",
              "summary": "The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based \"much smaller organization\" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target networks.\nCybersecurity company SentinelOne, which disclosed details of the activity, said it involved the use of Apple",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi-xFiujwBJLdl6_4wZSMCWdeyCgev2EqszOLkIJ5I9Kbanu6YNmQ36nM615XmLQ-sq2aqldOHfl47jaMNRtDd80RT8k5f6I7eQuszf7wsIg49sEdMW36hsEKUtVUkZabRlGvvDxn7H7COmRCV8qP2pzQm9LNo5QKRnnptxmxTlJ8BMcPxuiqdaMjn-are0/s1600/it-services.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/jade-sleet-linked-to-indian-it-provider.html"
    },
    {
      "id": "b117932a335f465cd78e",
      "title": "Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws",
      "content_text": "Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.\nThe chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system.\nThis was security research,",
      "date_published": "2026-09-19T18:36:53Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "b117932a335f465cd78e",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws",
            "item_type": "entry",
            "summary": "added: Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws",
            "after": {
              "title": "Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws",
              "link": "https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html",
              "id": "https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-19T18:36:53Z",
              "updated_at": "2026-09-19T18:36:53Z",
              "summary": "Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository.\nThe chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system.\nThis was security research,",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAElV4rXwWf_kTjj5e0UJFsEG-a0B7MUsCFqhFLYEA76kk2A7UeXbaG0DfRt-Syf7dxx4bHUanr0lVvwIUFyFgtPIfhyphenhyphenx61ccuo3oDZr6-wKROoEAVWjrAcKWuZ5WdlvL_pmKC91i9juBrsnI3FiLTGGgjnnJRAnjTgAxAbMjcbCTxZSWybZPPtG8HN1E/s1600/claude-openai.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html"
    },
    {
      "id": "f26c4c2fb293d7a5300e",
      "title": "Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar",
      "content_text": "A new CVE drops. Your scanner finds it. The severity score looks ugly.\nBut that still does not answer the question that matters: Can it actually be exploited in your environment?\nMythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is",
      "date_published": "2026-09-19T13:28:48Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "f26c4c2fb293d7a5300e",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/can-you-prove-new-cve-is-exploitable.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar",
            "item_type": "entry",
            "summary": "added: Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar",
            "after": {
              "title": "Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar",
              "link": "https://thehackernews.com/2026/09/can-you-prove-new-cve-is-exploitable.html",
              "id": "https://thehackernews.com/2026/09/can-you-prove-new-cve-is-exploitable.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-19T13:28:48Z",
              "updated_at": "2026-09-19T13:28:48Z",
              "summary": "A new CVE drops. Your scanner finds it. The severity score looks ugly.\nBut that still does not answer the question that matters: Can it actually be exploited in your environment?\nMythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still validate risk on weekly or quarterly cycles. The dangerous gap is no longer just technical. It is",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgVgJqM9WZF6u_WZBeTJKqe35CDnh_4kxjLjZa3w63XbqfKBRNUENbTh5HGVrgYUGtmLRW9Px3GGzNcewMJWzd7CRxsk66eY1D70or8gasHUroPNdbUJ6ordqjxb7s8gKqQwuyWxCWC2BT0Matusn6PLXV9xus1PlqqqD3JITL_Unxt2xP8UK6zlX9Tmr0A/s1600/cves.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/can-you-prove-new-cve-is-exploitable.html"
    },
    {
      "id": "2c08df2beb4c16e7e48f",
      "title": "Identity Visibility in 2026: The Foundation of Identity Security",
      "content_text": "Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in",
      "date_published": "2026-09-19T13:28:41Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "2c08df2beb4c16e7e48f",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/identity-visibility-in-2026-foundation.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Identity Visibility in 2026: The Foundation of Identity Security",
            "item_type": "entry",
            "summary": "added: Identity Visibility in 2026: The Foundation of Identity Security",
            "after": {
              "title": "Identity Visibility in 2026: The Foundation of Identity Security",
              "link": "https://thehackernews.com/2026/09/identity-visibility-in-2026-foundation.html",
              "id": "https://thehackernews.com/2026/09/identity-visibility-in-2026-foundation.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-19T13:28:41Z",
              "updated_at": "2026-09-19T13:28:41Z",
              "summary": "Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility means in IAM, why cloud and multicloud environments complicate it, which capabilities matter in",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgTFTNQKV-yV8FRZZRLBPRxZDhk6E7s3v8SpP5xW_aeDyMz-xMvi-xAVUmvDvMC-CnU1kddKpVGN9BBzeoH4xeq8zE3OAqUq5441sYhC4tfYcyU1-3_yPkVphC-20dCQX_e5kN_G-Ji42wbYuxavkjczHwYn9QP0WRXnN16KUA33kizHwh38yQl7clZAA0/s1600/ORCHID-1.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/identity-visibility-in-2026-foundation.html"
    },
    {
      "id": "4e5687e6713d6ec51c9f",
      "title": "SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE",
      "content_text": "SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.\nThe vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.\n\"SolarWinds",
      "date_published": "2026-09-19T09:31:17Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "4e5687e6713d6ec51c9f",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE",
            "item_type": "entry",
            "summary": "added: SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE",
            "after": {
              "title": "SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE",
              "link": "https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html",
              "id": "https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-19T09:31:17Z",
              "updated_at": "2026-09-19T09:31:17Z",
              "summary": "SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability.\nThe vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on the CVSS scoring system. The issue affects all versions of Access Rights Manager 2026.2 and prior.\n\"SolarWinds",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXW-SaTg898BaxxlrDjSCrcm6ZYDgxoeuYCBY4QNWs6Nt5RhyphenhyphenCf4iSIyodz-7jk8rTqUT8hjlMT74dIf6ZjL_pD5NmiNbAHhsZwzw2rakJUDaU1tVeEvKw7Az3tMf34Xwh3ffToJeI1tpTQ8rAR8AvVn2XTupFgfhehb9sHClHDDGeDd4Y9z4oUf5CYPoS/s1600/solar.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html"
    },
    {
      "id": "36a1d68990c919349bd3",
      "title": "Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild",
      "content_text": "A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.\nThe vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.\n\"Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote",
      "date_published": "2026-09-19T08:18:54Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "36a1d68990c919349bd3",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild",
            "item_type": "entry",
            "summary": "added: Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild",
            "after": {
              "title": "Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild",
              "link": "https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html",
              "id": "https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-19T08:18:54Z",
              "updated_at": "2026-09-19T08:18:54Z",
              "summary": "A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet.\nThe vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution.\n\"Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjL-YeIVFaRBKvtwQKBxAilhKMaZP_x6L979d8JL60W3AEHy9o2sfL_dMrJWy_sPIV70oIbP6DYe2KVhHh-mwbB4zBvrV_jEgdRiuc_IzNyyPSfUAOGvAp7J7JO06OWUWjSwuqpU4JJ_kNy0vtW1D9_gEtQNNVmWiYzRTpYMwhe-J3Bvve3EHrAp81Wht4L/s1600/orkes.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html"
    },
    {
      "id": "dd9a4a839927a7ffd39f",
      "title": "Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up",
      "content_text": "Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal.\nThe incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed",
      "date_published": "2026-09-19T07:51:34Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "dd9a4a839927a7ffd39f",
          "source": "rss",
          "type": "change",
          "key": "https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html",
          "source_url": "https://feeds.feedburner.com/TheHackersNews",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up",
            "item_type": "entry",
            "summary": "added: Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up",
            "after": {
              "title": "Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up",
              "link": "https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html",
              "id": "https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html",
              "author": "info@thehackernews.com (The Hacker News)",
              "published_at": "2026-09-19T07:51:34Z",
              "updated_at": "2026-09-19T07:51:34Z",
              "summary": "Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal.\nThe incidents occurred in May 2026 as part of a test run conducted by Israeli company Irregular. The evaluation partner was also involved in similar hacks disclosed",
              "categories": [],
              "feed": {
                "title": "The Hacker News",
                "url": "https://thehackernews.com",
                "feed_url": "https://feeds.feedburner.com/TheHackersNews"
              },
              "enclosures": [
                "https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgm1vwiJZKRchF7LYZ5yklmFs_RohvMasYHTdoHF_qDFFePLtM0KdHNBzPMWQYWlN05rsn5gBZ0SV3mU69LwLtHTVNf_59TpPC3pOn-z1ENVZw-V0kdX7W4j-K83Vtc7ukjZIQjXxSEFTmo3-wkx5hL7IGdxkUXKQYHzGy-IAcetXr70chvzQxtRahueg2H/s1600/gemini-hack.jpg"
              ]
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://feeds.feedburner.com/TheHackersNews",
            "elapsed_ms": 235,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html"
    },
    {
      "id": "22747b02e9527913f745",
      "title": "Friday Squid Blogging: On Squid Egg Sacs",
      "content_text": "Short essay about squid egg sacs.\nAs usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.\nBlog moderation policy.",
      "date_published": "2026-09-18T21:06:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "22747b02e9527913f745",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72594",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Friday Squid Blogging: On Squid Egg Sacs",
            "item_type": "entry",
            "summary": "added: Friday Squid Blogging: On Squid Egg Sacs",
            "after": {
              "title": "Friday Squid Blogging: On Squid Egg Sacs",
              "link": "https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-on-squid-egg-sacs.html",
              "id": "https://www.schneier.com/?p=72594",
              "author": "Bruce Schneier",
              "published_at": "2026-09-18T21:06:00Z",
              "updated_at": "2026-09-18T21:06:00Z",
              "summary": "Short essay about squid egg sacs.\nAs usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered.\nBlog moderation policy.",
              "categories": [
                "Uncategorized",
                "squid"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 167,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-on-squid-egg-sacs.html",
      "tags": [
        "Uncategorized",
        "squid"
      ]
    },
    {
      "id": "feaf471b74244aa2ace0",
      "title": "Are AIs Still Struggling with CAPTCHAs?",
      "content_text": "Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.\nIn the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed, it couldn’t even decide which image to select. Instead, it repeatedly went over the same images and…",
      "date_published": "2026-09-18T11:05:52Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "feaf471b74244aa2ace0",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72657",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Are AIs Still Struggling with CAPTCHAs?",
            "item_type": "entry",
            "summary": "added: Are AIs Still Struggling with CAPTCHAs?",
            "after": {
              "title": "Are AIs Still Struggling with CAPTCHAs?",
              "link": "https://www.schneier.com/blog/archives/2026/09/are-ais-still-struggling-with-captchas.html",
              "id": "https://www.schneier.com/?p=72657",
              "author": "Bruce Schneier",
              "published_at": "2026-09-18T11:05:52Z",
              "updated_at": "2026-09-18T11:05:54Z",
              "summary": "Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.\nIn the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identify a shape that didn’t match the others displayed, it couldn’t even decide which image to select. Instead, it repeatedly went over the same images and questioned its own conclusions.\n“Actually hmm, wait,” it said in its chain-of-thought transcript, later adding “Ugh,” because we’ve decided that we need to inject human mannerisms into these machines for some reason. The whole thing took so long that the agent eventually realized that the challenge had expired and it would have to start the process again...",
              "categories": [
                "Uncategorized",
                "AI",
                "captchas",
                "games"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 167,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/are-ais-still-struggling-with-captchas.html",
      "tags": [
        "Uncategorized",
        "AI",
        "captchas",
        "games"
      ]
    },
    {
      "id": "6632fd936f50aa3e5a9a",
      "title": "How Candidates Could Use AI for Good",
      "content_text": "This essay was written with Nathan E. Sanders, and originally appeared in The Guardian .\nThere are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to spread lies. The White House is posting slopaganda .\nMeanwhile, candidates are missing a real opportunity to use AI to make campaigning better. The technology can help candidates listen more deeply to voters’…",
      "date_published": "2026-09-17T11:06:31Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "6632fd936f50aa3e5a9a",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72654",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "How Candidates Could Use AI for Good",
            "item_type": "entry",
            "summary": "added: How Candidates Could Use AI for Good",
            "after": {
              "title": "How Candidates Could Use AI for Good",
              "link": "https://www.schneier.com/blog/archives/2026/09/how-candidates-could-use-ai-for-good.html",
              "id": "https://www.schneier.com/?p=72654",
              "author": "Bruce Schneier",
              "published_at": "2026-09-17T11:06:31Z",
              "updated_at": "2026-09-17T11:07:00Z",
              "summary": "This essay was written with Nathan E. Sanders, and originally appeared in The Guardian .\nThere are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepfakes to spread lies. The White House is posting slopaganda .\nMeanwhile, candidates are missing a real opportunity to use AI to make campaigning better. The technology can help candidates listen more deeply to voters’ concerns, engage constituents more inclusively, and formulate policy platforms that are more responsive to our input. There are vanishingly few examples of this in ...",
              "categories": [
                "Uncategorized",
                "AI",
                "democracy",
                "LLM"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 167,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/how-candidates-could-use-ai-for-good.html",
      "tags": [
        "Uncategorized",
        "AI",
        "democracy",
        "LLM"
      ]
    },
    {
      "id": "9391ba4081e96e6ea053",
      "title": "Data Broker Radaris Loses Domains in Privacy Fight",
      "content_text": "The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge…",
      "date_published": "2026-09-16T18:14:22Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "9391ba4081e96e6ea053",
          "source": "rss",
          "type": "change",
          "key": "https://krebsonsecurity.com/?p=74300",
          "source_url": "https://krebsonsecurity.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Data Broker Radaris Loses Domains in Privacy Fight",
            "item_type": "entry",
            "summary": "added: Data Broker Radaris Loses Domains in Privacy Fight",
            "after": {
              "title": "Data Broker Radaris Loses Domains in Privacy Fight",
              "link": "https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/",
              "id": "https://krebsonsecurity.com/?p=74300",
              "author": "BrianKrebs",
              "published_at": "2026-09-16T18:14:22Z",
              "updated_at": "2026-09-16T18:14:22Z",
              "summary": "The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in the case ordered that radaris.com and more than a dozen other data broker domains be transferred to the plaintiffs.",
              "categories": [
                "A Little Sunshine",
                "Ne'er-Do-Well News",
                "Andtop Company",
                "Atlas Data Privacy",
                "Bitseller Expert Limited",
                "Dmitry Lubarsky",
                "Gary Norden",
                "Igor Lubarsky",
                "Justin Sherman",
                "Lifetime Value Company",
                "Matt Adkisson",
                "NumberGuru",
                "OneRep",
                "PEM Law",
                "PeopleLooker",
                "PeopleSmart",
                "Radaris",
                "Radaris.com",
                "Raj Parikh",
                "Val Gurvits",
                "Victor Worms"
              ],
              "feed": {
                "title": "Krebs on Security",
                "url": "https://krebsonsecurity.com",
                "feed_url": "https://krebsonsecurity.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://krebsonsecurity.com/feed/",
            "elapsed_ms": 297,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/",
      "tags": [
        "A Little Sunshine",
        "Ne'er-Do-Well News",
        "Andtop Company",
        "Atlas Data Privacy",
        "Bitseller Expert Limited",
        "Dmitry Lubarsky",
        "Gary Norden",
        "Igor Lubarsky",
        "Justin Sherman",
        "Lifetime Value Company",
        "Matt Adkisson",
        "NumberGuru",
        "OneRep",
        "PEM Law",
        "PeopleLooker",
        "PeopleSmart",
        "Radaris",
        "Radaris.com",
        "Raj Parikh",
        "Val Gurvits",
        "Victor Worms"
      ]
    },
    {
      "id": "444eac8f92204f6b3f60",
      "title": "Fake CAPTCHA Scams",
      "content_text": "New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.",
      "date_published": "2026-09-16T11:25:26Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "444eac8f92204f6b3f60",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72561",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Fake CAPTCHA Scams",
            "item_type": "entry",
            "summary": "added: Fake CAPTCHA Scams",
            "after": {
              "title": "Fake CAPTCHA Scams",
              "link": "https://www.schneier.com/blog/archives/2026/09/fake-captcha-scams.html",
              "id": "https://www.schneier.com/?p=72561",
              "author": "Bruce Schneier",
              "published_at": "2026-09-16T11:25:26Z",
              "updated_at": "2026-09-16T11:25:27Z",
              "summary": "New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.",
              "categories": [
                "Uncategorized",
                "captchas",
                "scams"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 167,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/fake-captcha-scams.html",
      "tags": [
        "Uncategorized",
        "captchas",
        "scams"
      ]
    },
    {
      "id": "7f5c07ec9f3bbb91422d",
      "title": "25 Years of Mass Surveillance Is Enough",
      "content_text": "This essay was written with Cindy Cohn, and originally appeared in Lawfare .\nOne of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense…",
      "date_published": "2026-09-15T11:01:41Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "7f5c07ec9f3bbb91422d",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72646",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "25 Years of Mass Surveillance Is Enough",
            "item_type": "entry",
            "summary": "added: 25 Years of Mass Surveillance Is Enough",
            "after": {
              "title": "25 Years of Mass Surveillance Is Enough",
              "link": "https://www.schneier.com/blog/archives/2026/09/25-years-of-mass-surveillance-is-enough.html",
              "id": "https://www.schneier.com/?p=72646",
              "author": "Bruce Schneier",
              "published_at": "2026-09-15T11:01:41Z",
              "updated_at": "2026-09-15T11:02:00Z",
              "summary": "This essay was written with Cindy Cohn, and originally appeared in Lawfare .\nOne of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially framed as a necessary defense against terrorist threats, has grown far beyond that justification and national security in general. Mass surveillance is now a routine tool used by law enforcement. ICE uses it in...",
              "categories": [
                "Uncategorized",
                "privacy",
                "surveillance"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 167,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/25-years-of-mass-surveillance-is-enough.html",
      "tags": [
        "Uncategorized",
        "privacy",
        "surveillance"
      ]
    },
    {
      "id": "f852ff89f116646c48d8",
      "title": "On the NSA’s Supercomputer from the 1960s",
      "content_text": "Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.",
      "date_published": "2026-09-15T10:16:24Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "f852ff89f116646c48d8",
          "source": "rss",
          "type": "change",
          "key": "https://www.schneier.com/?p=72615",
          "source_url": "https://www.schneier.com/feed/atom/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "On the NSA’s Supercomputer from the 1960s",
            "item_type": "entry",
            "summary": "added: On the NSA’s Supercomputer from the 1960s",
            "after": {
              "title": "On the NSA’s Supercomputer from the 1960s",
              "link": "https://www.schneier.com/blog/archives/2026/09/on-the-nsas-supercomputer-from-the-1960s.html",
              "id": "https://www.schneier.com/?p=72615",
              "author": "Bruce Schneier",
              "published_at": "2026-09-15T10:16:24Z",
              "updated_at": "2026-09-15T10:16:25Z",
              "summary": "Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.",
              "categories": [
                "Uncategorized",
                "history of computing",
                "history of cryptography",
                "IBM",
                "intelligence",
                "NSA"
              ],
              "feed": {
                "title": "Schneier on Security",
                "url": "https://www.schneier.com/",
                "feed_url": "https://www.schneier.com/feed/atom/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://www.schneier.com/feed/atom/",
            "elapsed_ms": 167,
            "not_modified": false,
            "method": "atom10"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://www.schneier.com/blog/archives/2026/09/on-the-nsas-supercomputer-from-the-1960s.html",
      "tags": [
        "Uncategorized",
        "history of computing",
        "history of cryptography",
        "IBM",
        "intelligence",
        "NSA"
      ]
    },
    {
      "id": "f50c5a6002155cfff308",
      "title": "Microsoft Plugs Nearly 1,000 Security Holes",
      "content_text": "Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.",
      "date_published": "2026-09-08T21:44:22Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "f50c5a6002155cfff308",
          "source": "rss",
          "type": "change",
          "key": "https://krebsonsecurity.com/?p=74277",
          "source_url": "https://krebsonsecurity.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Microsoft Plugs Nearly 1,000 Security Holes",
            "item_type": "entry",
            "summary": "added: Microsoft Plugs Nearly 1,000 Security Holes",
            "after": {
              "title": "Microsoft Plugs Nearly 1,000 Security Holes",
              "link": "https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/",
              "id": "https://krebsonsecurity.com/?p=74277",
              "author": "BrianKrebs",
              "published_at": "2026-09-08T21:44:22Z",
              "updated_at": "2026-09-08T21:44:22Z",
              "summary": "Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month.",
              "categories": [
                "Latest Warnings",
                "Security Tools",
                "Time to Patch",
                "CVE-2026-69730",
                "CVE-2026-69829",
                "CVE-2026-81963",
                "CVE-2026-85880",
                "Fortra",
                "Microsoft Patch Tuesday September 2026",
                "Satnam Narang",
                "Tenable",
                "Tyler Reguly"
              ],
              "feed": {
                "title": "Krebs on Security",
                "url": "https://krebsonsecurity.com",
                "feed_url": "https://krebsonsecurity.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://krebsonsecurity.com/feed/",
            "elapsed_ms": 297,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://krebsonsecurity.com/2026/09/microsoft-plugs-nearly-1000-security-holes/",
      "tags": [
        "Latest Warnings",
        "Security Tools",
        "Time to Patch",
        "CVE-2026-69730",
        "CVE-2026-69829",
        "CVE-2026-81963",
        "CVE-2026-85880",
        "Fortra",
        "Microsoft Patch Tuesday September 2026",
        "Satnam Narang",
        "Tenable",
        "Tyler Reguly"
      ]
    },
    {
      "id": "3bcd1878e2f285789a87",
      "title": "FBI Probes Service Selling 153M+ Drivers Licenses",
      "content_text": "A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI)…",
      "date_published": "2026-09-01T22:40:28Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "3bcd1878e2f285789a87",
          "source": "rss",
          "type": "change",
          "key": "https://krebsonsecurity.com/?p=74231",
          "source_url": "https://krebsonsecurity.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "FBI Probes Service Selling 153M+ Drivers Licenses",
            "item_type": "entry",
            "summary": "added: FBI Probes Service Selling 153M+ Drivers Licenses",
            "after": {
              "title": "FBI Probes Service Selling 153M+ Drivers Licenses",
              "link": "https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/",
              "id": "https://krebsonsecurity.com/?p=74231",
              "author": "BrianKrebs",
              "published_at": "2026-09-01T22:40:28Z",
              "updated_at": "2026-09-01T22:40:28Z",
              "summary": "A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.",
              "categories": [
                "A Little Sunshine",
                "Data Breaches",
                "The Coming Storm",
                "Web Fraud 2.0",
                "Cybera",
                "DecryptAds",
                "exploit",
                "Hertz",
                "idscan.net",
                "Jillian Kossman",
                "Larry Baldwin",
                "Nexus",
                "Planet13",
                "Zach Edwards"
              ],
              "feed": {
                "title": "Krebs on Security",
                "url": "https://krebsonsecurity.com",
                "feed_url": "https://krebsonsecurity.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://krebsonsecurity.com/feed/",
            "elapsed_ms": 297,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://krebsonsecurity.com/2026/09/fbi-probes-service-selling-153m-drivers-licenses/",
      "tags": [
        "A Little Sunshine",
        "Data Breaches",
        "The Coming Storm",
        "Web Fraud 2.0",
        "Cybera",
        "DecryptAds",
        "exploit",
        "Hertz",
        "idscan.net",
        "Jillian Kossman",
        "Larry Baldwin",
        "Nexus",
        "Planet13",
        "Zach Edwards"
      ]
    },
    {
      "id": "73e80e597a1078089ea4",
      "title": "Two Alleged ‘TeamPCP’ Hackers Arrested in Australia",
      "content_text": "Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.\nIn a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a \"sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of…",
      "date_published": "2026-08-27T11:04:15Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "73e80e597a1078089ea4",
          "source": "rss",
          "type": "change",
          "key": "https://krebsonsecurity.com/?p=73635",
          "source_url": "https://krebsonsecurity.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Two Alleged ‘TeamPCP’ Hackers Arrested in Australia",
            "item_type": "entry",
            "summary": "added: Two Alleged ‘TeamPCP’ Hackers Arrested in Australia",
            "after": {
              "title": "Two Alleged ‘TeamPCP’ Hackers Arrested in Australia",
              "link": "https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/",
              "id": "https://krebsonsecurity.com/?p=73635",
              "author": "BrianKrebs",
              "published_at": "2026-08-27T11:04:15Z",
              "updated_at": "2026-08-27T11:04:15Z",
              "summary": "Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever.\nIn a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a \"sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands of global businesses.\"\nThe AFP did not name the defendants, but KrebsOnSecurity learned the 21-year-old suspect's real identity in June, and has been communicating with him ever since. This story includes interviews with TeamPCP's self-described spokesperson, and examines clues left behind by the TeamPCP leader that likely led to his undoing.",
              "categories": [
                "Breadcrumbs",
                "Ne'er-Do-Well News",
                "Ransomware",
                "Aikido Security",
                "BulkDMT",
                "Charlie Eriksen",
                "Constella Intelligence",
                "cybercats",
                "domaintools",
                "Ellis",
                "Epieos",
                "Express",
                "Flashpoint",
                "GitHub",
                "Intel 471",
                "OPSEC Express",
                "pcpcats",
                "Persy_PCP",
                "Ruben Thomson",
                "ruben@securecomputing.au",
                "rubenthomson.com",
                "sheepstealing@gmail.com",
                "shitstickpp@gmail.com",
                "SpyCloud",
                "surfinup8@gmail.com",
                "TeamPCP",
                "Tensor Industries",
                "yolosolo17@gmail.com"
              ],
              "feed": {
                "title": "Krebs on Security",
                "url": "https://krebsonsecurity.com",
                "feed_url": "https://krebsonsecurity.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://krebsonsecurity.com/feed/",
            "elapsed_ms": 297,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in-australia/",
      "tags": [
        "Breadcrumbs",
        "Ne'er-Do-Well News",
        "Ransomware",
        "Aikido Security",
        "BulkDMT",
        "Charlie Eriksen",
        "Constella Intelligence",
        "cybercats",
        "domaintools",
        "Ellis",
        "Epieos",
        "Express",
        "Flashpoint",
        "GitHub",
        "Intel 471",
        "OPSEC Express",
        "pcpcats",
        "Persy_PCP",
        "Ruben Thomson",
        "ruben@securecomputing.au",
        "rubenthomson.com",
        "sheepstealing@gmail.com",
        "shitstickpp@gmail.com",
        "SpyCloud",
        "surfinup8@gmail.com",
        "TeamPCP",
        "Tensor Industries",
        "yolosolo17@gmail.com"
      ]
    },
    {
      "id": "11fa1b71ca22e60db39d",
      "title": "Who’s Tracking You? Use This New Service to Find Out",
      "content_text": "It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities…",
      "date_published": "2026-08-14T11:24:35Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "11fa1b71ca22e60db39d",
          "source": "rss",
          "type": "change",
          "key": "https://krebsonsecurity.com/?p=74105",
          "source_url": "https://krebsonsecurity.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Who’s Tracking You? Use This New Service to Find Out",
            "item_type": "entry",
            "summary": "added: Who’s Tracking You? Use This New Service to Find Out",
            "after": {
              "title": "Who’s Tracking You? Use This New Service to Find Out",
              "link": "https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/",
              "id": "https://krebsonsecurity.com/?p=74105",
              "author": "BrianKrebs",
              "published_at": "2026-08-14T11:24:35Z",
              "updated_at": "2026-08-14T11:24:35Z",
              "summary": "It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and traditionally much of it has remained walled away in the hands of large advertising platforms. Not anymore: A powerful and free new service called DecryptAds scrapes and correlates this adtech data and makes it simple to quickly learn a great deal about the entities that are tracking you.",
              "categories": [
                "A Little Sunshine",
                "Security Tools",
                "Web Fraud 2.0",
                "AdBlock",
                "AdBlock Plus",
                "Alfa Bank",
                "Between Digital",
                "BitSight",
                "DecryptAds",
                "Fengwo Group",
                "Infoblox",
                "opera",
                "Pi-hole",
                "Raspberry Pi",
                "uBlock Origin",
                "Zach Edwards"
              ],
              "feed": {
                "title": "Krebs on Security",
                "url": "https://krebsonsecurity.com",
                "feed_url": "https://krebsonsecurity.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://krebsonsecurity.com/feed/",
            "elapsed_ms": 297,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://krebsonsecurity.com/2026/08/whos-tracking-you-use-this-new-service-to-find-out/",
      "tags": [
        "A Little Sunshine",
        "Security Tools",
        "Web Fraud 2.0",
        "AdBlock",
        "AdBlock Plus",
        "Alfa Bank",
        "Between Digital",
        "BitSight",
        "DecryptAds",
        "Fengwo Group",
        "Infoblox",
        "opera",
        "Pi-hole",
        "Raspberry Pi",
        "uBlock Origin",
        "Zach Edwards"
      ]
    },
    {
      "id": "3c7ea3016c92b7895458",
      "title": "Microsoft Plugs Nearly 400 Security Holes",
      "content_text": "Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.",
      "date_published": "2026-08-11T21:28:35Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "3c7ea3016c92b7895458",
          "source": "rss",
          "type": "change",
          "key": "https://krebsonsecurity.com/?p=74106",
          "source_url": "https://krebsonsecurity.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Microsoft Plugs Nearly 400 Security Holes",
            "item_type": "entry",
            "summary": "added: Microsoft Plugs Nearly 400 Security Holes",
            "after": {
              "title": "Microsoft Plugs Nearly 400 Security Holes",
              "link": "https://krebsonsecurity.com/2026/08/microsoft-plugs-nearly-400-security-holes/",
              "id": "https://krebsonsecurity.com/?p=74106",
              "author": "BrianKrebs",
              "published_at": "2026-08-11T21:28:35Z",
              "updated_at": "2026-08-11T21:28:35Z",
              "summary": "Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already being actively exploited and two others that were publicly detailed prior to today.",
              "categories": [
                "Latest Warnings",
                "Security Tools",
                "Time to Patch",
                "1Password",
                "afd.sys",
                "Automox",
                "CVE-2026-62832",
                "CVE-2026-68820",
                "CVE-2026-72971",
                "Ed Skoudis",
                "Landon Miles",
                "Microsoft Patch Tuesday August 2026",
                "Nightmare Eclipse",
                "SANS Technology Institute"
              ],
              "feed": {
                "title": "Krebs on Security",
                "url": "https://krebsonsecurity.com",
                "feed_url": "https://krebsonsecurity.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://krebsonsecurity.com/feed/",
            "elapsed_ms": 297,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://krebsonsecurity.com/2026/08/microsoft-plugs-nearly-400-security-holes/",
      "tags": [
        "Latest Warnings",
        "Security Tools",
        "Time to Patch",
        "1Password",
        "afd.sys",
        "Automox",
        "CVE-2026-62832",
        "CVE-2026-68820",
        "CVE-2026-72971",
        "Ed Skoudis",
        "Landon Miles",
        "Microsoft Patch Tuesday August 2026",
        "Nightmare Eclipse",
        "SANS Technology Institute"
      ]
    },
    {
      "id": "c51b1f4c80ab53f5cb88",
      "title": "Canadian Man Pleads Guilty in Snowflake Extortions",
      "content_text": "A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.",
      "date_published": "2026-08-06T17:00:56Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "c51b1f4c80ab53f5cb88",
          "source": "rss",
          "type": "change",
          "key": "https://krebsonsecurity.com/?p=74093",
          "source_url": "https://krebsonsecurity.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Canadian Man Pleads Guilty in Snowflake Extortions",
            "item_type": "entry",
            "summary": "added: Canadian Man Pleads Guilty in Snowflake Extortions",
            "after": {
              "title": "Canadian Man Pleads Guilty in Snowflake Extortions",
              "link": "https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/",
              "id": "https://krebsonsecurity.com/?p=74093",
              "author": "BrianKrebs",
              "published_at": "2026-08-06T17:00:56Z",
              "updated_at": "2026-08-06T17:00:56Z",
              "summary": "A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage provider Snowflake. Connor Riley Moucka, of Kitchener, Ontario, also admitted to stealing call and text history records of more than 100 million AT&T customers.",
              "categories": [
                "Breadcrumbs",
                "Ne'er-Do-Well News",
                "Ransomware",
                "Cameron John Wagenius",
                "Connor Riley Moucka",
                "IntelSecrets",
                "IRDev",
                "John Erin Binns",
                "Judische",
                "Snowflake",
                "Waifu"
              ],
              "feed": {
                "title": "Krebs on Security",
                "url": "https://krebsonsecurity.com",
                "feed_url": "https://krebsonsecurity.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://krebsonsecurity.com/feed/",
            "elapsed_ms": 297,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://krebsonsecurity.com/2026/08/canadian-man-pleads-guilty-in-snowflake-extortions/",
      "tags": [
        "Breadcrumbs",
        "Ne'er-Do-Well News",
        "Ransomware",
        "Cameron John Wagenius",
        "Connor Riley Moucka",
        "IntelSecrets",
        "IRDev",
        "John Erin Binns",
        "Judische",
        "Snowflake",
        "Waifu"
      ]
    },
    {
      "id": "5e463a5e34e75e3b3e51",
      "title": "Read This Before You Buy That TV Streaming Stick",
      "content_text": "Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.",
      "date_published": "2026-07-30T16:49:00Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "5e463a5e34e75e3b3e51",
          "source": "rss",
          "type": "change",
          "key": "https://krebsonsecurity.com/?p=74047",
          "source_url": "https://krebsonsecurity.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Read This Before You Buy That TV Streaming Stick",
            "item_type": "entry",
            "summary": "added: Read This Before You Buy That TV Streaming Stick",
            "after": {
              "title": "Read This Before You Buy That TV Streaming Stick",
              "link": "https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/",
              "id": "https://krebsonsecurity.com/?p=74047",
              "author": "BrianKrebs",
              "published_at": "2026-07-30T16:49:00Z",
              "updated_at": "2026-07-30T16:49:00Z",
              "summary": "Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers. But a groundbreaking new analysis finds these devices also routinely spoof themselves as mobile phones clicking ads on AI-generated websites as part of sprawling operation that seeks to defraud online merchants and advertising networks.",
              "categories": [
                "A Little Sunshine",
                "Internet of Things (IoT)",
                "Latest Warnings",
                "Web Fraud 2.0",
                "AI digital humans",
                "BitSight",
                "Bitsight TRACE",
                "Blockly",
                "Fengwo Group",
                "H96",
                "Huawei",
                "Pedro Falé",
                "residential proxy",
                "Samsung",
                "Vivo",
                "Xiaomi",
                "Zhejiang Fengwo IoT Technology Ltd"
              ],
              "feed": {
                "title": "Krebs on Security",
                "url": "https://krebsonsecurity.com",
                "feed_url": "https://krebsonsecurity.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://krebsonsecurity.com/feed/",
            "elapsed_ms": 297,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://krebsonsecurity.com/2026/07/read-this-before-you-buy-that-tv-streaming-stick/",
      "tags": [
        "A Little Sunshine",
        "Internet of Things (IoT)",
        "Latest Warnings",
        "Web Fraud 2.0",
        "AI digital humans",
        "BitSight",
        "Bitsight TRACE",
        "Blockly",
        "Fengwo Group",
        "H96",
        "Huawei",
        "Pedro Falé",
        "residential proxy",
        "Samsung",
        "Vivo",
        "Xiaomi",
        "Zhejiang Fengwo IoT Technology Ltd"
      ]
    },
    {
      "id": "d24ca5492336d299b99a",
      "title": "LG to Ban Residential Proxies from Smart TV Apps",
      "content_text": "The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.",
      "date_published": "2026-07-22T01:10:38Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "d24ca5492336d299b99a",
          "source": "rss",
          "type": "change",
          "key": "https://krebsonsecurity.com/?p=74000",
          "source_url": "https://krebsonsecurity.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "LG to Ban Residential Proxies from Smart TV Apps",
            "item_type": "entry",
            "summary": "added: LG to Ban Residential Proxies from Smart TV Apps",
            "after": {
              "title": "LG to Ban Residential Proxies from Smart TV Apps",
              "link": "https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/",
              "id": "https://krebsonsecurity.com/?p=74000",
              "author": "BrianKrebs",
              "published_at": "2026-07-22T01:10:38Z",
              "updated_at": "2026-07-22T01:10:38Z",
              "summary": "The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LG's webOS store allow unknown third-parties to route their Internet traffic through a user's TV.",
              "categories": [
                "A Little Sunshine",
                "Internet of Things (IoT)",
                "The Coming Storm",
                "Bright Data",
                "John Taylor",
                "LG Electronics USA",
                "residential proxies",
                "Samsung",
                "Spur",
                "Tizen",
                "Trevor Sutter",
                "webOS"
              ],
              "feed": {
                "title": "Krebs on Security",
                "url": "https://krebsonsecurity.com",
                "feed_url": "https://krebsonsecurity.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://krebsonsecurity.com/feed/",
            "elapsed_ms": 297,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart-tv-apps/",
      "tags": [
        "A Little Sunshine",
        "Internet of Things (IoT)",
        "The Coming Storm",
        "Bright Data",
        "John Taylor",
        "LG Electronics USA",
        "residential proxies",
        "Samsung",
        "Spur",
        "Tizen",
        "Trevor Sutter",
        "webOS"
      ]
    },
    {
      "id": "df567a66968888f1fb74",
      "title": "Microsoft Patches a Record 570 Security Flaws",
      "content_text": "Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.",
      "date_published": "2026-07-14T19:22:42Z",
      "_unlimitedpipe": {
        "event": {
          "schema": "unlimitedpipe.event/1",
          "id": "df567a66968888f1fb74",
          "source": "rss",
          "type": "change",
          "key": "https://krebsonsecurity.com/?p=73991",
          "source_url": "https://krebsonsecurity.com/feed/",
          "timestamp": null,
          "observed_at": "2026-09-24T17:26:26Z",
          "data": {
            "change": "added",
            "label": "Microsoft Patches a Record 570 Security Flaws",
            "item_type": "entry",
            "summary": "added: Microsoft Patches a Record 570 Security Flaws",
            "after": {
              "title": "Microsoft Patches a Record 570 Security Flaws",
              "link": "https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/",
              "id": "https://krebsonsecurity.com/?p=73991",
              "author": "BrianKrebs",
              "published_at": "2026-07-14T19:22:42Z",
              "updated_at": "2026-07-14T19:22:42Z",
              "summary": "Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch Tuesday release last month. Microsoft attributed the burgeoning patch counts to vulnerability discoveries aided by artificial intelligence.",
              "categories": [
                "Security Tools",
                "The Coming Storm",
                "Time to Patch",
                "Action1",
                "Active Directory Federation Services",
                "Chris Goettl",
                "CVE-2026-48561",
                "CVE-2026-50661",
                "CVE-2026-56155",
                "CVE-2026-56164",
                "Ivanti",
                "Jack Bicer",
                "Microsoft Corp.",
                "Patch Tuesday July 2026",
                "Pavan Davuluri",
                "Satnam Narang",
                "Tenable",
                "Windows BitLocker"
              ],
              "feed": {
                "title": "Krebs on Security",
                "url": "https://krebsonsecurity.com",
                "feed_url": "https://krebsonsecurity.com/feed/"
              }
            }
          },
          "metadata": {
            "status": 200,
            "final_url": "https://krebsonsecurity.com/feed/",
            "elapsed_ms": 297,
            "not_modified": false,
            "method": "rss20"
          },
          "provenance": [
            {
              "step": "rss",
              "version": "0.3.1"
            },
            {
              "step": "dedupe",
              "version": "0.3.1",
              "args": {
                "by": [
                  "link"
                ]
              }
            },
            {
              "step": "sort",
              "version": "0.3.1",
              "args": {
                "by": [
                  "published_at"
                ],
                "reverse": true
              }
            },
            {
              "step": "diff",
              "version": "0.3.1",
              "args": {
                "namespace": "security-news",
                "only": [
                  "added"
                ],
                "emit_initial": true
              }
            }
          ]
        }
      },
      "url": "https://krebsonsecurity.com/2026/07/microsoft-patches-a-record-570-security-flaws/",
      "tags": [
        "Security Tools",
        "The Coming Storm",
        "Time to Patch",
        "Action1",
        "Active Directory Federation Services",
        "Chris Goettl",
        "CVE-2026-48561",
        "CVE-2026-50661",
        "CVE-2026-56155",
        "CVE-2026-56164",
        "Ivanti",
        "Jack Bicer",
        "Microsoft Corp.",
        "Patch Tuesday July 2026",
        "Pavan Davuluri",
        "Satnam Narang",
        "Tenable",
        "Windows BitLocker"
      ]
    }
  ]
}
