MalwareTips Newswire

Security updates, independent AV tests and useful news for the MalwareTips community.
BleepingComputer ·

The EU CRA's Real Question: What Shipped, and When Did You Know?

The EU Cyber Resilience Act's vulnerability reporting requirements take effect September 11, giving software vendors as little as 24 hours to report actively exploited flaws. ActiveState explains why knowing exactly what shipped and when vulnerabilities were discovered will be critical to meeting the new requirements. [...]
Read original article
Zero Day Initiative ·

The September 2026 Security Update Review

Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extend break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check out the Patch Report webcast on our YouTube channel. It should be posted within a couple of hours after the release. Adobe Patches for September 2026 For the first part of the August release, Adobe released 10 bulletins addressing 172 unique CVEs in Adobe ColdFusion, Acrobat Reader, Commerce (two bulletins), Campaign Classic, Experience Manager, Photoshop, Illustrator, Animate, and Adobe Photoshop Mobile. Here’s this month’s overview table: Adobe Patches for September 2026 Adobe Patches for September 2026 Bulletin ID Product CVE Count Highest Severity Highest CVSS Exploited Deployment Priority APSB26-146 Adobe Commerce 1 Critical 10.0 Yes 1 APSB26-142 Adobe Campaign Classic 1 Critical 10.0 No 1 APSB26-119 Adobe ColdFusion 9 Critical 9.9 No 1 APSB26-98 Adobe Experience Manager 107 Critical 9.9 No 2 APSB26-138 Adobe Commerce 8 Critical 9.3 No 2 APSB26-141 Adobe Acrobat and Reader 32 Critical 8.8 No 2 APSB26-130 Adobe Photoshop 8 Critical 8.6 No 3 APSB26-131 Adobe Illustrator 3 Critical 8.6 No 3
Read original article
The Hacker News ·

Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution

A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversary demonstrates deep operational knowledge of Brazilian financial infrastructure, including the instant payment
Read original article
Help Net Security ·

Threat actors are giving AI agents a bigger role in cyberattacks

AI agents are automating parts of cyberattacks with less human involvement, including vulnerability scanning, credential harvesting, and troubleshooting, according to Google Threat Intelligence Group’s Q3 2026 AI Threat Tracker. (Source: Google) The report draws on Mandiant incident response engagements, threat actor tracking, and live platform defenses. Researchers observed attackers moving from basic prompts toward workflows where AI systems handle several connected tasks. A six-hour credential theft campaign In Q2 2026, Mandiant investigated a suspected financially … More → The post Threat actors are giving AI agents a bigger role in cyberattacks appeared first on Help Net Security.
Read original article
Help Net Security ·

Mars Security brings threat intelligence to detection in real time

Mars Security has announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts advisories from CISA, Mandiant, and other intelligence sources into MITRE ATT&CK-mapped detection rules across CrowdStrike, Wiz, Splunk, and cloud telemetry, each one tested against 30 days of the customer’s own data before it goes live. Mars believes it is the first platform … More → The post Mars Security brings threat intelligence to detection in real time appeared first on Help Net Security.
Read original article
Help Net Security ·

“Zero-click” WeChat worm could hijack accounts and spread via a single call

Researchers with security company Calif have discovered, weaponized, and privately reported to Tencent a critical vulnerability that allowed them to create “WeWorm”, a worm that spreads via WeChat calls without any user interaction. During its rampage, the WeWorm compromises the WeChat account of each user, and uses the saved contacts to propagate itself further, potentially reaching millions of devices within hours. The worm can hop from smartphone to smartphone, regardless of whether they are running … More → The post “Zero-click” WeChat worm could hijack accounts and spread via a single call appeared first on Help Net Security.
Read original article
Check Point Research ·

The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT

Research by: Alexey Bukhteyev Key Takeaways Introduction Over the past several years, AI assistants have moved far beyond text generation. Modern systems can execute code, install additional dependencies, analyze user files, and access data through connected services. These capabilities significantly increase the practical value of LLMs, but they also change the security model: protecting user […] The post The Shared Clipboard Inside the Sandbox: Cross-Account Data Leakage in ChatGPT appeared first on Check Point Research.
Read original article
Load more