Infosecurity News

Researchers Build WeChat Zero-Click Worm Hijacking Phones via Calls
The hacking tool, built using a combination of AI models, is effective against Android and iOS devices

Gigabud Uses Android App Cloning to Evade Fraud Detection
Gigabud clones banking apps into a work profile to break the link between malware alerts and fraud

ClickFix Moves into the Browser to Steal Cryptocurrency
ClickFix campaign uses browser-injected JavaScript and Google Sheets to steal cryptocurrency

NHIs Now the Number One Corporate Entry Point for Hackers
SpyCloud claims non-human identities are the most likely route into the enterprise

Microsoft Shatters Patch Tuesday Record With 974 CVE Fixes in September 2026
The update contained 119 critical flaws and two zero days, with security teams needing to prioritize updates

SAP Patches Maximum Severity “Overpass” Flaw
Onapsis urges SAP customers to patch “Overpass” vulnerability, which has a CVSS score of 10.0

France Establishes New Government-Focused Cyber Incident Response Unit
After a major cyber-attack targeted France's national tax authority, the Prime Minister called for the establishment of a new dedicated cyber incident response capability

Grindr Settles UK Data Privacy Claims for £26m
Grindr settled UK claims over alleged unlawful processing of sensitive user data

AI Coding Tools Now a Prime Target for Threat Actors, Google Warns
Google warned that the rapid integration of AI-assisted coding tools has significantly expanded software supply chain risks

THost9 Android RAT Pairs Packed Loader With ADB Worm
THost9 hides its payload and uses ADB to spread across exposed Android devices and containers

BigBear 2 PhaaS Campaign Steals 5000+ Microsoft Credentials
CloudSEK has uncovered BigBear 2.0, a new phishing-as-a-service operation targeting Microsoft 365

Trezor Supply Chain Breach Now Impacts 81,000 Customers
Crypto wallet-maker Trezor says a data breach at supplier ShipMonk is far worse than originally thought

NCSC Warns Shadow AI Creates New Security Risks
NCSC warns unapproved AI tools can expose corporate data and create new security risks

N-able Releases Hotfix for Critical Remote Code Execution Vulnerability
The vulnerability, CVE-2026-86218, was allocated a maximum-severity rating by the software provider itself

Rhysida Publishes Berlin Government Data After €2m Extortion Demand Refused
The ransomware group’s published dataset reportedly includes Berlin state employee data, as well as highly sensitive emergency plans

North Korea’s Lazarus Operates Through Six Distinct Cyber Clusters
Sekoia and Kudelski Security have observed that North Korea's Lazarus umbrella is split into six distinct clusters, focused on espionage, financial theft and sanctions evasion

Multiple Class Action Lawsuits Filed Against IDScan
Several victims of a recent breach of driver’s license information have sued the company they believe responsible

Researcher Publishes CrowdStrike Privilege Escalation Zero Day
A security researcher has posted a zero-day exploit in CrowdStrike which could allow hackers to escalate privileges

OpenAI Pledges $1bn to Bring its AI Cybersecurity Tools to Essential Services
OpenAI has committed to subsidizing access to Daybreak, helping defenders deploy its AI models in its existing cybersecurity infrastructure

G7 Urges Fast-Track on Quantum-Safe Cybersecurity Rules
The G7 has published a call to action, urging governments to launch national strategies dedicated to the post-quantum encryption transition



