Cyber Security News.
Cyber Security News World’s #1 Premier Cybersecurity and Hacking News Portal
- FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attackby Guru Baran on September 8, 2026 at 5:15 pm
Fortinet has disclosed a high-severity certificate validation flaw in the Agentless ZTNA portal of FortiOS and FortiProxy that could let an unauthenticated remote attacker intercept traffic flowing between the ZTNA portal and the backend destination website. Tracked as CVE-2026-84393 and documented under advisory FG-IR-26-174, the issue was published on September 8, 2026, and carries a The post FortiOS and FortiProxy ZTNA Validation Vulnerability Allows Attacker to Perform a Man-in-the-Middle Attack appeared first on Cyber Security News.
- Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malwareby Guru Baran on September 8, 2026 at 4:50 pm
An active exploitation campaign targeting FortiGate firewalls, in which attackers weaponize a critical vulnerability to plant a custom-built Node.js remote access trojan (RAT) that turns compromised perimeter devices into long-term footholds for espionage and data theft. The SOCRadar Threat Research Unit (STRU) has identified, with high confidence, that threat actors are actively exploiting CVE-2025-25249, a The post Hackers Actively Exploiting FortiGate Firewalls to Deploy Custom Node.js Malware appeared first on Cyber Security News.
- CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacksby Guru Baran on September 8, 2026 at 4:25 pm
CISA has added a critical Google Chromium V8 type confusion vulnerability, tracked as CVE-2026-85046, to its Known Exploited Vulnerabilities (KEV) Catalog, warning that the flaw is being actively exploited in attacks. CVE-2026-85046 affects the V8 JavaScript and WebAssembly engine used by Chromium-based browsers. The vulnerability stems from type confusion, classified under CWE-843, a weakness that The post CISA Warns of Chromium Type Confusion 0-Day Vulnerability Actively Exploited in Attacks appeared first on Cyber Security News.
- Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacksby Guru Baran on September 8, 2026 at 3:42 pm
Ivanti has disclosed a wave of security advisories affecting three flagship enterprise products, Endpoint Manager Mobile, Neurons for ITSM, and Sentry, exposing organizations to risks ranging from privilege escalation to full remote code execution. The disclosures, published on September 8, 2026, cover ten distinct CVEs, several rated critical, underscoring the breadth of exposure across Ivanti’s The post Ivanti EPMM, Neurons and Sentry Vulnerabilities Enable Privilege Escalation and RCE Attacks appeared first on Cyber Security News.
- Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Accessby Abinaya on September 8, 2026 at 3:22 pm
Dell has disclosed three critical vulnerabilities in its Secure Connect Gateway 5.0 platform that could allow attackers to gain unauthorized access, execute commands remotely, and obtain root-level control of affected systems. The flaws affect Dell Secure Connect Gateway 5.0 Appliance versions earlier than 5.36.00.16 and Secure Connect Gateway 5.0 Application versions earlier than 5.36.00.00. Dell The post Dell Secure Connect Gateway Vulnerabilities Allow Hackers to Gain Unauthorized Access appeared first on Cyber Security News.
- ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channelby Guru Baran on September 8, 2026 at 3:20 pm
A covert cross-account communication channel inside ChatGPT let an attacker hijack a victim’s session and silently exfiltrate data from connected apps like Gmail, all while the victim saw nothing unusual in their conversation. The vulnerability exploited ChatGPT’s code-execution containers, isolated sandboxes the assistant uses when a task requires running code or installing software packages. These The post ChatGPT Sandbox Flaw Lets Attackers Steal Gmail Data Across Accounts via Hidden Channel appeared first on Cyber Security News.
- Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentestsby Cybernewswire on September 8, 2026 at 2:02 pm
Boston, MA, USA, September 8th, 2026, CyberNewswire Specialized team of AI agents that discover, attack, and validate web vulnerabilities, leveraging pre-existing site context to eliminate noise and speed remediation. Reflectiz, the continuous web exposure management company, today launched a multi-agent penetration testing platform for websites. Multiple specialized AI agents discover, attack, and validate vulnerabilities across The post Reflectiz Launches Agentic Pentesting for Websites: Up to 10x Coverage vs Conventional Pentests appeared first on Cyber Security News.
- Mars Security Launches Real-Time Intel-to-Detection Engine That Turns Live Threat Intelligence Into Backtested Detections in Minutesby Cybernewswire on September 8, 2026 at 1:20 pm
New York, NY, United States, September 8th, 2026, CyberNewswire Mars Security, the autonomous threat hunting and detection engineering platform founded by offensive security veterans, today announced Real-Time Intel-Based Detection, a capability that turns newly published threat intelligence into validated, ready-to-deploy detection rules within minutes of release. Built by former offensive operators, the new capability converts The post Mars Security Launches Real-Time Intel-to-Detection Engine That Turns Live Threat Intelligence Into Backtested Detections in Minutes appeared first on Cyber Security News.
- Claude Mythos AI Autonomously Executes Full Cyber Kill Chain Without Human Guidanceby Tushar Subhra Dutta on September 8, 2026 at 12:50 pm
Claude Mythos is the first model reported to complete a cyber kill chain without step-by-step human direction. The finding does not describe malware or a confirmed victim breach. It is a controlled test, but shows how quickly autonomous attack capability is advancing. The concern is speed. The model found weaknesses, entered a defended enterprise network, The post Claude Mythos AI Autonomously Executes Full Cyber Kill Chain Without Human Guidance appeared first on Cyber Security News.
- Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domainby Tushar Subhra Dutta on September 8, 2026 at 12:10 pm
A new intrusion campaign shows how quickly a Windows domain can be turned into a launchpad for deeper compromise. The operators used a Sliver command-and-control beacon, account creation, credential theft and remote administration to establish control after gaining an initial foothold. The activity was staged from an exposed server and aimed at one unnamed US The post Hackers Disable Endpoint Protection and Deploy Sliver Across Compromised Windows Domain appeared first on Cyber Security News.














