{
  "schema_version": 2,
  "issue_date": "2026-09-11",
  "generated_at": "2026-09-11T23:06:30.067Z",
  "insight_context": {
    "schema_version": 2,
    "mode": "current",
    "checked_at": "2026-09-11T23:06:28.860Z",
    "report_date": "2026-09-11",
    "manifest_generated_at": "2026-09-11T16:18:47Z",
    "report_url": "https://ricomanifesto.github.io/SentryInsight/"
  },
  "articles": [
    {
      "id": "reporting-ed5e0e272a95",
      "title": "Hackers abused Claude to extract secrets from 1.8M Android apps",
      "link": "https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/",
      "date": "2026-09-11T20:19:09.000Z",
      "source": "Bleeping Computer",
      "summary": "Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-9846387cf4d2",
      "title": "Threat Actor Generates 1M Personalized Fraud Emails in 3 Days",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/1m-personalized-fraud-emails-3-days",
      "date": "2026-09-11T19:21:08.000Z",
      "source": "Dark Reading",
      "summary": "Cybercriminals behind malicious email campaigns no longer have to compromise volume for credibility, or vice versa, thanks to AI.",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-a16d62911725",
      "title": "Florida confirms DMV database breached via stolen police account",
      "link": "https://www.bleepingcomputer.com/news/security/florida-confirms-dmv-database-breached-via-stolen-police-account/",
      "date": "2026-09-11T19:00:29.000Z",
      "source": "Bleeping Computer",
      "summary": "The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police department employee…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-c299141b7513",
      "title": "CISA Calls for More Guidance, Less Spin, as Cyber Outages Escalate",
      "link": "https://www.darkreading.com/cyber-risk/cisa-calls-for-more-guidance-less-spin-as-cyber-outages-escalate",
      "date": "2026-09-11T18:44:03.000Z",
      "source": "Dark Reading",
      "summary": "A new joint government advisory signals a regulatory shift, pressing organizations to adopt more transparent breach notification and incident response protocols.",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-149efb9377d4",
      "title": "Why AI Is So Good at Scamming Humans",
      "link": "https://www.darkreading.com/cyber-risk/ai-scamming-humans",
      "date": "2026-09-11T18:14:06.000Z",
      "source": "Dark Reading",
      "summary": "Fred Heiding of Menlo Park Intelligence talks with the Dark Reading News Desk about his research on frontier models, and their ability to influence human behavior and create emotional dependency.",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-82dfd2b2ae38",
      "title": "Passkey-themed phishing attacks lead to Microsoft 365 data theft",
      "link": "https://www.bleepingcomputer.com/news/security/passkey-themed-phishing-attacks-lead-to-microsoft-365-data-theft/",
      "date": "2026-09-11T17:26:50.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from Microsoft 365 services…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-f232a487313b",
      "title": "AI Governance Can't Wait",
      "link": "https://www.darkreading.com/cyber-risk/ai-governance-cannot-wait",
      "date": "2026-09-11T17:10:56.000Z",
      "source": "Dark Reading",
      "summary": "Adversaries can manipulate AI defensive reasoning to silently compromise target networks.",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-a8b89596a45d",
      "title": "GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure",
      "link": "https://thehackernews.com/2026/09/gitlab-cvss-10-file-read-flaw-draws-in.html",
      "date": "2026-09-11T16:30:18.000Z",
      "source": "The Hacker News",
      "summary": "GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-a9e03aba59c7",
      "title": "Artifactory flaws chained in attacks deploying backdoor malware",
      "link": "https://www.bleepingcomputer.com/news/security/artifactory-flaws-chained-in-attacks-deploying-backdoor-malware/",
      "date": "2026-09-11T16:29:44.000Z",
      "source": "Bleeping Computer",
      "summary": "Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-ec242e7e40e9",
      "title": "Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks",
      "link": "https://thehackernews.com/2026/09/anthropic-says-seven-china-based-ai.html",
      "date": "2026-09-11T16:15:29.000Z",
      "source": "The Hacker News",
      "summary": "Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Knowledge distillation by itself is a legitimate training method. It refers to a machine learning technique where a large, powerful AI model assumes the role of a \"teacher\" to…",
      "firstSeen": "2026-09-11T20:45:34.169Z"
    },
    {
      "id": "reporting-3c8d9734ba4d",
      "title": "Papercut AI Swarm Attack Heralds Changes for Cyber Kill Chain",
      "link": "https://www.darkreading.com/cyberattacks-data-breaches/papercut-ai-swarm-attack-cyber-kill-chain",
      "date": "2026-09-11T15:48:27.000Z",
      "source": "Dark Reading",
      "summary": "From creating lab environments for staging and testing agentic attacks to reconnaissance to lateral movement and exfiltration, the most innovative attackers are widely incorporating AI.",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-0f8accb03f10",
      "title": "Claude Used to Automate Exploitation and Data Theft Across Multiple Victims",
      "link": "https://thehackernews.com/2026/09/claude-used-to-automate-exploitation.html",
      "date": "2026-09-11T14:29:47.000Z",
      "source": "The Hacker News",
      "summary": "Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threat actors, which the artificial intelligence (AI) company has branded Generative Threat Groups (GTGs), span state-sponsored groups, financially motivated criminals, commercial…",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-dae251a2004b",
      "title": "Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection",
      "link": "https://thehackernews.com/2026/09/russian-state-sponsored-hackers-use.html",
      "date": "2026-09-11T14:10:20.000Z",
      "source": "The Hacker News",
      "summary": "Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has been attributed to a cyber espionage group it calls GTG-20006 (where \"GTG\" stands for Generative Threat Group), which aligns with broader reporting linking the cluster to Midnight…",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-4cfe00191671",
      "title": "How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface",
      "link": "https://www.bleepingcomputer.com/news/security/how-threat-actors-are-turning-trusted-ai-platforms-into-an-attack-surface/",
      "date": "2026-09-11T14:01:11.000Z",
      "source": "Bleeping Computer",
      "summary": "Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts, shared AI conversations, sponsored search results, and ClickFix-style lures…",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-336c262bc83e",
      "title": "Your Critical Vulnerabilities Might Not Be Your Biggest Risk",
      "link": "https://thehackernews.com/2026/09/your-critical-vulnerabilities-might-not.html",
      "date": "2026-09-11T11:30:00.000Z",
      "source": "The Hacker News",
      "summary": "Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compromise. A critical vulnerability may look alarming on a scanner report, but if it sits behind strong segmentation, identity controls, and other defenses that prevent an attacker…",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-3b1ca1686e68",
      "title": "GitLab urges users to patch max severity path traversal flaw",
      "link": "https://www.bleepingcomputer.com/news/security/gitlab-urges-users-to-patch-max-severity-path-traversal-flaw/",
      "date": "2026-09-11T11:15:22.000Z",
      "source": "Bleeping Computer",
      "summary": "GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706…",
      "firstSeen": "2026-09-11T16:12:08.815Z"
    },
    {
      "id": "reporting-726c616a6c1c",
      "title": "Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-teams-outlook-launch-failures-on-arm-windows-pcs/",
      "date": "2026-09-11T09:39:37.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-42df196f2b73",
      "title": "Trezor: 347,000 users targeted in phishing attacks after Brevo breach",
      "link": "https://www.bleepingcomputer.com/news/security/trezor-347-000-users-targeted-in-phishing-attacks-after-brevo-breach/",
      "date": "2026-09-11T07:55:15.000Z",
      "source": "Bleeping Computer",
      "summary": "Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-6d77d0f66755",
      "title": "Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors",
      "link": "https://thehackernews.com/2026/09/attackers-chain-jfrog-artifactory-flaws.html",
      "date": "2026-09-11T07:31:05.000Z",
      "source": "The Hacker News",
      "summary": "Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-11c8b517d375",
      "title": "China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor",
      "link": "https://thehackernews.com/2026/09/china-linked-unc3569-exploited-sogou.html",
      "date": "2026-09-11T07:14:09.000Z",
      "source": "The Hacker News",
      "summary": "A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital said in research published Thursday. The attack started with a crafted link and ended with the attacker able to do anything the logged-in user could do. Tencent, which owns…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-07c0f38a80ce",
      "title": "Conti ransomware gang member sentenced to 4 years in prison",
      "link": "https://www.bleepingcomputer.com/news/security/conti-ransomware-gang-member-sentenced-to-four-years-in-prison/",
      "date": "2026-09-11T06:48:37.000Z",
      "source": "Bleeping Computer",
      "summary": "A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-af3b87dfbf9c",
      "title": "PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws",
      "link": "https://thehackernews.com/2026/09/papercut-replaces-emergency-patches.html",
      "date": "2026-09-11T06:46:18.000Z",
      "source": "The Hacker News",
      "summary": "PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download. \"These are Regular Maintenance Releases (MR) that…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-788925358fae",
      "title": "Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware",
      "link": "https://thehackernews.com/2026/09/cisco-fmc-flaws-exploited-to-steal.html",
      "date": "2026-09-11T06:19:59.000Z",
      "source": "The Hacker News",
      "summary": "Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks leverage CVE-2026-20079 (CVSS score: 10.0), an authentication bypass vulnerability in the web interface of FMC software that could allow an unauthenticated, remote attacker to bypass…",
      "firstSeen": "2026-09-11T10:56:47.636Z"
    },
    {
      "id": "reporting-133227570f5c",
      "title": "Indonesia Hit by Android Banking App-Cloning Campaign",
      "link": "https://www.darkreading.com/mobile-security/indonesia-android-banking-app-cloning-campaign",
      "date": "2026-09-11T01:00:00.000Z",
      "source": "Dark Reading",
      "summary": "The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.",
      "firstSeen": "2026-09-11T03:57:25.671Z"
    },
    {
      "id": "reporting-b8fb164281cc",
      "title": "New Android malware encrypts files, steals data, and harasses victims",
      "link": "https://www.bleepingcomputer.com/news/security/new-android-malware-encrypts-files-steals-data-and-harasses-victims/",
      "date": "2026-09-10T21:40:43.000Z",
      "source": "Bleeping Computer",
      "summary": "A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims…",
      "firstSeen": "2026-09-10T23:01:19.108Z"
    },
    {
      "id": "reporting-432786c4f1ef",
      "title": "Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data",
      "link": "https://www.darkreading.com/threat-intelligence/voice-callers-exploit-byod-microsoft-365-corporate-data",
      "date": "2026-09-10T20:36:03.000Z",
      "source": "Dark Reading",
      "summary": "Threat actors are leveraging Microsoft's Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.",
      "firstSeen": "2026-09-10T23:01:19.108Z"
    },
    {
      "id": "reporting-5125040d57bf",
      "title": "September Windows Server updates break Remote Desktop Services",
      "link": "https://www.bleepingcomputer.com/news/microsoft/september-windows-server-updates-break-remote-desktop-services/",
      "date": "2026-09-10T20:34:37.000Z",
      "source": "Bleeping Computer",
      "summary": "Windows admins report that the September 2026 security updates are causing Remote Desktop Services (RDS) failures on Windows Server 2019, 2022, and 2025 servers, preventing users from connecting and, in some cases, requiring a hard reset to restore functionality…",
      "firstSeen": "2026-09-10T20:40:15.245Z"
    },
    {
      "id": "reporting-1b1eebcbc6b8",
      "title": "Surfshark VPN says hackers breached internal testing, proxy servers",
      "link": "https://www.bleepingcomputer.com/news/security/surfshark-vpn-says-hackers-breached-internal-testing-proxy-servers/",
      "date": "2026-09-10T19:15:07.000Z",
      "source": "Bleeping Computer",
      "summary": "Surfshark disclosed that hackers accessed one of its internal test servers after a configuration error exposed it to the internet…",
      "firstSeen": "2026-09-10T20:40:15.245Z"
    },
    {
      "id": "reporting-627a6cdeb049",
      "title": "Microsoft Excel KB5002914 update breaks copy and paste for some users",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-excel-kb5002914-update-breaks-copy-and-paste-for-some-users/",
      "date": "2026-09-10T19:07:33.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft Excel users report that this week's KB5002914 Office security update is breaking copy-and-paste operations and formula dragging, with affected users saying that removing or rolling back the update restores normal functionality…",
      "firstSeen": "2026-09-10T20:40:15.245Z"
    },
    {
      "id": "reporting-69cf1fb2ff89",
      "title": "ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories",
      "link": "https://thehackernews.com/2026/09/threatsday-200-android-flaws-browser.html",
      "date": "2026-09-10T17:47:38.000Z",
      "source": "The Hacker News",
      "summary": "A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for access and takes too much. A trusted service becomes part of a phishing chain. An old bug still gets results. An exposed system stays exposed. A package looks useful right up until it isn’t. Different stories, same basic problem: the path in was often already…",
      "firstSeen": "2026-09-10T20:40:15.245Z"
    },
    {
      "id": "reporting-09079ade99ff",
      "title": "AI-powered attack exploited PaperCut flaws to hack 395 organizations",
      "link": "https://www.bleepingcomputer.com/news/security/ai-powered-attack-exploited-papercut-flaws-to-hack-395-organizations/",
      "date": "2026-09-10T15:55:56.000Z",
      "source": "Bleeping Computer",
      "summary": "A threat actor, likely Russian-speaking, used hundreds of AI agents to develop and launch a global exploitation campaign targeting vulnerable PaperCut NG/MF servers…",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-da907d9c99a0",
      "title": "Cisco FMC flaws exploited by ransomware gang, state-sponsored hackers",
      "link": "https://www.bleepingcomputer.com/news/security/cisco-fmc-flaws-exploited-by-ransomware-gang-state-sponsored-hackers/",
      "date": "2026-09-10T15:43:58.000Z",
      "source": "Bleeping Computer",
      "summary": "Cisco Talos says two recently patched Secure Firewall Management Center (FMC) vulnerabilities have been exploited by three separate threat clusters linked to ransomware and state-sponsored attacks…",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-fd125d81e655",
      "title": "Nightmare-Eclipse Strikes Again With 'ShieldCrash' Windows Exploit",
      "link": "https://www.darkreading.com/vulnerabilities-threats/nightmare-eclipse-strikes-again-shieldcrash-windows-exploit",
      "date": "2026-09-10T15:29:12.000Z",
      "source": "Dark Reading",
      "summary": "The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-5c2c44a4efea",
      "title": "IDScan confirms breach tied to 153 million stolen driver’s licenses",
      "link": "https://www.bleepingcomputer.com/news/security/idscan-confirms-breach-tied-to-153-million-stolen-drivers-licenses/",
      "date": "2026-09-10T14:55:33.000Z",
      "source": "Bleeping Computer",
      "summary": "Identity verification company IDScan has confirmed that hackers accessed customer data stored in its cloud platform, days after reports linked the company to a massive database containing more than 153 million driver's license scans…",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-ec21f6065228",
      "title": "Google Play Early Access Abused to Push Thousands of Deceptive Android Apps",
      "link": "https://thehackernews.com/2026/09/google-play-early-access-abused-to-push.html",
      "date": "2026-09-10T14:36:47.000Z",
      "source": "The Hacker News",
      "summary": "Bad actors are misusing Google Play's Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early Access apps are apps that haven't been released on the official Android app marketplace. The main idea behind the program is for developers to solicit user feedback for new applications or features they may be working on before their…",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-87c0628b9f68",
      "title": "New 'BlueMoon' kit exploited Windows and Chrome zero-day flaws",
      "link": "https://www.bleepingcomputer.com/news/security/new-bluemoon-kit-exploited-windows-and-chrome-zero-day-flaws/",
      "date": "2026-09-10T14:11:34.000Z",
      "source": "Bleeping Computer",
      "summary": "Multiple cyber-espionage groups deployed an exploit kit dubbed \"BlueMoon\" that leveraged zero-day vulnerabilities in Microsoft Windows and Google Chrome…",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-b046b5002a57",
      "title": "The Top 4 Threats We Found by Investigating Every Alert for a Quarter",
      "link": "https://www.bleepingcomputer.com/news/security/the-top-4-threats-we-found-by-investigating-every-alert-for-a-quarter/",
      "date": "2026-09-10T14:00:10.000Z",
      "source": "Bleeping Computer",
      "summary": "Identity was the target in roughly half of all confirmed malicious activity. Prophet Security breaks down the four main attack patterns seen across customer environments between May and July 2026, and explains why some attacks succeeded while others were blocked…",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-33af29f71c8c",
      "title": "Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE",
      "link": "https://thehackernews.com/2026/09/check-point-discloses-two-98-rated-vpn.html",
      "date": "2026-09-10T11:45:05.000Z",
      "source": "The Hacker News",
      "summary": "Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an unauthenticated remote attacker to run code, but only \"under specific conditions\" that it has not described. One flaw affects Check Point's Security Gateways, its firewall appliances. The other affects those gateways and the Security…",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-cd20e349d2f5",
      "title": "PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances",
      "link": "https://thehackernews.com/2026/09/papercut-attacker-uses-hundreds-of-ai.html",
      "date": "2026-09-10T11:41:53.000Z",
      "source": "The Hacker News",
      "summary": "A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security flaws in PaperCut NG/MF and break into hundreds of instances. According to independent reports from Blackpoint Cyber and GreyNoise, the activity originates from \"45.142.193[.]132,\" an IP address that has been linked to…",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-4cb585b593c9",
      "title": "Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks",
      "link": "https://thehackernews.com/2026/09/gigabud-creates-android-work-profiles.html",
      "date": "2026-09-10T11:33:43.000Z",
      "source": "The Hacker News",
      "summary": "The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app inside it, security firm Group-IB said in a report published on September 9. A work profile is a separate space that Android typically reserves for employer apps, and what's inside it is kept separate from everything in the personal space. That…",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-96264ce6cb02",
      "title": "Microsoft says September updates fix mouse settings reset issues",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-resolves-mouse-settings-reset-bug-windows-11-update/",
      "date": "2026-09-10T11:14:28.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft has fixed a known issue that wiped mouse settings on some Windows 11 systems after installing the KB5120998 August 2026 preview update…",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-10251c3ec1ce",
      "title": "CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline",
      "link": "https://thehackernews.com/2026/09/cisa-flags-exploited-cisco-citrix.html",
      "date": "2026-09-10T10:36:46.000Z",
      "source": "The Hacker News",
      "summary": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch (FCEB) agencies to apply the patches by September 12, 2026. The vulnerabilities are listed below - CVE-2026-20079 (CVSS score: 10.0) - An authentication…",
      "firstSeen": "2026-09-10T16:08:44.400Z"
    },
    {
      "id": "reporting-e8f0461d2748",
      "title": "CISA: WatchGuard RCE flaw now exploited in ransomware attacks",
      "link": "https://www.bleepingcomputer.com/news/security/cisa-watchguard-rce-flaw-now-exploited-in-ransomware-attacks/",
      "date": "2026-09-10T09:10:20.000Z",
      "source": "Bleeping Computer",
      "summary": "The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has confirmed that ransomware gangs are also exploiting a critical WatchGuard Firebox firewall vulnerability, which it flagged as actively exploited in December…",
      "firstSeen": "2026-09-10T10:58:44.216Z"
    },
    {
      "id": "reporting-8b5cb7068fea",
      "title": "Microsoft fixes bug that wiped Windows desktop settings",
      "link": "https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-bug-that-wiped-windows-desktop-settings/",
      "date": "2026-09-10T08:08:16.000Z",
      "source": "Bleeping Computer",
      "summary": "Microsoft says the September 2026 Patch Tuesday updates fix a known issue causing desktop settings to be lost or reset on some Windows devices…",
      "firstSeen": "2026-09-10T10:58:44.216Z"
    },
    {
      "id": "reporting-fd5c4de79625",
      "title": "Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example \"sk-1234\" Admin Key",
      "link": "https://thehackernews.com/2026/09/nearly-1-in-10-exposed-litellm-gateways.html",
      "date": "2026-09-10T07:12:55.000Z",
      "source": "The Hacker News",
      "summary": "Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM's own setup guide. LiteLLM is an open-source AI gateway, the software a company puts between its applications and the model providers it pays for. That key is the gateway's administrator credential. Anyone who holds it can read every…",
      "firstSeen": "2026-09-10T10:58:44.216Z"
    },
    {
      "id": "reporting-fa7734e88a6b",
      "title": "Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6",
      "link": "https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html",
      "date": "2026-09-10T07:04:01.000Z",
      "source": "The Hacker News",
      "summary": "Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Claude Opus 4.6 that breached \"…",
      "firstSeen": "2026-09-10T10:58:44.216Z"
    },
    {
      "id": "reporting-7605d83887d6",
      "title": "EU Cyber Resilience Act to Enforce New Reporting Requirements",
      "link": "https://www.darkreading.com/cybersecurity-operations/eu-cyber-resilience-act-reporting-requirements",
      "date": "2026-09-10T07:00:00.000Z",
      "source": "Dark Reading",
      "summary": "Starting Friday, European organizations will have just 24 hours to notify the EU government any time they discover serious product security incidents.",
      "firstSeen": "2026-09-10T10:58:44.216Z"
    },
    {
      "id": "reporting-06d5e914515a",
      "title": "Trezor warns users of email provider breach, phishing attacks",
      "link": "https://www.bleepingcomputer.com/news/security/trezor-warns-users-of-email-provider-breach-phishing-attacks/",
      "date": "2026-09-10T06:56:33.000Z",
      "source": "Bleeping Computer",
      "summary": "Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks…",
      "firstSeen": "2026-09-10T10:58:44.216Z"
    },
    {
      "id": "reporting-8e055682245b",
      "title": "Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks",
      "link": "https://www.bleepingcomputer.com/news/security/cisco-confirms-cve-2026-20079-secure-fmc-flaw-exploited-in-attacks/",
      "date": "2026-09-09T21:40:44.000Z",
      "source": "Bleeping Computer",
      "summary": "Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks…",
      "firstSeen": "2026-09-09T23:05:38.037Z"
    },
    {
      "id": "reporting-1e9110d4393f",
      "title": "AdaptHealth confirms 4.1 million people exposed in July cyberattack",
      "link": "https://www.bleepingcomputer.com/news/security/adapthealth-confirms-41-million-people-exposed-in-july-cyberattack/",
      "date": "2026-09-09T21:30:36.000Z",
      "source": "Bleeping Computer",
      "summary": "Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group…",
      "firstSeen": "2026-09-09T23:05:38.037Z"
    },
    {
      "id": "reporting-323b6c23b480",
      "title": "Mythos Vulnerability Firehose Hits a Human Bottleneck",
      "link": "https://www.darkreading.com/application-security/mythos-vulnerability-firehose-hits-human-bottleneck",
      "date": "2026-09-09T21:19:55.000Z",
      "source": "Dark Reading",
      "summary": "An analysis of Project Glasswing findings shows only a fraction of the bugs it has discovered have reached disclosure, and an even smaller number have been fixed.",
      "firstSeen": "2026-09-09T23:05:38.037Z"
    },
    {
      "id": "reporting-9c92e5a0f52d",
      "title": "US Government Accuses Chinese AI Firms of Distilling Frontier Models",
      "link": "https://www.darkreading.com/application-security/us-government-chinese-ai-firms-distilling-frontier-models",
      "date": "2026-09-09T19:47:50.000Z",
      "source": "Dark Reading",
      "summary": "US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX's Grok to reduce development costs.",
      "firstSeen": "2026-09-09T20:45:06.462Z"
    },
    {
      "id": "reporting-8df866a72a61",
      "title": "U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto",
      "link": "https://thehackernews.com/2026/09/us-disrupts-xinbi-guarantee-scam.html",
      "date": "2026-09-09T18:26:05.000Z",
      "source": "The Hacker News",
      "summary": "The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscating two cryptocurrency wallets, and deploying the Scam Center Strike Force to Madagascar to help disrupt 13 scam compounds run by Chinese organized crime…",
      "firstSeen": "2026-09-09T20:45:06.462Z"
    }
  ]
}
