The cybersecurity landscape is rapidly deteriorating with multiple high-profile exploits targeting popular software like Chrome, Edge, and Microsoft 365. Exploits are being actively used to execute commands on compromised systems, steal session cookies, and launch phishing attacks. Companies like N-able are struggling to keep up with patching vulnerabilities, highlighting the urgent need for robust security measures. Meanwhile, OpenAI's chief scientist warns of unforeseen consequences from rapidly advancing AI, emphasizing the importance of responsible development and testing.
Cybersecurity researchers discovered PEEP, a post-exploitation toolkit targeting Chrome and Edge users. PEEP, disguised as a bookmarks extension, injects malicious code into browser profiles, enabling attackers to execute commands on compromised hosts.
OpenAI's chief scientist warned that no one is prepared for the consequences of artificial intelligence. OpenAI released GPT-6 Astra, claiming it is their most powerful AI model to date.
Huntress researchers identified three separate incidents where attackers used ScreenConnect to spread a four-stage VBScript chain to newly connected hosts. The malicious payload was distributed via diverse initial access methods including Quick Assist scams, phishing-delivered MSI installers, and fake software.
Check Point Research identified JSCeal malware, a compiled V8 JavaScript program, that steals session cookies to bypass Google authentication. This malware can harvest credentials, conduct surveillance, and intercept traffic using obfuscation techniques like RC4-protected strings and control-flow flattening.
Threat actors are targeting Microsoft 365 executives with IT help desk vishing to steal multi-factor authentication tokens using an adversary-in-the-middle (AitM) technique. This allows them to gain unauthorized access to accounts and exfiltrate sensitive data for extortion purposes.
Attackers used QR codes embedded in text to bypass email image blocking, allowing malicious content display despite user precautions. A supply chain attack compromised a trusted software source, resulting in credential theft from unsuspecting users.
TantoSec developed an exploit chain that leverages an AES-CBC padding oracle vulnerability in Telerik UI for ASP.NET AJAX to achieve unauthenticated remote code execution against applications configured with a specific, non-default setting. Progress patched the vulnerability chain in July 2023.
N-able issued Hotfix 4 for its N-central RMM platform to address an unauthenticated remote code execution (RCE) vulnerability affecting builds below version 2026.3.1.14. The company states the flaw has been exploited in the wild, though this is unconfirmed.
Intruder analyzed misconfiguration data from 3,000 organizations across AWS, Azure, and Google Cloud, finding distinct risk profiles for each provider. The 2026 Cloud Security Index report highlights that security checklists may not be effective due to these varying vulnerabilities across cloud platforms.
Zhou Yu from Columbia University and Arklex AI developed a simulation-driven testing method using synthetic user personas, trajectory entropy, and automated CI/CD pipelines to evaluate multi-turn AI agents. This technique helps identify edge cases before deployment, improving compliance and reliability for self-learning AI workflows at scale.
OpenAI, AIRPPU, and WAN-IFRA launched a program to support 100 Ukrainian news organizations. The program will utilize artificial intelligence techniques to enhance innovation, resilience, and independent journalism within the sector.
Apple will launch a new foldable iPhone Ultra on September 9th. The company will also announce updates to its AirPods and HomePod product lines.
Multiple companies are exploring underground hydrogen reserves as a potential zero-carbon fuel source. This exploration aims to quantify the amount of accessible hydrogen and develop extraction techniques for widespread utilization.
Phil Schiller, former Apple senior vice president, left the company due to disagreements with CEO John Ternus regarding App Store strategy. Schiller was concerned about Ternus' plan to increase recurring revenue from the App Store.
Researchers are using opaque recurrence techniques to improve AI model performance. This technique, which involves training models on vast datasets without fully understanding how they learn, can lead to more accurate predictions but also raises concerns about transparency and bias.
Grindr will pay £26 million to settle claims brought by the UK's Information Commissioner's Office (ICO). The ICO alleged that Grindr shared users' HIV status and other personal data with third-party advertising partners without consent, violating UK privacy laws.
Authors are disputing the distribution plan for the $100 million Anthropic AI settlement, arguing that publishers and agents are seeking an excessive portion. The authors claim the proposed allocation unfairly favors these intermediaries over the creators of the copyrighted works used in Anthropic's training data.
Dozens of AI-generated songs, images, and videos featuring Dolly Parton have been posted online since her death in late August. These creations utilize AI techniques to imitate Parton's likeness and artistic style, raising ethical concerns about the misuse of AI technology.
Nathan Fielder and Lance Oppenheim's documentary "You Can See Everything" provides extensive access to Elizabeth Holmes. The film premiered at the Telluride Film Festival on Sunday, generating significant buzz among attendees.