CyberSecure Specialist

Users in Houthi-Held Yemen Tried to Develop Advanced Weapons With AI, Anthropic Says

Anthropic says Claude users in northern Yemen, territory controlled by Iran-backed Houthi rebels, tried to use the AI model to develop advanced missiles. AI is already transforming warfare from Ukraine to Gaza, and its use on a rugged and remote battlefield is likely to increase concerns about its rapid spread. Anthropic said the users of the accounts, which it blocked after identifying them, did not succeed in “fielding an operational device” but did carry out…

Read More

Safe word: What is it and why do you need one?

Digital Security AI scams are now hyper-realistic. But there’s one simple way to see through them. Phil Muncaster 09 Sep 2026  •  , 5 min. read AI voice scams are no longer as niche as they once were. The technology is both cheap and convincing: a worrying combination that has lowered the barrier to entry for would-be scammers. According to a Hiya report from March, one-in-four Americans say they’ve received a deepfake voice call in…

Read More

GuardBreaker: Derailing AI-assisted malware analysis with a code comment

Business Security LLM-based code scanners won’t help attackers build a nuclear weapon, but that refusal could work in their favor Tomáš Foltýn 10 Sep 2026  •  , 4 min. read Malware developers have long adapted their code and tactics to the defenses and scrutiny that are likely to stand in their way. Using various evasion and anti-analysis methods, they routinely attempt to hinder code analysis or prevent their malware from revealing its true behavior while…

Read More

Mandiant Founder Kevin Mandia Joins Amazon Board

Amazon has appointed cybersecurity veteran Kevin Mandia to its board of directors, strengthening the technology giant’s security expertise at the board level. Mandia was elected to the board on September 8 and brings more than 30 years of experience responding to cyber threats across the public and private sectors, Amazon announced. He is the founder and CEO of cybersecurity firm Armadin and a co-founder and general partner at cybersecurity-focused venture capital firm Ballistic Ventures. Mandia is…

Read More

New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

The security researcher known as Nightmare Eclipse has released another Microsoft Defender zero-day exploit, right after Microsoft’s record-breaking September 2026 patches. Dubbed ‘ShieldCrash’, the exploit targets fully patched Windows systems for privilege escalation. The proof-of-concept (PoC) exploit code demonstrates an arbitrary file read with System privileges, according to Nightmare Eclipse, also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare. However, the underlying vulnerability can be exploited to gain full System privileges, allowing attackers to drop…

Read More

Microsoft Plugs Nearly 1,000 Security Holes

Microsoft Corp. today issued updates to plug at least 974 security holes in its Windows operating systems and other software, by far its biggest single patch batch ever. Microsoft says artificial intelligence is helping to speed the discovery of vulnerabilities, but security experts warn that many organizations already are struggling to prioritize the more human-intensive endeavor of testing and deploying so many fixes each month. Image: Shutterstock.com, Kirill Makarov. This month’s patch bundle obliterates the…

Read More

Microsoft Patches Record 974 Vulnerabilities, Including Two Exploited Zero-Days

Microsoft on Tuesday rolled out a record number of patches, fixing 974 CVEs across its products, including two vulnerabilities exploited in the wild as zero-days. The first exploited zero-day, CVE-2026-85880, is a heap buffer overflow issue in the Windows Advanced Local Procedure Call (ALPC) that could allow a local attacker to gain System privileges. “An attacker who can execute code in a low-privilege AppContainer could exploit this vulnerability locally to escape the sandbox and elevate…

Read More

Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits

The security researcher known as Nightmare Eclipse has dropped three zero-day exploits targeting products from Avast, CrowdStrike, and Nvidia. Also known as Chaotic Eclipse, Infinite Nightmare, and MSNightmare, the security researcher came to fame for a series of zero-day exploits targeting Microsoft’s products, but has recently moved to other vendors as well. In late August, Nightmare Eclipse released a privilege escalation zero-day in a Kaspersky endpoint security product. Dubbed HardBreacher, the exploit has been patched…

Read More

Elementor Pro WordPress Plugin Vulnerability Exploited to Hack Sites

Hackers have been exploiting a critical-severity vulnerability in the Elementor Pro WordPress plugin to hack websites, WordPress security firm Defiant warns. A highly popular drag-and-drop website builder, Elementor is a free WordPress plugin with over 10 million installations. Elementor Pro is the paid version that offers additional features, including a Form widget with support for File Upload fields. The bug, tracked as CVE-2026-32475 (CVSS score of 9.8), is described as an arbitrary file upload issue…

Read More

In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation

SecurityWeek’s weekly cybersecurity news roundup offers a concise overview of important developments that may not receive full standalone coverage yet remain relevant to the broader threat landscape. This curated summary highlights key stories across vulnerability disclosures, emerging attack methods, policy updates, industry reports, and other noteworthy events to help readers maintain a well-rounded awareness of the evolving cybersecurity environment. Here are this week’s highlights:  Microsoft releases cloud patches Microsoft has released patches for nine vulnerabilities…

Read More