Skip to content

N-able Patches Critical Zero-Day in N-central

Administrators are advised to check their deployments for newly created user accounts they don’t recognize. The post N-able Patches Critical Zero-Day in N-central appeared first on SecurityWeek.

Stealing AI Reasoning Traces

Interesting research: “Stealing Reasoning Traces from Proprietary LLM APIs“: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect intellectual property and limit information leakage. Rather than storing these traces server-side, providers return them to the client as blocks of encrypted text, which theRead More »Stealing AI Reasoning Traces

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggler by Sansec, which discovered zero-day exploitation starting September 4, 2026. “This updateRead More »Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has operated out of the Indian state of Rajasthan sinceRead More »BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. “Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s ownRead More »PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

What are agentic pentesting tools?

Traditional security testing tools excel at applying proven security checks quickly and consistently. Agentic pentesting tools add another dimension: they use AI agents to explore applications, adapt their testing based on runtime behavior, and investigate attack paths that may require multiple steps or changing strategies…. Read more The post WhatRead More »What are agentic pentesting tools?

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins. The activity, which mainly singles out directors, vice presidents, and other executive staff

Copyright © 2026 infosecintel.net