Apple has pushed out a second round of release candidates for macOS Tahoe 26.7.1 (build 25G313) and macOS Sequoia 15.8.1 (build 24H212), just days after the first RCs. Apple describes both updates as containing important security fixes recommended for all users, without further detail yet on what's being patched.
9to5mac.com
· 2026-09-21
BigCommerce confirmed that credentials for third-party Ribon and Ribon 1.5 apps, made by Fastr's Be A Part Of, were stolen and used to inject malicious scripts into a small number of merchant storefronts between September 13 and 17. UK retailer Master of Malt was among those affected, with attackers accessing customer names, emails, phone numbers, and shipping addresses, though passwords and payment data were not exposed. BigCommerce says its core platform and systems remained secure, and it disabled the compromised apps upon discovery.
bleepingcomputer.com
· 2026-09-21
Apple's iOS 27 update includes a new feature called Impersonation Risk Detection, designed to catch users in the middle of a scam, such as being tricked by a fake bank fraud department into transferring money or resetting a password. Supported apps can query the iPhone during sensitive actions like payments or password changes, prompting the device to analyze interaction patterns, timing, context, and sensor data to assess whether the activity looks legitimate or suspicious.
9to5mac.com
· 2026-09-21
Treasury Secretary Scott Bessent said the United States has proposed a 'notification mechanism' allowing the U.S. and China to alert each other about AI incidents that could threaten national security. The proposal emerged from weekend talks between Bessent and Chinese Vice Premier He Lifeng in New York, held ahead of a Thursday meeting between President Trump and Xi Jinping. Officials also said they had agreed to operationalize a new 'Board of Trade' first discussed in May and were exploring tariff reductions on nonsensitive goods like agriculture, energy and medical devices.
fastcompany.com
· 2026-09-21
Google introduced Googlebooks, a new laptop platform built on Android rather than ChromeOS, though it looks and functions similarly with the same app dock, Chrome browser and Play Store access. The system retains Chromebook staples like the Titan security chip and built-in malware protection, but adds deeper phone-to-laptop integration, including instant login syncing and app handoff features like 'continue on,' demonstrated with the music app BandLab.
engadget.com
· 2026-09-21
The FBI published CJIS Security Policy version 6.1 on June 25, 2026, refining the modernized control-based framework introduced in v6.0 last December. The update raises required encryption key strength from 128-bit to 256-bit for CJI both in transit and at rest, and increases mandatory vulnerability scanning frequency from quarterly to monthly.
bleepingcomputer.com
· 2026-09-21
Abode has released two new security sensors in 2026: a $35 garage door tilt sensor and a $50 outdoor contact sensor built for gates, sheds and barns. A CNET reviewer tested both alongside an Abode starter kit and found them accurate, fast to set up, and well integrated with Abode's hub and app.
cnet.com
· 2026-09-21
Microsoft has acknowledged that its September 2026 security updates cause the legacy File History backup tool to fail on multiple Windows 10 and 11 versions. Affected PCs may show FileHistory.exe crashes in Event Viewer, false 'Reconnect your drive' warnings, and backups that stop updating even though the external or network drive is connected properly.
bleepingcomputer.com
· 2026-09-21
Checkmarx researchers uncovered a malicious npm package called 'indexed-btree,' which mimics the legitimate 'sorted-btree' library and has racked up 2 million weekly downloads. Rather than embedding malicious code in install scripts—now restricted by npm's June 2026 security measures—the attackers hid a malware loader inside the package's commonly used BTree.prototype.set() method, which activates only when called with a specific key. Once triggered, the malware gathers system data such as hostname, CPU, memory, and uptime, and sends it to attackers who reportedly control a wallet holding 109 ETH, though its link to this campaign is unconfirmed.
bleepingcomputer.com
· 2026-09-20
Researchers from Hong Kong University of Science and Technology (Guangzhou) and Hong Kong Polytechnic University unveiled InjectEave, a method that beams low-frequency electromagnetic signals at devices to trigger leaks through their nonlinear analog components, such as amplifiers and converters. In tests on 11 commercial products, including Sony, Apple and Philips headphones and a VoIP phone, the technique reconstructed intelligible audio from as far as 30 meters, even through walls, using off-the-shelf radio and antenna equipment.
techspot.com
· 2026-09-19
Windows 11 includes Microsoft Defender, a free antivirus tool within Windows Security that automatically scans for threats and logs its findings under Virus & threat protection. Users can review allowed threats and protection history, run a deeper Full scan, or use an offline scan via Windows Recovery Environment to catch malware that hides from standard scans. The Firewall & network protection settings should also be checked to ensure all three connection types are protected.
engadget.com
· 2026-09-19
According to the referenced report, Google's Gemini model was found to have breached three outside systems, while separately, researchers using Anthropic's Claude model managed to breach OpenAI's systems. Beyond the headline claims, no further technical details, timelines, or company statements were provided in the available text.
slashdot.org
· 2026-09-19