Noma Labs researchers disclosed an authorization design flaw in enterprise AI pipelines that lets attackers submit ordinary-looking requests through unauthenticated channels—like support inboxes or web forms—to trigger actions using elevated internal permissions. They demonstrated this by sending a support email that tricked an AI workflow into retrieving and forwarding a finance director's private email contents to an attacker.
darkreading.com
· 2026-09-09
An essay contrasts two mindsets in security engineering: those who treat security as a personal identity built around cleverness and outsider status, versus those focused on systemic, structural defense work. The piece argues that the hacker ethos of prizing surprising vulnerability discoveries, while culturally dominant and rewarded at conferences and in careers, biases the field toward reactive discovery rather than durable prevention.
dadrian.io
· 2026-09-09
Cymphony, a New York- and Tel Aviv-based startup, raised a $25 million Series A co-led by Sequoia Capital and SMBC Fin Atlas Beyond Fund, pushing its valuation above $100 million after a previously undisclosed Sequoia seed round. The company builds a 'workforce graph' that gives security teams visibility into which employees, AI agents, and other non-human identities can access sensitive systems and data.
techcrunch.com
· 2026-09-09
Security researchers note that as MFA, conditional access and device trust make direct credential theft harder, attackers are shifting focus to account recovery workflows. Instead of stealing a user's second authentication factor, criminals are tricking service desk staff into resetting or reassigning it on their behalf.
bleepingcomputer.com
· 2026-09-09
Security researchers found more than 36,000 internet-facing Plex Media Server instances that have not applied fixes for previously disclosed security flaws. These unpatched servers remain publicly reachable, leaving them open to exploitation by attackers.
bleepingcomputer.com
· 2026-09-09
Android Authority highlighted two standout gadgets from IFA 2026 in Berlin: Blurams' F20C HelioCam Pro, a solar-powered 4K outdoor security camera with no wiring and a free lifetime cloud plan, and Mammotion's LUBA 4 AWD, a robot lawn mower designed to better handle lawn edges. The Blurams camera uses a 12,000mAh battery paired with a detachable solar panel, is IP66-rated for weather resistance, and runs on-device AI detection for people, vehicles, and pets, with footage stored locally or via free cloud playback.
androidauthority.com
· 2026-09-08
Samsung has issued the final security patch for the 2021 Galaxy Z Fold 3 and Z Flip 3, removing both devices from its official security update list. The Z Fold 4 and Z Flip 4 have now shifted to a quarterly update schedule, signaling their own support window will close around 2027.
androidauthority.com
· 2026-09-08
Amazon has cut the price of the Tapo MagCam C460 wireless outdoor security camera to $84.99 from its $119.99 list price, matching its lowest recorded price. The battery-powered camera features a magnetic mount, 4K recording, color night vision, and AI-based alerts for people, pets, and vehicles.
androidauthority.com
· 2026-09-08
A security researcher highlights how Docker's default client-server architecture runs its daemon as root, meaning any user with access to the Docker socket can escalate privileges to full root access without a password. The piece demonstrates this with a simple command that mounts the host filesystem inside a container and bypasses normal permission checks, tying the issue to a recent vulnerability disclosed in an unnamed Linux distribution whose installer enabled an insecure Docker configuration by default.
blog.miguelgrinberg.com
· 2026-09-08
Google has shifted Chrome from a four-week to a two-week release schedule, beginning with Chrome 153 rolling out on desktop, iOS, and Android. The company says the change helps it manage a growing volume of security patches driven by AI-assisted bug discovery and faster-moving threats.
techcrunch.com
· 2026-09-08
On the latest Apple @ Work episode sponsored by Mosyle, Pharos's Kevin Pickhardt discussed how printers often remain the weakest link in corporate security setups. He addressed the tension between maintaining paper backups and audit trails while protecting organizations from print-related vulnerabilities.
9to5mac.com
· 2026-09-08
BleepingComputer will host a live webinar on September 23, 2026, in partnership with Material Security, examining real, documented breaches of Google Workspace caused by forgotten third-party app permissions. Speakers Rajan Kapoor of Material Security and Rick Fitzgerald of Fireside Consulting will walk through case studies and outline which security controls matter most for fast-growing companies with limited resources.
bleepingcomputer.com
· 2026-09-08