Latest news as of 9/9/2026, 12:57:00 AM
The Hacker News
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting package names, but all of them deliver a powerful RAT and infostealer payload," OpenSourceMalware researcher Paul
Dark Reading
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
The Register
What, you didn't think the top gangs were busy watching agents escape their sandboxes too, did you?
Graham Cluley
f someone offered you 90% off the official price to access Claude, the powerful AI model from Anthropic, would you be tempted? It turns out that around 900 people were, and they may be regretting their decision. Read more in my article on the Fortra blog.
Bleeping Computer
Levi Strauss & Co. (Levi's) says that hackers used social engineering on three of its employees to gain access to and steal corporate data stored on their machines. [...]
Dark Reading
In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real organizations.
The Register
Attackers turned admin access into a route downstream, while N-able tells N-central customers to patch – again
The Register
Timer interrupts reopen branch predictor poisoning window, with a working Zen 2 exploit to prove it
Bleeping Computer
Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [...]
The Register
Investigation into whether staff improperly accessed Minnie Merriman’s file after she was named for the first time this week