Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
thehackernews.com

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

A security researcher released working exploit code for four Linux kernel vulnerabilities—DirtyAH6, TUNderflow, PPPoEject, and DiagSpill—that allow local privilege escalation to root. The Linux kernel team patched all four in the weeks before the code was published, so systems with current kernels remain safe. The exploits target memory‑safety bugs in networking code and can crash machines; they are intended for isolated testing. Users running older kernels should update promptly to avoid exposure.
ICTK and Jiran Security Partner on ‘Q-BRIDGE’ to Commercialize End-to-End PQC Migration Frameworks
quantumcomputingreport.com

ICTK and Jiran Security Partner on ‘Q-BRIDGE’ to Commercialize End-to-End PQC Migration Frameworks

ICTK Co., Ltd., a South Korean quantum‑security fabless firm, and Jiran Security, a cybersecurity specialist, signed a memorandum of understanding to launch Q‑BRIDGE, a commercial service that delivers end‑to‑end post‑quantum cryptography (PQC) migration for enterprises, government agencies and financial institutions. The partnership combines Jiran’s Crypto Discovery platform, which audits cryptographic assets, identifies vulnerabilities and creates migration roadmaps, with ICTK’s hardware‑rooted security architecture built on its VIA PUF™ hardware root‑of‑trust chips. Jiran will conduct initial diagnostics for more [...]
GeeTest Showcases Adaptive Bot Management Innovations at GISEC Global 2026
finanznachrichten.de

GeeTest Showcases Adaptive Bot Management Innovations at GISEC Global 2026

GeeTest, a prominent bot‑management provider, unveiled new adaptive security tools at GISEC Global 2026 in Dubai. The company showcased dynamic, risk‑based CAPTCHA, device fingerprinting, and a configurable business rules engine designed to detect sophisticated automated attacks while minimizing user friction. Live demos highlighted real‑time challenge generation that outperforms traditional CAPTCHA libraries, targeting high‑risk touchpoints such as registration, login, and payment. GeeTest’s booth attracted cybersecurity professionals from fintech, e‑commerce, gaming, and digital services, offering hands‑on demonstrations and threat‑scenario [...]
Comp AI sets eyes on a continuously agentic future for security and compliance
techcrunch.com

Comp AI sets eyes on a continuously agentic future for security and compliance

Comp AI, a cybersecurity and compliance startup founded in January by Lewis Carhart, Claudio Fuentes and Mariano Fuentes, announced a $34 million Series A financing led by Roo Capital and Grand Ventures, bringing its total funding to $37.5 million. Drawing on lessons from their previous venture LeapAI—where manual SOC 2 compliance slowed product development—the trio built an “agentic” platform that automates policy drafting, evidence collection and continuous monitoring of compliance controls. The system also offers AI‑driven penetration testing and aims to keep security postures [...]
Best Antivirus for Windows 2026: 5 to Install, 1 to Avoid
gizmodo.com

Best Antivirus for Windows 2026: 5 to Install, 1 to Avoid

A 2026 review ranks five paid Windows antivirus products and Microsoft Defender. Norton 360 tops the list, completing a full scan in 13 minutes 22 seconds and offering a robust firewall and 250 GB cloud backup. Bitdefender excels on older PCs, keeping CPU usage at 11 % and memory at 183 MB during a sweep. Avast One delivers a free, lab‑certified solution. NordVPN Threat Protection Pro provides full Windows protection for VPN subscribers. McAfee + offers unlimited device coverage but has the slowest scan. Microsoft [...]
Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program
infosecurity-magazine.com

Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program

SE Labs, a UK security testing firm, announced its six‑month PIVOT program on September 15 to benchmark cybersecurity vendors against the world’s most dangerous threat actors. The program employs a team of ethical hackers who simulate nation‑state and ransomware groups, testing vendors’ detection, interruption, and containment capabilities across full attack chains. Participants include Broadcom (Symantec, Carbon Black), CrowdStrike, Fortinet, Palo Alto Networks, and Sophos. Testing began in July, will finish in October, and results are slated for [...]
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
thehackernews.com

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

Cybersecurity researchers uncovered the KREMLIN banking malware, active since May 2025, that lures Brazilian bank customers with fake documents and installs a malicious browser extension on Chrome and Edge. The multi‑stage payload uses JavaScript loaders, custom C++ installers, and blockchain‑based command‑and‑control via Ethereum smart contracts to evade detection. The extension bypasses Chromium integrity checks, harvests credentials, session tokens, and browser data, and exfiltrates it to a C2 server while maintaining persistence through scheduled tasks.
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
thehackernews.com

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

Cybersecurity researchers uncovered BambooToken, a multi‑platform malware that has operated since February 2023, targeting Windows and Linux systems across Asia and South America. The campaign uses the MQTT protocol for command‑and‑control, a rare choice for malware. BambooToken is delivered via Tendyron’s OnKey USB security token, exploiting DLL sideloading to evade detection. The malware collects extensive system data, exfiltrates antivirus information, and has been observed communicating from Chinese IP addresses and Cloudflare‑proxied domains.