<?xml version="1.0" encoding="utf-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title><![CDATA[Security - Newslocker]]></title><link>https://www.newslocker.com/en-us/profession/security_news/</link><atom:link rel="self" href="https://www.newslocker.com/en-us/profession/security_news/rss/" /><atom:link rel="hub" href="http://pubsubhubbub.appspot.com" /><description><![CDATA[Find your latest Security news with just one click. Don't miss out on anything happening in your profession!]]></description><language>en-us</language><copyright>Copyright (C) 2026 newslocker.com</copyright><lastBuildDate>Fri, 11 Sep 2026 23:19:00 +0200</lastBuildDate><item><title><![CDATA[Max severity GitLab path traversal flaw under active reconnaissance]]></title><description><![CDATA[The flaw could enable sensitive files to be read with just an HTTP request.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/max-severity-gitlab-path-traversal-flaw-under-active-reconnaissance/</link><pubDate>Fri, 11 Sep 2026 23:19:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/max-severity-gitlab-path-traversal-flaw-under-active-reconnaissance/</guid></item><item><title><![CDATA[Check Point patches two critical VPN gateway bugs]]></title><description><![CDATA[Check Point fixed two 9.8-severity VPN flaws before any known exploitation in the wild.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/check-point-patches-two-critical-vpn-gateway-bugs/</link><pubDate>Fri, 11 Sep 2026 21:00:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/check-point-patches-two-critical-vpn-gateway-bugs/</guid></item><item><title><![CDATA[Dead drops in public: What the AI agent stashed on Hugging Face]]></title><description><![CDATA[A technical breakdown of artifacts the agent left in public repositories during the July 2026 Hugging Face intrusion.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/dead-drops-in-public-what-the-ai-agent-stashed-on-hugging-face/</link><pubDate>Fri, 11 Sep 2026 20:33:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/dead-drops-in-public-what-the-ai-agent-stashed-on-hugging-face/</guid></item><item><title><![CDATA[Anthropic finds 4th real-world attack by Claude agent, details models’ ‘biased reasoning’]]></title><description><![CDATA[Mythos 5 was highlighted as being especially prone to believing the real world was a simulation.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/anthropic-finds-4th-real-world-attack-by-claude-agent-details-models-biased-reasoning/</link><pubDate>Fri, 11 Sep 2026 19:51:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/anthropic-finds-4th-real-world-attack-by-claude-agent-details-models-biased-reasoning/</guid></item><item><title><![CDATA[AI governance needs to become part of the CISO’s GRC program]]></title><description><![CDATA[Here's why CISOs must include Ai in the company's GRC program.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/ai-governance-needs-to-become-part-of-the-cisos-grc-program/</link><pubDate>Fri, 11 Sep 2026 18:21:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/ai-governance-needs-to-become-part-of-the-cisos-grc-program/</guid></item><item><title><![CDATA[Ping YOUniverse: How to classify and manage AI agents]]></title><description><![CDATA[There are four kinds of AI agents, and each must be handled differently, Ping executives said.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/ping-youniverse-how-to-classify-and-manage-ai-agents/</link><pubDate>Fri, 11 Sep 2026 18:09:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/ping-youniverse-how-to-classify-and-manage-ai-agents/</guid></item><item><title><![CDATA[How coding agents are changing application risk]]></title><description><![CDATA[Coding agents expand application risk beyond AI models to the tools, context and systems around them.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/how-coding-agents-are-changing-application-risk/</link><pubDate>Fri, 11 Sep 2026 18:00:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/how-coding-agents-are-changing-application-risk/</guid></item><item><title><![CDATA[When English becomes exploit code: The hidden risk inside MCP servers]]></title><description><![CDATA[A harmless-looking sentence can influence an agent's choices once it enters a model's context.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/when-english-becomes-exploit-code-the-hidden-risk-inside-mcp-servers/</link><pubDate>Thu, 10 Sep 2026 22:28:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/when-english-becomes-exploit-code-the-hidden-risk-inside-mcp-servers/</guid></item><item><title><![CDATA[CISA: WatchGuard Firebox bug exploited in ransomware campaigns]]></title><description><![CDATA[Ransomware gangs are exploiting a WatchGuard Firebox flaw that CISA flagged nine months ago.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/cisa-watchguard-firebox-bug-exploited-in-ransomware-campaigns/</link><pubDate>Thu, 10 Sep 2026 21:47:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/cisa-watchguard-firebox-bug-exploited-in-ransomware-campaigns/</guid></item><item><title><![CDATA[A security framework for coding agents and their harnesses]]></title><description><![CDATA[The five layers of securing AI agent harnesses.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/a-security-framework-for-coding-agents-and-their-harnesses/</link><pubDate>Thu, 10 Sep 2026 20:59:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/a-security-framework-for-coding-agents-and-their-harnesses/</guid></item><item><title><![CDATA[What CIO-CISO alignment looks like when it's working]]></title><description><![CDATA[Cushman &amp; Wakefield leaders share five practices for building an effective CIO-CISO partnership.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/what-cio-ciso-alignment-looks-like-when-its-working/</link><pubDate>Thu, 10 Sep 2026 19:34:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/what-cio-ciso-alignment-looks-like-when-its-working/</guid></item><item><title><![CDATA[A credo for the AI era: Trust, but Decompile]]></title><description><![CDATA[Here&rsquo;s why defenders today have to take apart and analyze code the way a hacker would.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/a-credo-for-the-ai-era-trust-but-decompile/</link><pubDate>Thu, 10 Sep 2026 18:11:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/a-credo-for-the-ai-era-trust-but-decompile/</guid></item><item><title><![CDATA[PaperCut MF/NG flaws attacked with hundreds of AI agents]]></title><description><![CDATA[The AI-assisted campaign enabled attackers to gain domain admin in as little as 5 minutes.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/papercut-mfng-flaws-attacked-with-hundreds-of-ai-agents/</link><pubDate>Thu, 10 Sep 2026 15:55:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/papercut-mfng-flaws-attacked-with-hundreds-of-ai-agents/</guid></item><item><title><![CDATA[Skullcandy Dime 3 earbuds vulnerable to Bluetooth hijacking]]></title><description><![CDATA[The vulnerability, tracked as CVE-2025-20701, affects firmware version 1.0.0.28 of the Skullcandy Dime 3 earbuds, which utilize the Airoha Bluetooth Audio SDK, the Carnegie Mellon University CERT Coordination Center (CERT/CC) warned.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/skullcandy-dime-3-earbuds-vulnerable-to-bluetooth-hijacking/</link><pubDate>Thu, 10 Sep 2026 15:38:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/skullcandy-dime-3-earbuds-vulnerable-to-bluetooth-hijacking/</guid></item><item><title><![CDATA[Gigabud banking trojan uses app cloning to evade fraud detection]]></title><description><![CDATA[Researchers at Group-IB have identified that Gigabud is now being paired with Vwork, a modified version of the Shelter app, attributed to the GoldFactory threat group.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/gigabud-banking-trojan-uses-app-cloning-to-evade-fraud-detection/</link><pubDate>Thu, 10 Sep 2026 01:46:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/gigabud-banking-trojan-uses-app-cloning-to-evade-fraud-detection/</guid></item><item><title><![CDATA[Over 36,000 Plex media servers remain unpatched against security vulnerabilities]]></title><description><![CDATA[The unpatched Plex Media Server instances are running versions 1.43.2 and earlier.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/over-36000-plex-media-servers-remain-unpatched-against-security-vulnerabilities/</link><pubDate>Thu, 10 Sep 2026 01:45:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/over-36000-plex-media-servers-remain-unpatched-against-security-vulnerabilities/</guid></item><item><title><![CDATA[Ping YOUniverse: The next stage of human authentication]]></title><description><![CDATA[Ping Identity says its combination of biometrics and verifiable documentation is the next step in access management.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/ping-youniverse-the-next-stage-of-human-authentication/</link><pubDate>Fri, 04 Sep 2026 23:25:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/ping-youniverse-the-next-stage-of-human-authentication/</guid></item><item><title><![CDATA[New Linux toolkit found in trojanized HAProxy targeting South Korean organizations]]></title><description><![CDATA[The implant, identified by Rapid7 Labs with medium confidence as originating from North Korean state-sponsored actors, targets entities in South Korea's automotive and media sectors.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/new-linux-toolkit-found-in-trojanized-haproxy-targeting-south-korean-organizations/</link><pubDate>Fri, 04 Sep 2026 22:51:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/new-linux-toolkit-found-in-trojanized-haproxy-targeting-south-korean-organizations/</guid></item><item><title><![CDATA[PostGREShell vulnerability allows server takeover]]></title><description><![CDATA[The vulnerability stems from missing authorization in PostgreSQL's logical decoding feature.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/postgreshell-vulnerability-allows-server-takeover/</link><pubDate>Fri, 04 Sep 2026 22:44:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/postgreshell-vulnerability-allows-server-takeover/</guid></item><item><title><![CDATA[Upwind Security raises $300 million in Series C funding]]></title><description><![CDATA[Upwind Security offers a platform that automatically maps cloud assets and refreshes data every 30 seconds to account for frequent configuration changes.]]></description><link>https://www.newslocker.com/en-us/profession/security_news/upwind-security-raises-300-million-in-series-c-funding/</link><pubDate>Fri, 04 Sep 2026 22:41:00 +0200</pubDate><guid>https://www.newslocker.com/en-us/profession/security_news/upwind-security-raises-300-million-in-series-c-funding/</guid></item></channel></rss>