129Articles
10Categories
2026-09-16Date
🚨 CISA KEV 1[−]
16 Sep KEVCISA Adds One Known Exploited Vulnerability to CatalogCISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-58704 Google Pixel Improper Authorization Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors…CISA.GOV
🐛 COMMON VULNERABILITIES AND EXPOSURES 16[−]
16 SepAttackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command ExecutionA critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauth…THEHACKERNEWS.COM
16 SepGoogle Patches Pixel Modem Flaw Amid Signs of Limited Targeted ExploitationGoogle has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass d…THEHACKERNEWS.COM
16 Sep KEVAcronis cPanel Backup Plugin Vulnerability Exploited in Targeted AttacksAcronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to…THEHACKERNEWS.COM
16 SepActive Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin TokensA critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result…THEHACKERNEWS.COM
16 Sep KEVOracle’s September patches put Fusion Middleware back in the hot seatOracle’s September 2026 Critical Security Patch Update has arrived with 673 new security patches spanning 17 Oracle product families, with Oracle E-Business Suite accounting for the largest share at 159 patches, followed by Fusion Middleware with 153. Of these, 19 E-Business Suit…CSOONLINE.COM
16 SepZDI-26-707: (0Day) MindsDB OpenBBtable Code Injection Remote Code Execution VulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of MindsDB. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-92207.ZERODAYINITIATIVE.COM
16 SepZDI-26-706: (0Day) CrewAI crewAI Framework Agent Loading Unsafe Reflection Remote Code Execution VulnerabilityThis vulnerability allows remote attackers to execute arbitrary code on affected installations of CrewAI crewAI. User interaction is required to exploit this vulnerability in that the target must load a malicious agent configuration from the repository. The ZDI has assigned a CVS…ZERODAYINITIATIVE.COM
16 SepZDI-26-705: (0Day) BusyBox libarchive Symlink Directory Traversal Arbitrary File Creation VulnerabilityThis vulnerability allows remote attackers to create arbitrary files on affected installations of BusyBox. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 6.1…ZERODAYINITIATIVE.COM
16 SepZDI-26-704: (0Day) Airbyte OneDrive Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure VulnerabilityThis vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92204.ZERODAYINITIATIVE.COM
16 SepZDI-26-703: (0Day) Airbyte SharePoint Connector _get_shared_drive_object Server-Side Request Forgery Information Disclosure VulnerabilityThis vulnerability allows remote attackers to initiate arbitrary server-side requests on affected installations of Airbyte. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.7. The following CVEs are assigned: CVE-2026-92203.ZERODAYINITIATIVE.COM
16 SepVU#212479: Sentry Seer vulnerability allows attacker-controlled input to be executed in a privileged environmentOverview A vulnerability exists in Sentry Seer when the system is configured to automatically hand issues to a coding agent for remediation. Successful exploitation results in arbitrary code execution within the coding‑agent environment and access to connected source repositories…KB.CERT.ORG
16 SepGoogle patches Pixel modem zero-day exploited in targeted attacksGoogle has fixed a high-severity Pixel modem vulnerability that may already have been exploited in limited, targeted attacks. Tracked as CVE-2026-58704, the flaw was fixed as part of the September 2026 Pixel security update, which brings supported devices to the 2026-09-05 securi…CYBERINSIDER.COM
16 SepPixel Modem Zero-Day Exploited in Targeted AttacksGoogle announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepParallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source: JFrog) The danger is highest on developer laptops, …HELPNETSECURITY.COM
16 SepAcronis backup plugin flaw exploited in targeted attacks (CVE-2026-87886)A Linux privilege escalation vulnerability (CVE-2026-87886) affecting Acronis’ backup extensions for cPanel, WebHost Manager (WHM), and Plesk, is being leveraged by attackers, the backup and recovery company warns. “Exploitation of this vulnerability has been detected…HELPNETSECURITY.COM
16 SepGoogle Patches Pixel Modem Zero-Day Exploited in Targeted AttacksGoogle has patched a high-severity zero-day in the Pixel cellular modem after finding evidence that the vulnerability was exploited in limited, targeted attacks. Google has released its September 2026 Pixel security update, addressing a large set of vulnerabilities, including a h…SECURITYAFFAIRS.COM
⚠️ VULNERABILITY DISCLOSURE 35[−]
16 SepRevolut hands customer data to criminals, Microsoft patches break Remote Desktop, Conti developer gets four yearsRevolut Fooled by Fake Govt Data Requests, Microsoft RDP Patch Fallout, and Conti Dev Sentenced David Shipley covers multiple cybersecurity headlines: Revolut disclosed extensive customer data after fraudsters used fake emergency requests from a legitimate government email accoun…CYBERSECURITYTODAY.LIBSYN.COM
16 SepAttacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 RepositoriesMandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended software that the attac…THEHACKERNEWS.COM
16 SepThreat Intelligence Alone Won't Close the Exploitation GapA leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted expl…THEHACKERNEWS.COM
16 SepAttackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web ShellsThreat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, …THEHACKERNEWS.COM
16 SepGoogle says some Pixel phone owners were hacked in zero-day attacksThe Pixel phone maker said there are indications that a bug in the phone's modem "may be under limited, targeted exploitation."TECHCRUNCH.COM
16 SepBig Tech’s AI safety rift signals disruption and disparity for enterprisesA growing divide among leading AI companies over how to secure increasingly powerful models is beginning to translate into challenges for enterprise IT, with implications for how organizations access, deploy, and govern AI systems. The latest flashpoint came after Meta CEO Mark Z…CSOONLINE.COM
16 SepAI agent authorization risks remain a gap in new NIST-CISA token security guidanceAI agents’ actions are out of scope for new guidance from US authorities on securing identity and access tokens, but there is still plenty enterprises can do to protect their systems from rogue humans and AI agents alike. “ Protecting Tokens and Assertions from Forgery, Theft, an…CSOONLINE.COM
16 SepYou don’t have to join the hack-back program to inherit its riskThe obvious question about Washington’s new private offensive cyber program is which security vendors will join it. The CSO question is what happens to you when one of your vendors does. The August 12 National Security Presidential Memorandum , “Expanding Capabilities to Combat T…CSOONLINE.COM
16 SepAI made software development unrecognizable. Is cybersecurity next?The rapid emergence of AI has radically changed a host of professions, with software engineering and development perhaps the most transformed of all pursuits. The usual “ solitary ritual ” of a developer writing code for hours is giving way to collaboration with an army of chatbo…CSOONLINE.COM
16 SepHundreds of OpenAI agents attack RubyGems platformA swarm of hundreds of OpenAI agents uploaded “malicious packages” to RubyGems and tried to steal API keys, the Ruby community gem hosting service revealed Friday. OpenAI confirmed part of the disclosure, saying , “our agents used the RubyGems platform to access the internet to c…CSOONLINE.COM
16 SepZDI-26-708: (0Day) Microsoft Windows HTTP Proxy Privilege Escalation VulnerabilityThis vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS ratin…ZERODAYINITIATIVE.COM
16 SepVU#369093: MLflow dspy and statsmodels flavors bypass pickle deserialization controlOverview A vulnerability in MLflow’s dspy and statsmodels model flavors allows unauthorized pickle deserialization executions despite a safety control. Specifically, the dspy flavor conditionally applies the control based on the model path’s file extension, and the statsmodels fl…KB.CERT.ORG
16 Sep KEVGoogle Pixel owners urged to patch actively exploited modem flawGoogle’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.MALWAREBYTES.COM
16 SepNightEagle targets Russian companiesKaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.SECURELIST.COM
16 SepHackers exploit zero-day flaw in Cisco email gatewayResearchers warn the vulnerability could be used by state-linked actors for espionage.CYBERSECURITYDIVE.COM
16 SepPHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin BugAttackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshellsINFOSECURITY-MAGAZINE.COM
16 SepZero-Day Flaw in TP-Link Cameras Enables EavesdroppingOPSWAT researchers find two zero-days in TP-Link camerasINFOSECURITY-MAGAZINE.COM
16 Sep KEVCritical ScreenConnect flaw now actively exploited in attacksAttackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]BLEEPINGCOMPUTER.COM
16 Sep KEVGoogle fixes actively exploited Android zero-day on Pixel devicesGoogle has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. [...]BLEEPINGCOMPUTER.COM
16 SepFirst Agentic AI Data Breach Reported to Spanish RegulatorSpanish regulators say an AI agent chained together a successful login, vulnerability discovery, and access to personal data in a potential milestone for autonomous cyberattacks. The post First Agentic AI Data Breach Reported to Spanish Regulator appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepUnauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to TakeoverVulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepHackuity Raises $19 Million for AI-Powered Vulnerability ManagementThe company will use the new capital to expand its vulnerability operations platform and support international growth. The post Hackuity Raises $19 Million for AI-Powered Vulnerability Management appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepCyber Op Targets South Korean Media & Automotive SectorsA likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.DARKREADING.COM
16 SepCohesity adds recovery capabilities for AI agents and the data they manageCohesity has introduced Cohesity Agent Resilience. This new Cohesity Data Cloud capability will discover, protect, and recover the infrastructure behind enterprise AI agents. A unified view of an agent and the state it depends on. (Source: Cohesity) The company outlined its visio…HELPNETSECURITY.COM
16 SepCenterPoint Energy confirms data breach following claims on hacking forumCenterPoint Energy disclosed that an unauthorized third party got into customer data through one of its external systems, after online claims by a hacker that millions of records had been stolen from the company. CenterPoint Energy is a Houston-based public utility company that p…HELPNETSECURITY.COM
16 SepNozomi Compass helps industrial teams manage OT assets and vulnerabilitiesNozomi Networks announced Nozomi Compass, an OT asset and service management platform designed to help organizations manage industrial assets, vulnerabilities, and exposures. The platform brings asset data, remediation workflows, and operational processes together, reducing relia…HELPNETSECURITY.COM
16 SepOne runaway AI agent racked up a $50,000 cloud billOrganizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud environments. At the same time, attacks are expanding from direct prompts to indirect prompt injection and AI supply chain compr…HELPNETSECURITY.COM
16 SepRevolut Data Leak May Trace Back to Compromised Italian Government AccountsA suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut data exposure may be part of a much broader cyber incident involving compromised Ita…SECURITYAFFAIRS.COM
16 SepData Broker Radaris Loses Domains in Privacy FightThe consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey priva…KREBSONSECURITY.COM
16 SepHouse passes bill to equip local law enforcement with scam-fighting toolsThe Guarding Unprotected Aging Retirees from Deception Act (GUARD) attempts to address a common complaint from the victims of online scams like pig butchering — that such cases typically do not rise to the level of a federal investigation but local law enforcement is unequipped t…THERECORD.MEDIA
16 SepMalware bypasses browser checks to force install Chrome, Edge extensionsA banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. [...]BLEEPINGCOMPUTER.COM
16 SepLinkedIn fights for the right to tell customers when the feds want their dataMicrosoft’s top lawyer argued Tuesday that legislators “must make secrecy [orders] the exception” in government subpoenas demanding information about LinkedIn users. LinkedIn, which is owned by Microsoft, is fighting what it calls overly broad subpoena demands from the US governm…CSOONLINE.COM
16 SepCybercrime finds its sea legs.Officials investigate suspected cyberattacks on U.S.-bound oil tankers. Iranian operators deploy Chosen Brick surveillance malware. Ukraine cracks down on scam call centers. Researchers uncover two TP-Link camera zero-days. Maria Varmazis looks at weapons in space. CenterPoint En…THECYBERWIRE.COM
16 SepKey lawmaker suggests action on AI safety legislation will wait until 2027“It's really complicated, and I wouldn't want to do something in a lame duck session to do it quickly and not get it right,” said House Energy and Commerce Chairman Brett Guthrie about the FRONTIER Act.THERECORD.MEDIA
16 SepCanada: Nipigon hospital hit by ransomware attackMike Stimpson reports: Some patient services may be affected as the general hospital in Nipigon responds to what it describes as a “cyber security incident.” An incident involving ransomware affected information technology systems, Nipigon District Memorial Hospital stated in a p…DATABREACHES.NET
📋 SECURITY BULLETINS 1[−]
16 SepWindows 11 KB5124008 update breaks domain trust for some usersMicrosoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise systems, preventing users from logging in with valid domain credentials. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 14[−]
16 SepCISA looks to recruit general infrastructure security experts rather than sector-focused advisers“I need people that can pivot from day to day,” the agency’s acting chief told reporters.CYBERSECURITYDIVE.COM
16 SepCISA and NIST Issue Guidance to Protect Cloud Identity TokensCISA and NIST issued final guidance to help protect cloud identity tokens and assertionsINFOSECURITY-MAGAZINE.COM
16 SepNCSC and Allies Warn of Iranian Spyware CampaignThe UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidentsINFOSECURITY-MAGAZINE.COM
16 SepCISA promotes a fresh way to deter cyberattackers: Lie to themIt’s the first guidance from the Cybersecurity and Infrastructure Security Agency on deploying decoys, like honeypots, to detect and distract adversaries. The post CISA promotes a fresh way to deter cyberattackers: Lie to them appeared first on CyberScoop .CYBERSCOOP.COM
🔥 INCIDENT REPORTING 19[−]
16 SepThree Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and WipersEnterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a thr…THEHACKERNEWS.COM
16 SepN0va Phishkit Targets US and EU Businesses: A New Challenge for Identity SecurityN0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity. Fro…THEHACKERNEWS.COM
16 SepHackers publish thousands of drivers’ data after breaching Florida motor vehicle databaseThe ShinyHunters gang leaked the files online after saying the Florida state agency did not pay their ransom demand.TECHCRUNCH.COM
16 SepUS authorities investigate cyberattacks against oil tankersPhantomRaven infostealer targets bug bounty opportunities. Business news: Physical AI security firm Exein lands $270 million.THECYBERWIRE.COM
16 SepInternational Meteor Organization says cyberattack dealt ‘critical blow’ to websiteA website used around the world for reporting meteors faces weeks of downtime as the organization moves away from systems that were hacked recently.THERECORD.MEDIA
16 SepEU chief wants joint response to cyberattacks, sabotageDelivering her annual State of the Union address in Strasbourg, Ursula von der Leyen said threats were “mounting on our soil,” pointing to recent incidents in Denmark, Lithuania and Poland and an attempted drone attack in Leipzig.THERECORD.MEDIA
16 SepCoast Guard, FBI board US-bound foreign ships in order to probe for cyberattacksThe agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.” The post Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks appeared first on CyberScoop…CYBERSCOOP.COM
16 SepCyber-Attacks Cost Organizations $52,000 on AverageHiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000INFOSECURITY-MAGAZINE.COM
16 SepRevolut hackers used infostealer to hijack Italian government emailsAttackers behind the recent Revolut data exposure allegedly used compromised Italian government email accounts for months to submit fraudulent customer information requests, according to new findings from Duel and Hudson Rock. The hackers are also reportedly demanding 10,000 Bitc…CYBERINSIDER.COM
16 SepSpain's data agency gets first report of AI-powered data breachThe Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). [...]BLEEPINGCOMPUTER.COM
16 SepThe true cost of a ransomware attack, with and without BCDRThe ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to…BLEEPINGCOMPUTER.COM
16 SepWebinar: What happens in the first hours of a Google Workspace breachThe first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. [...]BLEEPINGCOMPUTER.COM
16 Sep280,000 Impacted by Premier Medical Group Data BreachIn June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information. The post 280,000 Impacted by Premier Medical Group Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepBragJack Attack Can Turn a Browser's Agentic AI Against ItA new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious actions, and exfiltrate data.DARKREADING.COM
16 SepRubrik MCP gives AI agents controlled access to security intelligenceRubrik has announced Rubrik MCP (Model Context Protocol), giving an organization’s AI agents a secure, programmable path to Rubrik’s data, identity, and application intelligence. Support for MCP expands Rubrik AI, which is now trusted by one-third of its global customers, and uni…HELPNETSECURITY.COM
16 SepCitrix adds AI-powered browser activity analysis to SecurAccessCitrix has announced Citrix Session Insights, a new AI-powered capability for Citrix SecurAccess with Chrome Enterprise that helps organizations capture, analyze and understand browser activity from users and autonomous agents. By combining visual session evidence, AI-powered ris…HELPNETSECURITY.COM
16 SepTexas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records StolenCenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder stole personal information belonging to some of its customers. The Houston-based ut…SECURITYAFFAIRS.COM
16 SepCoast Guard, FBI boarded tanker after attack by ‘foreign cyber actors’U.S. personnel boarded an oil tanker in the Gulf of Mexico to “ensure integrity of the vessel’s operational and information technology systems," after an apparent cyberattack, the U.S. Coast Guard said.THERECORD.MEDIA
16 SepSmashing Security podcast #485: These researchers got drunk to hack an LG TVResearchers wanted to test if LG's smart TVs come with any security risks - but their lawyers noticed a snag: the terms and conditions would forbid it. So they came up with a solution. They got plastered before setting up the TV, on the reasoning that you can't be legally bound t…GRAHAMCLULEY.COM
🕵️ THREAT INTELLIGENCE 21[−]
16 SepFake CAPTCHA ScamsNew variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.SCHNEIER.COM
16 SepKREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session TokensCybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used l…THEHACKERNEWS.COM
16 SepISC Stormcast For Wednesday, September 16th, 2026 https://isc.sans.edu/podcastdetail/10096, (Wed, Sep 16th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
16 SepAI Is More Than a Nuclear RaceAI is being compared to a nuclear race, cyber conflict, and the Industrial Revolution at the same time. Its strategic assets may include factories, models, research, and intellectual property—all of which can be software. Slowing development without understanding the technology m…YOUTUBE.COM
16 SepYour Team Can Change LeadershipLeadership isn’t purely top-down. Teams and followers can collectively influence the people above them, even when those leaders have formal authority. Bad leadership can persist for a long time, but reputation and repeated resistance can gradually create consequences. Individual …YOUTUBE.COM
16 SepFollowership, CyberSecurity Leadership, and Judgement as a Defining Skill - BSW #465The overwhelming majority of people, across the full span of their professional lives, operate without formal authority over the domains in which they work (i.e., leadership). Yet followership has almost no sustained literature, no targeted development, and no rigorous framework …YOUTUBE.COM
16 SepTreasury’s Scott Bessent says no liability exemptions for AI labsThe secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.” The post Treasury’s Scott Bessent says no liability exemptions for AI labs appeared first on CyberScoop…FEDSCOOP.COM
16 SepHackers Got Inside a Flock Camera. Its Data Shows How the System Really WorksA hacker collective pulled down a Flock camera and dumped its data. The files included thousands of videos and logs showing that the device captured 1.6 million images of 50,000 vehicles in 21 days.WIRED.COM
16 SepAtomic macOS (AMOS) Stealer ActivityModern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
16 SepApple uses secure camera hardware to verify photos are real capturesApple has announced Apple Reference Image, a new iPhone photography mode designed to cryptographically prove that a photograph originated from a real camera sensor while preserving the photographer’s privacy. The opt-in feature will debut on the main cameras of the iPhone 18 Pro …CYBERINSIDER.COM
16 SepIranian malware steals Telegram and WhatsApp data from targetsIranian state cyber actors are using Windows malware called CHOSEN BRICK to target dissidents, activists, and journalists, with capabilities that include stealing Telegram and WhatsApp browser data, emails, screenshots, and audio. The malware has been used internationally since a…CYBERINSIDER.COM
16 SepVirtual Event Today: Attack Surface Management SummitJoin SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces. The post Virtual Event Today: Attack Surface Management Summit appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepEU Chief Warns of AI-Powered Hacking, Moves to Rein In Social MediaUrsula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children. The post EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media appeared first on SecurityWeek…SECURITYWEEK.COM
16 SepAIUC Raises $40 Million to Certify Enterprise AI AgentsThe company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepUS, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance MalwareUS, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepChrome, Firefox Updates Patch 115 VulnerabilitiesGoogle resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox. The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
16 SepSelf-improving AI should slow down, von der Leyen tells EU lawmakersEuropean Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can support their own efforts to do that. In her State of the Union address to the European Parliament in …HELPNETSECURITY.COM
16 SepIranian hackers use CHOSEN BRICK data-stealing malware to spy on dissidents and journalistsIranian state cyber actors are deploying malware called CHOSEN BRICK against individuals they see as a threat to the regime, reaching victims through social messaging apps and infecting their Windows devices, three Western intelligence agencies warned. The UK’s National Cyb…HELPNETSECURITY.COM
16 SepBTS #82 - Firmware Analysis, Linux Malware, Future of AIBelow the Surface episode 82 was recorded on September 10, 2026, with host Paul Asadoorian joined by Vlad Babkin and Chase Snyder. The conversation moves across several current security stories, but its center of gravity is clear: modern infrastructure depends on trust mechanisms…ECLYPSIUM.COM
16 SepCISOs Need the CFO’s TrustA CISO’s influence depends on relationships well beyond the security organization. Strong connections with the CFO, legal, HR, CIO, and technical leadership can shape how security decisions are made. The CFO relationship is particularly important because cybersecurity risk needs …YOUTUBE.COM
16 SepIranian hackers use CHOSEN BRICK Windows malware to spy on targetsGovernment agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents, activists, and journalists worldwide. [...]BLEEPINGCOMPUTER.COM
🌐 CYBER THREAT LANDSCAPE 2[−]
16 SepMajor Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face ChangesA group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT programINFOSECURITY-MAGAZINE.COM
16 SepBambooToken: The Malware That Speaks MQTT to Stay Under the RadarLumen exposes BambooToken, a stealthy malware family using MQTT and sideloading to quietly infect targets across Asia and beyond. BambooToken is a new malware family that uses MQTT, a lightweight messaging protocol commonly found in smart devices and industrial systems, to quietl…SECURITYAFFAIRS.COM
🎙️ PODCASTS 1[−]
16 SepRisky Business #853 -- We're all gonna die, apparentlyOn this week’s show Patrick Gray and James Wilson are joined by former US Cyber Command executive director turned PwC’s Cyber, Data & Technology Risk leader Morgan Adamski to talk through the week’s news, including: More tech guys penned more open letters and AI will destroy …RISKY.BIZ
📡 INFOSEC NEWS 19[−]
16 SepWeekly Threat Bulletin – September 16th, 2026These are the top threats you should know about this week.F5.COM
16 SepOne Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and ClaudeSecurity researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extensio…THEHACKERNEWS.COM
16 SepParallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install FixParallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine as a normal user, so it does not work over the network. JFr…THEHACKERNEWS.COM
16 SepSecuring the unpatchable in an age of AI-driven vulnerabilitiesAdvances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deployment of NGFW/IPS combinations can provide a powerful compensator…TALOSINTELLIGENCE.COM
16 SepAgents at Large | Tracing Illicit OpenAI Agent Activity on Hugging FaceTwo Hugging Face accounts reveal that OpenAI's agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.SENTINELONE.COM
16 SepAI helps scammers build convincing antivirus renewal pagesA fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.MALWAREBYTES.COM
16 SepWhat CEOs Actually Think When They Watch CMOs Operate with David PolitisWhen David Politis sits down with Gianna and Charles on CyberCMO Confidential, you’re getting something rare: A CEO who loves marketing telling you exactly what he thinks when he watches CMOs operate. Why the CRO wins if you let them, why he stops listening the moment someone say…THECYBERWIRE.COM
16 SepThree Ukrainians to face charges for alleged hack of 610,000 Roblox accountsThree Ukrainians are set to stand trial for allegedly stealing access to more than 610,000 Roblox accounts and selling them to buyers in Russia, authorities said.THERECORD.MEDIA
16 SepFlock camera use by internal affairs unit puts DC police at odds with officers’ unionWashington, D.C.'s police department has used information from Flock cameras for misconduct investigations, prompting a formal complaint from its officers' union.THERECORD.MEDIA
16 SepUkraine moves to crack down on scam call centers after corruption scandalUkraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes to protect scam operations.THERECORD.MEDIA
16 SepMicrosoft says Copilot buttons still missing in classic OutlookMicrosoft says it's still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. [...]BLEEPINGCOMPUTER.COM
16 SepWindows Server 2022 reaches end of mainstream support next monthMicrosoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. [...]BLEEPINGCOMPUTER.COM
16 SepScans Targeting Hospitality Applications, (Wed, Sep 16th)Earlier today, I noted an odd request showing up in our "First Seen" report: ISC.SANS.EDU
16 SepFighting Your Dragons Through Tough Tech TimesCybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections during historical tech industry downturns.DARKREADING.COM
16 SepPhysical AI security company Exein lands $270 million.Scottish MSSP Quorum Cyber has agreed to acquire Swiss agentic SOC provider Ontinue.THECYBERWIRE.COM
16 SepArchitecting a secure landing zone in the AWS European Sovereign CloudThe AWS European Sovereign Cloud is a new, independent cloud for Europe, physically and logically separate from existing AWS Regions and operated within the European Union (EU). It provides the same services, features, and APIs as AWS commercial Regions, but runs as a distinct AW…AWS.AMAZON.COM
16 SepAI Security Spending Jumps as Fear Outpaces Proof of ValueCISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move?DARKREADING.COM
16 SepAnthropic wants Claude to analyze your bank account and financial dataAnthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Claude and "understand your money." [...]BLEEPINGCOMPUTER.COM