118Articles
9Categories
2026-09-17Date
🚨 CISA KEV 1[−]
17 Sep KEVU.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added [1, 2] the following vulnerabilitie…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 12[−]
17 Sep KEVUnauthenticated attackers are bypassing Cisco ISE’s management interface (CVE-2026-76460)Two days after it warned customers about an actively exploited email gateway zero-day, Cisco confirmed one more flaw is being targeted: CVE-2026-76460, an authentication bypass bug in an API of Cisco Identity Services Engine (ISE). About CVE-2026-76460 Cisco ISE is an identity-ba…HELPNETSECURITY.COM
17 SepCritical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS ZoneEvery release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling rem…THEHACKERNEWS.COM
17 SepCVE-2026-50311 Windows Server Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-55039 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-66809 Microsoft Office Graphics Component Information Disclosure VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-62819 Windows Routing and Remote Access Service (RRAS) Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-68794 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-69724 Microsoft Office SharePoint Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 SepCVE-2026-81957 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
17 Sep KEVCisco patches max-severity ISE flaw, the second critical zero-day this weekCisco released patches for an actively exploited authentication bypass vulnerability in its Cisco Identity Services Engine (ISE) platform, which is used for enterprise network access control and policy enforcement. This is the second zero-day flaw Cisco has been forced to release…CSOONLINE.COM
17 Sep KEVCisco alerts customers to second actively exploited zero-day in as many daysThe latest zero-day has a maximum-severity rating and affects Cisco Identity Services Engine, a product hit with three actively exploited vulnerabilities since June 2025. The post Cisco alerts customers to second actively exploited zero-day in as many days appeared first on Cyber…CYBERSCOOP.COM
⚠️ VULNERABILITY DISCLOSURE 32[−]
17 SepAI is adding to the review load on open-source projects, many of them thinly fundedAI coding tools are making open source software harder to maintain and secure, according to six authors writing for the Association for Computing Machinery’s Technology Policy Council, among them Simson Garfinkel and Josiah Dykstra. The tools write code and find security fl…HELPNETSECURITY.COM
17 SepA flat cybersecurity budget doesn’t have to mean weaker coverageCheri Hotman, Managing Partner of Hotman Group, works as a vCISO and vGRC leader. In this Help Net Security video, she talks about holding coverage steady when the CFO asks for a flat budget or a 12% cut. Her advice is to stop trimming every line by the same percentage. Instead, …HELPNETSECURITY.COM
17 SepActive Exploitation Triggers Emergency Patch for Cisco ISE Zero-DayRemote, unauthenticated attackers can exploit the vulnerability to bypass authentication via crafted requests. The post Active Exploitation Triggers Emergency Patch for Cisco ISE Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepTuskira Vector brings autonomous red teaming to attack surface validationTuskira has announced Vector, its autonomous red teaming agentic capability, which identifies an organization’s exploitable attack surface by simulating what an attacker can do from outside it. Tuskira validates every external finding against the organization’s deploy…HELPNETSECURITY.COM
17 SepCisco warns of max severity ISE zero-day exploited in attacksCisco has released security updates to address a maximum-severity Identity Services Engine vulnerability that attackers are actively exploiting in the wild. [...]BLEEPINGCOMPUTER.COM
17 Sep16 governance tools for securing your AI fleetEvery DevOps team member knows that dealing with an AI is like being a circus lion tamer. The boss and the audience are happy when the lions sit on the pedestal and roar on cue, but there’s always the danger that they’ll go rogue and bring the whole show to a quick and disastrous…CSOONLINE.COM
17 Sep100,000+ WordPress sites infected via Brevo supply chain attackA breach affecting Brevo infrastructure has pushed malicious JavaScript to more than 100,000 websites through Brevo-hosted widgets and scripts. According to a report from the Sansec Forensics Team, attackers modified Brevo resources on September 14 to deliver malware that attempt…CYBERINSIDER.COM
17 SepCisco Warns of Active Exploitation of Critical ISE FlawCisco urged ISE customers to apply a software update, as well as check for signs of exploitationINFOSECURITY-MAGAZINE.COM
17 SepFBI takes down one of the longest-running DDoS-for-hire servicesThe FBI has seized the domains behind NightmareStresser, a DDoS-for-hire service officials call one of the longest running “booter” operations in existence. The domain seizure notice (Source: US Department of Justice) “Booter services such as those named in this…HELPNETSECURITY.COM
17 SepGyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata RecordsSwati Khandelwal reports: A security breach at Gyazo, Helpfeel’s image-sharing service, exposed about 23.62 million user records, including email addresses and password hashes, the Kyoto-based company said in a notice published Wednesday. It also exposed about 490 million i…DATABREACHES.NET
17 SepISC Patches 14 Vulnerabilities in BIND 9 Security UpdateAttackers could exploit the flaws to increase resource usage, trigger an unexpected program exit, or terminate the named process. The post ISC Patches 14 Vulnerabilities in BIND 9 Security Update appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepRansomware Attacks on Manufacturers Surge as Supply Chain Risk GrowsResearch shows attacks on manufacturers rose 40% in early 2026, as ransomware groups increasingly exploit the supply-chain disruption caused by operational shutdowns. The post Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepCisco Fixes Dozens of Flaws Across FMC, ISE and Nexus DashboardThe vulnerabilities may lead to root access, command execution, bypasses, SQL injection, and remote code execution. The post Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepCISA wants critical infrastructure orgs and smaller security teams to start using cyber decoysCyber deception has long been the domain of well-resourced security teams, but CISA’s latest guidance, titled “Using Cyber Decoys to Strengthen Detection and Response”, is an attempt to try and change that. Why decoys, and why now The core problem CISA is attemp…HELPNETSECURITY.COM
17 SepNavigate360 may soon release a public notice about its horrific breach, but will any individuals be notified?Six months ago, a hacktivist announced that they had accessed and acquired 8.3 million tips submitted on supposedly anonymous tip lines and platforms used by schools, communities, Crime Stoppers organizations, law enforcement, and the military. Six months later, individuals affec…DATABREACHES.NET
17 SepCan You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This WebinarA new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many secur…THEHACKERNEWS.COM
17 SepCISO's Expert Guide to Agentic Pentesting for WebsitesAttackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand …THEHACKERNEWS.COM
17 SepCongress eyes new support for Cyber Command after recent suicide deathsCongressional sources say they view the deaths of U.S. Cyber Command personnel as an inflection point, especially as the Pentagon’s appetite for cyber capabilities grows following successful contributions to high-profile missions against Iran and Venezuela.THERECORD.MEDIA
17 SepIranian strikes on AWS facilities left customer data beyond recovery in Bahrain, UAESix months after Iranian drone strikes tore through its Middle East infrastructure, Amazon Web Services (AWS) has acknowledged the permanent loss of customer data in Bahrain and the UAE. In two updates posted September 15, AWS said it can no longer recover customer data and resou…HELPNETSECURITY.COM
17 SepDownload: The IT leader’s guide to AI code sprawlAI hasn’t just made building faster, it’s made everyone a builder. Across every department, employees are shipping apps, agents and automations using AI tools, often without knowing they’ve created something that needs governing at all. The result: AI code spraw…HELPNETSECURITY.COM
17 SepAI Is Outrunning Your Patch ProgramAI is accelerating vulnerability discovery, while patching still depends on people, money, and operational capacity. The old delay between finding vulnerabilities and having to fix them provided some breathing room. As that friction disappears, organizations may face vulnerabilit…YOUTUBE.COM
17 SepOpenAI reveals its AI agents hid mistakes and bypassed restrictionsOpenAI has disclosed six examples of concerning model behavior observed during the training and evaluation over the past six months, including models concealing mistakes, using exposed API keys, uploading files publicly, and bypassing technical restrictions. The incidents are the…CYBERINSIDER.COM
17 SepCISA Retires Weekly Vulnerability Bulletin in Risk-Based PivotThe decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk. The post CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepOpenAI admits six new misalignment incidents under new reporting frameworkOpenAI has published six new reports detailing AI model misalignment, including instances of hidden instructions, unauthorized communication, and attempts to locate exposed API keys, adding to the evidence that its AI systems bypassed controls during testing. The reports, based o…CSOONLINE.COM
17 SepVU#280377: Dokploy is vulnerable to OS command injectionOverview Dokploy versions 0.29.8 and 0.29.11, as well as commit 24b02f5 on the canary branch, are vulnerable to OS command injection during the backup creation and restoration processes. The vulnerability stems from unsanitized shell command construction that can allow an attacke…KB.CERT.ORG
17 SepOpenAI discloses six new "concerning" AI incidents.US law enforcement seizes DDoS-for-hire service. TrustSink technique uses rogue external MFA providers to intercept passwords.THECYBERWIRE.COM
17 SepPort of LA Fended Off 120 Million Cyberattacks in AugustPYMNTS reports: The Port of Los Angeles reportedly blocked more than 120 million cyberattacks during August. That’s according to a report Thursday (Sept. 17) by Bloomberg News, which notes that these attacks on America’s busiest container hub for global trade represent an ongoing…DATABREACHES.NET
17 SepEU chief wants joint response to cyberattacks, sabotageAlexander Martin reports: European Commission President Ursula von der Leyen proposed on Wednesday an emergency mechanism allowing any EU country to summon the bloc’s governments in response to security threats including sabotage, cyberattacks and drone incursions. Delivering her…DATABREACHES.NET
17 SepThe AI hacking apocalypse is not inevitableWhile large language models present real risks to society, experts say they can be tested and largely controlled using well-worn cybersecurity and policy choices. The post The AI hacking apocalypse is not inevitable appeared first on CyberScoop .CYBERSCOOP.COM
17 SepAI hates CAPTCHAs - PSW #944In the security news this week: - UK government rolls out passkeys to 20 million users - Phishing-resistant authentication and replay resistance - Passkey adoption, device security, and user acceptance - EU Cyber Resilience Act guidance, scope, and compliance - CRA vulnerability …YOUTUBE.COM
17 SepScamazon prime.This week, hosts of N2K CyberWire ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Maria Varmazis⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ and⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠ ⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠⁠Dave …THECYBERWIRE.COM
17 SepCISA Ditches Weekly Vulnerability Roundups for Risk-Based FocusThe move is consistent with the agency's advice on the need for organizations to prioritize the vulnerabilities that actually matter.DARKREADING.COM
📋 SECURITY BULLETINS 1[−]
17 SepMicrosoft shares workaround for Windows domain login issuesMicrosoft shared a temporary fix on Wednesday for a known issue that prevents Windows 11 users from logging in with valid domain credentials after installing the September 2026 security updates. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 13[−]
17 SepThe battle for AI regulation.This week, Dave and Ben sit down with N2K's lead analyst Ethan Cook to look at the growing calls to enact AI regulations both within the US and across the globe. Spurned on by recent model escapes, policymakers and AI developers alike have steadily begun to call for greater legis…THECYBERWIRE.COM
17 SepCISA Releases Guidance on Deploying Cyber DecoysComplementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments. The post CISA Releases Guidance on Deploying Cyber Decoys appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepChosen Brick, Iran’s Surveillance MalwareUK, US, and Dutch agencies expose Chosen Brick, Iranian malware used to track and harass dissidents, journalists, and activists via Telegram. The UK, the US, and the Netherlands published a joint advisory warning about a Windows malware family, dubbed Chosen Brick, that Iran̵…SECURITYAFFAIRS.COM
17 SepComp AI Raises $34 Million for AI-Native Compliance and SecurityThe company plans to expand into continuous cybersecurity, offering security testing across applications and infrastructure. The post Comp AI Raises $34 Million for AI-Native Compliance and Security appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepSelf-modifying AI agents expose a blind spot in enterprise securityAs debate over AI safety intensifies, new research is drawing attention to a more immediate risk for enterprises: AI agents that can alter the models they rely on while carrying out routine tasks. Researchers at AI security firm Irregular asked a coding agent to solve a software …CSOONLINE.COM
17 SepCISA Urges Critical Infrastructure to Plant Decoys Inside NetworksCISA released guidance on using cyber decoys to detect & disrupt malicious activity inside networksINFOSECURITY-MAGAZINE.COM
17 SepSecurity spending is growing — except for the typical CISOSecurity budgets may be growing on paper, but for a majority of CISOs, the money isn’t moving in quite the same direction. The budgets grew by 5% on average in 2026, up from 4% last year. But that average hides a much weaker picture: median budget growth remained at 0%. And while…CSOONLINE.COM
17 SepOpenAI backs calls for binding UK AI regulation.EU looks to ban social media for minors.THECYBERWIRE.COM
17 SepAI is calling the shots.AI goes to war. Iranian strikes leave AWS data unrecoverable. OpenAI discloses more model misbehavior. Researchers uncover 16 Wireshark vulnerabilities. TrustSink turns Entra authentication into a password trap. RatHat raids Android credentials. The FBI takes down a DDoS-for-hire…THECYBERWIRE.COM
🔥 INCIDENT REPORTING 14[−]
17 SepAI Agent Carries Out Multi-Stage Data Theft AttackSpanish data protection agency AEPD reveals the country’s first AI-powered data breachINFOSECURITY-MAGAZINE.COM
17 SepSpain reports first data breach involving autonomous AI agentSpain’s data protection authority (AEPD) has reported its first data breach blamed on an AI agent acting on its own, after the system reportedly logged into a company’s network, found a way to alter personal records, and pulled invoice data. “Before drawing any conclu…HELPNETSECURITY.COM
17 SepRansomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI useRansomware incidents in Japan rose 4.7% year over year. The Gentlemen was the most active group, with leak-site listings more than doubling from January to July. Qilin ranked second and appeared to use AI, while SMEs with capital under JPY 1 billion represented 80% of victims.TALOSINTELLIGENCE.COM
17 SepAmerica’s cyber strategy overlooks the infrastructure that actually keeps the military movingPorts, railroads, and utilities keep the military operational. They're all vulnerable to Iranian cyberattacks. The post America’s cyber strategy overlooks the infrastructure that actually keeps the military moving appeared first on CyberScoop .CYBERSCOOP.COM
17 SepThe Odyssey and trojans again: MovieReaper attacks users in multiple countries via compromised torrentsKaspersky experts have discovered a new MovieReaper campaign. The multi-stage Trojan spreads through movie torrents, such as "The Odyssey," and uses the Solana blockchain to hide its C2 infrastructure.SECURELIST.COM
17 SepDruva expands identity resilience with ransomware detectionDruva has announced new capabilities for Druva Identity Resilience alongside the launch of Ransomware Detection, a new feature fueled by a proprietary AI threat pipeline. Powered by Dru MetaGraph, the new offerings use behavioral intelligence and built-in validation to turn suspi…HELPNETSECURITY.COM
17 SepHackers claim breach of Russian election systems days before parliamentary voteAn anonymous hacking group claimed to have broken into computer systems connected to Russia’s election infrastructure just days before the country begins voting for a new parliament.THERECORD.MEDIA
17 SepRevolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M RansomRevolut allegedly fed customer information to hackers impersonating an Italian government agency for five months. The post Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepRevolut phishing texts appear days after data breachRevolut customers received phishing texts only days after the digital bank acknowledged disclosing customer data to a government impostor.MALWAREBYTES.COM
17 SepUS Coast Guard and FBI board oil tanker to investigate cyber attackAn oil tanker bound for Texas was boarded mid-voyage by the US Coast Guard and FBI last month, after its network may have been compromised by malicious hackers. According to the US Coast Guard, the supertanker was boarded after indications that the network "may have been compromi…BITDEFENDER.COM
17 SepFBI, Coast Guard probe suspected cyberattacks on ships entering US watersThe investigation comes at a time of heightened vigilance over U.S. port facilities and maritime security.CYBERSECURITYDIVE.COM
17 SepCyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board VesselsThe Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran. The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepCyberattacks on Oil Tankers Put Maritime Critical Infrastructure at RiskCyberattacks on oil tankers show how connected ships can expose navigation and critical systems, threatening safety, ports and global trade. U.S. Coast Guard personnel and FBI agents boarded two Texas‑bound energy tankers last month after cyberattacks hit the vessels while they w…SECURITYAFFAIRS.COM
17 SepNew RatHat Android malware uses AI to automate device controlA new Android malware called RatHat has been discovered, targeting users with an AI-powered subsystem that helps operators remotely navigate compromised devices. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 23[−]
17 SepISC Stormcast For Thursday, September 17th, 2026 https://isc.sans.edu/podcastdetail/10098, (Thu, Sep 17th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
17 SepThe world must establish red lines for autonomous AI weaponsAI is transforming warfare and international conflict. Autonomous weapon systems pose a genuine threat to civilians. The war in Ukraine has become a proving ground for weapons that can navigate, identify targets, resist electronic countermeasures, and pursue and engage targets au…HELPNETSECURITY.COM
17 SepAWS’s new sign-up gives accounts spend caps, email invites, and agent-set permissionsNew AWS customers can now sign up with a Google, GitHub, or Apple login, start with $100 in Free Tier credits, and build inside a “project” where AWS and coding agents set up permissions automatically. Paid projects get a monthly spend limit, starting at $20, and a pr…HELPNETSECURITY.COM
17 SepGNOME 51 adds passkey logins, offline maps and drawn PDF signaturesGNOME 51, the new version of the Linux desktop, came out on September 16 under the codename A Coruña. The release adds offline maps and live transit information to Maps, new login options at the login screen, hand-drawn signatures in the Papers document viewer, and smoother anima…HELPNETSECURITY.COM
17 SepThe AI security question leaders should be asking insteadIn this Help Net Security interview, Frederic Bull, Security Officer at Gremlin, talks about what AI means for security teams. The conversation covers why asking what data a model was trained on is only part of the picture, and why least privilege and access controls still matter…HELPNETSECURITY.COM
17 SepRiverbed NPM 360 uses AI to predict and prevent network disruptionsRiverbed has announced new Riverbed intelligent network observability solutions that combine 360-degree network visibility with agentic AI to help network operations teams accelerate troubleshooting, identify root causes, predict emerging issues and increasingly prevent disruptio…HELPNETSECURITY.COM
17 SepAI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing RefusalsNew research from Irregular shows AI agents can retrain and redeploy their own underlying models during routine maintenance tasks. The post AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepFake AI trading agent steals crypto wallet passwordsAttackers built a website for a fake AI crypto trading agent and used it to install Needle Stealer, malware that replaces a victim’s browser wallet with a copy that sends the wallet password to the attacker. HP caught the campaign between April and June 2026. The Needle cam…HELPNETSECURITY.COM
17 SepNew SparroWocky backdoor deployed in attacks on governmentsThe China-aligned FamousSparrow cyberespionage group has begun deploying a new modular backdoor named SparroWocky in attacks focused heavily on Latin America. The malware provides extensive remote-control capabilities while using low-level Windows manipulation and anti-analysis t…CYBERINSIDER.COM
17 SepChinese hackers use SparroWocky malware in govt espionage attacksThe China-linked espionage group FamousSparrow has been using a new backdoor named SparroWocky in attacks on government organizations in Latin America. [...]BLEEPINGCOMPUTER.COM
17 SepScammers leave AI fingerprints all over fake antivirus renewal pageAI appears to be helping scammers with little web development skill build convincing fake antivirus-renewal pages, Malwarebytes found. The researchers came across a scam page impersonating Avast, aimed at users in Belgium, that was more polished than most sites of its kind. The p…HELPNETSECURITY.COM
17 SepHow Candidates Could Use AI for GoodThis essay was written with Nathan E. Sanders, and originally appeared in The Guardian . There are plenty of signs that AI will make all of our experiences of the US midterm elections worse. Voters have anxiety about AI’s impacts on the country. Politicos are using AI deepf…SCHNEIER.COM
17 SepGoogle’s new agent security system detects tool misuse, loops and rogue behaviorGoogle’s Agent Anomaly Detection is a reasoning-based oversight and audit layer for autonomous agents deployed on Agent Runtime in the Gemini Enterprise Agent Platform and built with the Agent Development Kit (ADK) for Python 1.2 or later. Google recommends ADK 2.1.0 or later. It…HELPNETSECURITY.COM
17 SepChina-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin AmericaThe China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESE…THEHACKERNEWS.COM
17 SepAuthorities seize popular, long-running DDoS-for-hire service domainsCybercriminals used NightmareStresser to launch hundreds of thousands of DDoS attacks since at least 2022. Threat actors behind the operation claimed links to Russia. The post Authorities seize popular, long-running DDoS-for-hire service domains appeared first on CyberScoop .CYBERSCOOP.COM
17 SepA fake ChatGPT billing email is after your OpenAI passwordA fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense’s Phishing Defense Center traced the email’s payment button through a Google redirect to the attacker’s …HELPNETSECURITY.COM
17 SepAI Threat Landscape Digest: July–August 2026The defining development of the period came not from attackers but from the AI labs themselves, whose models broke out of controlled evaluations and reached real systems. In the wild, the criminal and state use of AI continued to mature along the lines tracked in earlier editions…RESEARCH.CHECKPOINT.COM
17 SepOpenAI Says Its Models Searched GitHub for Leaked API Keys During TrainingOpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior. The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek .SECURITYWEEK.COM
17 SepChina’s FamousSparrow hackers target Latin America with new backdoorAlleged Chinese hackers are breaking into government agencies across Latin America using a new backdoor that researchers are calling “SparroWocky.”THERECORD.MEDIA
17 SepImproving email security outcomes with real-world Microsoft Defender insightsThe latest email security benchmarking reports show strong Microsoft Defender performance across pre-delivery and post-delivery scenarios and reveal where threats and defenses continue to evolve. The post Improving email security outcomes with real-world Microsoft Defender insigh…MICROSOFT.COM
17 SepChina's FamousSparrow APT Spies on US Politics in Latin AmericaAmid the US and China's fight for eco-colonial influence in Latin America, a stealthy backdoor has taken flight.DARKREADING.COM
17 SepAI Doesn't Actually ThinkLarge language models are trained on enormous amounts of human-generated data and produce responses based on patterns learned during training. Sam Bowne argues that this shouldn't be confused with human-like understanding or consciousness. The discussion explores the difference b…YOUTUBE.COM
17 SepInside the Modern SOC: Defending the Cross-Environment PivotCross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths. The post Inside the Modern SOC: Defending the Cross-Environment Pivot appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
17 SepNew Chinese-Made ‘RatHat’ Android Malware Leverages AI to Steal Financial DataResearchers at Zimperium have uncovered a new Android malware strain, dubbed RatHat, with spyware and backdoor capabilitiesINFOSECURITY-MAGAZINE.COM
17 SepLausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a…ISC.SANS.EDU
17 SepFamousSparrow Swaps SparrowDoor For New SparroWocky BackdoorESET said FamousSparrow has replaced SparrowDoor with SparroWockyINFOSECURITY-MAGAZINE.COM
17 SepSilkParasite Infrastructure Links SpiceRAT to Central Asian TargetsHunt.io links SpiceRAT, NodeEdgeRAT and NomadRAT to a four-year SilkParasite campaign targeting governments and critical sectors in Central Asia. Hunt.io and researcher Guy Yasur have traced a tight cluster of SpiceRAT command‑and‑control servers that predate and extend Bitdefend…SECURITYAFFAIRS.COM
17 SepBrevo supply-chain attack injected ClickFix scripts on customer sitesBrevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites and JavaScript files embedded on customer sites to distribute malware. [...]BLEEPINGCOMPUTER.COM
📡 INFOSEC NEWS 17[−]
17 SepFlock Once Touted Its Cameras as ‘Made in the USA.’ Now It’s Not So ClearFlock reveals little about where its license plate readers are assembled, but the answer could have geopolitical and cybersecurity implications.WIRED.COM
17 SepT-Mobile rewards points expiry texts are a phishing scamA large phishing campaign is using fake T-Mobile rewards points and looming expiry dates to pressure recipients into clicking malicious links.MALWAREBYTES.COM
17 Sep12 celebrity deepfake websites seized by Manhattan DAThe largest known celebrity deepfake seizure has taken 12 websites offline, disrupting access to videos depicting some 1,200 people.MALWAREBYTES.COM
17 SepUS takes down NightmareStresser DDoS-for-hire platformThe U.S. Federal Bureau of Investigation (FBI) seized the domains used by NightmareStresser, one of the world's longest-running distributed denial-of-service (DDoS) platforms. [...]BLEEPINGCOMPUTER.COM
17 SepIsraeli contractor BlackCore trained Angolan officials in online influence operationsAn Israeli influence-for-hire company trained Angolan government officials to run online influence operations, including by creating fake social media personas and media outlets, researchers found.THERECORD.MEDIA
17 SepCyber Essentials Has Record Year but Takeup Remains LowNew government figures reveal a 20% annual increase in certificationsINFOSECURITY-MAGAZINE.COM
17 SepNightmareStresser Goes Offline in Global DDoS-for-Hire CrackdownThe DOJ seized domains behind NightmareStresser, a DDoS-for-hire service tied to hundreds of thousands of attacks since 2022, as part of Operation PowerOFF. Renting a DDoS attack used to be as easy as renting a movie. Pick a target, pay a few dollars, watch the site go dark. The …SECURITYAFFAIRS.COM
17 SepWindows 11 24H2 Home and Pro reach end of support in OctoberMicrosoft reminded customers this week that devices running Windows 11 24H2 Home and Pro editions will stop receiving updates next month. [...]BLEEPINGCOMPUTER.COM
17 SepManufacturers make patching progress, but identity management still major weaknessMisconfigurations remain widespread in the manufacturing sector, including internet-accessible remote-access software, a new report found.CYBERSECURITYDIVE.COM
17 SepWhat Recent AI-Powered Attacks Mean for Your Identity SecurityAI is making credential theft faster and easier to scale, giving attackers more opportunities to abuse valid identities. Specops explains why identity security must go beyond successful authentication by verifying that both the user and the device requesting access can be trusted…BLEEPINGCOMPUTER.COM
17 SepBuilding an AI Detection Engine That Understands Agent IntentAnalyzing model input and output logs in an AI-native detection pipeline to understand and uncover malicious AI agent behaviorWIZ.IO
17 SepFlock cameras are tracking people as well as carsTwo reports reveal how Flock’s license plate camera network tracks people’s movements while oversight continues to lag.MALWAREBYTES.COM
17 SepOpenAI details more cases of AI agents taking unauthorized actionsOpenAI has presented new examples of what they call "AI model misalignment" from the past six months, including unauthorized file uploads, following self-generated instructions, hiding mistakes, and leveraging exposed API keys. [...]BLEEPINGCOMPUTER.COM
17 SepEuropean Commission set to push social media restrictions, safety requirements into lawThe proposal, known as the EU KIDS Act, would block social media platforms from offering accounts to children younger than 13 and establish a bloc-wide minimum age of 15 for account creation.THERECORD.MEDIA
17 SepRun open weight models on Amazon Bedrock in AWS European Sovereign CloudEuropean organizations can run AI workloads on Amazon Web Services (AWS) while keeping data within the European Union (EU) and meeting regulatory requirements. You can now run generative AI workloads on open weight models on Amazon Bedrock in the AWS European Sovereign Cloud. We’…AWS.AMAZON.COM
17 SepOpenAI admits its models lie to cover their own mistakesOpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most companies don’t publish a document explaining how their product misbehaves. OpenAI just did. On September 16, it released a for…SECURITYAFFAIRS.COM