🚨 CISA KEV 1[−]
18 Sep KEVCISA Adds Two Known Exploited Vulnerabilities to CatalogCISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-39964 Linux Kernel Race Condition Vulnerability CVE-2026-53266 Linux Kernel Out-of-Bounds Write Vulnerability These types of vulnerabil…CISA.GOV
🐛 COMMON VULNERABILITIES AND EXPOSURES 5[−]
18 SepCritical Orkes Conductor Vulnerability Exploited in AttacksCVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions. The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepCheck Point Fixes Critical CVE-2026-91843 Allowing Root Code ExecutionCheck Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed. Check Point addressed CVE-2026-91843 (CVSS score of 9.8), a critical vulnerability in its Security Management and Log Servers. …SECURITYAFFAIRS.COM
18 SepMicrosoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege EscalationMicrosoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for c…THEHACKERNEWS.COM
18 Sep KEVCISA is ending its monthly vulnerability bulletinThe rise in AI-generated security threats may just have generated one casualty: the death of the weekly bulletin of security threats from the US Cybersecurity Infrastructure and Security Agency (CISA). The agency will discontinue its weekly bulletin of known vulnerabilities from …CSOONLINE.COM
18 SepCisco Zero-Day Highlights API Endpoint Authentication IssuesThe authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.DARKREADING.COM
⚠️ VULNERABILITY DISCLOSURE 37[−]
18 SepOpenAI models steal credentials and lie, Microsoft writes AI rules it can't enforce, Congress punts AI safety to 2027OpenAI Models Self-Jailbreak & Leak Data, Microsoft's "Humanist AI" Promise, Windows Patch Tuesday Fallout, and AI Laws Delayed Host David Shipley covers reports that OpenAI disclosed six recent incidents of internal models exhibiting concerning behavior—writing jailbreak instruc…CYBERSECURITYTODAY.LIBSYN.COM
18 Sep98% of fraudulent hires have company credentials by the time they’re caughtA 90-day period between hiring and onboarding is creating a blind spot in enterprise identity security, according to HYPR’s State of HR Identity Fraud Detection report. “Adversaries no longer need to breach a network when they can pass a remote interview and receive authentic cre…HELPNETSECURITY.COM
18 SepCheck Point, Kaspersky, Tanium Patch Product VulnerabilitiesCheck Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges. The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepStrong fundamentals make next-gen security possibleRisk management has always been a difficult job, but the current threat landscape has taken the challenge to a new level. I’ve spent years leading cybersecurity efforts at large enterprises, including Hyatt and United Airlines, and in that time I’ve seen cybercriminals grow incre…CSOONLINE.COM
18 SepFake parcel delivery messages steal your card and bank detailsParcel delivery phishing messages impersonate familiar couriers and use small fees or promised refunds to steal personal and financial information.MALWAREBYTES.COM
18 SepArcjet brings security controls and audit trails to AI agentsArcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams the governance and compliance evidence they need. Arcjet brings observability, enforcement, and audit capabilities across agen…HELPNETSECURITY.COM
18 SepZero-click RCE vulnerability hit four major AI coding agents, two remain unpatchedFour major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the employee running the agent, according to AIR. “It i…HELPNETSECURITY.COM
18 SepCISA Upgrades Vulnerability Reporting Platform with More AutomationThe US cybersecurity agency is moving to a new vulnerability coordination platform called VINCE-NTINFOSECURITY-MAGAZINE.COM
18 SepNew Check Point flaw lets hackers execute code with root privilegesCheck Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]BLEEPINGCOMPUTER.COM
18 SepWeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension StorageCybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associ…THEHACKERNEWS.COM
18 SepAuditing in the age of (good enough) AISecurity firms have published numerous blog posts describing how they pointed their agent harness at a codebase and found dozens of bugs ( we’re one of them ). However, these posts tend to focus on agentic code review, which is just one aspect of how we use AI in our security rev…TRAILOFBITS.COM
18 SepGyazo data breach exposed 23.6 million user records and 490M image metadataHelpfeel has disclosed a major data breach affecting its Gyazo image-sharing service, after an attacker exploited a vulnerability in an upload server to execute arbitrary commands and access backend systems. The incident exposed approximately 23.62 million user-related records an…CYBERINSIDER.COM
18 SepMicrosoft Patches 18 Vulnerabilities in AI, Cloud ProductsMicrosoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepBots with good manners are better at fooling people on social mediaMost people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability to separate human comments from AI-generated ones in a s…HELPNETSECURITY.COM
18 Sep23 Million User Records Compromised in Gyazo Data BreachGyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI CodeHacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts. The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepRaon data leak: Insider leak of 1,894 cases went undetected for 4 yearsChoi Won-woo reports: Internal data amounting to 1,894 cases from the Korean-type heavy ion accelerator ‘Raon,’ built with a state budget of 1.5 trillion Korean won [USD $1,080,038,017.50 at today’s rates] was confirmed to have been leaked externally. The estimated time of …DATABREACHES.NET
18 SepInternational Meteor Organization says cyberattack dealt ‘critical blow’ to websiteJonathan Greig reports: A cyberattack has shut down the website of the premier international organization responsible for tracking meteors. The International Meteor Organization (IMO) has continued tracking asteroids and meteor through its Facebook page, but its website now carri…DATABREACHES.NET
18 SepResearchers used Anthropic’s Claude to hack into OpenAISecurity researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an internal code repository before reporting the flaws.TECHCRUNCH.COM
18 SepWebinar: Which Google Workspace security controls actually matter?Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams shou…BLEEPINGCOMPUTER.COM
18 SepIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawNoteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared f…SECURITYWEEK.COM
18 SepA zero-click RCE flaw in AI coding agents could have exposed enterprise systemsPopular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plu…CSOONLINE.COM
18 SepGhostCode attackers abuse device codes to take over Microsoft 365 accountsMicrosoft 365 users are being tricked into handing over access to their accounts by a new phishing kit, GhostCode, that exploits a weakness in a legitimate device authorization flow. Researchers in eSentire’s threat response unit identified the campaign in late August 2026. The k…CSOONLINE.COM
18 SepCisco patches a maximum-severity zero-day.Gyazo data breach affects more than 23 million user records. China's FamousSparrow deploys a new backdoor.THECYBERWIRE.COM
18 SepInternational security agencies warn about North Korean hackers exploiting job seekers to steal crypto, dataThe U.S., Japan, Germany and Australia said WaterPlum operators pose as prospective employers and have infected more than 30,000 devices worldwide. The post International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data appeared first…CYBERSCOOP.COM
18 SepCISA ends weekly vulnerability roundups as part of shift to prioritization approachThe agency wants to help companies sort through the AI-fueled avalanche of bug reports.CYBERSECURITYDIVE.COM
18 SepINTERPOL says it used AI to identify 126 criminals from 100,000 imagesINTERPOL says an international counter-terrorism operation used artificial intelligence and facial recognition technology to identify 126 suspected foreign terrorist fighters from imagery collected from jihadist groups online. Operation Shams II, coordinated by INTERPOL between J…CYBERINSIDER.COM
18 SepGyazo server flaw exploited to steal 23.6 million user recordsThe Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]BLEEPINGCOMPUTER.COM
18 SepNew WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code ExecutionWordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security …THEHACKERNEWS.COM
18 SepResearchers use AI to find widespread software decoder flawThe bug, since patched, gave attackers remote code execution privileges and access to user accounts and production environments, including Meta’s core product suite and an OpenAI software repository. The post Researchers use AI to find widespread software decoder flaw appeared fi…CYBERSCOOP.COM
18 SepGyazo Data Breach Exposes 23 Million User RecordsA Gyazo breach exposed 23 million user records after attackers exploited a vulnerability in Helpfeel’s image upload server. Japanese software company Helpfeel is notifying Gyazo users about a data breach that compromised 23 million user records. Attackers gained unauthorized acce…SECURITYAFFAIRS.COM
18 SepPublic Exploits Released for Four Linux Kernel Flaws That Enable Local RootA security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affe…THEHACKERNEWS.COM
18 SepThe Cisco root route.Cisco patches a maximum-severity vulnerability in its Identity Services Engine. Court documents describe AI as “an astonishing theft of unprecedented proportions.” Researchers chain vulnerabilities to take over employee ChatGPT accounts. Microsoft and Check Point patch vulnerabil…THECYBERWIRE.COM
18 SepEarly Scattered Spider member pleads guilty to cybercrime spreeAhmed Elbadawy pocketed massive proceeds from his crimes. Prosecutors are seeking the forfeiture of about $17.6 million in virtual currency, luxury vehicles, and a vast collection of jewelry and designer bags. The post Early Scattered Spider member pleads guilty to cybercrime spr…CYBERSCOOP.COM
18 SepRansomware attack on Kansas county will affect some servicesJoseph McCarty reports: A Kansas county’s government says it has been hit by a ransomware attack. Ellis County discovered the attack on parts of its information technology systems Thursday morning. Officials said they “immediately took steps to contain the disruption” by isolatin…DATABREACHES.NET
18 SepForeign actors breach Colorado water systemsAlayna Alvarez reports: Foreign actors last month breached two small Colorado water utilities and manipulated equipment used to control drinking water systems. The two privately owned utilities, each serving fewer than 200 people, were breached in late August, Gov. Jared Polis…DATABREACHES.NET
18 SepThe U.S. military leaked more than 93,000 tips via insecure P3 Global Intel. Has anyone been notified?As part of DataBreaches.net’s ongoing investigation into the Navigate360 breach, this report covers approximately 94,000 unclassified but sensitive tips submitted through P3 Global Intel apps and websites used by the military. What has Homeland Security done in response to …DATABREACHES.NET
📋 SECURITY BULLETINS 2[−]
18 SepMicrosoft fixes broken copy and paste for Excel 2016 usersMicrosoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. [...]BLEEPINGCOMPUTER.COM
18 SepAndroid apps can now check security patches down to individual device componentsNew AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is. The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status of individual device components an…HELPNETSECURITY.COM
📢 SECURITY ADVISORIES 10[−]
18 SepMost WordPress pros still lack a breach recovery planMelapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident. The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and adminis…HELPNETSECURITY.COM
18 SepMicrosoft Teams will let admins block custom file extensionsMicrosoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]BLEEPINGCOMPUTER.COM
18 SepTransparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previousl…THEHACKERNEWS.COM
🔥 INCIDENT REPORTING 11[−]
18 SepRatHat Android Malware Abuses ADB to Retain Shell Access After UninstallCybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smis…THEHACKERNEWS.COM
18 SepAI Agent Breaches Spanish Organization, Modifies Personal DataAI-driven cyberattacks used to be exotic. Soon, it'll be odd if threat actors aren't using agents to do all of their bidding.DARKREADING.COM
18 SepManufacturing Accounts for 22% of all Ransomware VictimsBlack Kite has found that manufacturing remained the most targeted sector for ransomware attacks, and saw a big jump in incidents in H1 2026INFOSECURITY-MAGAZINE.COM
18 SepBrevo Supply Chain Attack Injects Malware Into 100,000 WebsitesHackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts. The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepA Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and IdentityAnalysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42 .UNIT42.PALOALTONETWORKS.COM
18 SepAre AIs Still Struggling with CAPTCHAs?Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simp…SCHNEIER.COM
18 SepHacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to RussiaOver the past year, Russian cybersecurity firm Kaspersky said it investigated several incidents involving the group at Russian businesses.THERECORD.MEDIA
18 SepNew Settra Ransomware Variant Deployed in Attacks on Retail and ManufacturingHuntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacksINFOSECURITY-MAGAZINE.COM
18 SepFBI, Coast Guard boarded hacked oil tankers heading towards US coastThe feds are said to be investigating the compromise of the tankers' networks, which in one case interfered with one of the tanker's navigation and propulsion systems.TECHCRUNCH.COM
18 SepSettra ransomware variant deployed in recent attacksSecurity researchers warned that hackers are using VPN credentials for initial access and deploying RMM tools.CYBERSECURITYDIVE.COM
18 SepAn Undercover Google Analyst Infiltrated a Notorious Supply Chain Hacking GangTeamPCP pulled off the worst-ever software supply chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.WIRED.COM
🕵️ THREAT INTELLIGENCE 17[−]
18 SepISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100, (Fri, Sep 18th)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
18 SepNew infosec products of the week: September 18, 2026Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and Tuskira. Dataminr uses agentic AI to predict and verify security threats Dataminr has announced Dataminr Advanced for Corporate Se…HELPNETSECURITY.COM
18 SepAbandoned IoT apps keep sending sensitive data to broken serversMillions of people still run smart home and IoT companion apps, the apps used to control devices like smart plugs, cameras, and thermostats, that stopped receiving updates years ago. Researchers at the University of Massachusetts Amherst analyzed 61,500 abandoned Android IoT apps…HELPNETSECURITY.COM
18 SepHardcoded MCP credentials found in public GitHub filesHardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report. The company anal…HELPNETSECURITY.COM
18 SepHTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)In June 2026 the IETF published RFC 10008[ 1 ], defining a new HTTP method: "QUERY". The HTTP protocol faced already by changes (HTTP/2, HTTP/2) but it's the first new standard HTTP verb since "PATCH" in 2010!
ISC.SANS.EDU
18 SepSignal tests account registration with phone number on AndroidSignal is testing a long-requested option that lets users create accounts without providing a phone number, with the feature arriving in the Android 8.28 beta. Numberless accounts instead use an Account ID and Account Key and require a one-time payment intended to deter spam. Sig…CYBERINSIDER.COM
18 SepMIND Secures $72 Million for AI-Powered DLPThe company will use the funding to accelerate platform development and expand its presence in key enterprise markets. The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm StealerA financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment ma…THEHACKERNEWS.COM
18 SepFake LastPass downloads on GitHub pushed password-stealing malwareA malware campaign impersonates LastPass on GitHub to trick users into installing an information stealer that can harvest browser passwords, cryptocurrency wallets, and messaging app sessions. The campaign, detailed in a report by LastPass and Delphos Labs, used fake GitHub pages…CYBERINSIDER.COM
18 SepNightmareStresser DDoS Service Disrupted in International OperationActive since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world. The post NightmareStresser DDoS Service Disrupted in International Operation appeared first on SecurityWeek .SECURITYWEEK.COM
18 SepIs AI toast? Building an AI Talkie ToasterIntroduction Talkie Toaster is a character in the BBC sci-fi comedy Red Dwarf. He is an AI Toaster whose purpose in life is to be your cheerful breakfast companion and to provide you with all your toasting needs, only he is a little too obsessed with toasting. While only appearin…PENTESTPARTNERS.COM
18 SepYour Flock Camera Runs 2017 SoftwareThe discussion examines a Flock camera reportedly running Android 8.1, with a 2018 security patch level and Linux 3.18. It also highlights a hard-coded API token associated with Flock cameras. Outdated operating systems can leave devices exposed to known vulnerabilities. Embedded…YOUTUBE.COM
18 SepNations take action on North Korean IT workers after UN reportA report published Wednesday said that as of July, Vietnam, Laos, Pakistan and Argentina took meaningful steps to respond to allegations involving North Korea listed in an October study.THERECORD.MEDIA
18 SepDon’t Call Us, We’ll Call Your APIs | TraderTraitor Backdoors Resurface on Victim With No Crypto TiesNorth Korean operators built a foothold on a DevOps engineer's Mac in a campaign whose job interview lures deliver malware via Terraform lock files.SENTINELONE.COM
18 SepEclypsium Infrastructure Assurance PlatformThe post Eclypsium Infrastructure Assurance Platform appeared first on Eclypsium .ECLYPSIUM.COM
18 SepFriday Squid Blogging: On Squid Egg SacsShort essay about squid egg sacs. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.SCHNEIER.COM
18 SepBacteria, Spartans, AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet - SWN #617Bacteria, Spartans Invade Athens, Agentic AI gone wild, Cisco, WordPress, Settra, Plugin4Shell, Josh Marpet, and More on this episode of the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-617YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 4[−]
18 SepRatHat Turns Android Accessibility Into an Attack WeaponRatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones. RatHat is the new Android trojan you should know about. Zimperium researchers just published a breakdown of a strain they’ve tr…SECURITYAFFAIRS.COM
18 SepNew Android malware uses AI to steal bank logins and PINsRatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.MALWAREBYTES.COM
18 SepFake LastPass Authenticator GitHub repos push new Rapuncel infostealerAn ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]BLEEPINGCOMPUTER.COM
18 SepEY Survey Finds Autonomous AI Implementation Outpaces OversightA new survey of senior AI execs shows that while organizations are rapidly deploying AI and autonomous systems, their process and controls are not keeping pace.DARKREADING.COM
📡 INFOSEC NEWS 8[−]
18 SepMicrosoft fixes bug behind ‘Defender Antivirus is turned off’ alertsMicrosoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. [...]BLEEPINGCOMPUTER.COM
18 SepAn Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositorie…THEHACKERNEWS.COM
18 SepPlugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding AgentsA flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The fir…THEHACKERNEWS.COM
18 SepMeta’s Copyright System Is Being Weaponized Against Albanian ProtestersAfter three months of daily anti-government protests—dubbed the Flamingo Revolution—the sudden mass suspension of Instagram accounts has led to fears of brigading against demonstrators.WIRED.COM
18 SepDid an AI really try to break free from human control?An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.MALWAREBYTES.COM
18 SepSecure enterprise sharing with access reviews for Microsoft 365Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can …BLEEPINGCOMPUTER.COM
18 SepMFA Won't Save You From OAuth Consent AbuseMFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.DARKREADING.COM
18 SepVectra AI Launches Ascent to Help Address New Era of AI-Driven AttacksThe new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.DARKREADING.COM