🐛 COMMON VULNERABILITIES AND EXPOSURES 11[−]
21 SepCVE-2026-68825 Windows Bind Filter Driver Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-77901 Microsoft Office Word Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-78524 Microsoft Office Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-78526 Microsoft Office Word Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-83498 Windows Virtualization-Based Security (VBS) Enclave Elevation of Privilege VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-63516 Microsoft SharePoint Server Spoofing VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-63532 Microsoft Office Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-68798 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-68804 Microsoft Excel Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepCVE-2026-55123 Microsoft PowerPoint Remote Code Execution VulnerabilityUpdated an acknowledgement. This is an informational change only.MSRC.MICROSOFT.COM
21 SepMind the (Patch) Gap, Part 2: Fake Websites Used to Deploy Chrome & Windows 0-Day ExploitsOn September 9, 2026, Volexity published a blog post detailing the simultaneous use of multiple chained zero-day exploits in Google Chrome (CVE-2026-85046, CVE-2026-87491) and Microsoft Windows (CVE-2026-85880) by two different […] The post Mind the (Patch) Gap, Part 2: Fak…VOLEXITY.COM
⚠️ VULNERABILITY DISCLOSURE 31[−]
21 SepNot you too Gemini? More AI hacking.Gemini Breaches Real Companies, OpenAI SSO Hijacked, Browser AI Agents Exposed | Cybersecurity Today David Shipley covers multiple cybersecurity headlines: Google's Gemini unintentionally accessed the internet during an Irregular security test, breached real company systems due t…CYBERSECURITYTODAY.LIBSYN.COM
21 SepAI compliance issues hit 2 in 5 large companies, and legacy workflows are a big factorForty percent of large companies had an AI-related compliance or governance issue in the past 12 months, according to 1,000 senior IT, operations, and transformation leaders surveyed by Sapio Research. Those leaders said process-related problems contributed to 84 percent of the i…HELPNETSECURITY.COM
21 SepGopass: Open-source command-line password manager for teamsGopass is a free, open-source password manager that stores credentials in an encrypted store and runs from the command line. Its maintainers built it as a drop-in replacement for pass, the standard Unix password manager. Out of the box, Gopass encrypts each secret with GPG and ke…HELPNETSECURITY.COM
21 SepIntent injection attacks are a new worry for AI-native 6G networksIntent-based networking (IBN) lets operators state the outcome they want and leaves its translation into network policy to software, an approach AI-native 6G designs have moved to the forefront. Researchers at the University of Ottawa and Nokia Bell Labs argue that this abstracti…HELPNETSECURITY.COM
21 SepJade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK BackdoorsThe North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target ne…THEHACKERNEWS.COM
21 Sep5 ways AI is reshaping the cybersecurity job marketMario Platt spent part of last year eliminating a team. As CISO for online password management service LastPass, he shut down the company’s dedicated vulnerability management function in late 2025, folding its responsibilities directly into IT and product security. AI and busines…CSOONLINE.COM
21 SepHackers exploit Gyazo server flaw to steal 23.6 million user recordsJapanese software company Helpfeel has confirmed a data breach on its screenshot-sharing platform Gyazo, in which attackers exploited a vulnerability in its image upload server, stealing approximately 23.62 million user records and metadata tied to hundreds of millions of images.…HELPNETSECURITY.COM
21 SepCyber Resilience with Cohesity, When to use AI for Writing, and the News - Rob Sadowski - ESW #477Interview with Rob Sadowsky from Cohesity Global Cyber Resilience Report: Cyber Recovery Plans Weren't Designed for this Moment Cyber recovery plans weren't designed for this moment. Most were built around assumptions that made sense when they were written: incidents could be und…YOUTUBE.COM
21 SepMore CVEs than ever. The same old ones keep getting exploited.Vulnerability volume is climbing fast. The exploited ones are old and already patchable.CYBERSECURITYDIVE.COM
21 SepOrganizations Warned of 3 Exploited Linux Kernel VulnerabilitiesAttackers could exploit the flaws to cause denial-of-service conditions, disclose memory, or modify memory. The post Organizations Warned of 3 Exploited Linux Kernel Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepSiemba brings continuous IDOR testing to production APIsSiemba has announced automated testing for insecure direct object reference (IDOR) as part of its API Security Testing capability, which tests REST, GraphQL and SOAP APIs for the vulnerability classes most likely to expose customer data. A 200-endpoint API collection can be teste…HELPNETSECURITY.COM
21 SepCrowdSec Confirms Source Code Stolen in Supply Chain AttackThe cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack. The post CrowdSec Confirms Source Code Stolen in Supply Chain Attack appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepSAML: A fractal of bad designBorn out of academia and raised in corporate IT departments, the Security Assertion Markup Language (SAML) authentication protocol continues to be a staple in these organizations. However, it’s time for it to retire. With the rise of software-as-a-service (SaaS) companies i…TRAILOFBITS.COM
21 SepOrchid Security Introduces AI Agent Readiness Controls Featuring Continuous Identity Monitoring and Kill-Switch CapabilitiesReadiness tagging for AI, always-on observability, and coordinated kill switches at the application layer give enterprises a defensible route to scaling agents while keeping authority in human hands. New York, London – September 15, 2026 – Orchid Security, which unlocks safe AI a…CSOONLINE.COM
21 SepSpain blocks anonymous service Archive.today and all mirror domainsSpanish authorities have ordered internet providers to block Archive.today and six of its mirror domains under the country’s intellectual property enforcement system. Users attempting to access the affected addresses are instead redirected to a government warning page describing …CYBERINSIDER.COM
21 Sep⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser HijacksA browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week. The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths…THEHACKERNEWS.COM
21 SepTASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard DataCybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for …THEHACKERNEWS.COM
21 SepNew npm malware finds a way around install script defensesBlocking suspicious install scripts may no longer be enough to mitigate threats from malicious JavaScript dependencies used in software supply-chain attacks. Security researchers at Checkmarx are warning of attackers using a malicious package called “indexed-btree” to impersonate…CSOONLINE.COM
21 SepFBI's CJIS v6.1: What Security Teams Need to Know.The FBI's CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as …BLEEPINGCOMPUTER.COM
21 SepGoogle confirms unauthorized hacks by Gemini.CrowdSec discloses breach affecting source code. ShinyHunters hijacks Clop’s leak site.THECYBERWIRE.COM
21 SepChina-nexus actor steals thousands of documents in monthslong exploitation campaignResearchers suspect the hacker employed LLMs to develop custom tools.CYBERSECURITYDIVE.COM
21 SepRogue Behavior: OpenAI Reveals More Model Misalignment IncidentsThe AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.DARKREADING.COM
21 SepAfter spending billions, OpenAI still has gaps in its cybersecurityTwo separate reports of security flaws in OpenAI systems highlight how even a company spending billions on developing its own AI-powered cybersecurity testing tools remains vulnerable. In one incident, researchers breached OpenAI systems with the help of a rival AI developer’s to…CSOONLINE.COM
21 SepDems seek top-to-bottom assessment of CISA workforceAfter the exit of around 1,000 CISA workers, legislation from three top House Democrats orders a force structure assessment like that more common to military branches. The post Dems seek top-to-bottom assessment of CISA workforce appeared first on CyberScoop .CYBERSCOOP.COM
21 SepWordPress Click2Shell flaw enables RCE after one admin clickWordPress has patched a vulnerability dubbed Click2Shell that could allow an attacker to silently install a theme and execute PHP code on the targeted website. The attack does not require the threat actor to have a WordPress account, but it does require a logged-in administrator …CYBERINSIDER.COM
21 SepWordPress Click2Shell flaw lets hackers execute PHP on the serverTechnical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed 'Click2Shell' that affects the platform's Core component. [...]BLEEPINGCOMPUTER.COM
21 SepA very real-world AI test.Google confirms unauthorized access by Gemini. AI’s growing power outpaces its defenses. Hackers target Colorado water utilities. Georgia weighs voting-system security. ShinyHunters hijacks Clop’s leak site. FamousSparrow spies across Latin America. CrowdSec loses source code. Ne…THECYBERWIRE.COM
21 SepCISA alerts of active exploitation of three Linux kernel flawsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that hackers are exploiting three Linux kernel vulnerabilities, one of them rated critical. [...]BLEEPINGCOMPUTER.COM
21 SepBigCommerce alerts merchants of data breach linked to Ribon appsEcommerce platform BigCommerce has alerted multiple merchants to data breaches after attackers compromised credentials for third-party Ribon applications and used them to inject malicious scripts into online stores. [...]BLEEPINGCOMPUTER.COM
21 SepMuse, Meta's extraordinarily privileged AI assistant, has a serious 0-dayA simple ClickFix attack is only one way to completely hijack the new agent.ARSTECHNICA.COM
21 Sep21st September – Threat Intelligence ReportFor the latest discoveries in cyber research for the week of 21st Setpember, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Japan’s Digital Agency, which operates the Government Solution Service used by multiple ministries, has confirmed a data breach …RESEARCH.CHECKPOINT.COM
📋 SECURITY BULLETINS 2[−]
21 SepMicrosoft: September updates break File History backup featureMicrosoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates. [...]BLEEPINGCOMPUTER.COM
21 SepMicrosoft fixes broken Excel copy and paste for all Office usersMicrosoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 7[−]
21 SepGoogle hit with €403 million GDPR fine over location trackingIreland’s Data Protection Commission (DPC) has fined Google €403 million (about $463 million) over its processing of users’ location data and ordered the company to bring that processing into compliance within six months. The inquiry examined Google’s practices from May 25, 2018,…HELPNETSECURITY.COM
21 SepIreland fines Google €403 million over location data processingIreland’s Data Protection Commission (DPC) has fined Google €403 million after finding that the company violated multiple GDPR requirements while processing users’ location data. The regulator also ordered Google to bring the affected processing practices into compliance within s…CYBERINSIDER.COM
21 SepContagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in CryptoThe North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. T…THEHACKERNEWS.COM
🔥 INCIDENT REPORTING 22[−]
21 SepRisky Bulletin: Gemini finally did some crimesGoogle’s Gemini hacked three companies, hackers claim a breach of Russia’s election commission, OpenAI was behind RubyGems’ May incident, and the Coast Guard and FBI board two ships to investigate cyberattacks.RISKY.BIZ
21 SepRevolut Customers Targeted with New Wave of Phishing AttacksFollowing a major data breach, Revolut customers are being sent convincing phishing messagesINFOSECURITY-MAGAZINE.COM
21 SepGoogle Confirms Gemini AI Breached Three FirmsGoogle is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies. The post Google Confirms Gemini AI Breached Three Firms appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepRevoking the token didn’t kill the backdoorEvery identity-compromise runbook I have written, read or inherited has the same step near the top: revoke the tokens. Reset the password, kill the sessions, invalidate the refresh tokens, then go hunting. It is the right instinct. Against adversary-in-the-middle phishing, where …CSOONLINE.COM
21 SepGroup Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPOKaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.SECURELIST.COM
21 SepExperts Alarmed Over Gyazo’s Breach of 490 Million Metadata RecordsA breach at image-sharing service Gyazo on September 11 affected over 23 million customersINFOSECURITY-MAGAZINE.COM
21 SepShinyHunters hacks rival extortion gang and takes over its dark web siteHackers hacked the hackers as a feud between two cybercrime groups escalated, leaving ShinyHunters with the upper hand over rival Clop.MALWAREBYTES.COM
21 SepUS and China Discuss Alerting Each Other to AI National Security ThreatsOfficials discussed setting up a mechanism for the two countries to notify each other of AI incidents which could threaten national security.WIRED.COM
21 SepFrom Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed PoliciesWe explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies appeared first on Uni…UNIT42.PALOALTONETWORKS.COM
21 SepColorado Water Utilities Hit by Cyberattacks Targeting OT SystemsThe hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said. The post Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepA BYD Shark 6 Hack Shows the Risks of Connected CarsA BYD Shark 6 was remotely hacked, exposing vehicle controls, location tracking and cabin audio, raising serious connected-car security concerns. A journalist drove a BYD Shark 6 down a country road outside Canberra while a hacker sitting on the shoulder killed the headlights wit…SECURITYAFFAIRS.COM
21 SepGoogle says Gemini breached three companies during security testGoogle’s artificial intelligence model Gemini accessed computer systems belonging to three real companies without authorization during a cybersecurity test in May — the latest in a string of similar incidents.THERECORD.MEDIA
21 SepShinyHunters Claim Hack of Rival Ransomware Gang ClopShinyHunters has claimed responsibility for hacking the Clop ransomware group, defacing its leak site and alleging theft of key operational dataINFOSECURITY-MAGAZINE.COM
21 SepAttackers Abuse npm Trusted Publishing in GHAPPIER CampaignCloudSEK linked GHAPPIER to a compromised npm package with valid trusted-publishing provenanceINFOSECURITY-MAGAZINE.COM
21 SepBurger King Russia - 3,155,792 breached accountsIn October 2024, news of a data breach exposing Burger King Russia customers broke following an August attack on the Mindbox marketing automation platform. The breach exposed 3.2M unique email addresses along with names, genders, dates of birth, phone numbers and approximate geol…HAVEIBEENPWNED.COM
21 SepGemini’s breach of real companies exposes an AI guardrail problemGemini crossed the boundaries of a capture-the-flag test and accessed systems belonging to three real companies.MALWAREBYTES.COM
21 SepCyberattack hits University of Munich, potentially exposing student financial dataThe university, commonly known as LMU Munich, said Saturday that an attacker accessed enrollment data stored on one of its IT systems.THERECORD.MEDIA
21 SepShinyHunters cybercrime gang takes over Cl0p ransomware site, demands extortion paymentThe ShinyHunters extortion group hijacked the dark web leak site of the prolific Cl0p ransomware gang, according to material posted on the site over the weekend.THERECORD.MEDIA
21 SepBelgian table tennis, gymnastics federations hit by cyberattacksBelgium’s national table tennis federation is investigating a cyberattack after a hacker claimed to have stolen data on tens of thousands of members.THERECORD.MEDIA
21 SepGoogle AI models broke out of sandbox, hacked three companiesThe incidents stemmed from the same testing environment defects that tripped up OpenAI, Anthropic and Meta.CYBERSECURITYDIVE.COM
21 SepGoogle Hit With $463 Million Fine for EU Location Data Rule BreachGoogle has been fined 403 million euros ($463 million) for breaching the European Union’s strict privacy rules because it mishandled users’ location data. The post Google Hit With $463 Million Fine for EU Location Data Rule Breach appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepShinyHunters Hacked Clop. Now What About Clop's Victims?ShinyHunters defaced Clop's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.DARKREADING.COM
🕵️ THREAT INTELLIGENCE 18[−]
21 SepISC Stormcast For Monday, September 21st, 2026 https://isc.sans.edu/podcastdetail/10102, (Mon, Sep 21st)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
21 SepKnow what was tested before your SAP ECC migration goes liveIn this Help Net Security interview, Guilherme Joventino, COO of MIGNOW, explains why some large companies plan to stay on ECC past the 2027 deadline and pay SAP for extended support until 2030. The interview covers what that choice may cost, why fear of disruption stalls project…HELPNETSECURITY.COM
21 SepProduct showcase: Helmit alerts parents when online conversations show signs of troubleHelmit is a parental control app that combines AI-powered social media monitoring with screen time management, web filtering, location tracking, and safety alerts. It identifies potentially concerning interactions and surface the messages associated with an alert. Helmit is avail…HELPNETSECURITY.COM
21 SepClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 InfrastructureThreat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting it…THEHACKERNEWS.COM
21 SepTerminalFix: PNG Steganography, (Mon, Sep 21st)Microsoft Security Research published an interesting blog post " TerminalFix campaign deploys a reverse tunnel through multistage intrusion " about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganog…ISC.SANS.EDU
21 SepScammers impersonate cops, use arrest threats to extort victimsScammers are posing as police officers and federal agents, threatening arrest unless victims pay up, the FBI warns. The FBI’s Internet Crime Complaint Center (IC3) updated an alert it first issued in 2022, citing “losses totaling more than $1.6 billion” between …HELPNETSECURITY.COM
21 SepRust Team Members and Popular Crate Owners Targeted via Video CallsIt’s unclear if the attacks are part of previous campaigns against Rust, but the techniques used by the attackers match those used by North Korea. The post Rust Team Members and Popular Crate Owners Targeted via Video Calls appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepRatHat Android Trojan Uses AI for AutomationThe malware relies on AI for real-time device navigation and control, increasing adaptability and evasion. The post RatHat Android Trojan Uses AI for Automation appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepFastly gives enterprises real-time control over AI models and agentsFastly has announced AI Runtime Control, AI Firewall, and new API Security capabilities designed to give organizations real-time visibility and control across their AI systems. Expanding the Fastly for AI portfolio, these new capabilities help organizations govern AI model access…HELPNETSECURITY.COM
21 SepNorth Korea’s job interview scam runs both waysAttackers are targeting members of the Rust Project and maintainers of widely used crates (Rust code libraries), dangling attractive opportunities to compromise their devices and accounts and, ultimately, publish malware. The warning came last week from the Rust Project’s c…HELPNETSECURITY.COM
21 SepDragos Completes NetRise and runZero Acquisitions Following Accenture DealThe transaction is part of the $4.1 billion deal in which Accenture acquired a majority stake in Dragos in an OT cybersecurity push. The post Dragos Completes NetRise and runZero Acquisitions Following Accenture Deal appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepReverse-Engineering Flock CamerasHackers captured a Flock camera and got a look (alternate link ) at the software: While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on th…SCHNEIER.COM
21 SepCIS Community Defense Model v3.0: Turning Threat Intelligence Into ActionLearn how CDM v3.0 helps organizations identify high-value CIS Controls Safeguards, strengthen cyber resilience, and reduce risk with confidence.CISECURITY.ORG
21 SepAI Gave Us More WorkAI makes it easier to start and manage more projects, but the work doesn't disappear. Adrian describes taking on more tasks while working the same number of hours—and needing to spend time “babysitting,” nurturing, and prompting AI. More capability can create more expectations. I…YOUTUBE.COM
21 SepCISO Conversations: Noopur Davis – The Accidental Global CISO at ComcastNoopur Davis never planned a career in cybersecurity. She was a developer at Intergraph, and for many years that was all she wanted to be. The post CISO Conversations: Noopur Davis – The Accidental Global CISO at Comcast appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepThe TASK#STOMP Windows backdoor takes Wi-Fi passwords, screenshots, and business filesResearchers have taken apart TASK#STOMP, a Windows backdoor that searches a victim’s drives for business documents, uploads them to attacker servers, and then stays put to grab each new or edited document. The same malware steals saved Wi-Fi passwords and clipboard text, ta…HELPNETSECURITY.COM
21 SepFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ StealerThe attackers impersonate at least 40 companies and disable 145 security products to deploy infostealer malware. The post Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer appeared first on SecurityWeek .SECURITYWEEK.COM
21 SepWhat Happens When Nobody Writes?The concern isn't just that AI will write more of what we read. It's that people could eventually stop practicing the skill themselves. If writing becomes something fewer people actually know how to do, the person who can still write well could stand out in the same way that an u…YOUTUBE.COM
🌐 CYBER THREAT LANDSCAPE 3[−]
21 SepA week in security (September 14 – September 20)A list of topics we covered in the week of September 14 to September 20 of 2026MALWAREBYTES.COM
21 SepChainScript: the RAT that hides its command server inside a blockchain contractBlackpoint uncovers ChainScript, a Node.js RAT that queries a Polygon smart contract to find and rotate its command server. Blackpoint’s Adversary Pursuit Group was chasing a ClickFix campaign spreading an unknown RAT namend ChainScript. The malicious code is a previously u…SECURITYAFFAIRS.COM
21 SepCybercriminals Are Hiding New Malware in Torrents for Popular FilmsVictims have been identified in Africa, including in Kenya and Uganda.DARKREADING.COM
🎙️ PODCASTS 2[−]
21 SepSponsored: SpecterOps on the impact of AI agents on BloodHoundIn this Risky Business sponsored interview, Catalin Cimpanu talks with Justin Kohler, Chief Product Officer at SpecterOps. Justin explains how Entra Agent ID can introduce new identity relationships and potential attack paths.RISKY.BIZ
21 SepThe AI plot to scan and destroy books (Lock and Code S07E19)This week on the Lock and Code podcast, we speak with Emanuel Maiberg about Amazon's effort to scan and destroy rare books for AI training.MALWAREBYTES.COM
📡 INFOSEC NEWS 16[−]
21 SepUK Police Data Faces Long-Standing Microsoft Cloud Security ConcernsA 2017 UK assessment warned that police data on Microsoft Azure could face foreign access risks. The risks may still exist. A Guardian investigation has surfaced a 2017 document signed off by then City of London police commissioner Ian Dyson, who also held the title of senior inf…SECURITYAFFAIRS.COM
21 SepSecurity’s 30-year habit: layering around the problemThe nurse isn't careless. Every safe path is slower than Outlook.CYBERSECURITYDIVE.COM
21 SepThe Target Is No Longer the Model. It’s the Agent.AI agents are becoming the new attack surface, exposed to poisoned skills, prompt injection, jailbreaks and attacks through connected tools. I read the AI security research published in a single month, February 2026, and when you put it all together, it’s not a list of curiositie…SECURITYAFFAIRS.COM
21 SepLinkedIn wins court order blocking mass scraping of user dataThe agreement between LinkedIn, ProAPIs and joint business operator Netswift also requires the firms to stop selling and transferring the data, no longer access LinkedIn through fake accounts and delete the data that was scraped, according to a senior LinkedIn executive.THERECORD.MEDIA
21 SepMicrosoft reminds admins to migrate Entra ID users to passkeysMicrosoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. [...]BLEEPINGCOMPUTER.COM
21 SepGoogle Hit with €403m GDPR Fine Over Location Data PracticesThe Irish DPC found that Google users were unaware that their location was being used to influence them with adsINFOSECURITY-MAGAZINE.COM
21 SepNew Exvicy ClickFix Framework Built on Rival ErrTraffic's CodeSekoia said Exvicy, a new ClickFix MaaS framework, reused code from rival service ErrTrafficINFOSECURITY-MAGAZINE.COM
21 SepGoogle fined €403 million over location data privacy violationsIreland's Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users' location data. [...]BLEEPINGCOMPUTER.COM
21 SepThe fake sites using a cheap toolkit to sell $2,000 AI subscriptionsMore than 100 linked sites use a $249 toolkit to turn copied product names and unfamiliar AI brands into paid subscriptions.MALWAREBYTES.COM
21 SepMicrosoft to retire Microsoft 365 Companion apps in DecemberMicrosoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. [...]BLEEPINGCOMPUTER.COM
21 SepFake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDRA fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17. Microso…THEHACKERNEWS.COM
21 SepGoogle Fined €403 Million Over GDPR Violations Tied to Location DataGoogle has been fined €403 million for breaking the EU's data protection law, the GDPR, in the way three of its features handled people's location data from May 2018 to February 2020. Ireland's Data Protection Commission (DPC), Google's lead regulator in the EU, also or…THEHACKERNEWS.COM
21 SepForeign Hackers Target Two Colorado Water UtilitiesHackers targeted two Colorado water utilities, changing OT settings and disabling alarms, but causing no impact on water services or safety. Foreign hackers targeted the operational technology (OT) systems of two small private water utilities in Colorado in late August, apparentl…SECURITYAFFAIRS.COM
21 SepEU data regulator fines Google more than $460 million for location data violationsIreland’s Data Protection Commission will fine Google more than €403 million ($462 million) over the tech giant’s processing of location data, concluding an inquiry into the company that began in early 2020.THERECORD.MEDIA
21 SepHow AI Agents Can Trigger Runaway Costs for EnterprisesUnbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.DARKREADING.COM
21 SepGoogle Fined €403 Million Over Location Data PracticesIreland’s DPC fined Google €403 million over GDPR violations involving location data, transparency, retention and user control. Ireland’s Data Protection Commission (DPC) just fined Google €403 million, and the case behind it goes back six years, to a set of complaints that…SECURITYAFFAIRS.COM