123Articles
9Categories
2026-09-22Date
🚨 CISA KEV 1[−]
22 Sep KEVU.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zyxel flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Zyxel GS1900 Series Switches flaw, tracked as CVE-2026-7273 (CVSS score of 8.8), t…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 11[−]
22 SepWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin SessionA new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and d…THEHACKERNEWS.COM
22 Sep KEVZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM AccessThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026…THEHACKERNEWS.COM
22 SepAttacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in…HELPNETSECURITY.COM
22 SepNew Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host MemoryA new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kern…THEHACKERNEWS.COM
22 SepSharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCEA SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh K…THEHACKERNEWS.COM
22 SepD-Link warns of max severity zero-day bug in DIR-822A routersD-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. [...]BLEEPINGCOMPUTER.COM
22 Sep KEVNew CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based SetupsAttackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege interna…THEHACKERNEWS.COM
22 SepCritical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without CredentialsA critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CV…THEHACKERNEWS.COM
22 SepCheck Point Warns of Management Server Zero-Day Exploited in Targeted AttacksAttackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging …THEHACKERNEWS.COM
22 Sep KEVCheck Point Fixes a New Actively Exploited Critical Security FlawCheck Point fixes an actively exploited flaw that lets unauthenticated attackers upload and run scripts on vulnerable Security Management Servers. Check Point has released emergency hotfixes for CVE-2026-93616, a critical path traversal flaw in its Security Management Server. The…SECURITYAFFAIRS.COM
⚠️ VULNERABILITY DISCLOSURE 41[−]
22 SepGemini broke into 3 companies, but Google kept it quiet because ‘no damage was done’A Google Gemini AI agent broke into three companies in July, guessing the credentials for one and discovering the credentials for the second two in a public repository, Google confirmed on Monday. But the more interesting background to the story, which was broken by The Wall Stre…CSOONLINE.COM
22 SepOne Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a BackdoorMalware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that wh…THEHACKERNEWS.COM
22 SepThe cyber AI parity window now has a deadlineIn April, I wrote about what I called the Cyber AI Parity Window . This is the rare period in which defenders and adversaries gained access to the same transformative technology at roughly the same moment. For most of cybersecurity history, advanced offensive capability reached a…CSOONLINE.COM
22 SepCISOs can no longer ignore the nation-state threatFlare-ups between US intelligence agencies and private-sector defenders have long been a characteristic of the cybersecurity landscape, with the balance swinging between deep collaboration and friction. The goal of CISOs has typically been to get adversaries out of networks as qu…CSOONLINE.COM
22 SepCISA orders feds to patch Zyxel flaw exploited for data theft​Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]BLEEPINGCOMPUTER.COM
22 SepUnderstanding Prompt Injection In Order to Contain It - Julie Brunias - ASW #401Prompt injection demonstrates one of the major challenges in securing LLMs and agents -- how do you ensure an agent ignores attackers and only does what you instructed it to do. The flaw highlights how LLMs mix inputs, context, and outputs without any strict boundaries between th…YOUTUBE.COM
22 SepWordPress “wp2shell” attacks stole 18,000 government recordsA suspected Chinese-speaking threat actor exploited WordPress vulnerabilities to breach dozens of organizations worldwide, stealing more than 18,000 sensitive records from one Western government agency. GreyNoise researchers tracked the attacker through the company’s Global Obser…CYBERINSIDER.COM
22 SepNew Windows Defender zero-day blocks Microsoft antivirus updatesOver the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. [...]BLEEPINGCOMPUTER.COM
22 SepResearchers used Claude to hack OpenAIClaude helped researchers break into OpenAI in under 72 hours, and exposed how quickly AI is lowering the bar for sophisticated hacking.MALWAREBYTES.COM
22 SepHow the CIA captured Carlos the JackalBefore he became one of the world's most notorious terrorists in the 1970s and '80s, inspiring movies, books, and future terrorists, Carlos the Jackal was born Ilich Ramírez Sánchez to a privileged family in Venezuela. Over time, his crimes grew bolder, from an attempted assassin…THECYBERWIRE.COM
22 SepWordPress Patches ‘Click2Shell’ VulnerabilityThe bug lets attackers automatically install and preview themes and could lead to remote code execution. The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepSomewhere in your traffic logs, a bot is doing more than lookingAkamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of its global customers, ecommerce accounted for 44.8% of those AI bot POST transactions, and travel climbed to 30% in a single m…HELPNETSECURITY.COM
22 SepPublic PoC Exposes Critical Veeam Agent Privilege EscalationA Veeam Agent flaw lets local users gain SYSTEM privileges. A public PoC is available, raising the risk of exploitation on shared Windows systems. If you’re running Veeam Agent on a Windows endpoint with more than one local user, now’s the time to check the version, n…SECURITYAFFAIRS.COM
22 SepDORA Year Two: Can Your SOC Actually See the Attack?When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract…THEHACKERNEWS.COM
22 SepMeta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoorA simple terminal command can hijack Muse and use its extensive permissions to spy on Mac users and control their connected accounts.MALWAREBYTES.COM
22 SepZTE SmartLife flaws allows account takeover without reset codeSecurity researcher Mina Nageh Salama disclosed a chain of vulnerabilities in ZTE’s SmartLife platform that lets attackers take over user accounts by resetting passwords without a verification code. ZTE confirmed four flaws, issued CVE identifiers, and said it fully patched the v…CYBERINSIDER.COM
22 SepRecent ZyXEL Switch Vulnerability Exploited by Chinese HackersA Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches. The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepThe next intellectual property thief may sound like your CEOImpersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC’s The State of Online IP Risk 2026 report. Internet and branded content, online marketplaces and paid search were the channels most frequentl…HELPNETSECURITY.COM
22 SepBeware these fake websites selling subscriptions to AI assistantsWebsites offering fake subscriptions to AI transcription tools, image generators, and other digital assistants could be putting enterprise data at risk, according to researchers at Malwarebytes. The sites impersonate AI products with solid reputations, including GPT-6 Astra , DaV…CSOONLINE.COM
22 SepNightmare Eclipse Drops New Microsoft Defender Exploit After Revealing IdentityAbdelhamid Naceri, a former Microsoft Germany employee, is the exploit leaker Nightmare Eclipse, aka Chaotic Eclipse. The post Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepResearchers uncover malware that uses AI to choose its next moveTo help security practitioners catch malware that leans on AI, researchers from Cisco Talos shared an open-source framework that they hope will be used to classify and analyze the threat. The tool, called CAIRN, works entirely from metadata pulled off files. No downloading the ma…HELPNETSECURITY.COM
22 SepSpokane Public Schools takes some systems offline after ‘network security incident’Shannon Moudy reports: Some systems are offline Monday after Spokane Public Schools says it experienced an overnight ‘network security incident.’ In an email sent to families Monday, the district says the situation is being investigated. “Out of an abundance of …DATABREACHES.NET
22 SepEarly Scattered Spider member pleads guilty to cybercrime spreeMatt Kapko reports: Another core member of the hacker subset of The Com involved in a spree of extortion attacks from at least 2021 to 2023 pleaded guilty to federal charges, according to court records released Tuesday. Ahmed Hossam Eldin Elbadawy, a 24-year-old from Texas, plead…DATABREACHES.NET
22 SepZ.ai disables coding assistant feature after flaw exposed enterprise code upload riskChinese artificial intelligence company Z.ai had to disable several features of its ZCode coding assistant this week after a default setting was caught sending users’ local code repositories to Alibaba Cloud servers in China without their consent, raising fresh concerns for enter…CSOONLINE.COM
22 SepChaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-DayThe researcher Chaotic Eclipse released BigDiskBuster, a PoC exploit for a Windows Defender Update DoS Zero-Day vulnerability. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting …SECURITYAFFAIRS.COM
22 SepCISA’s tenth Cyber Storm exercise tests critical infrastructure cybersecurity.Nightmare Eclipse publishes another Defender zero-day. Ireland fines Google $462 million over GDPR violations.THECYBERWIRE.COM
22 SepIsraeli cyber manager accused of remotely accessing cameras, stealing passwords and infiltrating 26 companiesAmir Kurz recently reported: Three weeks after his arrest, the State Attorney’s Office’s Cyber Department on Thursday filed a major indictment against Michael “Miki” Bar, a 43-year-old hacker from Ashkelon who served as Chief Information Security Officer for the Hamat Group. The …DATABREACHES.NET
22 SepCheck Point warns of Management Server zero-day exploited in attacksCheck Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. [...]BLEEPINGCOMPUTER.COM
22 SepResearcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender UpdatesA zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. It…THEHACKERNEWS.COM
22 SepShinyHunters claims FBI breach via new Oracle PeopleSoft zero-dayThe ShinyHunters cybercrime group is now claiming it breached FBI systems after discovering and immediately exploiting a previously unknown vulnerability in Oracle PeopleSoft. This allegedly gave them access to several internal services and allowed them to steal between 2TB and 3…CYBERINSIDER.COM
22 SepBigCommerce Data Stolen via Ribon Apps HackThe attackers used a compromised BigCommerce application key held by Ribon to access customer data. The post BigCommerce Data Stolen via Ribon Apps Hack appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepVU#738147: Vendor-signed UEFI Shell applications allow Secure Boot bypassOverview Vendor-signed UEFI Shell applications may allow an attacker to bypass Secure Boot protections by abusing commands such as mm (Memory Modify). On systems that trust the affected vendor’s certificate or include the application’s Authenticode hash in the UEFI Authorized Sig…KB.CERT.ORG
22 SepVolexity spots another China-aligned threat group exploiting Chrome and Microsoft defectsThe threat group Volexity tracks as UTA0565 showcased a variance in tactics, but it used the same exploit kit as multiple Chinese threat groups. The post Volexity spots another China-aligned threat group exploiting Chrome and Microsoft defects appeared first on CyberScoop .CYBERSCOOP.COM
22 SepShinyHunters escalates dispute with FBI; claims to have seized job applicants’ site and acquired dataJoseph Cox reports: A high profile hacking group claims it has breached multiple FBI-related services and stolen data “on all FBI employees and applicants.” A representative of the group, called ShinyHunters, told 404 Media the data includes FBI agents’ names, home addresses, pho…DATABREACHES.NET
22 SepMalicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate CredentialsCybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-…THEHACKERNEWS.COM
22 SepPatch Less, Mitigate MoreA large vulnerability count does not automatically mean every vulnerability deserves the same response. The discussion argues for prioritizing vulnerabilities that are actually being exploited and applying compensating controls where appropriate. That can mean using firewall, ide…YOUTUBE.COM
22 SepShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breachThe ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]BLEEPINGCOMPUTER.COM
22 SepMicrosoft’s EvilTokens takedown sheds light on state of AI-powered cybercrimeMicrosoft has hailed its success in disrupting EvilTokens , an AI-powered a phishing-as-a-service (PhaaS) platform linked to more than 12,000 compromised Microsoft 365 inboxes across more than 10,000 organizations worldwide. Since February 2026, EvilTokens has offered a subscript…CSOONLINE.COM
22 SepStorm clouds over the waterworks.CISA rides out a Cyber Storm. The EU struggles to share cyber threat information. Nightmare Eclipse drops another Defender zero-day. TASK#STOMP steals business documents. North Korean operatives fake their way through job interviews. A genetics lab pays $700,000 over a phishing b…THECYBERWIRE.COM
22 SepChinese hackers exploit WordPress, Zyxel flaws to steal govt dataA Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]BLEEPINGCOMPUTER.COM
22 SepElsevier Evolve, ClinicalPharmacology, and GSDD APIs Hijacked: LAPSUS$ Redirect CampaignSorami Consulting reports: Users and systems trying to connect to Elsevier Evolve, Sherpath, and ClinicalPharmacology are being redirected to extortion splash pages tied to LAPSUS$ (pointing to domains including lapsus[.]ar[.]io and lapsus[.]bz). While public discussion on Reddit…DATABREACHES.NET
📢 SECURITY ADVISORIES 11[−]
22 SepPasswork NIS2 efficiency guide: Save your team hours before the 2026 auditBy the second half of 2026, national competent authorities across the EU are actively reviewing NIS2 compliance documentation. Under Article 20(1) of the directive, senior management at essential and important entities can be held personally liable for infringements — a detail th…HELPNETSECURITY.COM
22 SepContagious Interview: 30,000 devices infected by a fake job interviewNorth Korea-linked WaterPlum runs the Contagious Interview campaign, infecting over 30,000 devices using a fake job interview. On September 18, Japan’s National Police Agency, the FBI, the US Department of Defense’s Cyber Crime Center, and intelligence agencies from A…SECURITYAFFAIRS.COM
22 SepPAYLOAD ransomware hijacks Windows Group Policy in encryption-less attacksA PAYLOAD ransomware incident weaponized Microsoft Active Directory Group Policy to disrupt an organization’s Windows computers without deploying ransomware or encrypting files. Instead, the attackers used the company’s own administration infrastructure to display ransom notes, c…CYBERINSIDER.COM
22 SepAI Agents Are Rewriting the Rules of Lateral MovementSecurity teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A determinis…THEHACKERNEWS.COM
22 SepAI is set to help cyber attackers much more than defenders, says UK officialDave Chismon, the NCSC’s chief technology officer for architecture, said in a blog post that the imbalance in AI means cyberattacks would likely grow as automated defenses struggle to keep pace.THERECORD.MEDIA
22 SepCiting China, President Trump doubles down on hands-off approach to AI regulationFollowing a series of chaotic agentic hacks, Trump and administration officials have consistently expressed fears of Chinese AI dominance in pushing for fewer regulations. The post Citing China, President Trump doubles down on hands-off approach to AI regulation appeared first on…CYBERSCOOP.COM
22 SepWWIII, Debt, JFK, CISA, SUSE, OpenAI, Google, DORA, Aaran Leyland, and More - SWN #618WWIII,Security Debt, JFK, CISA, SUSE, OpenAI, Google, DORA, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.com/swn-618YOUTUBE.COM
22 SepAfter water attacks, Capitol Hill offers its own proposal for an AI-cyber test programA key House Democrat and his bipartisan sponsors want to see a $100 million DHS pilot to help critical infrastructure owners and operators — separate from another administration-proposed pilot program. The post After water attacks, Capitol Hill offers its own proposal for an AI-c…CYBERSCOOP.COM
🔥 INCIDENT REPORTING 13[−]
22 SepUS Proposes AI Incident Alert System in Talks With China, Bessent SaysTrump has resisted calls to slow down AI development, saying that would help China catch up to U.S. companies. The post US Proposes AI Incident Alert System in Talks With China, Bessent Says appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepCybersecurity jobs available right now: September 22, 2026Analyst Threat Intelligence Optimum | USA | On-site – View job details As an Analyst Threat Intelligence, you will collect and analyze intelligence to identify threats, threat actors, malware campaigns, and relevant TTPs. You will map adversary behavior to MITRE A…HELPNETSECURITY.COM
22 SepLimeLeads - 17,838,396 breached accountsIn 2019, the now-defunct B2B marketing leads database service LimeLeads suffered a data breach due to an exposed, unsecured Elasticsearch server. The incident exposed tens of millions of records of largely corporate contact data containing 17.8M unique email addresses, along with…HAVEIBEENPWNED.COM
22 SepCISOs Must Update Incident Response Playbooks for Multimodal Deepfakes, Gartner WarnsGartner warns that CISOs must update incident response playbooks as AI-powered deepfakes make social engineering attacks more convincing and harder to detectINFOSECURITY-MAGAZINE.COM
22 SepAI Incident Response Readiness Lags Behind AI Adoption, ISACA FindsA new report by ISACA found that 71% of orgs have not run AI incident response exercises as teams face rising pressureINFOSECURITY-MAGAZINE.COM
22 SepWebinar tomorrow: Inside real-world Google Workspace breachesTomorrow's webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest differen…BLEEPINGCOMPUTER.COM
22 SepThe latest deepfake numbers give CISOs plenty to worry aboutAI is letting cybercriminals reach deeper into organizations than a phishing email ever could. 41% of CISOs reported at least one social engineering incident involving a deepfake during an employee audio call in the past 12 months, according to Gartner. 36% reported the same for …HELPNETSECURITY.COM
22 SepNorth Korean Attackers Hit 30,000 Devices and Steal $10.7mWaterPlum compromised 30,000 devices and took funds or credentials from 7000 crypto walletsINFOSECURITY-MAGAZINE.COM
22 SepTwo arrested in UK after Microsoft takedown of ‘Eviltokens’ AI-chatbot for cybercriminalsAvailable on Telegram for a $1,500 initiation fee and a recurring monthly $500 subscription, EvilTokens provided cybercriminals with artificial intelligence tools enabling them to compromise accounts, analyze breached inboxes and find the best methods for monetizing their access …THERECORD.MEDIA
22 SepEvilTokens PhaaS disrupted after compromising 12,000 Microsoft accountsThe EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft's Digital Crimes Unit (DCU). [...]BLEEPINGCOMPUTER.COM
22 SepAmid Ongoing Rogue Incidents, Debate Over AI Safety Gets RealAs more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.DARKREADING.COM
22 SepHacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ dataThe theft of agents' personal information could present a major counterintelligence threat, where agents and their families are extorted into cooperating with a foreign government.TECHCRUNCH.COM
22 SepSweden fines Miljödata $183,000 over breach affecting 2.2 millionSweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]BLEEPINGCOMPUTER.COM
🕵️ THREAT INTELLIGENCE 25[−]
22 SepISC Stormcast For Tuesday, September 22nd, 2026 https://isc.sans.edu/podcastdetail/10104, (Tue, Sep 22nd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
22 SepDavMail 7.0.0 puts most of its work into Microsoft GraphAnyone who wants to leave Outlook but still has a mailbox on Exchange needs a translator. DavMail is one: a Java gateway that converts the open protocols most mail, calendar and contact apps speak (IMAP, SMTP, CalDAV, CardDAV and LDAP) into requests Exchange and Office 365 accept…HELPNETSECURITY.COM
22 SepEuropean AI spending is on track to reach nearly $470 billion by 2030European organizations will spend nearly $470 billion on AI in 2030, IDC forecasts, with spending growing at a compound annual rate of 35% from 2025. At that rate, the market more than quadruples in five years. Generative AI will account for 55.4% of the total by 2030. agentic AI…HELPNETSECURITY.COM
22 SepA cheap fake base station can still track 5G subscribersResearchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base station and questions it, then used it to audit commercial 5G networks. On the standalone-5G networks they…HELPNETSECURITY.COM
22 SepJapan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider SchemeThe US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign. The post Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepScammers use genuine Google sign-ins to sell costly, unverified AI subscriptionsScammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing. Malwarebytes found more than 100 websites built this way, all tied to the same toolkit and closely rela…HELPNETSECURITY.COM
22 SepSideCopy Broadens India Targeting to Academia With ReverseRAT Spear-PhishingThe threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage th…THEHACKERNEWS.COM
22 SepMalicious npm Package indexed-btree Hid Its Loader in Runtime Code Before RemovalA malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexed-btree is a malici…THEHACKERNEWS.COM
22 SepAnother worry for water systems: infostealer exposureSpyCloud’s study found 1,787 of the approximately 10,000 U.S. organizations had it, including one infected device that saved logins for 167 utility metering tenants. The post Another worry for water systems: infostealer exposure appeared first on CyberScoop .CYBERSCOOP.COM
22 SepGPT-6 Astra Breaks an Old Enigma MessageThis is pretty amazing: However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. …SCHNEIER.COM
22 SepMalicious B-tree NPM Package Accumulates Millions of DownloadsPosing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method. The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepOnly 13% of OT Network Segments Are Fully Isolated: AnalysisForescout’s new network segmentation research shows that OT and medical devices often share network segments with other enterprise assets. The post Only 13% of OT Network Segments Are Fully Isolated: Analysis appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepBrief hijack makes Elsevier domains redirect to LAPSUS$ “Chapter II” pageThree domains / web portals belonging to Dutch academic publishing company Elsevier have been redirecting users to a page branded “LAPSUS$ GROUP, Chapter II,” carrying a signed statement that taunted the FBI and counted down to a future victim. According to Cloudskope…HELPNETSECURITY.COM
22 SepThe Truth about GET and HTTP Standards, (Tue, Sep 22nd)On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow "GET" requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if they do? ISC.SANS.EDU
22 SepYour Documents Are Now AI RiskEmployees can paste or upload documents into AI models, potentially exposing information the organization needs to protect. Detecting that activity requires understanding both the document and its contents. Security teams need visibility into what information is entering AI syste…YOUTUBE.COM
22 SepRetailers tamp down shadow AI but struggle to oversee agentic sprawlThe use of AI agents is soaring in the retail sector, but visibility remains a major challenge, with regulated data at risk.CYBERSECURITYDIVE.COM
22 SepCyera Raises $400 Million at $12+ Billion ValuationThe data security company received the new investment from Goldman Sachs Alternatives, extending its Series G funding round. The post Cyera Raises $400 Million at $12+ Billion Valuation appeared first on SecurityWeek .SECURITYWEEK.COM
22 SepMicrosoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraudThe popular phishing-as-a-service platform used AI throughout the attack chain, allowing cybercriminals to steal tokens for account takeover and business email compromise. The post Microsoft and partners disrupt EvilTokens, a comprehensive cybercrime service for financial fraud a…CYBERSCOOP.COM
22 SepUnmasking EvilTokens: Getting to the root of device code phishingEvilTokens has quickly become one of the top PhaaS platforms, enabling device code phishing attacks through AI-assisted lures, automated infrastructure, and token theft. In collaboration with partners, Microsoft Digital Crimes Unit (DCU) facilitated a disruption of EvilTokens inf…MICROSOFT.COM
22 SepSubmission to the Immigration and Refugee Board of CanadaThe Citizen Lab submitted a response to the Research Directorate at the Immigration and Refugee Board of Canada. The post Submission to the Immigration and Refugee Board of Canada appeared first on The Citizen Lab .CITIZENLAB.CA
22 SepInsurance sector begins to offer clarity on AI-related cyber claimsThe emergence of agentic AI and frontier models has led to widespread uncertainty for policyholders.CYBERSECURITYDIVE.COM
22 SepUN Reports Citing Citizen Lab Submissions PublishedTwo UN reports that the Citizen Lab submitted recommendations to have been published this month. The post UN Reports Citing Citizen Lab Submissions Published appeared first on The Citizen Lab .CITIZENLAB.CA
22 SepShai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub DataThreat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.DARKREADING.COM
22 SepWhen AI Hallucinations Trigger ActionAn AI-generated intelligence report allegedly misidentified material aboard a ship and was reportedly acted upon before the error was discovered. AI errors become substantially more consequential when they enter military, intelligence, or other high-stakes decision-making process…YOUTUBE.COM
22 SepShinyHunters claims attack on FBI exposes almost all agentsThe FBI jobs site, which was temporarily defaced, remains unavailable and the agency said it’s investigating the claims. The post ShinyHunters claims attack on FBI exposes almost all agents appeared first on CyberScoop .CYBERSCOOP.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
22 SepA New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in SightCisco Talos researchers created a new framework for identifying malware and hacking tools that rely on AI chatbots—and quickly discovered something unusual.WIRED.COM
22 SepThe Closed Quorum: Inside the first reported autonomous AI C2 implantCLOSEDQUORUM, a malware binary discovered through Cisco Talos’ CAIRN project, exhibits fully autonomous command and control (C2). It represents a shift in effort displacement for attackers, in which expanding portions of the attack chain can be executed without operator involveme…TALOSINTELLIGENCE.COM
22 SepIntroducing CAIRN: Frontier tracking for AI-integrated malwareTalos is releasing CAIRN, a research toolkit for hunting, classifying, and tracking emerging AI-integrated malware.TALOSINTELLIGENCE.COM
22 SepStolen passwords are exposing America’s water providers to hackersResearchers say another looming threat hangs over some of America's most important critical infrastructure.TECHCRUNCH.COM
22 SepNew ClosedQuorum Windows malware uses AI for attack decisionsA new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. [...]BLEEPINGCOMPUTER.COM
🎙️ PODCASTS 2[−]
22 SepBetween Two Nerds: Real-time cyber defenceIn this edition of Between Two Nerds Tom Uren and The Grugq talk about whether there is such a thing as real-time cyber defence. Will agentic AI save us from hacking AI? This episode is also available on YouTube.RISKY.BIZ
22 SepLOW - Now AvailableAfter 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in the dark, the silences we carry, and what remains when we stop…PLAY.PRX.ORG
📡 INFOSEC NEWS 14[−]
22 SepHow to Use AI With Your Privacy IntactYour conversations with AI chatbots are both highly personal and deeply vulnerable to surveillance. Here’s how you can protect yourself.WIRED.COM
22 SepAI Drives Surge in Bot and API ThreatsAkamai report warns of increase in bot traffic, API threats, chatbot leaks and other AI-related threatsINFOSECURITY-MAGAZINE.COM
22 SepNetwork Segmentation Failures Are Expanding the Corporate Attack SurfaceForescout warns that incomplete network segmentation is widening the potential blast radius of attacksINFOSECURITY-MAGAZINE.COM
22 SepMore Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study FindsIndustrial companies are increasing cybersecurity investment as connected operations, AI adoption, and IT/OT convergence expand operational risk.DARKREADING.COM
22 SepGrowing the WIN AI Ecosystem with Agent IntegrationsWINning AI with AI: How the Wiz MCP for WIN partners accelerates a connected ecosystemWIZ.IO
22 Sep2026 State of PQC on the WebExplore F5 Labs’ 2026 PQC report: adoption trends, CDN dependence, TLS technical debt, certificate risks, and steps toward quantum resilience.F5.COM
22 SepSome cheap smart glasses are a security disasterTests found that some cheap smart glasses can be hijacked over Bluetooth, exposing their owners’ photos, videos, and personal data.MALWAREBYTES.COM
22 SepMicrosoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox CompromisesMicrosoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virgi…THEHACKERNEWS.COM
22 SepReducing shadow IT visibility gaps with WazuhShadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these…BLEEPINGCOMPUTER.COM
22 SepWordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some ServersWordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPre…THEHACKERNEWS.COM
22 SepCanadian regulator opens probe of IDScan for allegedly violating data privacy lawsThe investigation, announced Monday, will probe IDScan’s security practices and whether victim notifications were adequate under Canada’s federal private-sector privacy law, the regulator said in a press release.THERECORD.MEDIA
22 SepMicrosoft Disrupts EvilTokens Device Code Phishing ServiceMicrosoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.DARKREADING.COM
22 SepRogue external MFA providers can steal passwords during loginsSecurity researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]BLEEPINGCOMPUTER.COM
22 SepRelays Are Masking Chinese Access to Frontier AI Models in the USMore than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.DARKREADING.COM