🚨 CISA KEV 2[−]
23 Sep KEVCVE-2026-94127: Critical Unauthenticated RCE in F5 BIG-IP APMOverview On September 22, 2026, F5 published a security advisory for CVE-2026-94127 , a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3.1 score of 9.8. An unauthenticated attacker with network acce…RAPID7.COM
23 Sep KEVU.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalogU.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerab…SECURITYAFFAIRS.COM
🐛 COMMON VULNERABILITIES AND EXPOSURES 15[−]
23 SepF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth ServersAttackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access token…THEHACKERNEWS.COM
23 SepChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP MalwareA Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome …THEHACKERNEWS.COM
23 SepCVE-2026-87902: how close is your WordPress to remote code execution?WordPress 7.1.2 fixes an unauthenticated file inclusion bug active since version 4.7, patchable but exploitable into remote code execution. WordPress 7.1.2 shipped on September 22 address an unauthenticated local file inclusion, tracked as CVE-2026-87902 (CVSS score of 9.2), whic…SECURITYAFFAIRS.COM
23 SepWordPress 7.1.2 fixes critical unauthenticated path traversal vulnerability (CVE-2026-87902)WordPress released version 7.1.2 to fix a critical flaw that lets an unauthenticated attacker make the software load a PHP file of the attacker’s choosing from outside the site’s active theme folders. On sites where the server and the active theme meet certain conditi…HELPNETSECURITY.COM
23 SepAttackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instancesCheck Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026. The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-…HELPNETSECURITY.COM
23 SepExploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container EscapeA use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream …THEHACKERNEWS.COM
23 SepMikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH KeyTwo MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2…THEHACKERNEWS.COM
23 SepVU#754548: Cinnamon's kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlersOverview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This…KB.CERT.ORG
23 SepVU#273940: Enterprise Access Management EAM does not rotate RSA keysOverview Imprivata Enterprise Access Management (EAM), an authentication and single sign-on platform for enterprise and clinical environments, contains a vulnerability in versions 26.2.6 and below. The product provides no supported mechanism to rotate its RSA key pair after deplo…KB.CERT.ORG
23 SepHackers start exploiting critical WordPress flaw for code executionThreat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]BLEEPINGCOMPUTER.COM
23 SepF5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE AttacksF5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager…SECURITYAFFAIRS.COM
23 SepCheck Point warns of hackers exploiting Security Gateway VPN RCE flawCybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]BLEEPINGCOMPUTER.COM
23 Sep KEVF5 fixes actively exploited zero-day flaw in BIG-IP APMTechnology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch …CSOONLINE.COM
23 SepIs This A Joke? In The Auth Header? (F5 BIG-IP UnAuth Heap-Overflow to RCE CVE-2026-94127)Well, well, well, well, well, well, well, well, well, well, well, well, well, well, well. We're back. Sorry. We've been watching the onslaught of vulnerabilities flood the internet. Every man, dog, and their grandmas (apparently?) are now using LLMs to find and reproduc…LABS.WATCHTOWR.COM
⚠️ VULNERABILITY DISCLOSURE 37[−]
23 SepAI malware just removed the human from the attack loopAttackers using AI have greatly benefited when it comes to speed and scale, and now, says Cisco Talos, the technology has evolved to execute large portions of the attack chain entirely without human involvement. Researchers at the threat intelligence group have identified what th…CSOONLINE.COM
23 SepPrismor: Open-source runtime control plane for AI agentsPrismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before the call runs. Every call gets one of three verdicts: …HELPNETSECURITY.COM
23 SepWeekly Update 522: Live From Oslo with Scott HelmePresently sponsored by: SACR's Endpoint Control and Prevention report, live Oct 1 with its author and Origin's founder, deep on endpoint AI observability. Register. Heads up: the first 7 mins is a bit quiet until we worked out the external mic was misbehaving - sorry! But get thr…TROYHUNT.COM
23 SepCheck Point Patches Exploited Management Server Zero-DayThe critical-severity flaw could allow unauthenticated attackers to upload and execute arbitrary scripts. The post Check Point Patches Exploited Management Server Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepCritical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG InputA new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from …THEHACKERNEWS.COM
23 SepF5 patches BIG-IP APM zero-day flaw exploited in RCE attacksF5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. [...]BLEEPINGCOMPUTER.COM
23 SepCritical F5 BIG-IP Vulnerability Exploited as Zero-DayUnauthenticated attackers could send malicious traffic to BIG-IP to achieve remote code execution. The post Critical F5 BIG-IP Vulnerability Exploited as Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepOkta bets on identity to control AI agents, but is identity enough?Concerns over agentic risks are rising, and identity and access management (IAM) giant Okta believes it’s making the moves of a would-be leader in this emerging cyber market. “Identity is the primary control plane for securing AI,” said Okta CEO and co-founder Todd McKinnon in an…CSOONLINE.COM
23 SepArista Urges Immediate Patching of Exploited VCO Zero-DayRemote attackers could trigger the critical-severity flaw to access privileged internal functionality. The post Arista Urges Immediate Patching of Exploited VCO Zero-Day appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepMicrosoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxesThe EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft. With authorization from the US District Court for the Eastern District of V…HELPNETSECURITY.COM
23 SepShinyHunters Claims FBI Hack Via PeopleSoft Zero DayInfamous threat group ShinyHunters claims to have personal information on thousands of FBI employeesINFOSECURITY-MAGAZINE.COM
23 SepResearch on Models Engaging in Genie-Like BehaviorNew paper: “ Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .” Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call se…SCHNEIER.COM
23 SepAdobe Patches Critical Flaws in Connect, AEM FormsThe nine critical security defects could be exploited for arbitrary code execution and privilege escalation. The post Adobe Patches Critical Flaws in Connect, AEM Forms appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepEvilTokens made phishing-as-a-service look easy. Then it got taken downMicrosoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 org…SECURITYAFFAIRS.COM
23 SepMeta’s Muse AI Assistant Rolled Out With a Serious Security FlawMeta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do “whatever” they wanted on a victim’s Mac, highlighting the inherent dangers of AI helpers.WIRED.COM
23 Sep KEVArista patches actively exploited VeloCloud Orchestrator zero-dayArista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]BLEEPINGCOMPUTER.COM
23 SepPortnox detects and removes unauthorized AI applications from managed devicesPortnox has announced new capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy, restricting, quarantining, or removing unapproved or risky applications the moment they’re detected. The capability address…HELPNETSECURITY.COM
23 SepNetwork Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposureNetwork Solutions has launched Dark Web Monitoring, a new security capability that alerts small businesses when information associated with their domain appears in known breach data and provides steps they can take to reduce risk. Stolen credentials and other information exposed …HELPNETSECURITY.COM
23 SepDarkMe RAT trades zero-days for plain phishing emailsDarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again. This time around, its distribution has been simplified: instead of leveraging zero-day …HELPNETSECURITY.COM
23 SepBarracuda brings AI security and governance within reach of smaller organizationsBarracuda Networks has launched Barracuda AI Data Security, the AI security and governance solution purpose-built for resource-constrained organizations and managed service providers (MSPs). The solution enables businesses to accelerate AI adoption by protecting sensitive data, e…HELPNETSECURITY.COM
23 Sep KEVInfraTrust report warns network management systems under attackAttackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]BLEEPINGCOMPUTER.COM
23 SepHow One Kubernetes YAML Can Hand Over a GCP OrganizationA Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into …BLEEPINGCOMPUTER.COM
23 SepHow dynamic application security testing validates risk at runtimeSecurity teams already have long queues of potential application vulnerabilities. The useful question is what happens next: can they see how a weakness behaves in a running application, reproduce the attack, and give developers enough evidence to fix it? Dynamic application secur…RAPID7.COM
23 SepThe EU spent billions on a cyberattack shield — nobody checked if it workedThe EU built an early-warning system to catch the next major cyberattack before it spreads. Roughly 20 months later, auditors have found it still is not fully switched on. Jonathan Bent reports: Brussels has allocated €1.4 billion to defending Europe from cyberattacks. Its own au…DATABREACHES.NET
23 SepShinyHunters claims FBI breach after alleged PeopleSoft zero-day attackShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U.S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FB…SECURITYAFFAIRS.COM
23 SepRyuk Ransomware Operator Sentenced to 24 Months in PrisonAbinaya reports: An Armenian national extradited from Ukraine to the United States has been sentenced to federal prison for his role in Ryuk ransomware attacks that targeted organizations worldwide, including a company in Oregon. Karen Vardanyan, 35, received a 24-month federal p…DATABREACHES.NET
23 SepLatvia arrests suspected hacker for electronics repair company breachDaryna Antoniuk reports: Latvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims, authorities said Wednesday. The first attack was detected in February, while a second — u…DATABREACHES.NET
23 SepMalicious AI agents steal 600K credit cards, infect 100+ sites with skimmersA financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]BLEEPINGCOMPUTER.COM
23 SepThe AI Vulnerability That Isn’t AIPlugin4Shell affected plugin installation mechanisms in several AI coding tools. Air Security says the flaw could allow an attacker to bypass the expected plugin version and install something else. The incident is a reminder that AI products still depend on ordinary software comp…YOUTUBE.COM
23 SepPentagon cyber chief: The demand far exceeds supplyAt DefenseTalks on Tuesday, Katie Sutton said the Pentagon now receives far more requests to use cyber operations than its forces can fulfill, eight years after gaining that authority. The post Pentagon cyber chief: The demand far exceeds supply appeared first on CyberScoop .CYBERSCOOP.COM
23 SepAttackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp RegistryCybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido…THEHACKERNEWS.COM
23 SepNo evidence of successful foreign meddling in 2024 election, spy agencies foundU.S. intelligence officials found no evidence that any foreign adversary successfully interfered in the 2024 presidential election, according to sources familiar with the findings of a classified assessment.THERECORD.MEDIA
23 SepThe hunters go after the bureau.ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM zero-day. Ransomware activity remains high. Microsoft disrup…THECYBERWIRE.COM
23 SepCanva hacked via vendor’s Salesforce instance; Other customers affected as wellA new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The …DATABREACHES.NET
23 SepICYMI: August 2026 @AWS SecurityRead all about the latest AWS security features, compliance updates, and hands-on resources in our monthly digest posts. You’ll find expert blog posts, new service capabilities, code samples, and workshops. AWS Security Blog posts August brought 20 AWS Security Blog posts organiz…AWS.AMAZON.COM
23 SepFBI Hack Exposed FBI’s Own Hacking UnitJoseph Cox reports: The catastrophic hack of at least thousands of FBI officials’ personal data, including their addresses, phone numbers, and even their spouses, includes members of the FBI’s secretive hacking team, potentially revealing who exactly is in that unit, 404 Media ha…DATABREACHES.NET
📋 SECURITY BULLETINS 1[−]
23 SepMicrosoft: September Windows updates break Always On VPN connectionsMicrosoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. [...]BLEEPINGCOMPUTER.COM
📢 SECURITY ADVISORIES 14[−]
23 SepBurnham announces plan for new UK center to fight disinformationThe United Kingdom will create a new national center "to detect, attribute and disrupt” hostile state disinformation, Prime Minister Andy Burnham announced at the United Nations General Assembly.THERECORD.MEDIA
23 Sep80,000 relay servers help users in China slip past U.S. AI region bansMore than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U.S. AI models, according to Team Cymru. “What we have uncovered is an entire ecosystem designed explicitly to break the frontier model providers’ T&Cs, enabling fraud and ill…HELPNETSECURITY.COM
23 SepGitHub App keys can still enable takeovers long after they are forgottenGitHub allows organizations to install GitHub Apps that automate and extend certain functionality on the platform and have access to selected repositories and permissions. But the private keys these applications use to authenticate themselves can remain valid for years unless man…CSOONLINE.COM
23 SepWatchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attackThe DHS inspector general said CISA lacks the power to compel agencies to implement its Binding Operational Directives. The post Watchdog finds most agencies failed to meet CISA cloud security orders, heightening risk of attack appeared first on CyberScoop .CYBERSCOOP.COM
🔥 INCIDENT REPORTING 18[−]
23 SepAmazon Slams the door on Meta's Muse AI AgentAmazon Blocks Meta's AI Shopping Agent, FBI Boards Hacked Oil Tankers & Microsoft Patches Break Backups David Shipley covers Amazon blocking Meta's new AI agent Muse from shopping on Amazon, citing failure to identify itself and potential privacy and security risks, as the broade…CYBERSECURITYTODAY.LIBSYN.COM
23 SepShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job ApplicantsThe cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents …THEHACKERNEWS.COM
23 SepRisky Business #854 -- We're JevpilledTHE RISKY BUSINESS WEEKLY SHOW IS NOW ON HIATUS FOR TWO WEEKS AND WILL RETURN OCTOBER 14 On this week’s show Patrick Gray and James Wilson are joined by Adam Boileau to talk through the week’s news, including: Google’s Gemini finally did some crimes OpenAI admits more agents did …RISKY.BIZ
23 SepEU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident ResponseThe EU Court of Auditors has criticized EU shortcomings in responding to major cyber incidentsINFOSECURITY-MAGAZINE.COM
23 SepRyuk ransomware member sentenced to 24 months in prisonAn Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. [...]BLEEPINGCOMPUTER.COM
23 SepUAE, Saudi Arabia Face Onslaught of Increasingly Complex CyberattacksThe United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.DARKREADING.COM
23 SepRansomware Attacks Reach Record High for 2026A total of 1073 firms fell victim to ransomware attacks globally in August, with the industrial sector the most affected, according to new NCC dataINFOSECURITY-MAGAZINE.COM
23 SepShinyHunters claims FBI breach was revenge for “false” reportThe extortion group says it stole sensitive data on FBI agents and job applicants, and wants the bureau to retract a warning about its tactics.MALWAREBYTES.COM
23 SepLatvia arrests suspected hacker for electronics repair company breachLatvian police arrested a 23-year-old man suspected of hacking at least two companies, stealing personal information and attempting to extort money from the victims.THERECORD.MEDIA
23 SepYou Own Your AI Agent’s ActionsThe organization established a principle that employees remain accountable for their agents’ actions, including actions taken by sub-agents created downstream. That creates a human chain of accountability even as identities become increasingly non-human. Real incidents were also …YOUTUBE.COM
23 SepCompromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPIUnknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeD…THEHACKERNEWS.COM
23 SepFBI investigating alleged ShinyHunters breach of its jobs siteThe ShinyHunters cybercriminal organization on Tuesday replaced agency images on the FBIjobs.gov site with a photo of a Pokemon that has become the group’s defacto mascot.THERECORD.MEDIA
23 SepRyuk ransomware operator gets 2-year sentence after extorting victims for $1.2 millionAn Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.THERECORD.MEDIA
23 Sep KEVBusinesses fear cyberattacks more than anything else, driven by AI and supply chain worriesMany companies still aren’t preparing thoroughly enough to face a hack, the insurance firm Travelers said in a new report.CYBERSECURITYDIVE.COM
23 SepShinyHunters claims to have breached the FBI.Microsoft disrupts the EvilTokens cybercrime platform. Business news: Cyera raises $400 million in a Series G extension.THECYBERWIRE.COM
23 SepRyuk ransomware operator gets 2-year sentence after extorting victims for $1.2 millionAn Armenian national and member of the Ryuk ransomware gang was sentenced to two years in federal prison for his role in launching attacks.THERECORD.MEDIA
23 SepRyuk ransomware operator sentenced to 2 years in prisonThe Armenian national was extradited from Ukraine to the United States last year and pleaded guilty to cybercrimes in July. The post Ryuk ransomware operator sentenced to 2 years in prison appeared first on CyberScoop .CYBERSCOOP.COM
23 SepFBI probes cyberattack tied to third-party jobs portalThe potentially serious breach highlights the supply chain risks facing even the most sophisticated organizations.CYBERSECURITYDIVE.COM
🕵️ THREAT INTELLIGENCE 30[−]
23 SepISC Stormcast For Wednesday, September 23rd, 2026 https://isc.sans.edu/podcastdetail/10106, (Wed, Sep 23rd)(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.ISC.SANS.EDU
23 SepRabbit’s new OS lives in the cloud and borrows your laptop to get things doneRabbit, the Santa Monica company that makes the r1 handheld, released OS3, an agentic operating system. It runs in Rabbit’s cloud and operates a user’s computers through a local agent that installs with one command. The user states a goal in a chat, and OS3 picks the …HELPNETSECURITY.COM
23 SepNetBSD 10.2 security fixes close a remote kernel bug in ipfilterA NetBSD box at the edge of a network, filtering traffic with ipfilter, has been carrying a kernel flaw that someone outside the machine can set off. The bug is a remotely triggerable null pointer dereference in ipfilter, meaning the kernel tries to read memory through a pointer …HELPNETSECURITY.COM
23 SepNearly two-thirds of tested websites fail every bot testMalicious bot activity increased 124% between July 2025 and June 2026, compared with 13.2% growth in human traffic. Traffic from AI agents and large language model crawlers rose 82.3% during the same period, according to DataDome’s State of Bot & Agent Security Report 2026. …HELPNETSECURITY.COM
23 SepProduct showcase: Scamwise checks the red flags before you take the baitScamwise is a free scam-checking service from Savi that examines suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud. The service works in any web browser on desktop, mobile, or tablet, with no account required. Scamwise is i…HELPNETSECURITY.COM
23 SepShinyHunters Claims FBI Hack, Demands Retraction of Threat ReportThe cybercrime group is unhappy with its description in an FBI report and threatens to leak stolen information. The post ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepClaude Opus 5.5 cuts costs and adds safeguards for autonomous AIClaude Opus 5.5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure. Developers can access it through the Claude Platform using the model name claude-opus-5-5. It includes watermarking measures designed to comply with the EU AI Act. Bu…HELPNETSECURITY.COM
23 SepBalancing AI Benefits and Risks as Your Next CISO Could be Artificial Intelligence - BSW #466As businesses race to embrace AI, security leaders are struggling to modernize cyber hygiene and prevent over-privileged agents from causing unintended harm. How do you balance the benefits of AI with the Risks of AI? Evan McHenry, Chief Information Security Officer at Robinhood …YOUTUBE.COM
23 SepOuterlimit Raises $16 Million to Stop Rogue AI Agents From Causing HarmEmerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions. The post Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm appeared firs…SECURITYWEEK.COM
23 SepChrome 154 Patches 108 VulnerabilitiesThe browser update resolves several critical-severity memory safety and memory corruption flaws. The post Chrome 154 Patches 108 Vulnerabilities appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepA Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at RiskDebates over the plausibility of these doomsday scenarios have heated up since several executives endorsed slowing the technology’s development for safety reasons. The post A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk appeared first on SecurityW…SECURITYWEEK.COM
23 SepGPT-6 Sol and Luna arrive with 50% lower API pricesOpenAI has expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models. Both are available in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise, and Edu users. Free and Go users can access GPT-6 Luna in the desktop app. The models are not yet available in Chat. OpenAI API us…HELPNETSECURITY.COM
23 SepAI-Powered Phishing Platform EvilTokens Disrupted by MicrosoftThe cybercrime platform leveraged AI at every step of the attack chain, including writing social engineering messages and deciding targets. The post AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepThe president has called for AI leadership. Here’s the mission.An AI compact built around capability, control, and continuity can ensure the country stays safe and secure while also leading the world in the technology. The post The president has called for AI leadership. Here’s the mission. appeared first on CyberScoop .CYBERSCOOP.COM
23 SepDiscord rolls out age checks that don’t require an ID or selfieDiscord is rolling out a new age assurance system that will classify most users as adults or teens without requiring them to upload a government ID or take a selfie. The company says more than 90% of users will be assigned an age group automatically, while those who need to confi…CYBERINSIDER.COM
23 SepAI agents steal 600,000 credit cards in attacks on online retailersA financially motivated threat actor is using autonomous AI agents to compromise online retailers at a reported average cost of roughly $25 per target. The campaign, active since at least July 2026, has reportedly stolen more than 600,000 unexpired payment card records, deployed …CYBERINSIDER.COM
23 SepChatGPT advertising system reportedly tracks users across websitesOpenAI’s advertising infrastructure can link activity on third-party advertiser websites to a user’s ChatGPT account through a cross-site cookie called __obi. The mechanism resembles established ad-tech tracking systems, but its use around an AI assistant raises additional privac…CYBERINSIDER.COM
23 SepHoneywell: OT Security Teams Embrace AI, but Autonomy Still RareOnly 21% of industrial security leaders report a complete OT asset inventory, even as 88% call their programs mature. The post Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepCofense measures employee readiness against real-world phishing threatsCofense has announced an expansion of its AI-driven Phishing Defense Platform through Cofense Command Center, its orchestration layer for measurement and reporting. The new Competency Dashboard measures how employees recognize, report and respond to phishing threats, giving secur…HELPNETSECURITY.COM
23 SepLookout targets smishing, voice cloning, and vishing with real-time mobile protectionLookout has launched Social Engineering Protection (SEP), a new module within the Lookout Mobile AI Security Platform. SEP provides automated, real-time protection against the next generation of AI-driven mobile threats, including linkless smishing attacks, synthetic voice clonin…HELPNETSECURITY.COM
23 SepFake Claude Max giveaway tricks users into handing over their Google account credentialsA fake Claude Max giveaway uses a spoofed Google sign-in window to steal users’ login credentials, Malwarebytes researchers have found. “Browser-in-the-browser” is not a new technique. Researchers have documented it since 2022, and in June Palo Alto NetworksR…HELPNETSECURITY.COM
23 SepSupporting ASD’s multi-factor authentication campaign: Why MFA matters more than everThe Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS…AWS.AMAZON.COM
23 SepAttackers Manipulate AI Chatbots in Mass Disinformation, Phishing CampaignThreat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.DARKREADING.COM
23 SepOpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systemsA Ukrainian official said the government will use the tools to automate cybersecurity functions in critical infrastructure as the war with Russia continues. The post OpenAI, Ukraine partner on ‘Daybreak’ program to protect power grids and water systems appeared first on CyberScoo…CYBERSCOOP.COM
23 SepIndustrial leaders face cyber resilience gap as attacks shake confidenceMore than one-third of organizations consider cyber risk as the top obstacle to growth.CYBERSECURITYDIVE.COM
23 SepReimagining the SOC for the agentic era in Microsoft DefenderWe are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together. The post Reimagining the SOC for the agentic era in Microsoft Defender appeared first on Microsoft Security Blog .MICROSOFT.COM
23 SepWorries About an AI Internet Takeover Gain New Urgency Among Doomsday ScenariosThe idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts. The post Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepIonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says SinIonQ’s new single processor quantum error decoder minimizes the classical computing overhead in quantum error correction. The post IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin appeared first on SecurityWeek .SECURITYWEEK.COM
23 SepShould Conscious AI Have Rights?The AI industry is beginning to discuss questions around consciousness, persona, and model welfare. Microsoft AI CEO Mustafa Suleyman has argued that claims of conscious AI are premature, while researchers in the emerging model-welfare field are examining whether future AI system…YOUTUBE.COM
23 SepAmericans’ views on data centers have turned more negativeAmerican attitudes toward data centers have turned noticeably more negative over the course of 2026, according to a new Pew Research Center survey. 54% of U.S. adults now say data centers are mostly bad for the environment, up from 39% in January. Half say they hurt home energy c…HELPNETSECURITY.COM
🌐 CYBER THREAT LANDSCAPE 5[−]
23 SepFake LastPass on GitHub Led to an Infostealer That Killed 145 Security ToolsAttackers spoofed LastPass on GitHub, used a Microsoft-signed driver to disable 145 security products, then deployed an infostealer. Someone impersonated LastPass on GitHub, got users to download a fake authenticator, and ended up killing 145 different antivirus and EDR products …SECURITYAFFAIRS.COM
23 SepWindows Botnet x47.c Offers AI API Draining, 18 Attack MethodsQrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxyingINFOSECURITY-MAGAZINE.COM
23 SepThis Windows Malware is Built to Let Up to Four AI Models Vote on Its Next MoveA Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talo…THEHACKERNEWS.COM
23 SepGitLab Email Addresses Can Be Weaponized for Supply Chain AttacksIncoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.DARKREADING.COM
23 SepNew RemControl Android banking malware targets users in Europe and CanadaA new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]BLEEPINGCOMPUTER.COM
🎙️ PODCASTS 1[−]
23 SepSmashing Security podcast #486: Vibe-coded shops, and hackable Flock camerasA store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand's national parks. What could possibly have gone wrong? Meanwhile, a hacker collective backed a truck int…GRAHAMCLULEY.COM
📡 INFOSEC NEWS 18[−]
23 SepWeekly Threat Bulletin – September 23rd, 2026These are the top threats you should know about this week.F5.COM
23 SepCreator Campaigns, LinkedIn Strategy, and RIP to the Funnel with CrowdStrike, LinkedIn, and Sandra LiuGianna sits down with Vab Dwivedi, VP of Digital Experience at CrowdStrike, Sandra Liu, a cybersecurity creator with over 200,000 LinkedIn followers, and Eric Becker, Enterprise Account Director at LinkedIn. They covered the CrowdStrike and Sandra Liu creator campaign, why Linked…THECYBERWIRE.COM
23 SepRisky Bulletin: Team Cymru unmasks shady Chinese proxy networkA network of 10,000 AI servers is masking malicious Chinese AI activity, Ukrainian hackers leak Russia’s naval secrets, ShinyHunters hacks the FBI, and the EvilTokens phishing service is disrupted by tech companies.RISKY.BIZ
23 SepNew cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server ControlA flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allo…THEHACKERNEWS.COM
23 Sep545 Hackers Tested It First. Now XRanges for AI Scores Your Security AgentAutonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. So…THEHACKERNEWS.COM
23 SepAnthropic and OpenAI Models Still Attempt Restricted Actions in Safety TestsAnthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up from Opus 5," and "achieves the best scor…THEHACKERNEWS.COM
23 SepLinkedIn adds new tools to fight fake profiles and bogus work historiesLinkedIn is rolling out new verification tools that let members vouch for colleagues’ work experience and give companies more control over accounts that falsely claim to employ them.TECHCRUNCH.COM
23 SepFake Claude Max giveaway hides a Google account phishing trapA convincing offer of a free Claude Max subscription uses a fake browser window to steal Google login information.MALWAREBYTES.COM
23 SepOAuth Token Theft Through Microsoft's Front Door | HuntressA sideloaded package turns a Microsoft-signed binary into an OAuth token theft tool. No phishing domain, no spoofed UI, no browser. Here's how to detect it.HUNTRESS.COM
23 SepHundreds of Leaked GitHub App Keys Still AuthenticateGitGuardian finds 474 leaked GitHub App keys still authenticating, including keys with admin accessINFOSECURITY-MAGAZINE.COM
23 SepA Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as YouThe private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you. GitLab shows each user this addre…THEHACKERNEWS.COM
23 SepWhat’s next for cybersecurity, according to Index Ventures’ Shardul ShahAs concern over AI safety and rogue agents continue to make headlines, it’s no surprise that cybersecurity stocks are rising, or that investors are pouring massive amounts of capital into startups trying to build the next generation of security for an AI-native world. We’re&…TECHCRUNCH.COM
23 SepHow device code phishing gives scammers access to your accountA scammer asks you to enter a code to open a file or join a meeting. Approving it could sign them in to your account instead.MALWAREBYTES.COM
23 SepCyera has secured a $400 million Series G extension from Goldman Sachs.A-LIGN has acquired Australian cloud security assessment firm AssurePoint.THECYBERWIRE.COM
23 SepUK regulator to investigate Pornhub parent company for alleged age verification failingsIn May, Pornhub began using a new age assurance process to verify some users’ ages, according to an Ofcom press release. The new method relies on signals from Apple that suggest under 18s in the UK “may have completed Apple’s age checks,” the press release said.THERECORD.MEDIA
23 SepEDR Evasion Stack Helps Process Injection Slip Past DefensesA process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.DARKREADING.COM
23 SepPlaceholder domain used in dev docs now serves ClickFix attacksThe "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. [...]BLEEPINGCOMPUTER.COM