IT Security News: today roundup CrowdStrike highlights training strategies to build resilient cybersecurity workforces. AWS launched open-weight AI models on Bedrock in Europe. A popular Twitch extension exposed account tokens for 30,000 users. Automated attackers scanned nearly two million Android…
Steam Windows 0-Day Vulnerability Allows Users to Silently Escalate to Full SYSTEM Privileges
A newly disclosed Windows zero-day affecting the Steam Client Service can reportedly let a standard local user obtain NT AUTHORITY\SYSTEM privileges…
CISA Wants Defenders to Deploy Fake Credentials and Systems to Catch Hackers
CISA has urged organizations to deploy fake credentials, systems, files, and data assets inside their environments to expose attackers after an initial…
OpenAI Models Searched for Leaked API Keys and Uploaded Files Without Permission
OpenAI has disclosed six cases in which AI models concealed errors, used an exposed API key, uploaded data to public services, and communicated through…
How Pentest Companies Adapt In The Era of AI
Every penetration testing firm is facing the same pressure right now. AI tools are faster, cheaper, and increasingly capable, and testers are using them…
FBI Takes Down NightmareStresser DDoS Service Used in Hundreds of Thousands of Attacks
The FBI has seized domains supporting NightmareStresser, disrupting one of the world’s longest-running DDoS-for-hire operations. The court-authorized…
New infosec products of the week: September 18, 2026
Here’s a look at the most interesting products from the past week, featuring releases from Akuity, Bitsight, Cohesity, Dataminr, Nozomi Networks, and…
BIND DNS Servers Hit by 14 Security Flaws Enabling Cache Poisoning and Remote Crashes
Internet Systems Consortium has released security updates for BIND 9 after identifying 14 vulnerabilities that could allow attackers to poison DNS caches,…
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files…
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked “hacktivist” persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a…
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
A critical vulnerability in Check Point’s Security Management and Log Servers could allow an attacker without login credentials to run code as root on…
ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed…
IT Security News Hourly Summary 2026-09-18 05h : 3 posts
3 posts published in the last hour 02:31USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech 02:02ISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100, (Fri, Sep 18th) 02:00IT Security News Hourly Summary 2026-09-18 04h : 3 posts
USA’s Venezuela takeover comes with bonus exposure to Chinese AI surveillance tech
Think tank points out that companies banned by Washington will help run the regime that Uncle Sam now controls
ISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100, (Fri, Sep 18th)
This post has no text preview — click the link below to read the original article. This article has been indexed from SANS Internet Storm Center, InfoCON: green Read the original article: ISC Stormcast For Friday, September 18th, 2026 https://isc.sans.edu/podcastdetail/10100,…
IT Security News Hourly Summary 2026-09-18 04h : 3 posts
3 posts published in the last hour 01:31Defining the Standard for AI Security 01:02Stop rewriting stable code: How Lightwell protects your bottom line and developer velocity 01:02OpenAI models steal credentials and lie, Microsoft writes AI rules it can’t enforce, Congress…
Defining the Standard for AI Security
Palo Alto Networks Named a Market Shaper in 2026 September Gartner® Emerging Market Quadrant for AI Application Security — Established Vendors. When we…
Stop rewriting stable code: How Lightwell protects your bottom line and developer velocity
How Lightwell breaks the forced-upgrade cycle to keep your systems protected and your developers focused on innovation.The Monday morning CISO…
OpenAI models steal credentials and lie, Microsoft writes AI rules it can’t enforce, Congress punts AI safety to 2027
OpenAI Models Self-Jailbreak & Leak Data, Microsoft’s “Humanist AI” Promise, Windows Patch Tuesday Fallout, and AI Laws Delayed Host David Shipley covers…
Revolut breach exposes widespread security weakness — trust
The Revolut breach highlights a vulnerability that experts say goes unnoticed in many enterprises: data release processes that conflate authentication…
OpenAI admits its models lie to cover their own mistakes
OpenAI launches a formal framework to disclose model misalignment, publishing six reports on models that lied, faked data, or bypassed rules. Most…
AI coding agents’ 0-click RCE flaw could hand attackers keys to the kingdom
Plugin4Shell attack affects all the major coding agents, researchers say
IT Security News Hourly Summary 2026-09-18 01h : 3 posts
3 posts published in the last hour 22:31Inside the Modern SOC: Defending the Cross-Environment Pivot 22:02Global public-private operation disrupts Sality botnet active for two decades 22:00IT Security News Hourly Summary 2026-09-18 00h : 7 posts
Inside the Modern SOC: Defending the Cross-Environment Pivot
Cross-environment attacks demand a new approach to security operations. Learn how Unit 42 Managed XSIAM helps SOC teams investigate complete attack paths.
Global public-private operation disrupts Sality botnet active for two decades
An international operation supported by Europol has disrupted the Sality peer-to-peer (P2P) botnet, a long-running criminal infrastructure used to…
