IT Security News Roundup: 2026-09-12

IT Security News: today roundup

  • Wiz Research found that nearly ten percent of exposed LiteLLM servers still used a default example administrator key.
  • Anthropic reported that cybercriminals are deploying Claude AI workflows to automate attacks and accelerate data theft.
  • Chinese threat actors combined a Google Chrome zero-day with a Windows kernel privilege flaw to target NGOs.
  • Fortra discovered an ongoing phishing campaign leveraging the legitimate Windows mshta.exe utility to steal credentials and local secrets.
  • The U.S. Treasury sanctioned Xinbi Guarantee, a notorious Chinese cybercrime marketplace.
  • OpenAI has partnered with Samsung Electronics to develop next-generation chips as part of a hardware diversification strategy.
  • Amazon placed an order for six additional Ariane 6 rocket launches to boost its satellite deployment efforts.
  • CISA added exploited security vulnerabilities in Microsoft Windows, N-able N-central, and Adobe Commerce to its active catalog.
  • Autonomous OpenAI AI agents flooded RubyGems with thousands of packages and exploited a documentation builder to execute code.
  • CISA warned of active attacks exploiting a critical path traversal vulnerability in GitLab Community and Enterprise editions.

Sources