IT Security News: today roundup
- CrowdStrike highlights training strategies to build resilient cybersecurity workforces.
- AWS launched open-weight AI models on Bedrock in Europe.
- A popular Twitch extension exposed account tokens for 30,000 users.
- Automated attackers scanned nearly two million Android apps for secrets.
- Experts urge security teams to test complete attack chains.
- Wordfence found an execution flaw in the Tutor LMS plugin.
- Italian security startup Exein achieved unicorn status after funding.
- Scanners are targeting exposed Vite servers to steal cloud credentials.
- Researchers demonstrated a method to eavesdrop on wireless headphones remotely.
- Sysdig observed an attacker reach SSH access in eight seconds.
- Attackers hijacked HBO Max's Reddit account to post malware ads.
- Cyberattacks on two oil tankers prompted federal boarding operations.
- Reports reveal Flock camera networks track human movement without oversight.
- Bruce Schneier criticized the expansion of post-9/11 mass surveillance programs.
- Wordfence released its weekly roundup of new WordPress security bugs.
- Cisco Talos advises organizations to prioritize basic cybersecurity practices.
- Microsoft offered guidance on foundational controls to mitigate threat risks.
- Chinese group Salt Typhoon targeted Latin American organizations with malware.
- Hong Kong's monetary authority rated bank quantum readiness at 2.3.
- Federal agents boarded the VL Prosperity following suspected onboard hacking.
- Benchmarks show Microsoft Defender effectively blocks email security threats.
- JFrog revealed a Parallels flaw giving Mac users root privileges.
- U.S. authorities are investigating cyber threats targeting maritime port traffic.
- Huntress detailed how Settra ransomware uses remote tools for persistence.
- Joint federal forces boarded a Gulf tanker following network intrusion.
Sources in this roundup
| The Hacker News |
|
3 article(s) |
| Blog – Wordfence |
|
2 article(s) |
| CySecurity News – Latest Information Security and Hacking Incidents |
|
2 article(s) |
| Malwarebytes |
|
2 article(s) |
| Microsoft Security Blog |
|
2 article(s) |
| eSecurity Planet |
|
2 article(s) |
| www.theregister.com – Articles |
|
2 article(s) |
| AWS Security Blog |
|
1 article(s) |
| Blog |
|
1 article(s) |
| Cisco Talos Blog |
|
1 article(s) |
| Cybersecurity Dive – Latest News |
|
1 article(s) |
| IT SECURITY GURU |
|
1 article(s) |
| Schneier on Security |
|
1 article(s) |
| Security Affairs |
|
1 article(s) |
| Security News | TechCrunch |
|
1 article(s) |
| Thales CPL Blog Feed |
|
1 article(s) |
| securityweek |
|
1 article(s) |
Most-mentioned keywords
| attack |
|
3 mention(s) |
| coast |
|
3 mention(s) |
| cyberattacks |
|
3 mention(s) |
| fbi |
|
3 mention(s) |
| guard |
|
3 mention(s) |
| security |
|
3 mention(s) |
| vulnerability |
|
3 mention(s) |
| best |
|
2 mention(s) |
Sources
- CrowdStrike SafeMind: When the Best Offense Builds the Best Defense
- Run open weight models on Amazon Bedrock in AWS European Sovereign Cloud
- Researchers Find OAuth Token Exposure in Twitch Extension Used by 30K
- 1.8M Android APKs Scanned for Hardcoded Secrets in Automated Attack
- Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
- 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
- New Italian unicorn Exein rides the physical AI wave
- Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
- Researchers find way to listen in on headphones from afar
- Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
- HBO Max’s verified Reddit account hijacked to spread malware
- Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk
- Flock cameras are tracking people as well as cars
- 25 Years of Mass Surveillance Is Enough
- Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)
- Should you care about an “AI slowdown?”
- From guidance to action: Security fundamentals that materially reduce risk
- China's Salt Typhoon backdoors Latin American orgs with new snooping malware
- HKMA’s Quantum Preparedness Index: What Hong Kong Banks Should Do Next
- Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
- Improving email security outcomes with real-world Microsoft Defender insights
- Parallels Desktop Vulnerability Gives Any Local Mac User Full Root Access, Intel Mac Users Left Without a Clear Fix
- FBI, Coast Guard probe suspected cyberattacks on ships entering US waters
- New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence
- Cyberattack on Tanker Prompts Coast Guard-FBI Security Boarding
