IT Security News Roundup: 2026-09-23

IT Security News: today roundup

  1. CISA listed actively exploited Check Point, Arista, and F5 vulnerabilities.
  2. Attackers target Rust developers with malicious job interview invitations.
  3. Extortion group ShinyHunters hacked rival gang Clop's dark web site.
  4. US and China discussed mutual notifications for AI security threats.
  5. The suspension of CMMC Phase II impacts defense compliance strategies.
  6. TerminalFix campaign uses steganographic PNG images to deploy reverse tunnels.
  7. HealthTech apps require encryption and monitoring to safeguard patient data.
  8. PAYLOAD ransomware weaponizes Active Directory Group Policy Objects without binaries.
  9. Malicious Terraform providers delivered Go malware through the HashiCorp Registry.
  10. IonQ created a single-processor decoder to reduce quantum error-correction overhead.
  11. AWS uses managed policies to rapidly neutralize compromised IAM credentials.
  12. F5 patched a critical BIG-IP APM zero-day under active exploitation.
  13. Device code phishing tricks users into authorizing attacker account access.
  14. Image service Gyazo exposed metadata records for 23 million customers.
  15. Stolen Ribon app credentials exposed customer data across BigCommerce stores.
  16. F5 and CISA warned of active attacks against BIG-IP APM.
  17. Security experts warned that autonomous AI systems could pursue rogue agendas.
  18. The FBI is investigating a breach involving a third-party jobs portal.
  19. OWASP published its updated security risk list for Large Language Models.
  20. Leaked GitLab issue email addresses allow attackers to commit unauthorized code.
  21. Europol hosted the SIRIUS network meeting on European electronic evidence sharing.
  22. Revolut customers face targeted phishing campaigns following a major data breach.
  23. Index Ventures highlighted surging investments in AI-native cybersecurity startups.
  24. Attackers continue to target older, patchable flaws despite record CVE numbers.
  25. OpenAI expanded independent safety reviews into its AI model training process.
25
articles summarized
17
sources

Sources in this roundup

Blog
2 article(s)
Cybersecurity Dive – Latest News
2 article(s)
Malwarebytes
2 article(s)
Security Affairs
2 article(s)
The Hacker News
2 article(s)
securityweek
2 article(s)
www.infosecurity-magazine.com
2 article(s)
www.theregister.com – Articles
2 article(s)
CySecurity News – Latest Information Security and Hacking Incidents
1 article(s)
Hackread – Cybersecurity News, Data Breaches, AI and More
1 article(s)
News
1 article(s)
SANS Internet Storm Center, InfoCON: green
1 article(s)
Securelist
1 article(s)
Security Archives – TechRepublic
1 article(s)
Security Latest
1 article(s)
Security News | TechCrunch
1 article(s)
Unit 42
1 article(s)

Most-mentioned keywords

apm
3 mention(s)
big
3 mention(s)
day
3 mention(s)
exploited
3 mention(s)
zero
3 mention(s)
app
2 mention(s)
attacks
2 mention(s)
breach
2 mention(s)

Sources

  1. U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog
  2. Rustaceans warned of job interviews with a malicious payload
  3. ShinyHunters hacks rival extortion gang and takes over its dark web site
  4. US and China Discuss Alerting Each Other to AI National Security Threats
  5. The CMMC Phase II Suspension: What It Means for Your Compliance and Zero Trust Strategy
  6. TerminalFix: PNG Steganography, (Mon, Sep 21st)
  7. Mobile App Security in HealthTech: Safeguarding Patient Data Against Cybersecurity Threats
  8. Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
  9. Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
  10. IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin
  11. From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
  12. F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
  13. How device code phishing gives scammers access to your account
  14. Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
  15. BigCommerce Merchants Hit in Supply Chain Breach After Ribon App Credentials Were Stolen
  16. Someone's attacking a critical 0-day RCE in F5 BIG-IP APM
  17. Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
  18. FBI probes cyberattack tied to third-party jobs portal
  19. OWASP LLM Top 10 2026: Every Move Points the Same Direction
  20. A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
  21. SIRIUS SPoC network meets as EU enters new era for electronic evidence
  22. Revolut Customers Targeted with New Wave of Phishing Attacks
  23. What’s next for cybersecurity, according to Index Ventures’ Shardul Shah
  24. More CVEs than ever. The same old ones keep getting exploited.
  25. OpenAI Expands Outside Safety Reviews Into Model Training