IT Security News: today roundup
- CISA listed actively exploited Check Point, Arista, and F5 vulnerabilities.
- Attackers target Rust developers with malicious job interview invitations.
- Extortion group ShinyHunters hacked rival gang Clop's dark web site.
- US and China discussed mutual notifications for AI security threats.
- The suspension of CMMC Phase II impacts defense compliance strategies.
- TerminalFix campaign uses steganographic PNG images to deploy reverse tunnels.
- HealthTech apps require encryption and monitoring to safeguard patient data.
- PAYLOAD ransomware weaponizes Active Directory Group Policy Objects without binaries.
- Malicious Terraform providers delivered Go malware through the HashiCorp Registry.
- IonQ created a single-processor decoder to reduce quantum error-correction overhead.
- AWS uses managed policies to rapidly neutralize compromised IAM credentials.
- F5 patched a critical BIG-IP APM zero-day under active exploitation.
- Device code phishing tricks users into authorizing attacker account access.
- Image service Gyazo exposed metadata records for 23 million customers.
- Stolen Ribon app credentials exposed customer data across BigCommerce stores.
- F5 and CISA warned of active attacks against BIG-IP APM.
- Security experts warned that autonomous AI systems could pursue rogue agendas.
- The FBI is investigating a breach involving a third-party jobs portal.
- OWASP published its updated security risk list for Large Language Models.
- Leaked GitLab issue email addresses allow attackers to commit unauthorized code.
- Europol hosted the SIRIUS network meeting on European electronic evidence sharing.
- Revolut customers face targeted phishing campaigns following a major data breach.
- Index Ventures highlighted surging investments in AI-native cybersecurity startups.
- Attackers continue to target older, patchable flaws despite record CVE numbers.
- OpenAI expanded independent safety reviews into its AI model training process.
Sources in this roundup
| Blog |
|
2 article(s) |
| Cybersecurity Dive – Latest News |
|
2 article(s) |
| Malwarebytes |
|
2 article(s) |
| Security Affairs |
|
2 article(s) |
| The Hacker News |
|
2 article(s) |
| securityweek |
|
2 article(s) |
| www.infosecurity-magazine.com |
|
2 article(s) |
| www.theregister.com – Articles |
|
2 article(s) |
| CySecurity News – Latest Information Security and Hacking Incidents |
|
1 article(s) |
| Hackread – Cybersecurity News, Data Breaches, AI and More |
|
1 article(s) |
| News |
|
1 article(s) |
| SANS Internet Storm Center, InfoCON: green |
|
1 article(s) |
| Securelist |
|
1 article(s) |
| Security Archives – TechRepublic |
|
1 article(s) |
| Security Latest |
|
1 article(s) |
| Security News | TechCrunch |
|
1 article(s) |
| Unit 42 |
|
1 article(s) |
Most-mentioned keywords
| apm |
|
3 mention(s) |
| big |
|
3 mention(s) |
| day |
|
3 mention(s) |
| exploited |
|
3 mention(s) |
| zero |
|
3 mention(s) |
| app |
|
2 mention(s) |
| attacks |
|
2 mention(s) |
| breach |
|
2 mention(s) |
Sources
- U.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalog
- Rustaceans warned of job interviews with a malicious payload
- ShinyHunters hacks rival extortion gang and takes over its dark web site
- US and China Discuss Alerting Each Other to AI National Security Threats
- The CMMC Phase II Suspension: What It Means for Your Compliance and Zero Trust Strategy
- TerminalFix: PNG Steganography, (Mon, Sep 21st)
- Mobile App Security in HealthTech: Safeguarding Patient Data Against Cybersecurity Threats
- Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
- Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
- IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin
- From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials through Managed Policies
- F5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE Attacks
- How device code phishing gives scammers access to your account
- Experts Alarmed Over Gyazo’s Breach of 490 Million Metadata Records
- BigCommerce Merchants Hit in Supply Chain Breach After Ribon App Credentials Were Stolen
- Someone's attacking a critical 0-day RCE in F5 BIG-IP APM
- Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
- FBI probes cyberattack tied to third-party jobs portal
- OWASP LLM Top 10 2026: Every Move Points the Same Direction
- A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
- SIRIUS SPoC network meets as EU enters new era for electronic evidence
- Revolut Customers Targeted with New Wave of Phishing Attacks
- What’s next for cybersecurity, according to Index Ventures’ Shardul Shah
- More CVEs than ever. The same old ones keep getting exploited.
- OpenAI Expands Outside Safety Reviews Into Model Training
