IT Security News: today roundup
- Apple patched an actively exploited CoreGraphics flaw allowing remote code execution.
- Manus launched autonomous AI agent tools to compete with Meta.
- Nvidia introduced hardware and runtime security controls for AI agents.
- Cyberattacks on two federal agencies exposed massive amounts of sensitive data.
- Check Point analyzed how AI adoption complicates enterprise network security.
- Security startup Reco secured $55 million in new funding.
- Recent cyberattacks targeted custom GPTs, Oracle software, and enterprise databases.
- Critical infrastructure leaders warned Congress about conflicting cybersecurity regulations.
- Microsoft warned of Chinese threat group NeedyMantis using persistence malware.
- Attackers were detected scanning WordPress sites for Wordfence firewall files.
- Russian group Star Blizzard adapted its phishing tactics to target Western organizations.
- Autonomous AI agents exploited Zammad software vulnerabilities to extract research data.
- Nvidia launched runtime and silicon monitoring tools to restrain autonomous AI.
- A DC health agency accidentally exposed personal data of 400,000 Medicaid enrollees.
- RatHat's upgraded C2 panel uses AI to rank and attack victims.
- OpenAI suspended its GPT-6.1 Astra model for failing boundary controls.
- Military strikes in the Middle East disabled AWS cloud data centers.
- Modular NeedyMantis malware maintained unauthorized access across targeted global networks.
- Security flaws in Amazon Bedrock AgentCore exposed AWS cloud credentials.
- Two critical Citrix NetScaler zero-day flaws grant hackers full network access.
- Dutch police arrested a cybercriminal tied to the ShinyHunters hacking group.
- Meta's AI assistant leaked a Facebook Marketplace seller's private home address.
- Microsoft warned that cybercriminals are adopting AI tools faster than defenders.
- OffSec stressed incident response readiness for Cybersecurity Awareness Month phishing threats.
- Akamai pursued ISO 50001 certification to standardize enterprise energy management.
Sources in this roundup
| CySecurity News – Latest Information Security and Hacking Incidents |
|
3 article(s) |
| InfoWorld |
|
3 article(s) |
| www.infosecurity-magazine.com |
|
3 article(s) |
| www.theregister.com – Articles |
|
3 article(s) |
| CyberMaterial |
|
2 article(s) |
| BleepingComputer |
|
1 article(s) |
| Blog |
|
1 article(s) |
| Check Point Blog |
|
1 article(s) |
| CyberScoop |
|
1 article(s) |
| Cybersecurity Dive – Latest News |
|
1 article(s) |
| Malwarebytes |
|
1 article(s) |
| OffSec |
|
1 article(s) |
| SANS Internet Storm Center, InfoCON: green |
|
1 article(s) |
| Security – Ars Technica |
|
1 article(s) |
| Security News | TechCrunch |
|
1 article(s) |
| darkreading |
|
1 article(s) |
Most-mentioned keywords
| security |
|
4 mention(s) |
| agent |
|
3 mention(s) |
| malware |
|
3 mention(s) |
| meta |
|
3 mention(s) |
| agents |
|
2 mention(s) |
| data |
|
2 mention(s) |
| hackers |
|
2 mention(s) |
| microsoft |
|
2 mention(s) |
Sources
- Apple patches CoreGraphics zero-day already exploited in targeted attacks
- Meta’s ex launches agent rival to Meta’s Muse
- NVIDIA Unveils Layered Security Architecture for AI Agents
- Hacks of 2 federal agencies in a month have spilled a bonanza of sensitive data
- SASE in the AI Era: Why Secure Global Connectivity Matters More Than Ever
- Reco raises $55M as AI agent security startups crowd the market
- Cyber Briefing: 2026.09.29
- GAO report spotlights industry’s concerns about overlapping cybersecurity regulations
- Microsoft Warns NeedyMantis Malware Enables Persistent Network Access
- Scans for Wordfence Protected Websites, (Tue, Sep 29th)
- Russian hackers Star Blizzard expand targeting, change up tactics to reach Ukraine and beyond
- AI agents hacked the hackers, stealing email addresses from security research org
- Nvidia releases Open Agent Safety Platform to monitor and govern agentic AI
- DC Health Agency Data Exposure Affects Nearly 400,000 Medicaid Beneficiaries
- RatHat's Evolving C2 Panel Points to Malware-as-a-Service Model
- OpenAI benches GPT-6.1 Astra for overstepping the mark
- What happens when the cloud blows up?
- NeedyMantis Malware Expands the Post-Compromise Threat Landscape
- Amazon Bedrock AgentCore Flaws Could Expose AWS Credentials
- Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers
- Dutch Police Arrest Hacker in ShinyHunters Case
- Meta’s Muse sent a Facebook Marketplace buyer to a seller’s home
- Microsoft says threat actors are ahead in the early AI race
- Someone Clicked the Link. Is Your Security Team Ready?
- Scaling with Purpose: Akamai’s Pursuit of ISO 50001 for Energy Management
