Critical SolarWinds flaws and compromised MemTensor packages create opportunities for remote code execution and credential theft, while an AI-agent breach…
Category: CyberMaterial
Data Quality Overtakes Skills as Top Threat Hunting Challenge
Data quality has emerged as the primary obstacle facing threat hunting teams, overtaking skills shortages for the first time in five years of tracking by…
NIST Updates OT Security Guide; CISA/FBI ICS Advice
The National Institute of Standards and Technology has opened Revision 4 of its operational technology security guide for public comment, with the…
SolarWinds Patches Critical RCE Flaws
SolarWinds has issued security patches addressing two critical remote code execution vulnerabilities in its Observability Self-Hosted platform.
OpenAI Agent Hacked Australia Health Service
A security breach involving an OpenAI agent has compromised an Australian health service, triggering a formal government investigation into whether the…
Revolut launches facial recognition checkout system
Financial technology company Revolut has launched a pilot program for facial recognition payments at retail locations, starting with a three-day trial at…
MemTensor npm/PyPI packages compromised
The popular MemOS framework for large language models suffered a supply chain attack early Wednesday when attackers published malicious versions…
Cyber Briefing: 2026.09.23
AI-enabled phishing, browser vulnerabilities, compromised third-party credentials, and exposed customer data remain key areas of concern, with EvilTokens…
UniGetUI simplifies Windows PC migration
A detailed migration guide from ZDNet demonstrates how UniGetUI significantly reduces the time and effort required to set up a new Windows 11 PC.
EU KIDS Act Sets New Social Media Age Restrictions
The European Commission has proposed sweeping age restrictions on social media access for children across the EU through the KIDS Act, adopted September…
Microsoft Disrupts AI-Powered Phishing Platform EvilTokens
Microsoft has successfully disrupted EvilTokens, a sophisticated phishing platform that integrated artificial intelligence across its entire attack…
Okta positions identity as control plane for AI agents
Okta has announced an expanded platform for managing AI agent identities, positioning itself as a leader in securing what CEO Todd McKinnon calls “the…
Master of Malt confirms customer data breach
Master of Malt has confirmed a customer data breach affecting personal information after attackers compromised a third-party application integrated with…
Cyber Briefing: 2026.09.22
Exploitation of a ZyXEL switch vulnerability, a malicious NPM supply-chain package, unauthorized access to Belgian sports federation data, and legal…
Chinese Hackers Exploit ZyXEL Switch Vulnerability
A Chinese threat actor has successfully exploited a vulnerability in ZyXEL network switches, compromising nearly 1,000 devices and exfiltrating sensitive…
Cyber Briefing: 2026.09.21
The incidents include malware hidden inside PNG files, more than $1.6 billion in reported losses from police-impersonation scams, a supply-chain…
Malicious B-tree NPM Package Hides Malware
A malicious NPM package masquerading as a popular JavaScript library has been downloaded millions of times, representing a significant supply chain…
Belgian Sports Federations Hit by Cyberattacks
Two Belgian sports federations are investigating separate cybersecurity incidents involving potential theft of member data.
Gartner: 55% of VMware users will explore alternatives by 20
Gartner forecasts that more than half of VMware customers will begin evaluating alternative hybrid cloud platforms by 2029, reflecting growing…
British Columbia sues OpenAI over Tumbler Ridge shooting
The government of British Columbia has sued OpenAI in San Francisco federal court, alleging the company failed to prevent a mass shooting that killed…
