IT Security News Roundup: 2026-09-14

IT Security News: today roundup

  • ENISA warned that frontier AI is drastically accelerating cyberattacks, urging European defenders to respond at machine speed.
  • Microsoft warned that passkey-themed phishing attacks are hijacking Microsoft 365 accounts to steal enterprise cloud data.
  • A Telegram Desktop vulnerability allowed malicious JavaScript embedded in HTML chat exports to steal exported messages.
  • A cybersecurity tool uses WebRTC to tunnel network traffic through video-calling platforms to bypass domain whitelists.
  • An attacker breached Thai broadband provider 3BB, using the legitimate MeshCentral management tool to maintain remote root access.
  • Security expert Bruce Schneier published his schedule of upcoming public speaking engagements across several conferences and institutions.
  • China rejected Anthropic CEO Dario Amodei's AI slowdown proposal, labeling it an effort by the US to contain its tech sector.
  • Researchers demonstrated a new hardware attack requiring physical server access to breach DDR5 RAM and expose encrypted memory.
  • Hackers are actively exploiting an unauthenticated file upload vulnerability in a WooCommerce plugin to gain remote code execution.
  • Apple patched a record 261 vulnerabilities across all of its operating systems in its latest round of software updates.

Sources