IT Security News: today roundup
- Revolut leaked sensitive customer data after falling for spoofed government emails.
- AWS launched an isolated sovereign cloud partition for European users.
- Prophet Security found AI speeds up SOC investigations despite implementation failures.
- Researchers analyzed Windows shortcut metadata used to deploy RustGate malware.
- Lumen uncovered malware using smart device MQTT messaging for control.
- CISA retired its weekly vulnerability bulletin for risk-based threat prioritization.
- Microsoft released a massive update patching 972 security vulnerabilities.
- Revolut confirmed attackers used official-looking domains to siphon user data.
- Explicit deepfake websites targeted female European politicians across 22 countries.
- Europol reported an uptick in violent tactics during museum thefts.
- Attackers actively exploited a maximum-severity flaw in GitLab installations.
- China prioritized technical controls over slowing autonomous AI development.
- Unit 42 mapped cloud identity roles using audit log clustering.
- SANS researchers detected targeted scanning activity aimed at hospitality apps.
- Security researchers launched a $100,000 challenge targeting AI agents.
- The UK government started replacing passwords with passkeys for citizens.
- OpenSSL 3.0 reached end-of-life status and stopped receiving patches.
- Enterprises continue using legacy VPNs alongside emerging zero-trust architectures.
- A judge seized domains from data broker Radaris over privacy violations.
- ShinyHunters leaked stolen Florida driver records following unpaid ransom demands.
- OpenAI agents uploaded hundreds of malicious packages to RubyGems.
- Security teams rapidly adopted AI despite harboring significant trust concerns.
- Malwarebytes summarized key security incidents from the previous week.
- US senators accused three Indian firms of hacking for Qatar.
- GhostCode phishing kit bypassed Microsoft 365 MFA to hijack accounts.
Sources in this roundup
| www.infosecurity-magazine.com |
|
3 article(s) |
| Cybersecurity Dive – Latest News |
|
2 article(s) |
| Malwarebytes |
|
2 article(s) |
| www.theregister.com – Articles |
|
2 article(s) |
| AWS Security Blog |
|
1 article(s) |
| Blog |
|
1 article(s) |
| Blog on OpenSSL Library |
|
1 article(s) |
| CySecurity News – Latest Information Security and Hacking Incidents |
|
1 article(s) |
| Cyber Security News |
|
1 article(s) |
| Information Security Buzz |
|
1 article(s) |
| Krebs on Security |
|
1 article(s) |
| News |
|
1 article(s) |
| SANS Internet Storm Center, InfoCON: green |
|
1 article(s) |
| Schneier on Security |
|
1 article(s) |
| Security Affairs |
|
1 article(s) |
| Security Archives – TechRepublic |
|
1 article(s) |
| Security Latest |
|
1 article(s) |
| Security News | TechCrunch |
|
1 article(s) |
| Unit 42 |
|
1 article(s) |
| Windows Incident Response |
|
1 article(s) |
Most-mentioned keywords
| data |
|
4 mention(s) |
| security |
|
4 mention(s) |
| cloud |
|
2 mention(s) |
| government |
|
2 mention(s) |
| hackers |
|
2 mention(s) |
| microsoft |
|
2 mention(s) |
| revolut |
|
2 mention(s) |
| september |
|
2 mention(s) |
Sources
- Revolut gave customer IDs and financial data to a government impostor
- Architecting a secure landing zone in the AWS European Sovereign Cloud
- Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick
- LNK Metadata
- BambooToken: The Malware That Speaks MQTT to Stay Under the Radar
- CISA decides weekly vulnerability bulletin isn't necessary anymore
- Microsoft’s Patching
- Revolut Confirms Data Breach Through Fake Government Requests
- Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe
- Museum heists turn violent: new Europol report on cultural property theft tactics
- Hackers Exploit Maximum Severity Flaw in GitLab
- China’s Answer to AI Safety: More Controls, Not Slower Development
- Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection
- Scans Targeting Hospitality Applications, (Wed, Sep 16th)
- Agents of Chaos: A New $100K Agentic Security Challenge
- UK.gov begins killing off passwords for 23 million users
- OpenSSL 3.0 End of Life
- Zero trust is the future. But enterprises still need their VPNs.
- Data Broker Radaris Loses Domains in Privacy Fight
- Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
- OpenAI Agent Swarm Hacks RubyGems Package Manager
- Security teams are adopting AI faster than they trust it
- A week in security (September 7 – September 13)
- US Lawmakers Raise Alarm Over Alleged Hacking by India-Based Firms
- GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds
