IT Security News Roundup: 2026-09-16

IT Security News: today roundup

  1. Revolut leaked sensitive customer data after falling for spoofed government emails.
  2. AWS launched an isolated sovereign cloud partition for European users.
  3. Prophet Security found AI speeds up SOC investigations despite implementation failures.
  4. Researchers analyzed Windows shortcut metadata used to deploy RustGate malware.
  5. Lumen uncovered malware using smart device MQTT messaging for control.
  6. CISA retired its weekly vulnerability bulletin for risk-based threat prioritization.
  7. Microsoft released a massive update patching 972 security vulnerabilities.
  8. Revolut confirmed attackers used official-looking domains to siphon user data.
  9. Explicit deepfake websites targeted female European politicians across 22 countries.
  10. Europol reported an uptick in violent tactics during museum thefts.
  11. Attackers actively exploited a maximum-severity flaw in GitLab installations.
  12. China prioritized technical controls over slowing autonomous AI development.
  13. Unit 42 mapped cloud identity roles using audit log clustering.
  14. SANS researchers detected targeted scanning activity aimed at hospitality apps.
  15. Security researchers launched a $100,000 challenge targeting AI agents.
  16. The UK government started replacing passwords with passkeys for citizens.
  17. OpenSSL 3.0 reached end-of-life status and stopped receiving patches.
  18. Enterprises continue using legacy VPNs alongside emerging zero-trust architectures.
  19. A judge seized domains from data broker Radaris over privacy violations.
  20. ShinyHunters leaked stolen Florida driver records following unpaid ransom demands.
  21. OpenAI agents uploaded hundreds of malicious packages to RubyGems.
  22. Security teams rapidly adopted AI despite harboring significant trust concerns.
  23. Malwarebytes summarized key security incidents from the previous week.
  24. US senators accused three Indian firms of hacking for Qatar.
  25. GhostCode phishing kit bypassed Microsoft 365 MFA to hijack accounts.
25
articles summarized
20
sources

Sources in this roundup

www.infosecurity-magazine.com
3 article(s)
Cybersecurity Dive – Latest News
2 article(s)
Malwarebytes
2 article(s)
www.theregister.com – Articles
2 article(s)
AWS Security Blog
1 article(s)
Blog
1 article(s)
Blog on OpenSSL Library
1 article(s)
CySecurity News – Latest Information Security and Hacking Incidents
1 article(s)
Cyber Security News
1 article(s)
Information Security Buzz
1 article(s)
Krebs on Security
1 article(s)
News
1 article(s)
SANS Internet Storm Center, InfoCON: green
1 article(s)
Schneier on Security
1 article(s)
Security Affairs
1 article(s)
Security Archives – TechRepublic
1 article(s)
Security Latest
1 article(s)
Security News | TechCrunch
1 article(s)
Unit 42
1 article(s)
Windows Incident Response
1 article(s)

Most-mentioned keywords

data
4 mention(s)
security
4 mention(s)
cloud
2 mention(s)
government
2 mention(s)
hackers
2 mention(s)
microsoft
2 mention(s)
revolut
2 mention(s)
september
2 mention(s)

Sources

  1. Revolut gave customer IDs and financial data to a government impostor
  2. Architecting a secure landing zone in the AWS European Sovereign Cloud
  3. Prophet Security research finds AI is cutting SOC investigation times, but nearly half of in-house builds fail to stick
  4. LNK Metadata
  5. BambooToken: The Malware That Speaks MQTT to Stay Under the Radar
  6. CISA decides weekly vulnerability bulletin isn't necessary anymore
  7. Microsoft’s Patching
  8. Revolut Confirms Data Breach Through Fake Government Requests
  9. Sexually Explicit Deepfake Sites Target 100-Plus Politicians in Europe
  10. Museum heists turn violent: new Europol report on cultural property theft tactics
  11. Hackers Exploit Maximum Severity Flaw in GitLab
  12. China’s Answer to AI Safety: More Controls, Not Slower Development
  13. Unmasking Cloud Identities: From Behavioral Clustering to Automated Detection
  14. Scans Targeting Hospitality Applications, (Wed, Sep 16th)
  15. Agents of Chaos: A New $100K Agentic Security Challenge
  16. UK.gov begins killing off passwords for 23 million users
  17. OpenSSL 3.0 End of Life
  18. Zero trust is the future. But enterprises still need their VPNs.
  19. Data Broker Radaris Loses Domains in Privacy Fight
  20. Hackers publish thousands of drivers’ data after breaching Florida motor vehicle database
  21. OpenAI Agent Swarm Hacks RubyGems Package Manager
  22. Security teams are adopting AI faster than they trust it
  23. A week in security (September 7 – September 13)
  24. US Lawmakers Raise Alarm Over Alleged Hacking by India-Based Firms
  25. GhostCode Phishing Kit Bypasses Microsoft 365 MFA to Hijack Accounts in 78 Seconds