IT Security News Roundup: 2026-09-17

IT Security News: today roundup

  1. CrowdStrike highlights training strategies to build resilient cybersecurity workforces.
  2. AWS launched open-weight AI models on Bedrock in Europe.
  3. A popular Twitch extension exposed account tokens for 30,000 users.
  4. Automated attackers scanned nearly two million Android apps for secrets.
  5. Experts urge security teams to test complete attack chains.
  6. Wordfence found an execution flaw in the Tutor LMS plugin.
  7. Italian security startup Exein achieved unicorn status after funding.
  8. Scanners are targeting exposed Vite servers to steal cloud credentials.
  9. Researchers demonstrated a method to eavesdrop on wireless headphones remotely.
  10. Sysdig observed an attacker reach SSH access in eight seconds.
  11. Attackers hijacked HBO Max's Reddit account to post malware ads.
  12. Cyberattacks on two oil tankers prompted federal boarding operations.
  13. Reports reveal Flock camera networks track human movement without oversight.
  14. Bruce Schneier criticized the expansion of post-9/11 mass surveillance programs.
  15. Wordfence released its weekly roundup of new WordPress security bugs.
  16. Cisco Talos advises organizations to prioritize basic cybersecurity practices.
  17. Microsoft offered guidance on foundational controls to mitigate threat risks.
  18. Chinese group Salt Typhoon targeted Latin American organizations with malware.
  19. Hong Kong's monetary authority rated bank quantum readiness at 2.3.
  20. Federal agents boarded the VL Prosperity following suspected onboard hacking.
  21. Benchmarks show Microsoft Defender effectively blocks email security threats.
  22. JFrog revealed a Parallels flaw giving Mac users root privileges.
  23. U.S. authorities are investigating cyber threats targeting maritime port traffic.
  24. Huntress detailed how Settra ransomware uses remote tools for persistence.
  25. Joint federal forces boarded a Gulf tanker following network intrusion.
25
articles summarized
17
sources

Sources in this roundup

The Hacker News
3 article(s)
Blog – Wordfence
2 article(s)
CySecurity News – Latest Information Security and Hacking Incidents
2 article(s)
Malwarebytes
2 article(s)
Microsoft Security Blog
2 article(s)
eSecurity Planet
2 article(s)
www.theregister.com – Articles
2 article(s)
AWS Security Blog
1 article(s)
Blog
1 article(s)
Cisco Talos Blog
1 article(s)
Cybersecurity Dive – Latest News
1 article(s)
IT SECURITY GURU
1 article(s)
Schneier on Security
1 article(s)
Security Affairs
1 article(s)
Security News | TechCrunch
1 article(s)
Thales CPL Blog Feed
1 article(s)
securityweek
1 article(s)

Most-mentioned keywords

attack
3 mention(s)
coast
3 mention(s)
cyberattacks
3 mention(s)
fbi
3 mention(s)
guard
3 mention(s)
security
3 mention(s)
vulnerability
3 mention(s)
best
2 mention(s)

Sources

  1. CrowdStrike SafeMind: When the Best Offense Builds the Best Defense
  2. Run open weight models on Amazon Bedrock in AWS European Sovereign Cloud
  3. Researchers Find OAuth Token Exposure in Twitch Extension Used by 30K
  4. 1.8M Android APKs Scanned for Hardcoded Secrets in Automated Attack
  5. Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
  6. 100,000 WordPress Sites Exposed to Remote Code Execution via PHP Object Injection Vulnerability Found by Wordfence Argus in Tutor LMS
  7. New Italian unicorn Exein rides the physical AI wave
  8. Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
  9. Researchers find way to listen in on headphones from afar
  10. Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
  11. HBO Max’s verified Reddit account hijacked to spread malware
  12. Cyberattacks on Oil Tankers Put Maritime Critical Infrastructure at Risk
  13. Flock cameras are tracking people as well as cars
  14. 25 Years of Mass Surveillance Is Enough
  15. Wordfence Intelligence Weekly WordPress Vulnerability Report (September 7, 2026 to September 13, 2026)
  16. Should you care about an “AI slowdown?”
  17. From guidance to action: Security fundamentals that materially reduce risk
  18. China's Salt Typhoon backdoors Latin American orgs with new snooping malware
  19. HKMA’s Quantum Preparedness Index: What Hong Kong Banks Should Do Next
  20. Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
  21. Improving email security outcomes with real-world Microsoft Defender insights
  22. Parallels Desktop Vulnerability Gives Any Local Mac User Full Root Access, Intel Mac Users Left Without a Clear Fix
  23. FBI, Coast Guard probe suspected cyberattacks on ships entering US waters
  24. New Settra Ransomware Strain Deploys MeshAgent RMM for Persistence
  25. Cyberattack on Tanker Prompts Coast Guard-FBI Security Boarding