IT Security News Roundup: 2026-09-18

IT Security News: today roundup

  1. Europol assisted in dismantling a European horse trafficking network.
  2. Bruce Schneier discussed squid egg sacs in his weekly forum.
  3. CISA and NIST published final cloud identity token security guidance.
  4. Attackers hijacked an AI coding assistant to compromise internal repositories.
  5. Working exploit code was released for four Linux kernel vulnerabilities.
  6. Attackers hijacked HBO Max’s Reddit account to push malware.
  7. Apple introduced new website approvals and expanded parental security controls.
  8. Check Point uncovered scammers impersonating airline support on social media.
  9. Microsoft issued an update fixing broken Windows Remote Desktop features.
  10. Hackers Online Club published cybersecurity interview questions for 2026.
  11. A supply chain attack backdoored 1,500 WordPress websites.
  12. Wordfence discovered a critical remote code execution flaw in libheif.
  13. Microsoft warned of social engineering attacks targeting enterprise financial systems.
  14. Two Robinhood engineers face federal charges for crypto insider trading.
  15. Major security vendors joined SE Labs’ new UK testing program.
  16. A Helpfeel server flaw exposed 23 million Gyazo user records.
  17. The N0va phishkit targets Western businesses by abusing authentication flows.
  18. US authorities boarded hacked oil tankers suffering navigation system interference.
  19. Dataminr integrated its AI threat detection into Crisis24's platform.
  20. WordPress patched a flaw enabling unauthorized theme installations via links.
  21. SE Labs launched a six-month cybersecurity vendor evaluation testing program.
  22. Spanish regulators reviewed data protection models following AI-assisted attacks.
  23. Attackers are actively exploiting a zero-day flaw in Cisco gateways.
  24. Thales advocated expanding cloud sovereignty to include cryptographic key control.
  25. A Google analyst secretly infiltrated the TeamPCP supply-chain hacking group.
25
articles summarized
14
sources

Sources in this roundup

CyberMaterial
6 article(s)
The Hacker News
4 article(s)
Security Archives – TechRepublic
2 article(s)
eSecurity Planet
2 article(s)
www.infosecurity-magazine.com
2 article(s)
Blog – Wordfence
1 article(s)
Check Point Blog
1 article(s)
Hackers Online Club
1 article(s)
Schneier on Security
1 article(s)
Security Affairs
1 article(s)
Security Latest
1 article(s)
Security News | TechCrunch
1 article(s)
Thales CPL Blog Feed
1 article(s)
www.theregister.com – Articles
1 article(s)

Most-mentioned keywords

cloud
3 mention(s)
cyber
3 mention(s)
chain
2 mention(s)
changes
2 mention(s)
coast
2 mention(s)
data
2 mention(s)
execution
2 mention(s)
fraud
2 mention(s)

Sources

  1. Cyber Briefing: 2026.09.16
  2. Friday Squid Blogging: On Squid Egg Sacs
  3. CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
  4. Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
  5. Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
  6. HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware
  7. Apple Adds New Parental Controls to iPhone, iPad and Mac: Here’s What Changes
  8. Scammers Are Watching Airline Complaints and Posing as Customer Support
  9. Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V
  10. Top 30 Cybersecurity Interview Questions And Answers For 2026
  11. Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
  12. Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
  13. Microsoft warns of cloud storage and financial fraud campaign
  14. Robinhood engineers charged in $50K crypto fraud
  15. Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
  16. Gyazo Data Breach Exposes 23 Million User Records
  17. N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
  18. FBI, Coast Guard boarded hacked oil tankers heading toward US coast
  19. Dataminr, Crisis24 integrate AI threat detection
  20. New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
  21. SE Labs Launches PIVOT Testing Program
  22. Spain gets its first taste of AI-aided cyber attack
  23. Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
  24. UK Cloud Control: Why Sovereignty Has to Move Beyond Data Location
  25. An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang