IT Security News: today roundup
- Europol assisted in dismantling a European horse trafficking network.
- Bruce Schneier discussed squid egg sacs in his weekly forum.
- CISA and NIST published final cloud identity token security guidance.
- Attackers hijacked an AI coding assistant to compromise internal repositories.
- Working exploit code was released for four Linux kernel vulnerabilities.
- Attackers hijacked HBO Max’s Reddit account to push malware.
- Apple introduced new website approvals and expanded parental security controls.
- Check Point uncovered scammers impersonating airline support on social media.
- Microsoft issued an update fixing broken Windows Remote Desktop features.
- Hackers Online Club published cybersecurity interview questions for 2026.
- A supply chain attack backdoored 1,500 WordPress websites.
- Wordfence discovered a critical remote code execution flaw in libheif.
- Microsoft warned of social engineering attacks targeting enterprise financial systems.
- Two Robinhood engineers face federal charges for crypto insider trading.
- Major security vendors joined SE Labs’ new UK testing program.
- A Helpfeel server flaw exposed 23 million Gyazo user records.
- The N0va phishkit targets Western businesses by abusing authentication flows.
- US authorities boarded hacked oil tankers suffering navigation system interference.
- Dataminr integrated its AI threat detection into Crisis24's platform.
- WordPress patched a flaw enabling unauthorized theme installations via links.
- SE Labs launched a six-month cybersecurity vendor evaluation testing program.
- Spanish regulators reviewed data protection models following AI-assisted attacks.
- Attackers are actively exploiting a zero-day flaw in Cisco gateways.
- Thales advocated expanding cloud sovereignty to include cryptographic key control.
- A Google analyst secretly infiltrated the TeamPCP supply-chain hacking group.
Sources in this roundup
| CyberMaterial |
|
6 article(s) |
| The Hacker News |
|
4 article(s) |
| Security Archives – TechRepublic |
|
2 article(s) |
| eSecurity Planet |
|
2 article(s) |
| www.infosecurity-magazine.com |
|
2 article(s) |
| Blog – Wordfence |
|
1 article(s) |
| Check Point Blog |
|
1 article(s) |
| Hackers Online Club |
|
1 article(s) |
| Schneier on Security |
|
1 article(s) |
| Security Affairs |
|
1 article(s) |
| Security Latest |
|
1 article(s) |
| Security News | TechCrunch |
|
1 article(s) |
| Thales CPL Blog Feed |
|
1 article(s) |
| www.theregister.com – Articles |
|
1 article(s) |
Most-mentioned keywords
| cloud |
|
3 mention(s) |
| cyber |
|
3 mention(s) |
| chain |
|
2 mention(s) |
| changes |
|
2 mention(s) |
| coast |
|
2 mention(s) |
| data |
|
2 mention(s) |
| execution |
|
2 mention(s) |
| fraud |
|
2 mention(s) |
Sources
- Cyber Briefing: 2026.09.16
- Friday Squid Blogging: On Squid Egg Sacs
- CISA and NIST Issue Guidance to Protect Cloud Identity Tokens
- Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
- Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
- HBO Max Reddit Account Hacked: 108 Malicious Ads Push ClickFix Malware
- Apple Adds New Parental Controls to iPhone, iPad and Mac: Here’s What Changes
- Scammers Are Watching Airline Complaints and Posing as Customer Support
- Microsoft Issues Out-of-Band Windows Update After September Patch Breaks Remote Desktop, Hyper-V
- Top 30 Cybersecurity Interview Questions And Answers For 2026
- Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
- Wordfence Argus Discovers Critical Vulnerability in libheif, the Library That Opens iPhone Photos on Your Server
- Microsoft warns of cloud storage and financial fraud campaign
- Robinhood engineers charged in $50K crypto fraud
- Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
- Gyazo Data Breach Exposes 23 Million User Records
- N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
- FBI, Coast Guard boarded hacked oil tankers heading toward US coast
- Dataminr, Crisis24 integrate AI threat detection
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
- SE Labs Launches PIVOT Testing Program
- Spain gets its first taste of AI-aided cyber attack
- Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
- UK Cloud Control: Why Sovereignty Has to Move Beyond Data Location
- An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
