IT Security News Roundup: 2026-09-20

IT Security News: today roundup

  1. Attackers actively exploit a critical RCE flaw in Orkes Conductor.
  2. Researchers used Claude Opus 5 to infiltrate OpenAI's internal repositories.
  3. Malware analysis tracked a ClickFix campaign delivering MeshAgent tools.
  4. CISA added actively exploited Linux kernel vulnerabilities to its catalog.
  5. SolarWinds patched an unauthenticated RCE flaw in Access Rights Manager.
  6. Hackers increasingly utilize machine learning models to automate sophisticated cyberattacks.
  7. A Gyazo upload server flaw exposed millions of user records.
  8. An AI intelligence hallucination almost sparked a US-China military conflict.
  9. Security Affairs released a roundup detailing emerging malware and extensions.
  10. ZephrSec published a guide covering red team operational planning strategies.
  11. Oasis Security highlighted agentic access management to secure enterprise AI.
  12. Impersonation tactics enabled a data breach impacting fintech firm Revolut.
  13. A Microsoft executive labeled AI model training massive labor theft.
  14. Threat group JADEPUFFER began targeting enterprise AI models with ransomware.
  15. Security experts scrutinize hyperbolic claims surrounding fully autonomous AI attacks.
  16. Pierluigi Paganini published weekly security news on Gemini sandbox breakouts.
16
articles summarized
8
sources

Sources in this roundup

CySecurity News – Latest Information Security and Hacking Incidents
4 article(s)
Security Affairs
4 article(s)
Cyber Security News
3 article(s)
Cybersecurity News: Threats, Vulnerabilities & Privacy Updates – gHacks
1 article(s)
Hackers Online Club
1 article(s)
Help Net Security
1 article(s)
Malware-Traffic-Analysis.net – Blog Entries
1 article(s)
ZephrSec – Adventures In Information Security
1 article(s)

Most-mentioned keywords

exploited
3 mention(s)
affairs
2 mention(s)
newsletter
2 mention(s)
round
2 mention(s)
security
2 mention(s)
unauthenticated
2 mention(s)
access
1 mention(s)
adds
1 mention(s)

Sources

  1. Critical Orkes Conductor Flaw Exploited for Unauthenticated Remote Code Execution
  2. An AI Helped Researchers Break Into OpenAI
  3. 2026-09-15: SmartApeSG ClickFix to unidentified RAT to MeshAgent
  4. U.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalog
  5. Unauthenticated RCE Bug Fixed in SolarWinds Access Rights Manager
  6. AI-Powered Cyberattacks – How Hackers Use Machine Learning in 2026
  7. Gyazo Server Vulnerability Targeted to Steal Millions of User Records
  8. AI Hallucinations Nearly Triggered a US-China Military Confrontation
  9. SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115
  10. Below the Waterline Stage 1 – Red Team Planning
  11. Business Survival in the Age of AI
  12. Week in review: Cisco patches exploited email gateway 0-day, Revolut breach
  13. Court Filing Shows Microsoft Exec Called AI Training the "Largest Labor Theft in Human History"
  14. When Ransomware Targets AI Models: Defending the AI/ML Recovery Chain
  15. Autonomous AI Attacks: The Hugging Face Reality Check
  16. Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION