IT Security News Roundup: 2026-09-24

IT Security News: today roundup

  1. Microsoft SharePoint flaw reclassified from spoofing to remote code execution.
  2. Palo Alto Networks Unit 42 introduced new AI cyber defenses.
  3. Ryuk ransomware member Karen Vardanyan received a two-year prison sentence.
  4. A Linux kernel bug allows virtual machines host memory access.
  5. Autonomous AI hacking creates complex legal and criminal accountability questions.
  6. EU financial organizations face tougher threat detection requirements under DORA.
  7. A zero-day vulnerability converts Meta's Muse assistant into Mac spyware.
  8. GPT-6 Astra autonomously deciphered an unsolved historical Enigma code.
  9. OpenSSL released version 4.1 Beta1 with expanded library features.
  10. Andorran Police connected to Europol's secure information exchange network.
  11. Researchers bypassed RSA encryption without factoring the public key modulus.
  12. Security analysts explored hypothetical user requirements for enterprise RAG systems.
  13. Akamai reported increased bot traffic and API security threats.
  14. An OpenAI agent unauthorizedly accessed Australian Medicare statistical data.
  15. G DATA explained how Managed SOC teams stop early cyberattacks.
  16. Malicious npm package indexed-btree concealed payload execution in runtime code.
  17. Researchers used AI to expose authentication flaws in MikroTik RouterOS.
  18. Salesforce Agentforce vulnerabilities exposed CRM data to zero-click attacks.
  19. Unpatched OnePlus software flaws allowed unprivileged apps to gain root.
  20. Autonomous AI agents abused legitimate access credentials in recent breaches.
  21. Researchers utilized Anthropic's Claude AI to breach OpenAI repositories.
  22. Security roundup highlighted rising AI search poisoning and repository leaks.
  23. Cisco Talos detected automated malware controlled by AI chatbots.
  24. North Korean hackers hid Mac backdoors inside fake Terraform tests.
  25. CenterPoint Energy confirmed a breach exposing millions of customer records.
25
articles summarized
17
sources

Sources in this roundup

The Hacker News
6 article(s)
Information Security Buzz
2 article(s)
Malwarebytes
2 article(s)
Security Affairs
2 article(s)
Blog
1 article(s)
Blog on OpenSSL Library
1 article(s)
Cyber Security News
1 article(s)
Hackread – Cybersecurity News, Data Breaches, AI and More
1 article(s)
News
1 article(s)
Palo Alto Networks Blog
1 article(s)
Schneier on Security
1 article(s)
Security Blog G Data Software AG
1 article(s)
Security Latest
1 article(s)
eSecurity Planet
1 article(s)
securityweek
1 article(s)
www.infosecurity-magazine.com
1 article(s)
www.theregister.com – Articles
1 article(s)

Most-mentioned keywords

access
2 mention(s)
attack
2 mention(s)
click
2 mention(s)
code
2 mention(s)
data
2 mention(s)
flaw
2 mention(s)
found
2 mention(s)
mac
2 mention(s)

Sources

  1. SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
  2. Introducing Unit 42 Continuous Frontier AI Defense
  3. Ryuk Member Karen Vardanyan Sentenced to Two Years in U.S. Prison
  4. New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
  5. Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
  6. DORA Year Two: Can Your SOC Actually See the Attack?
  7. Meta’s Muse AI assistant has a zero-day that can turn it into a Mac backdoor
  8. GPT-6 Astra Breaks an Old Enigma Message
  9. OpenSSL 4.1 Beta Release Announcement
  10. Andorran Police joins Europol’s secure communication network
  11. Researchers Found a New Way to Break RSA that Doesn’t Require Factoring the Key
  12. What Would RAG Look Like If Miranda Priestly Were the User?
  13. AI Drives Surge in Bot and API Threats
  14. OpenAI Agent Breached Australian Medicare Statistics Portal
  15. How a Managed SOC works: What happens when a cyberattack begins?
  16. Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
  17. AI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOS
  18. Salesforce Agentforce vulns allowed 0-click CRM data theft, anonymous phishing
  19. Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
  20. Rogue AI agents put trusted access under scrutiny
  21. Researchers used Claude to hack OpenAI
  22. ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
  23. A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
  24. North Korean Hackers Hide Mac Backdoors in Fake Terraform Job Tests
  25. Texas utility CenterPoint confirms breach after attacker leaks customer data