IT Security News Roundup: 2026-09-25

IT Security News: today roundup

  1. CISA added actively exploited SharePoint and MikroTik flaws to KEV.
  2. A Tennessee science center hosted family squid dissection events.
  3. Researchers created 5G-Shark to intercept cellular signals without jamming.
  4. Chinese hackers exploited Chrome and Windows zero-days to deploy CLEANGULP.
  5. Threat actors actively targeted unpatched Roundcube email servers.
  6. AI integration in Microsoft DevLabs DebugMCP enabled remote code execution.
  7. ServiceNow patched critical AI Platform flaws allowing unauthorized data extraction.
  8. Fake business complaints targeted Asian companies to deliver malware archives.
  9. Apple released iOS 27 featuring expanded Siri AI capabilities.
  10. A WordPress formatting bug allowed server takeover through user comments.
  11. Voice phishing scammers mocked Google by publishing exposed attack scripts.
  12. TWEAKOS malware steals messaging accounts to sell on Telegram marketplaces.
  13. Sauron Loader targeted German organizations using evasive DLL side-loading techniques.
  14. The CARBONATO botnet deployed AI agents across exposed Docker servers.
  15. Hackers exploited Samsung MagicINFO software to assemble in-system cryptocurrency miners.
  16. Police arrested two human traffickers exploiting restaurant workers across Europe.
  17. A legacy Linux kernel vulnerability permitted local root privilege escalation.
  18. An analysis argued for embedding security controls directly into networks.
  19. OxygenOS flaws allowed zero-permission apps root access on OnePlus devices.
  20. Cybercrime group ShinyHunters claimed it breached the FBI for self-preservation.
  21. Suspected North Korean hackers stole $351.6 million from exchange Bitget.
  22. Cisco released the open-source CAIRN framework alongside cybersecurity news updates.
  23. Vercel fixed a critical Next.js vulnerability enabling server code execution.
  24. Apple released high-end Mac Studio desktops targeting enterprise AI workloads.
  25. ShinyHunters claimed it breached the FBI and stole employee records.
25
articles summarized
12
sources

Sources in this roundup

Cyber Security News
9 article(s)
The Hacker News
3 article(s)
www.theregister.com – Articles
3 article(s)
Security Affairs
2 article(s)
Blog
1 article(s)
Cybersecurity Headlines
1 article(s)
Hackread – Cybersecurity News, Data Breaches, AI and More
1 article(s)
News
1 article(s)
Panda Security Mediacenter
1 article(s)
Schneier on Security
1 article(s)
Security Archives – TechRepublic
1 article(s)
Silicon UK
1 article(s)

Most-mentioned keywords

hackers
4 mention(s)
malware
4 mention(s)
attackers
3 mention(s)
flaw
3 mention(s)
zero
3 mention(s)
access
2 mention(s)
apple
2 mention(s)
business
2 mention(s)

Sources

  1. U.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalog
  2. Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
  3. 5G-Shark Lures Phones to Rogue 5G Cells Without Network Jamming
  4. Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
  5. Attackers Target Unpatched Roundcube Servers With CVE-2026-48842
  6. From Debugging to Code Execution: RCE in Microsoft DevLabs’ DebugMCP?
  7. Critical ServiceNow Vulnerabilities Let Attackers Bypass Authorization – Update Now!
  8. Attackers Are Turning Everyday Business Emails Into Malware Delivery Machines
  9. Why would you want to turn off Apple Intelligence and Siri AI on iOS 27?
  10. WordPress Comment2Shell Vulnerability Lets Hackers Take Over Sites Through Comments
  11. Fake Google Security Team ad says 'no script reading' in voice phishing – then prints the script
  12. TWEAKOS Malware Turns Telegram Into a Stealer, C2 Platform and Stolen Account Marketplace
  13. Sauron Loader Malware Uses DLL Side-Loading and In-Memory Decryption to Evade Detection
  14. Researchers Found a Botnet That Uses an AI Agent to Operate Inside Compromised Servers
  15. Hackers Used a Samsung Flaw to Build a Cryptominer Inside Victim Systems
  16. International investigation identifies over 70 potential victims exploited in Indian restaurants
  17. 14-Year-Old Linux Kernel Flaw Lets Local Users Gain Root Access and Escape Containers
  18. Why security belongs in the network
  19. OnePlus 15 Flaws Let Zero-Permission Apps Gain Root Access Through OxygenOS Services
  20. ShinyHunters tells The Reg: We hacked the FBI to 'protect our business'
  21. Cryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 Million
  22. CAIRN framework, Muse zero-day, BigDiskBuster
  23. Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
  24. Apple Ships Desktops Pitched As Enterprise AI Alternative
  25. ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants