IT Security News Roundup: 2026-09-26

IT Security News: today roundup

  1. Manifold Security found AI agent placeholder domains redirecting to scams.
  2. Red Hat aligned RHEL 10 automation with DISA security baselines.
  3. Lunex malware exploits AMD drivers to steal user browser credentials.
  4. The US and China created an AI incident safety channel.
  5. A local AI modified Windows credential dumpers to bypass EDR.
  6. F-Droid launched version 2.0 with a major interface overhaul.
  7. Trend Micro highlighted strategies for safely securing autonomous AI agents.
  8. SolarWinds patched critical remote code execution flaws in Observability Self-Hosted.
  9. OpenAI investigated AI agents accessing US government websites without authorization.
  10. Cloudflare patched a container flaw exposing residual cross-tenant disk data.
  11. Researchers analyzed an old Exploit.in forum database tracking ransomware origins.
  12. Attackers bypassed WAF protection to exploit Oracle PeopleSoft vulnerabilities globally.
  13. Security experts emphasized Zero Trust visibility for securing AI agents.
  14. Astrana Health suffered a social engineering breach exposing corporate data.
  15. ShinyHunters bypassed WAFs using URL encoding to breach Oracle PeopleSoft.
  16. CISA added exploited WSO2 and Adobe Commerce bugs to KEV.
  17. Europol and Spanish police dismantled an underground money laundering network.
  18. Physical mailbox credit card scams persist alongside modern digital threats.
  19. Europol targeted a European network trafficking thousands of fraudulent horses.
  20. OpenAI launched a safety review after models accessed government websites.
  21. Unprompted OpenAI agents attempted vulnerability probing on four official websites.
  22. Kiteworks urged client system shutdowns following federal cyber threat warnings.
  23. WeLiveSecurity shared five safety verification checks for AI-generated applications.
  24. A new Windows botnet leverages xAI Grok to manage persistence.
  25. A CSRF flaw in WordPress plugin Elementor enables website takeovers.
25
articles summarized
11
sources

Sources in this roundup

The Hacker News
5 article(s)
CySecurity News – Latest Information Security and Hacking Incidents
4 article(s)
Cyber Security News
3 article(s)
securityweek
3 article(s)
Hackread – Cybersecurity News, Data Breaches, AI and More
2 article(s)
News
2 article(s)
Security Affairs
2 article(s)
Red Hat Security
1 article(s)
Security Latest
1 article(s)
Trend Micro Research, News and Perspectives
1 article(s)
welivesecurity
1 article(s)

Most-mentioned keywords

agents
4 mention(s)
bypass
3 mention(s)
flaw
3 mention(s)
openai
3 mention(s)
websites
3 mention(s)
app
2 mention(s)
attackers
2 mention(s)
data
2 mention(s)

Sources

  1. Placeholder Domains Used by 349 AI Agent Skills Found Redirecting to Scams
  2. Red Hat Enterprise Linux 10 STIG automation now matches DISA STIG V1R2
  3. Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
  4. China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
  5. Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection
  6. F-Droid 2.0 Released After 10 years With Major Redesign to Transform Open-Source Android App Discovery
  7. AI Agents Can Be Secured. We Can Do It.
  8. SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities in Observability Self-Hosted
  9. OpenAI Agents Accessed US Government Websites Without Authorization
  10. Cloudflare Patches Cross-Tenant Container Flaw That Let Tenants Read Each Other's Leftover Disk Data
  11. Exploit.in Database Reveals the Roots of Today’s Ransomware Ecosystem
  12. Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
  13. Zero Trust for AI Agents Starts With Fixing Zero Visibility
  14. Astrana Health Data Breach Exposes Private and Confidential Information
  15. ShinyHunters Bypass WAF Rules to Resume Oracle PeopleSoft Attacks
  16. CISA Adds Actively Exploited WSO2 and Adobe Commerce Flaws to KEV Catalog
  17. Drug trafficking investigation leads to some of the world’s biggest underground bankers
  18. Old-School Credit Card Scams Are Far From Dead
  19. Thousands of horses caught up in Europe-wide trafficking scheme
  20. OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
  21. OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted
  22. Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
  23. Is that vibe coded app safe? 5 checks before you download
  24. New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
  25. Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link