Good news: there’s a patch. Bad news: both CISA and F5 warn that it’s under active exploitation
Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
The idea that AI could break away and work toward its own agenda is looking increasingly plausible to researchers and experts.
FBI probes cyberattack tied to third-party jobs portal
The potentially serious breach highlights the supply chain risks facing even the most sophisticated organizations.
OWASP LLM Top 10 2026: Every Move Points the Same Direction
This is Post 4 of a four-part series: Post 1: Agentic AI Security: The Chatbot Era Is Over Post 2: Generative AI Security: Why AI Needs a New Kind of…
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your…
SIRIUS SPoC network meets as EU enters new era for electronic evidence
The 7th SIRIUS Single Point of Contact (SPoC) Network Meeting, organised by Europol’s EU Internet Referral Unit (EU IRU) together with the German Federal…
Revolut Customers Targeted with New Wave of Phishing Attacks
Following a major data breach, Revolut customers are being sent convincing phishing messages
What’s next for cybersecurity, according to Index Ventures’ Shardul Shah
As concern over AI safety and rogue agents continue to make headlines, it’s no surprise that cybersecurity stocks are rising, or that investors are…
More CVEs than ever. The same old ones keep getting exploited.
Vulnerability volume is climbing fast. The exploited ones are old and already patchable.
IT Security News Hourly Summary 2026-09-23 20h : 10 posts
10 posts published in the last hour 17:31OpenAI Expands Outside Safety Reviews Into Model Training 17:31Security’s 30-year habit: layering around the problem 17:31Reimagining the SOC for the agentic era in Microsoft Defender 17:31Cyber Briefing: 2026.09.23 17:31Open-Source AI Agents Breach 27…
OpenAI Expands Outside Safety Reviews Into Model Training
OpenAI plans to expand independent safety assessments into model training and evaluation, giving outside groups earlier access to test high-risk AI…
Security’s 30-year habit: layering around the problem
The nurse isn’t careless. Every safe path is slower than Outlook.
Reimagining the SOC for the agentic era in Microsoft Defender
We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection…
Cyber Briefing: 2026.09.23
AI-enabled phishing, browser vulnerabilities, compromised third-party credentials, and exposed customer data remain key areas of concern, with EvilTokens…
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
Gambit Security found AI agents breached 27 companies, stole 600,000 credit card records and installed payment skimmers across compromised retail sites.
The Visibility Gap in Phishing Detection: Where Sandboxing Makes a Difference
The difficult part of phishing detection for a security team often begins after the initial alert. A suspicious URL may look clean at first glance,…
Outerlimit Raises $16M to Build Zero Trust Security Layer for Autonomous AI Agents
Outerlimit has emerged from stealth with $16 million in pre-seed funding to develop a decentralized security and authorization layer for autonomous AI…
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. “ChainScript has…
GitLab Email Feature Vulnerability Lets Attackers Push Code Into Private Repositories
GitLab’s “Email work item to this project” feature can become a repository-compromise primitive when its private address is exposed, according to research…
IT Security News Hourly Summary 2026-09-23 19h : 12 posts
12 posts published in the last hour 16:31Month-Old UK Start-Up Achieves Nearly $4bn Valuation 16:31MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key 16:31Your bank is calling, but is it really your bank? How impersonation…
Month-Old UK Start-Up Achieves Nearly $4bn Valuation
‘World model’ start-up Emulate, founded by former Google DeepMind researchers, reportedly raising $700m at $3.7bn valuation
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password,…
Your bank is calling, but is it really your bank? How impersonation scams work
Receiving a call or email that appears to come from your bank can be unsettling. The message may warn that someone accessed your account, a…
Huawei Expands AI Clustering Strategy
Huawei tests SuperPoD AI compute stack with UnifiedBus, near-packaged optics, brings forward launch of next-gen AI chips
