As concern over AI safety and rogue agents continue to make headlines, it’s no surprise that cybersecurity stocks are rising, or that investors are…
More CVEs than ever. The same old ones keep getting exploited.
Vulnerability volume is climbing fast. The exploited ones are old and already patchable.
IT Security News Hourly Summary 2026-09-23 20h : 10 posts
10 posts published in the last hour 17:31OpenAI Expands Outside Safety Reviews Into Model Training 17:31Security’s 30-year habit: layering around the problem 17:31Reimagining the SOC for the agentic era in Microsoft Defender 17:31Cyber Briefing: 2026.09.23 17:31Open-Source AI Agents Breach 27…
OpenAI Expands Outside Safety Reviews Into Model Training
OpenAI plans to expand independent safety assessments into model training and evaluation, giving outside groups earlier access to test high-risk AI…
Security’s 30-year habit: layering around the problem
The nurse isn’t careless. Every safe path is slower than Outlook.
Reimagining the SOC for the agentic era in Microsoft Defender
We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection…
Cyber Briefing: 2026.09.23
AI-enabled phishing, browser vulnerabilities, compromised third-party credentials, and exposed customer data remain key areas of concern, with EvilTokens…
Open-Source AI Agents Breach 27 Companies, Steal 600,000 Credit Card Records
Gambit Security found AI agents breached 27 companies, stole 600,000 credit card records and installed payment skimmers across compromised retail sites.
The Visibility Gap in Phishing Detection: Where Sandboxing Makes a Difference
The difficult part of phishing detection for a security team often begins after the initial alert. A suspicious URL may look clean at first glance,…
Outerlimit Raises $16M to Build Zero Trust Security Layer for Autonomous AI Agents
Outerlimit has emerged from stealth with $16 million in pre-seed funding to develop a decentralized security and authorization layer for autonomous AI…
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. “ChainScript has…
GitLab Email Feature Vulnerability Lets Attackers Push Code Into Private Repositories
GitLab’s “Email work item to this project” feature can become a repository-compromise primitive when its private address is exposed, according to research…
IT Security News Hourly Summary 2026-09-23 19h : 12 posts
12 posts published in the last hour 16:31Month-Old UK Start-Up Achieves Nearly $4bn Valuation 16:31MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key 16:31Your bank is calling, but is it really your bank? How impersonation…
Month-Old UK Start-Up Achieves Nearly $4bn Valuation
‘World model’ start-up Emulate, founded by former Google DeepMind researchers, reportedly raising $700m at $3.7bn valuation
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password,…
Your bank is calling, but is it really your bank? How impersonation scams work
Receiving a call or email that appears to come from your bank can be unsettling. The message may warn that someone accessed your account, a…
Huawei Expands AI Clustering Strategy
Huawei tests SuperPoD AI compute stack with UnifiedBus, near-packaged optics, brings forward launch of next-gen AI chips
Arista Warns of Critical Actively Exploited VCO Vulnerability
Arista has published Security Advisory 0183 warning of a critical vulnerability in on-premises VeloCloud Orchestrator (VCO), tracked as CVE-2026-93952.…
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based “much smaller organization” in the information…
Email Makes Up Nearly 1 in 3 MSSP Analyses: How Tier 1 Can Triage Phishing Faster
MSSP Tier 1 analysts can cut phishing triage time with interactive analysis, fresh threat intelligence, clearer evidence and complete Tier 2 handoffs…
OpenAI Codex sandbox escape, President proposes AI Force, Cyber Command suicides
Researchers escape OpenAI Codex sandbox to run commands on host AI Force proposed to monitor technology Congress eyes new support for Cyber Command after…
Data Centre Demand Boosts NI Manufacturing
Demand for data centre equipment, including specialised power and storage systems, helps drive NI manufacturing above UK average
A week in security (September 14 – September 20)
A list of topics we covered in the week of September 14 to September 20 of 2026
India’s Second-Phase Semiconductor Push Attracts $12bn
Indian government’s second-phase programme to set up a chip supply chain in the country attracts $11bn to $12bn in investment interest
