ChatGPT subscription notices have become the latest cover for credential-stealing emails. The campaign uses a familiar billing problem to push recipients…
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
The agency wants to help companies sort through the AI-fueled avalanche of bug reports.
Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems
Feral Wolf is using exposed business software and weak server settings to reach corporate networks, then locking files with ransomware. The campaign shows…
Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face
Two Hugging Face accounts reveal that OpenAI’s agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.
Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges
Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications…
Did an AI really try to break free from human control?
An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.
Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
OPSWAT researchers find two zero-days in TP-Link cameras
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Global Crackdown
The U.S. Department of Justice has announced the court-authorized seizure of internet domains linked to “NightmareStresser,” one of the world’s…
Securing the unpatchable in an age of AI-driven vulnerabilities
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch.…
Unbound 1.26.1 Patches Critical RCE, DoS, and DNSSEC Flaws
A major security update has been issued for Unbound, the widely used validating DNS resolver developed by NLnet Labs. On September 16, 2026, the project…
IT Security News Hourly Summary 2026-09-18 17h : 16 posts
16 posts published in the last hour 14:3136,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check 14:31In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw 14:31Cyber Briefing: 2026.09.18 14:31Meta Plans Smart Glasses Without Camera,…
36,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check
A new scan found 36,769 self-hosted AI endpoints reachable online, highlighting gaps in access controls, patching, and monitoring.
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Noteworthy stories that might have slipped under the radar: Mandiant’s 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress…
Cyber Briefing: 2026.09.18
Iranian malware is using Telegram for command and control, AI is being used to build convincing fake antivirus renewal scams, and an autonomous AI agent…
Meta Plans Smart Glasses Without Camera, Amid Complaints
Facebook parent Meta reportedly preparing to launch smart glasses without camera, amid rising complaints around tech’s intrusiveness
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks
AI helps scammers build convincing antivirus renewal pages
A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.
US Official ‘Suspicious’ Of Anthropic Call For Antitrust Exemption
FTC chair Andrew Ferguson says AI companies looking to bring in regulations that ‘insulate their incumbency from challenge’
PeckBirdy C2 Traffic Seen Across Enterprise Networks While Hiding Behind Casino Domains
China-aligned threat actors are using low-quality Chinese-language casino and adult websites to conceal PeckBirdy command-and-control infrastructure,…
Cyberattack Knocks International Meteor Organization Website Offline
A cyberattack has forced the International Meteor Organization (IMO), one of the leading providers of meteor observation, to take much of the website…
Researchers used Anthropic’s Claude to hack into OpenAI
Security researchers used Anthropic’s Claude to exploit vulnerabilities in OpenAI’s systems, taking over employee accounts and gaining access to an…
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one,…
OpenAI Hacked By Anthropic Models – Research
HOC Shorts How OpenAI Hacked By Anthropic Models – Research The security researchers successfully breached OpenAI’s internal repositories…
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer…
