The feds are said to be investigating the compromise of the tankers’ networks, which in one case interfered with one of the tanker’s navigation and…
MikroTrick Attack Lets Hackers Gain Full Admin Control of MikroTik Routers Without Login
MikroTik router owners face a security problem after researchers reproduced a takeover chain that can hand an outsider full administrator control without…
Atomic macOS (AMOS) Stealer Activity
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats.
Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws
Google has released Chrome 153 to the Stable channel for Windows, macOS, and Linux, addressing 16 security vulnerabilities, including two critical…
IT Security News Hourly Summary 2026-09-18 18h : 14 posts
14 posts published in the last hour 15:32AI Agents Now Run Ransomware Attacks End-to-End Without Human Operators 15:31Linux Kernel Hit by Four Privilege Escalation Flaws Enabling Root Access 15:31NightEagle targets Russian companies 15:31Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI…
AI Agents Now Run Ransomware Attacks End-to-End Without Human Operators
Ransomware attacks are entering a new phase. Researchers have documented a campaign in which an AI agent planned, executed, and escalated an extortion…
Linux Kernel Hit by Four Privilege Escalation Flaws Enabling Root Access
Four newly disclosed Linux kernel vulnerabilities could allow local attackers to corrupt kernel memory and escalate privileges to root on affected…
NightEagle targets Russian companies
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is…
Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI Account Credentials
ChatGPT subscription notices have become the latest cover for credential-stealing emails. The campaign uses a familiar billing problem to push recipients…
CISA ends weekly vulnerability roundups as part of shift to prioritization approach
The agency wants to help companies sort through the AI-fueled avalanche of bug reports.
Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems
Feral Wolf is using exposed business software and weak server settings to reach corporate networks, then locking files with ransomware. The campaign shows…
Agents at Large | Tracing Illicit OpenAI Agent Activity on Hugging Face
Two Hugging Face accounts reveal that OpenAI’s agents staged relay code, internal probes and ChatGPT account registration beyond the published timeline.
Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges
Microsoft has patched a maximum-severity security flaw in Azure AI Foundry, its enterprise platform for building and managing generative AI applications…
Did an AI really try to break free from human control?
An unreleased OpenAI model wrote instructions telling itself to ignore developer controls. Here’s what actually happened.
Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
OPSWAT researchers find two zero-days in TP-Link cameras
FBI Seizes NightmareStresser DDoS-for-Hire Domains in Global Crackdown
The U.S. Department of Justice has announced the court-authorized seizure of internet domains linked to “NightmareStresser,” one of the world’s…
Securing the unpatchable in an age of AI-driven vulnerabilities
Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch.…
Unbound 1.26.1 Patches Critical RCE, DoS, and DNSSEC Flaws
A major security update has been issued for Unbound, the widely used validating DNS resolver developed by NLnet Labs. On September 16, 2026, the project…
IT Security News Hourly Summary 2026-09-18 17h : 16 posts
16 posts published in the last hour 14:3136,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check 14:31In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw 14:31Cyber Briefing: 2026.09.18 14:31Meta Plans Smart Glasses Without Camera,…
36,769 Self-Hosted AI Services Exposed Online — What Security Teams Should Check
A new scan found 36,769 self-hosted AI endpoints reachable online, highlighting gaps in access controls, patching, and monitoring.
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
Noteworthy stories that might have slipped under the radar: Mandiant’s 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress…
Cyber Briefing: 2026.09.18
Iranian malware is using Telegram for command and control, AI is being used to build convincing fake antivirus renewal scams, and an autonomous AI agent…
Meta Plans Smart Glasses Without Camera, Amid Complaints
Facebook parent Meta reportedly preparing to launch smart glasses without camera, amid rising complaints around tech’s intrusiveness
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
Huntress researchers highlighted a new ransomware variant, named Settra, and the post-compromise techniques used in two recent attacks
