ICYMI: 2026-09-17
Latest Headlines
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads
BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS
Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks
U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks
Flock Once Touted Its Cameras as ‘Made in the USA.’ Now It’s Not So Clear
Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training
CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom
Comp AI Raises $34 Million for AI-Native Compliance and Security
Ransomware Attacks on Manufacturers Surge as Supply Chain Risk Grows
Cisco Fixes Dozens of Flaws Across FMC, ISE and Nexus Dashboard
CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses
AI Agents Can Retrain Own Models Mid-Task, Leaking Secrets and Erasing Refusals
OpenAI Models Searched for Leaked API Keys and Uploaded Files Without Permission
FBI Takes Down NightmareStresser DDoS Service Used in Hundreds of Thousands of Attacks
BIND DNS Servers Hit by 14 Security Flaws Enabling Cache Poisoning and Remote Crashes
CISA Wants Defenders to Deploy Fake Credentials and Systems to Catch Hackers
Hacked Thai College Website Abused to Redirect Google Searchers to Illegal Online Casino
Hackers Turn Telegram Into a Command Center for HEAVYGRAM Surveillance Malware
SilkParasite-Linked Malware Infrastructure Traced Back Four Years Across Central Asia
North Korean IT Workers Use AI and Remote Desktop Tools to Fake Technical Interviews
FamousSparrow Exploits Public-Facing Exchange Servers to Deploy SparroWocky Backdoor
New RatHat Android malware uses AI to automate device control
OpenAI details more cases of AI agents taking unauthorized actions
Brevo supply-chain attack injected ClickFix scripts on customer sites
What Recent AI-Powered Attacks Mean for Your Identity Security
Windows 11 24H2 Home and Pro reach end of support in October
Chinese hackers use SparroWocky malware in govt espionage attacks
Cisco warns of max severity ISE zero-day exploited in attacks
Anthropic wants Claude to analyze your bank account and financial data
– MTZ