ICYMI: 2026-09-23
Latest Headlines
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
IonQ Targets Quantum Error-Correction Bottleneck With Single-CPU DecoderIonQ Says Sin
Worries About an AI Internet Takeover Gain New Urgency Among Doomsday Scenarios
Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk
Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm
GitLab Email Feature Vulnerability Lets Attackers Push Code Into Private Repositories
The Visibility Gap in Phishing Detection: Where Sandboxing Makes a Difference
Outerlimit Raises $16M to Build Zero Trust Security Layer for Autonomous AI Agents
New Cpanel Vulnerability Allows Attackers to Access Other Users’ Accounts
Critical IBM FTM Flaws Let Attackers Execute Code and Access Payment Systems
Ryuk Ransomware Operator Sentenced for Deploying Malware and Extorting Victim Networks
AWS Lambda Flaw Lets Attackers Bypass IAM Permissions and Access Cloud Services
Critical NEXT.JS Flaw Enables RCE Attacks Via Weaponized SVG File
Fake Crypto Wallet App Spreads PamStealer Malware to Steal Mac Passwords
The Domains Keep Disappearing, but the Malware Infrastructure Behind Them Never Moves
Placeholder domain used in dev docs now serves ClickFix attacks
New RemControl Android banking malware targets users in Europe and Canada
Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
Hackers start exploiting critical WordPress flaw for code execution
Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
InfraTrust report warns network management systems under attack
Arista patches actively exploited VeloCloud Orchestrator zero-day
Microsoft: September Windows updates break Always On VPN connections
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
– MTZ