ICYMI: 2026-09-24
Latest Headlines
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later
Autonomous AI Hacks Raise Thorny Questions of Legal Accountability
Kontext Security Emerges With $4 Million for AI Agent Runtime Controls
OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data
OT Security Guidance: NIST Drafts Updated Guide, CISA/FBI Advise on ICS Integrators
SolarWinds Patches Critical RCE Flaws in Observability Self-Hosted
Astrana Health Data Breach Impacts Private, Confidential Information
US Court Sentences Armenian Man to Prison for Ryuk Ransomware Attacks
MacSync malware uses public iCloud calendars to deliver new payloads
New Carbonato malware uses AI agents to hijack exposed Docker hosts
Exposed GitLab project email addresses let attackers push code
Hackers now exploit critical Roundcube flaw in code injection attacks
Windows 11 KB5124010 update released with 46 changes and fixes
CISA: Ransomware gangs now exploiting critical TeamCity flaw
OpenAI hacked Australian Medicare govt site, probed data providers
Microsoft fixes bug that broke Windows File History backup feature
– MTZ