September 18, 2026
Why this day matters
- Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. [...]
- Check Point fixed CVE-2026-91843, a critical flaw that could let attackers run code as root on Security Management and Log Servers with no login needed.
Enriched source records
Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.
Luna-enriched source article · helpnetsecurityMost WordPress pros still lack a breach recovery plan
Melapress surveyed 319 WordPress professionals, including agency staff, developers, designers, site owners and administrators, and found that most had experienced at least one known security incident.
Most WordPress pros still lack a breach recovery plan
Melapress surveyed 319 WordPress professionals, including agency staff, developers, designers, site owners and administrators, and found that most had experienced at least one known security incident.
Source published Sep 18, 2026, 4:30 AM UTC · Evidence retrieved Sep 18, 2026, 8:51 AM UTC
What happened
Melapress surveyed 319 WordPress professionals, including agency staff, developers, designers, site owners and administrators, and found that most had experienced at least one known security incident. [1] [2]
Fewer than three in ten respondents had a breach recovery plan. [3]
Why it matters
The article describes a recovery plan as establishing in advance who responds, where clean backups are kept, and who must be notified. [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Melapress, a maker of WordPress security plugins, surveyed 319 WordPress professionals and found that most had dealt with at least one known security incident.
- [2]
The respondents build and run WordPress sites for a living: agency staff, developers, designers, site owners and administrators.
- [3]
Across the whole group, fewer than three in ten have a breach recovery plan.
- [4]
A recovery plan settles in advance who responds, where the clean backups are, and who needs to be told.
Luna-enriched source article · helpnetsecurityHardcoded MCP credentials found in public GitHub files
Hush Security’s report found hardcoded API keys, access tokens, and other credentials used by AI coding tools in publicly accessible MCP configuration files on GitHub.
Hardcoded MCP credentials found in public GitHub files
Hush Security’s report found hardcoded API keys, access tokens, and other credentials used by AI coding tools in publicly accessible MCP configuration files on GitHub.
Source published Sep 18, 2026, 5:30 AM UTC · Evidence retrieved Sep 18, 2026, 8:51 AM UTC
What happened
Hush Security’s report found hardcoded API keys, access tokens, and other credentials used by AI coding tools in publicly accessible MCP configuration files on GitHub. [1]
The company analyzed around 82,000 configuration files and found hardcoded credential literals in 12% of credential slots. [2]
Why it matters
The exposed hardcoded credentials could potentially expose connected services and systems. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Hardcoded API keys, access tokens and other credentials used by AI coding tools have been found in publicly accessible MCP configuration files on GitHub, according to research from Hush Security’s The State of MCP Configuration: The Identity Security Gaps report.
- [2]
The company analyzed around 82,000 configuration files and found that 12% of credential slots contained a hardcoded credential literal, potentially exposing credentials for connected services and systems.
Luna-enriched source article · malwarebytes labsFake parcel delivery messages steal your card and bank details
Parcel-delivery phishing campaigns impersonate courier services and typically direct recipients to fake courier websites to collect personal and financial information.
Fake parcel delivery messages steal your card and bank details
Parcel-delivery phishing campaigns impersonate courier services and typically direct recipients to fake courier websites to collect personal and financial information.
Source published Sep 18, 2026, 7:44 AM UTC · Evidence retrieved Sep 18, 2026, 8:51 AM UTC
What happened
Parcel-delivery phishing campaigns impersonate courier services and typically direct recipients to fake courier websites to collect personal and financial information. [1] [2] [3] [4]
A recent campaign impersonating Belgium’s bpost claimed that a €4.95 customs fee prevented delivery, then requested personal information, card details, and banking information. [5] [6] [7] [8]
Why it matters
The campaign used URL shortening and multiple fake bpost domains; its pages copied bpost branding and displayed security labels that the source says did not prove the site or payment was secure. [9] [10] [11]
Submitted card details may be used for fraudulent purchases or sold to criminals, while personal and banking information may support later, more convincing scams. [12] [13]
Source-supported guidance
The source advises checking the sender and destination, being wary of unexpected fees or refunds, and treating requests for extensive financial information—especially an IBAN plus card details—as suspicious. [14] [15] [16] [17] [18] [19]
Some generated claims did not pass validation and were omitted. Only retained claims are shown.
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Parcel delivery phishing campaigns appear around the world under different courier names.
- [2]
In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered.
- [3]
Similar messages impersonate Colissimo and Chronopost in France, Correos in Spain, Poste Italiane in Italy, and PostNL in the Netherlands.
- [4]
The details vary, but the aim is usually the same: to persuade you to visit a fake courier website and provide personal and financial information.
- [5]
A fake bpost delivery email A recent campaign targeting customers of the Belgian postal service bpost begins with an email claiming that a package could not be delivered because €4.95 in customs duties has not been paid.
- [6]
Your package could not be delivered on September 9, 2026, because the customs duties (€4.95) have not been paid.
- [7]
However, the website does not stop at collecting the supposed fee.
- [8]
It asks for personal information, card details, and banking information.
- [9]
How the scam works The link first passes through a URL-shortening service ( hxxps://qr[.]paps[.]jp/1GWsa ) before redirecting to a fake bpost site.
- [10]
The campaign used several fake bpost domains, including: hxxps://bpost[.]be-pakje-ontvangen-nl-recevoir-colis-fr[.]my[.]id/ bpost[.]center , which is the domain shown in the screenshots below.
- [11]
The page copies bpost’s branding and displays security claims such as “Secure SSL connection,” “256-bit SSL,” “SEPA compliant,” and “Secure payment.” These labels were added by the scammers and do not prove that the page or payment is secure.
- [12]
Once submitted, card details may be used for fraudulent purchases or sold to other criminals.
- [13]
The personal and banking information may also be used to make later scams more convincing.
- [14]
Check the sender and destination.
- [15]
A message may use a courier’s name while coming from an unrelated email address or linking to a different domain.
- [16]
Be wary of unexpected fees or refunds.
- [17]
A small payment or promised refund can be used to persuade you to provide much more valuable information.
- [18]
Be wary of requests for extensive financial information.
- [19]
A request for an IBAN as well as card details should be treated with suspicion, particularly when it supposedly relates to a small delivery fee.
Luna-enriched source article · helpnetsecurityAndroid apps can now check security patches down to individual device components
AndroidX Security State libraries provide a more granular way to assess how securely patched an Android device is.
Android apps can now check security patches down to individual device components
AndroidX Security State libraries provide a more granular way to assess how securely patched an Android device is.
Source published Sep 18, 2026, 8:38 AM UTC · Evidence retrieved Sep 18, 2026, 8:51 AM UTC
What happened
AndroidX Security State libraries provide a more granular way to assess how securely patched an Android device is. [1]
Security State v1.1.0 and Security State Provider v1.0.0 let developers check the security status of individual device components. [2]
The libraries can indicate whether security updates are ready to be downloaded and installed on a specific device. [2]
Why it matters
The Security State Provider library offers a standard approach for phone manufacturers and developers building over-the-air update systems. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
New AndroidX Security State libraries provide a more granular way to determine how securely patched an Android device is.
- [2]
The stable Security State v1.1.0 and Security State Provider v1.0.0 libraries allow developers to check the security status of individual device components and determine whether security updates are ready to be downloaded and installed on a specific device.
- [3]
For phone manufacturers and developers who build over-the-air (OTA) update systems, the androidx.security.state.provider library provides a standard way … More → The post Android apps can now check security patches down to individual device components appeared first on Help Net Security .
Luna-enriched source article · helpnetsecurityZero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
AIR reported a zero-click remote code execution vulnerability affecting Claude Code, Codex, GitHub Copilot, and Gemini CLI.
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
AIR reported a zero-click remote code execution vulnerability affecting Claude Code, Codex, GitHub Copilot, and Gemini CLI.
Source published Sep 18, 2026, 8:49 AM UTC · Evidence retrieved Sep 18, 2026, 8:51 AM UTC
What happened
AIR reported a zero-click remote code execution vulnerability affecting Claude Code, Codex, GitHub Copilot, and Gemini CLI. [1]
The researchers characterized the issue as the first supply-chain vulnerability in the AI agent ecosystem. [2]
The article reported that anyone running a major coding agent that installs marketplace plugins is exposed. [3]
Why it matters
AIR said exploitation could give an attacker the same reach into company systems and data as the employee running the affected agent. [1]
Known limitations
The headline states that two of the four affected agents remained unpatched, but the supplied text does not identify which agents or provide patch status details. [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company’s systems and data as the employee running the agent, according to AIR.
- [2]
“It is the first supply chain vulnerability of the AI agent ecosystem,” the researchers said.
- [3]
“Anyone running a major coding agent that installs plugins from a marketplace is exposed.
- [4]
The exposure … More → The post Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched appeared first on Help Net Security .
Luna-enriched source article · helpnetsecurityArcjet brings security controls and audit trails to AI agents
Arcjet launched agent runtime security, a product intended to help engineering teams secure AI agents and provide security teams with governance and compliance evidence.
Arcjet brings security controls and audit trails to AI agents
Arcjet launched agent runtime security, a product intended to help engineering teams secure AI agents and provide security teams with governance and compliance evidence.
Source published Sep 18, 2026, 8:55 AM UTC · Evidence retrieved Sep 18, 2026, 2:51 PM UTC
What happened
Arcjet launched agent runtime security, a product intended to help engineering teams secure AI agents and provide security teams with governance and compliance evidence. [1]
The product provides observability, enforcement, and audit capabilities across agent workflows. [2]
Why it matters
The stated capabilities are intended to help teams discover running agents, control their actions, and understand what happened and why. [2]
The article frames AI agents as moving beyond chat interfaces into production workflows. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Arcjet has launched agent runtime security, a new product that helps engineering teams secure the AI agents they are building while giving security teams the governance and compliance evidence they need.
- [2]
Arcjet brings observability, enforcement, and audit capabilities across agent workflows so teams can discover which agents are running, control what they can do, and understand what happened and why.
- [3]
AI agents are moving beyond chat interfaces and into production workflows, where they can read … More → The post Arcjet brings security controls and audit trails to AI agents appeared first on Help Net Security .
Luna-enriched source article · the hacker newsClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to developing and distributing PhantomRaven, a JavaScript-based information stealer, through the npm package registry.
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to developing and distributing PhantomRaven, a JavaScript-based information stealer, through the npm package registry.
Source published Sep 18, 2026, 9:18 AM UTC · Evidence retrieved Sep 18, 2026, 1:23 PM UTC
What happened
A financially motivated threat actor has been linked to developing and distributing PhantomRaven, a JavaScript-based information stealer, through the npm package registry. [1]
The developer was assessed with high confidence as likely having used a large language model to write the malware, based on verbose comments, placeholder code, and statistical token-analysis patterns. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.
- [2]
"The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"
Luna-enriched source article · securityaffairsRatHat Turns Android Accessibility Into an Attack Weapon
RatHat is an Android trojan distributed through deceptive phishing sites, malvertising, smishing campaigns and third-party forums that lure victims into manually installing malicious APKs.
RatHat Turns Android Accessibility Into an Attack Weapon
RatHat is an Android trojan distributed through deceptive phishing sites, malvertising, smishing campaigns and third-party forums that lure victims into manually installing malicious APKs.
Source published Sep 18, 2026, 10:04 AM UTC · Evidence retrieved Sep 18, 2026, 2:51 PM UTC
What happened
RatHat is an Android trojan distributed through deceptive phishing sites, malvertising, smishing campaigns and third-party forums that lure victims into manually installing malicious APKs. [1] [2] [3]
After installation, RatHat abuses Android SessionInstaller APIs and Accessibility Service access to install payloads and access protected APIs. [4] [5] [6] [7]
The malware uses Accessibility access to enable Developer Options and Wireless Debugging, read the ADB pairing code from the screen, and pair with the phone’s debug interface without user interaction. [8] [9] [10] [11]
RatHat deploys a disguised FRP reverse-proxy client that tunnels remote access to the phone’s ADB shell from the internet, including by bypassing NAT and firewall protections. [12] [13] [14] [15]
Its credential-theft capabilities include Accessibility-based keylogging, browser URL scraping, raw touch-coordinate capture from /dev/input, banking-app overlays, and SMS interception for 2FA codes. [16] [17] [18] [19] [20]
RatHat sends the live Accessibility tree to a generative AI assistant, which returns screen coordinates, on-screen text or navigation commands to direct automated interaction. [21] [22] [23] [24]
The malware can resist removal: it displays a fake Google Play error during uninstall and, if removal succeeds, an external Go agent can silently reinstall the APK and re-grant permissions. [25] [26] [27]
Some generated claims did not pass validation and were omitted. Only retained claims are shown.
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
RatHat combines AI-driven screen control, Android debugging abuse and advanced credential theft to give attackers deep control of infected phones.
- [2]
It starts the way most mobile fraud does: a text message or a shady ad pointing to a fake app store.
- [3]
“RatHat is primarily distributed through deceptive phishing sites promoted via malvertising, smishing campaigns, and third-party forums, luring victims into manually downloading malicious APKs that appear to be legitimate apps” reads the report published by Zimperium.
- [4]
The second stage is a DEX file loaded directly into memory through reflection.
- [5]
It contains the code needed to unpack and install the final malware.
- [6]
The droppers also abuse native Android SessionInstaller APIs to get around restrictions on app installation and Accessibility Services, allowing the malware to install its payload and access protected APIs.
- [7]
The malware first tries to gain access to Android’s Accessibility Service.
- [8]
It then uses that access to silently enable Developer Options and Wireless Debugging on the victim’s phone.
- [9]
It doesn’t need a second device, a cable, or a user to manually approve a USB debugging connection.
- [10]
RatHat uses the same Accessibility Service to read the ADB pairing code directly from the phone’s screen.
- [11]
It then pairs with the phone’s own debug interface without any user interaction.
- [12]
The malware then places two disguised native binaries in /data/local/tmp .
- [13]
The other, libmedia_codec.so , is a modified FRP reverse-proxy client.
- [14]
Its role is to create a tunnel that lets the attacker connect remotely to the phone’s ADB shell from anywhere on the internet.
- [15]
A separate Go-based agent runs a local server and uses a disguised FRP component to expose it to the internet, allowing attackers to bypass NAT and firewall protections.
- [16]
The credential theft itself runs on three tracks.
- [17]
There’s a standard Accessibility-based keylogger reading text fields, a second component scraping URLs straight out of browser address bars, and then something considerably more interesting: a hardware-level keylogger running from that same ADB shell, reading raw touch coordinates off /dev/input .
- [18]
It’s a workaround for FLAG_SECURE, custom keyboards, and lock-screen protections all at once, because none of those defenses touch the input driver itself.
- [19]
On the banking side, RatHat serves fake overlays on top of real banking and payment apps, WeChat and Alipay included, to grab PINs and login credentials while the person thinks they’re using the real interface.
- [20]
Combine that with SMS interception for 2FA codes and you’ve got full account takeover without the victim noticing anything unusual happened.
- [21]
RatHat serializes the phone’s live Accessibility tree into XML and sends it to a mainstream generative AI assistant, which returns screen coordinates and text so the malware can decide where to tap next.
- [22]
This AI is used for non-malicious actions including: Resolving a named target’s centre coordinates on the screen as JSON to direct synthetic clicks.
- [23]
Resolving a target’s actual on-screen text from the XML (without translating).
- [24]
Signaling automatic navigation commands like SCROLL_DOWN.” That single change is what separates RatHat from a decade of scripted Android RATs.
- [25]
Persistence is where things get properly ugly.
- [26]
Uninstall the app and it throws up a fake Google Play error to cancel the removal.
- [27]
Manage to force it through anyway, and the Go agent running outside the app’s lifecycle notices, silently reinstalls the APK, and re-grants every permission, accessibility included, without a single tap from the user.
Luna-enriched source article · helpnetsecurityBots with good manners are better at fooling people on social media
A Surfshark study tested whether people could distinguish human comments from AI-generated comments in a social-media setting.
Bots with good manners are better at fooling people on social media
A Surfshark study tested whether people could distinguish human comments from AI-generated comments in a social-media setting.
Source published Sep 18, 2026, 10:15 AM UTC · Evidence retrieved Sep 18, 2026, 2:51 PM UTC
What happened
A Surfshark study tested whether people could distinguish human comments from AI-generated comments in a social-media setting. [1] [2]
The study included 1,722 participants worldwide, who correctly identified 40% of the bots presented to them overall. [2] [3]
Why it matters
The article reports that bots most likely to fool people were polite rather than loud or aggressive. [1] [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study.
- [2]
The company analyzed 1,722 participants worldwide, testing their ability to separate human comments from AI-generated ones in a social media setting.
- [3]
Overall, people caught just 40% of the bots placed in front of them.
- [4]
(Source: Surfshark) The bots that slipped by most often weren’t loud or aggressive.
Luna-enriched source article · the hacker newsWeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Researchers discovered 13 npm packages that deliver a previously undocumented JavaScript stealer called WeaselBiscuit.
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Researchers discovered 13 npm packages that deliver a previously undocumented JavaScript stealer called WeaselBiscuit.
Source published Sep 18, 2026, 10:40 AM UTC · Evidence retrieved Sep 18, 2026, 1:23 PM UTC
What happened
Researchers discovered 13 npm packages that deliver a previously undocumented JavaScript stealer called WeaselBiscuit. [1]
OpenSourceMalware reported that WeaselBiscuit has functional overlaps with malware strains associated with the DPRK-linked Contagious Interview campaign, including BeaverTail; the supplied text ends before naming the second strain. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.
- [2]
The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and
Additional source records
Material developmentsSaving another 100TB of RAM with math (and Rust)
Cloudflare published a source item for review.
Saving another 100TB of RAM with math (and Rust)
Cloudflare published a source item for review.
What happened
Cloudflare published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Saving another 100TB of RAM with math (and Rust) Cloudflare · Published 2026-09-18T17:23:58Z · Retrieved Sep 18, 2026, 7:10 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsroadmap — Anthropic
Anthropic published a source item for review.
roadmap — Anthropic
Anthropic published a source item for review.
What happened
Anthropic published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- roadmap — Anthropic Anthropic · Published 2026-09-18T16:00:25Z · Retrieved Sep 18, 2026, 7:10 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsThe new AgentCore runtime: Elastic, optimized, and consistently fast starts
Amazon Web Services published a source item for review.
The new AgentCore runtime: Elastic, optimized, and consistently fast starts
Amazon Web Services published a source item for review.
What happened
Amazon Web Services published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- The new AgentCore runtime: Elastic, optimized, and consistently fast starts Amazon Web Services · Published 2026-09-18T15:31:34Z · Retrieved Sep 18, 2026, 7:10 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsNations take action on North Korean IT workers after UN report
Therecord Media published a source item for review.
Nations take action on North Korean IT workers after UN report
Therecord Media published a source item for review.
What happened
Therecord Media published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Nations take action on North Korean IT workers after UN report Therecord Media · Published 2026-09-18T14:29:00Z · Retrieved Sep 18, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsHacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
Therecord Media published a source item for review.
Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia
Therecord Media published a source item for review.
What happened
Therecord Media published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Hacking group ‘NightEagle’ targeting China’s high-tech sector expands operations to Russia Therecord Media · Published 2026-09-18T13:24:00Z · Retrieved Sep 18, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsMicrosoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
Bleepingcomputer published a source item for review.
Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
Bleepingcomputer published a source item for review.
What happened
Bleepingcomputer published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts Bleepingcomputer · Published 2026-09-18T12:16:32Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsNightmareStresser DDoS Service Disrupted in International Operation
Securityweek published a source item for review.
NightmareStresser DDoS Service Disrupted in International Operation
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- NightmareStresser DDoS Service Disrupted in International Operation Securityweek · Published 2026-09-18T10:12:33Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsMicrosoft fixes broken copy and paste for Excel 2016 users
Bleepingcomputer published a source item for review.
Microsoft fixes broken copy and paste for Excel 2016 users
Bleepingcomputer published a source item for review.
What happened
Bleepingcomputer published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Microsoft fixes broken copy and paste for Excel 2016 users Bleepingcomputer · Published 2026-09-18T07:35:31Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsMIND Secures $72 Million for AI-Powered DLP
Securityweek published a source item for review.
MIND Secures $72 Million for AI-Powered DLP
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- MIND Secures $72 Million for AI-Powered DLP Securityweek · Published 2026-09-18T07:25:27Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsHTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
Sans Isc Diary published a source item for review.
HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
Sans Isc Diary published a source item for review.
What happened
Sans Isc Diary published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th) Sans Isc Diary · Published 2026-09-18T06:05:26Z · Retrieved Sep 18, 2026, 7:23 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsAbandoned IoT apps keep sending sensitive data to broken servers
Helpnetsecurity published a source item for review.
Abandoned IoT apps keep sending sensitive data to broken servers
Helpnetsecurity published a source item for review.
What happened
Helpnetsecurity published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Abandoned IoT apps keep sending sensitive data to broken servers Helpnetsecurity · Published 2026-09-18T06:00:45Z · Retrieved Sep 18, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsNew Check Point flaw lets hackers execute code with root privileges
Bleepingcomputer published a source item with critical severity.
New Check Point flaw lets hackers execute code with root privileges
Bleepingcomputer published a source item with critical severity.
What happened
Bleepingcomputer published a source item with critical severity.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- New Check Point flaw lets hackers execute code with root privileges Bleepingcomputer · Published 2026-09-18T09:34:33Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsCheck Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Securityaffairs published details for CVE-2026-91843.
Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution
Securityaffairs published details for CVE-2026-91843.
What happened
Securityaffairs published details for CVE-2026-91843.
Why it matters
A reviewed impact interpretation has not been published for this record.
Structured associations
Reviewed next steps
- Check asset inventory and patch status for CVE-2026-91843.
Evidence
- Check Point Fixes Critical CVE-2026-91843 Allowing Root Code Execution Securityaffairs · Published 2026-09-18T07:52:41Z · Retrieved Sep 18, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsCheck Point, Kaspersky, Tanium Patch Product Vulnerabilities
Securityweek published a source item with critical severity.
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Securityweek published a source item with critical severity.
What happened
Securityweek published a source item with critical severity.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Check Point, Kaspersky, Tanium Patch Product Vulnerabilities Securityweek · Published 2026-09-18T07:14:04Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsCISA Adds Two Known Exploited Vulnerabilities to Catalog
Cisa Ncas Current Activity published details for CVE-2025-39964, CVE-2026-53266.
CISA Adds Two Known Exploited Vulnerabilities to Catalog
Cisa Ncas Current Activity published details for CVE-2025-39964, CVE-2026-53266.
What happened
Cisa Ncas Current Activity published details for CVE-2025-39964, CVE-2026-53266.
Why it matters
A reviewed impact interpretation has not been published for this record.
Structured associations
Reviewed next steps
- Check asset inventory and patch status for CVE-2025-39964, CVE-2026-53266.
- Validate the source-stated mitigation in a controlled environment before rollout.
Evidence
- CISA Adds Two Known Exploited Vulnerabilities to Catalog Cisa Ncas Current Activity · Published 2026-09-18T12:00:00Z · Retrieved Sep 18, 2026, 3:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsCISA Upgrades Vulnerability Reporting Platform with More Automation
Infosecurity Magazine published a source item for review.
CISA Upgrades Vulnerability Reporting Platform with More Automation
Infosecurity Magazine published a source item for review.
What happened
Infosecurity Magazine published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- CISA Upgrades Vulnerability Reporting Platform with More Automation Infosecurity Magazine · Published 2026-09-18T10:00:00Z · Retrieved Sep 18, 2026, 2:52 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsBrevo Supply Chain Attack Injects Malware Into 100,000 Websites
Securityweek published a source item for review.
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Brevo Supply Chain Attack Injects Malware Into 100,000 Websites Securityweek · Published 2026-09-18T09:46:57Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsCritical Orkes Conductor Vulnerability Exploited in Attacks
Securityweek published details for CVE-2026-58138.
Critical Orkes Conductor Vulnerability Exploited in Attacks
Securityweek published details for CVE-2026-58138.
What happened
Securityweek published details for CVE-2026-58138.
Why it matters
A reviewed impact interpretation has not been published for this record.
Structured associations
Reviewed next steps
- Check asset inventory and patch status for CVE-2026-58138.
Evidence
- Critical Orkes Conductor Vulnerability Exploited in Attacks Securityweek · Published 2026-09-18T08:42:18Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsRatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
The Hacker News published a source item for review.
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
The Hacker News published a source item for review.
What happened
The Hacker News published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall The Hacker News · Published 2026-09-18T06:17:25Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Cloud and infrastructureChanging the game: How Google uses agentic AI to secure hundreds of millions of lines of code
Google Cloud published a source item for review.
Changing the game: How Google uses agentic AI to secure hundreds of millions of lines of code
Google Cloud published a source item for review.
What happened
Google Cloud published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Changing the game: How Google uses agentic AI to secure hundreds of millions of lines of code Google Cloud · Published 2026-09-18T16:00:00Z · Retrieved Sep 18, 2026, 7:10 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Cloud and infrastructureMicrosoft Patches 18 Vulnerabilities in AI, Cloud Products
Securityweek published a source item for review.
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Microsoft Patches 18 Vulnerabilities in AI, Cloud Products Securityweek · Published 2026-09-18T10:57:03Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureNew Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
Infosecurity Magazine published a source item for review.
New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing
Infosecurity Magazine published a source item for review.
What happened
Infosecurity Magazine published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- New Settra Ransomware Variant Deployed in Attacks on Retail and Manufacturing Infosecurity Magazine · Published 2026-09-18T13:30:00Z · Retrieved Sep 18, 2026, 2:52 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposure23 Million User Records Compromised in Gyazo Data Breach
Securityweek published a source item for review.
23 Million User Records Compromised in Gyazo Data Breach
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- 23 Million User Records Compromised in Gyazo Data Breach Securityweek · Published 2026-09-18T11:38:40Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureManufacturing Accounts for 22% of all Ransomware Victims
Infosecurity Magazine published a source item for review.
Manufacturing Accounts for 22% of all Ransomware Victims
Infosecurity Magazine published a source item for review.
What happened
Infosecurity Magazine published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Manufacturing Accounts for 22% of all Ransomware Victims Infosecurity Magazine · Published 2026-09-18T08:00:00Z · Retrieved Sep 18, 2026, 8:52 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposure98% of fraudulent hires have company credentials by the time they’re caught
Helpnetsecurity published a source item for review.
98% of fraudulent hires have company credentials by the time they’re caught
Helpnetsecurity published a source item for review.
What happened
Helpnetsecurity published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- 98% of fraudulent hires have company credentials by the time they’re caught Helpnetsecurity · Published 2026-09-18T05:00:51Z · Retrieved Sep 18, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityMigrating multi-model AI agents to Amazon Bedrock AgentCore runtime
Amazon Web Services published a source item for review.
Migrating multi-model AI agents to Amazon Bedrock AgentCore runtime
Amazon Web Services published a source item for review.
What happened
Amazon Web Services published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Migrating multi-model AI agents to Amazon Bedrock AgentCore runtime Amazon Web Services · Published 2026-09-18T15:38:53Z · Retrieved Sep 18, 2026, 7:10 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityAI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Securityweek published a source item for review.
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code Securityweek · Published 2026-09-18T12:45:24Z · Retrieved Sep 18, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityAuditing in the age of (good enough) AI
Trail of Bits published a source item for review.
Auditing in the age of (good enough) AI
Trail of Bits published a source item for review.
What happened
Trail of Bits published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Auditing in the age of (good enough) AI Trail of Bits · Published 2026-09-18T11:00:00Z · Retrieved Sep 18, 2026, 7:10 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityAI Agent Breaches Spanish Organization, Modifies Personal Data
Darkreading published a source item for review.
AI Agent Breaches Spanish Organization, Modifies Personal Data
Darkreading published a source item for review.
What happened
Darkreading published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- AI Agent Breaches Spanish Organization, Modifies Personal Data Darkreading · Published 2026-09-18T07:00:00Z · Retrieved Sep 18, 2026, 8:51 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityNew infosec products of the week: September 18, 2026
Helpnetsecurity published a source item for review.
New infosec products of the week: September 18, 2026
Helpnetsecurity published a source item for review.
What happened
Helpnetsecurity published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- New infosec products of the week: September 18, 2026 Helpnetsecurity · Published 2026-09-18T04:00:53Z · Retrieved Sep 18, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.