September 23, 2026
Why this day matters
- A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.
- The United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.
Enriched source records
Luna-generated claims retained by the evidence and claim-validation gates. Automated validation does not imply human review. A record does not need a CVE to be included.
Luna-enriched source article · helpnetsecurityProduct showcase: Scamwise checks the red flags before you take the bait
Scamwise is a free Savi service that checks suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud.
Product showcase: Scamwise checks the red flags before you take the bait
Scamwise is a free Savi service that checks suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud.
Source published Sep 23, 2026, 5:00 AM UTC · Evidence retrieved Sep 23, 2026, 8:51 AM UTC
What happened
Scamwise is a free Savi service that checks suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud. [1]
Scamwise works in a web browser on desktop, mobile, or tablet and does not require an account. [2]
Scamwise is also included in Savi’s iOS and Android app, which the source states is currently available only in the United States. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Scamwise is a free scam-checking service from Savi that examines suspicious messages, emails, websites, phone numbers, images, and real-world situations for signs of fraud.
- [2]
The service works in any web browser on desktop, mobile, or tablet, with no account required.
- [3]
Scamwise is included in the Savi app for iOS and Android, which is currently available only in the United States.
Luna-enriched source article · the hacker newsShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
ShinyHunters claimed it breached the U.S. Federal Bureau of Investigation and stole data belonging to current and former FBI employees.
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
ShinyHunters claimed it breached the U.S. Federal Bureau of Investigation and stole data belonging to current and former FBI employees.
Source published Sep 23, 2026, 5:30 AM UTC · Evidence retrieved Sep 23, 2026, 7:23 AM UTC
What happened
ShinyHunters claimed it breached the U.S. Federal Bureau of Investigation and stole data belonging to current and former FBI employees. [1] [2]
In a statement posted on the group’s dark—[source text truncated], ShinyHunters said it held sensitive data on almost all FBI agents and people who had applied for jobs with the FBI. [3] [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S.
- [2]
Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.
- [3]
"We have compromised the FBI.
- [4]
We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark
Luna-enriched source article · helpnetsecurityPrismor: Open-source runtime control plane for AI agents
Prismor is described as a free, open-source security layer for AI coding agents.
Prismor: Open-source runtime control plane for AI agents
Prismor is described as a free, open-source security layer for AI coding agents.
Source published Sep 23, 2026, 5:30 AM UTC · Evidence retrieved Sep 23, 2026, 8:51 AM UTC
What happened
Prismor is described as a free, open-source security layer for AI coding agents. [1]
The layer operates between coding agents such as Claude Code, Codex, or Cursor and the actions they request, checking each tool call against a policy before execution. [2]
Each tool call receives one of three verdicts: allow, warn, or block. [3]
Why it matters
The source identifies coding-agent activities including shell-command execution, file reading and writing, credential handling, and calls to outside APIs. [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Prismor is a free, open-source security layer for AI coding agents.
- [2]
It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before the call runs.
- [3]
Every call gets one of three verdicts: allow, warn, or block.
- [4]
AI coding agents run shell commands, read and write files, handle credentials, and call outside APIs, often chaining many steps … More → The post Prismor: Open-source runtime control plane for AI agents appeared first on Help Net Security .
Luna-enriched source article · the hacker newsCritical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
Vercel said a Next.js vulnerability could let attackers execute code on a server through ImageResponse, which generates Open Graph and other social-preview images.
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
Vercel said a Next.js vulnerability could let attackers execute code on a server through ImageResponse, which generates Open Graph and other social-preview images.
Source published Sep 23, 2026, 7:04 AM UTC · Evidence retrieved Sep 23, 2026, 1:23 PM UTC
What happened
Vercel said a Next.js vulnerability could let attackers execute code on a server through ImageResponse, which generates Open Graph and other social-preview images. [1]
The risk applies when an application inserts attacker-controlled values, such as text read from a request URL, into the generated image. [2]
Vercel said it fixed the flaw on September 22, but the supplied evidence truncates the version number. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said.
- [2]
The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image.
- [3]
Vercel, which develops Next.js, fixed the flaw on September 22 in version
Luna-enriched source article · the hacker newsF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Attackers are exploiting CVE-2026-94127, a critical flaw in F5 BIG-IP Access Policy Manager (APM) that can allow unauthenticated code execution on a BIG-IP system, according to F5.
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Attackers are exploiting CVE-2026-94127, a critical flaw in F5 BIG-IP Access Policy Manager (APM) that can allow unauthenticated code execution on a BIG-IP system, according to F5.
Source published Sep 23, 2026, 8:29 AM UTC · Evidence retrieved Sep 23, 2026, 1:23 PM UTC
What happened
Attackers are exploiting CVE-2026-94127, a critical flaw in F5 BIG-IP Access Policy Manager (APM) that can allow unauthenticated code execution on a BIG-IP system, according to F5. [1] [2]
The vulnerability affects only systems where APM operates as an OAuth authorization server issuing access tokens to applications. [2]
F5 disclosed the vulnerability on September 22 and released engineering hotfixes. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.
- [2]
The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications.
- [3]
F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
Luna-enriched source article · helpnetsecurityClaude Opus 5.5 cuts costs and adds safeguards for autonomous AI
Claude Opus 5.5 is available through Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure.
Claude Opus 5.5 cuts costs and adds safeguards for autonomous AI
Claude Opus 5.5 is available through Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure.
Source published Sep 23, 2026, 8:30 AM UTC · Evidence retrieved Sep 23, 2026, 8:51 AM UTC
What happened
Claude Opus 5.5 is available through Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure. [1]
Developers can access the model through the Claude Platform using the model name claude-opus-5-5. [2]
The model includes watermarking measures designed to comply with the EU AI Act. [3]
Opus 5.5 is designed for long and complex tasks, including codebase migrations, software audits, financial analysis, data collection and workflows involving several applications. [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Claude Opus 5.5 is available across Anthropic’s platforms, Amazon Web Services, Google Cloud and Microsoft Azure.
- [2]
Developers can access it through the Claude Platform using the model name claude-opus-5-5.
- [3]
It includes watermarking measures designed to comply with the EU AI Act.
- [4]
Built for long and complex tasks Opus 5.5 is designed for codebase migrations, software audits, financial analysis, data collection and workflows involving several applications.
Luna-enriched source article · helpnetsecurityMicrosoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
The EvilTokens phishing service compromised more than 12,000 inboxes across over 10,000 organizations, according to the supplied report.
Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes
The EvilTokens phishing service compromised more than 12,000 inboxes across over 10,000 organizations, according to the supplied report.
Source published Sep 23, 2026, 8:34 AM UTC · Evidence retrieved Sep 23, 2026, 8:51 AM UTC
What happened
The EvilTokens phishing service compromised more than 12,000 inboxes across over 10,000 organizations, according to the supplied report. [1]
A coalition led by Microsoft disrupted the EvilTokens service with law-enforcement and private-sector partners. [1]
With authorization from the U.S. District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with multiple partners to seize 50 websites used to operate the service. [2]
The partners disabled more than 150 domains tied to the EvilTokens service; the supplied span truncates the remainder of the sentence. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft.
- [2]
With authorization from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs to seize 50 websites used to operate the service and disable more than 150 domains tied to … More → The post Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes appeared first on Help Net Security .
Luna-enriched source article · helpnetsecurityGPT-6 Sol and Luna arrive with 50% lower API prices
OpenAI expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models.
GPT-6 Sol and Luna arrive with 50% lower API prices
OpenAI expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models.
Source published Sep 23, 2026, 10:08 AM UTC · Evidence retrieved Sep 23, 2026, 2:51 PM UTC
What happened
OpenAI expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models. [1]
GPT-6 Sol and Luna are available in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise, and Edu users. [2]
Free and Go users can access GPT-6 Luna in the desktop app. [3]
The models are not yet available in Chat. [4]
OpenAI API users can access the models as gpt-6-sol and gpt-6-luna. [5]
Why it matters
A phased ChatGPT rollout is underway to maintain service stability. [6]
Known limitations
The supplied evidence does not provide complete information about performance or cost changes. [7]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
OpenAI has expanded GPT-6 with the GPT-6 Sol and GPT-6 Luna models.
- [2]
Both are available in ChatGPT Work and Codex for Plus, Pro, Business, Enterprise, and Edu users.
- [3]
Free and Go users can access GPT-6 Luna in the desktop app.
- [4]
The models are not yet available in Chat.
- [5]
OpenAI API users can access them as gpt-6-sol and gpt-6-luna.
- [6]
A phased ChatGPT rollout is underway to maintain service stability.
- [7]
Performance and cost GPT-6 Sol delivers better … More → The post GPT-6 Sol and Luna arrive with 50% lower API prices appeared first on Help Net Security .
Luna-enriched source article · helpnetsecurityAttackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Check Point released emergency fixes for critical Management Server vulnerability CVE-2026-93616, which had been exploited as early as July 23, 2026.
Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances
Check Point released emergency fixes for critical Management Server vulnerability CVE-2026-93616, which had been exploited as early as July 23, 2026.
Source published Sep 23, 2026, 10:22 AM UTC · Evidence retrieved Sep 23, 2026, 2:51 PM UTC
What happened
Check Point released emergency fixes for critical Management Server vulnerability CVE-2026-93616, which had been exploited as early as July 23, 2026. [1]
Check Point confirmed that CVE-2026-85102, a pre-authentication remote-code-execution vulnerability in Check Point Quantum Security Gateway, was probed a few days after patches were released on September 9, 2026. [2]
Known limitations
The supplied excerpt is truncated and does not provide further details about the attacks, affected configurations, or the status of the fixes. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Check Point Software has released emergency fixes for a critical Check Point Management Server vulnerability (CVE-2026-93616) that has been exploited as far back as July 23, 2026.
- [2]
The company also confirmed that a pre-authentication remote code execution (RCE) vulnerability (CVE-2026-85102) in Check Point (Quantum) Security Gateway for which it released patches on September 9, 2026, started getting probed a few days after.
- [3]
“At the time [of the release of the patches], we had no evidence … More → The post Attackers hit Check Point Management Servers and Spark firewalls, F5 BIG-IP APM instances appeared first on Help Net Security .
Luna-enriched source article · securityaffairsEvilTokens made phishing-as-a-service look easy. Then it got taken down
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing-as-a-service kit operated by Storm-2992 that compromised more than 12,000 inboxes across over 10,000 organizations.
EvilTokens made phishing-as-a-service look easy. Then it got taken down
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing-as-a-service kit operated by Storm-2992 that compromised more than 12,000 inboxes across over 10,000 organizations.
Source published Sep 23, 2026, 11:00 AM UTC · Evidence retrieved Sep 23, 2026, 2:51 PM UTC
What happened
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing-as-a-service kit operated by Storm-2992 that compromised more than 12,000 inboxes across over 10,000 organizations. [1] [2] [3]
EvilTokens used AI to generate targeted phishing emails, analyze compromised mailboxes, identify payment controllers and prioritize accounts for further targeting. [4] [5] [6]
The attack used device-code phishing: victims entered an attacker-generated code on Microsoft’s legitimate login page, authorizing the attacker’s session without exposing the victim’s credentials. [7] [8] [9] [10]
Microsoft’s Digital Crimes Unit seized 50 websites and disabled more than 175 domains tied to the operation, with assistance from multiple technology, security and law-enforcement organizations. [17] [18] [19]
Why it matters
After access, attackers could register devices for persistence beyond password resets, create hidden inbox rules, and impersonate finance staff or vendors to redirect payments. [11] [12] [13]
The reported campaign affected MFA-protected accounts because the victim authorized the attacker’s session through Microsoft’s legitimate authentication flow; the article states the victim’s MFA did not fire. [14] [15] [16]
Some generated claims did not pass validation and were omitted. Only retained claims are shown.
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI.
- [2]
Within months it had compromised more than 12,000 inboxes across over 10,000 organizations.
- [3]
Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold to cybercriminals through Telegram.
- [4]
The platform includes 44 themes and uses AI to create targeted phishing emails based on a victim’s role.
- [5]
Once a mailbox was open, an AI assistant sifted through the contents, mapped who controlled payments, and flagged the accounts worth targeting.
- [6]
“Post-compromise, EvilTokens enabled threat actors to utilize AI assistants to sift through victim mailbox activity and engineer a phishing message based on the accessible email content.
- [7]
“Device code phishing occurs when threat actors insert themselves into this process.
- [8]
“When the user enters the code, they unknowingly authorize the threat actor’s session, granting access to the account without exposing credentials.” That gap between devices is exactly what gets abused.
- [9]
A fake email, styled as an invoice or a DocuSign request, sends the victim to a page that’s quietly requested a real Microsoft device code behind the scenes.
- [10]
The victim sees the code, gets told to enter it on Microsoft’s actual login page to “verify their identity,” and does exactly that.
- [11]
Below is the description provided by Coinbase of the attack on Microsoft’s device code login flow: The attacker’s access tokens survived password resets.
- [12]
Attackers registered devices in Entra ID for persistent access, created hidden inbox rules to suppress alerts and delete evidence, then impersonated finance staff, vendors, or executives inside live payment threads to redirect payments, including cryptocurrency.
- [13]
Attackers registered new devices to keep access alive past a password reset, built hidden inbox rules to bury their tracks, and then slid into ongoing email threads to redirect payments, sometimes in cryptocurrency, sometimes straight to a bank account.
- [14]
The links led to fake Microsoft or DocuSign pages displaying a code and instructing victims to enter it on Microsoft’s real website to “verify their identity.” Doing so authorized the attacker’s session.
- [15]
Because authentication happened on Microsoft’s legitimate infrastructure, MFA was bypassed entirely.
- [16]
The victim’s own MFA never gets a chance to fire, because the attacker’s session is the one that gets approved, not theirs.
- [17]
Taking it down needed more than one company.
- [18]
Microsoft’s Digital Crimes Unit led the legal side, seizing 50 websites and disabling over 175 domains tied to the operation.
- [19]
Coinbase, Cloudflare, Health-ISAC, OpenAI, Railway, SpyCloud, and Shadowserver all contributed pieces, and the mix says something about how these takedowns actually work now: it’s rarely just the software vendor.
Luna-enriched source article · the hacker newsExploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
DepthFirst reported that a Linux kernel use-after-free in the AF_UNIX socket subsystem can enable container escape and host-root access.
Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
DepthFirst reported that a Linux kernel use-after-free in the AF_UNIX socket subsystem can enable container escape and host-root access.
Source published Sep 23, 2026, 11:12 AM UTC · Evidence retrieved Sep 23, 2026, 1:23 PM UTC
What happened
DepthFirst reported that a Linux kernel use-after-free in the AF_UNIX socket subsystem can enable container escape and host-root access. [1]
The vulnerability is tracked as CVE-2026-80521 and has a CVSS score of 7.8. [2]
The upstream fix was made available on August 6, but Ubuntu had not shipped it for Ubuntu 26.04, 24.04, or 22.04 LTS releases at the time described. [2]
Why it matters
The reported impact combines container escape with gaining root privileges on the host. [1]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.
- [2]
The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases.
Luna-enriched source article · the hacker newsNew cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take full control of the server, according to the company.
New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take full control of the server, according to the company.
Source published Sep 23, 2026, 12:16 PM UTC · Evidence retrieved Sep 23, 2026, 1:23 PM UTC
What happened
A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take full control of the server, according to the company. [1]
A separate vulnerability in the WP Toolkit plugin allows an account holder to modify databases belonging to other accounts. [2]
cPanel has released fixed versions for both vulnerabilities. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22.
- [2]
A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.
- [3]
cPanel has released fixed versions for both,
Luna-enriched source article · helpnetsecurityFake Claude Max giveaway tricks users into handing over their Google account credentials
Malwarebytes researchers found a fake Claude Max giveaway using a spoofed Google sign-in window to steal users’ login credentials.
Fake Claude Max giveaway tricks users into handing over their Google account credentials
Malwarebytes researchers found a fake Claude Max giveaway using a spoofed Google sign-in window to steal users’ login credentials.
Source published Sep 23, 2026, 1:03 PM UTC · Evidence retrieved Sep 23, 2026, 2:51 PM UTC
What happened
Malwarebytes researchers found a fake Claude Max giveaway using a spoofed Google sign-in window to steal users’ login credentials. [1]
The campaign used a “browser-in-the-browser” phishing technique, which researchers have documented since 2022. [2] [3]
Stefan Dasic, the Malwarebytes researcher who analyzed the campaign, said phishing follows what people currently want. [5]
Why it matters
The campaign targeted users interested in Claude’s paid plans and sought Google account credentials through the spoofed sign-in window. [1] [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
A fake Claude Max giveaway uses a spoofed Google sign-in window to steal users’ login credentials, Malwarebytes researchers have found.
- [2]
“Browser-in-the-browser” is not a new technique.
- [3]
Researchers have documented it since 2022, and in June Palo Alto Networks’ Unit 42 reported a campaign that used draggable fake browser windows to target Microsoft 365 users.
- [4]
“Claude’s paid plans … More → The post Fake Claude Max giveaway tricks users into handing over their Google account credentials appeared first on Help Net Security .
- [5]
“Phishing follows whatever people want at the moment,” noted Stefan Dasic, the Malwarebytes researcher who analyzed the campaign.
Luna-enriched source article · helpnetsecurityLookout targets smishing, voice cloning, and vishing with real-time mobile protection
Lookout launched Social Engineering Protection (SEP), a module within its Mobile AI Security Platform.
Lookout targets smishing, voice cloning, and vishing with real-time mobile protection
Lookout launched Social Engineering Protection (SEP), a module within its Mobile AI Security Platform.
Source published Sep 23, 2026, 1:06 PM UTC · Evidence retrieved Sep 23, 2026, 2:51 PM UTC
What happened
Lookout launched Social Engineering Protection (SEP), a module within its Mobile AI Security Platform. [1]
Lookout says SEP provides automated, real-time protection against AI-driven mobile threats, including linkless smishing, synthetic voice cloning, and other vishing techniques. [2]
Why it matters
The source characterizes frontier AI as enabling social-engineering deception with greater realism, personalization, and scale. [3]
The source states that advanced AI models can generate context-aware messages tailored to individual employees. [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Lookout has launched Social Engineering Protection (SEP), a new module within the Lookout Mobile AI Security Platform.
- [2]
SEP provides automated, real-time protection against the next generation of AI-driven mobile threats, including linkless smishing attacks, synthetic voice cloning, and other voice phishing (vishing) techniques.
- [3]
Frontier AI is transforming social engineering by enabling attackers to create highly convincing deception with unprecedented realism, personalization, and scale.
- [4]
Advanced AI models can craft context-aware messages tailored to individual employees, while … More → The post Lookout targets smishing, voice cloning, and vishing with real-time mobile protection appeared first on Help Net Security .
Luna-enriched source article · helpnetsecurityBarracuda brings AI security and governance within reach of smaller organizations
Barracuda Networks launched Barracuda AI Data Security, an AI security and governance solution designed for resource-constrained organizations and managed service providers.
Barracuda brings AI security and governance within reach of smaller organizations
Barracuda Networks launched Barracuda AI Data Security, an AI security and governance solution designed for resource-constrained organizations and managed service providers.
Source published Sep 23, 2026, 1:20 PM UTC · Evidence retrieved Sep 23, 2026, 2:51 PM UTC
What happened
Barracuda Networks launched Barracuda AI Data Security, an AI security and governance solution designed for resource-constrained organizations and managed service providers. [1]
The solution is intended to protect sensitive data, enforce responsible AI use, and demonstrate compliance as businesses adopt AI. [2]
Built on the BarracudaONE platform, Barracuda AI Data Security combines AI visibility, data protection, threat defense, and governance in one solution. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Barracuda Networks has launched Barracuda AI Data Security, the AI security and governance solution purpose-built for resource-constrained organizations and managed service providers (MSPs).
- [2]
The solution enables businesses to accelerate AI adoption by protecting sensitive data, enforcing responsible AI use and demonstrating compliance.
- [3]
Built on the BarracudaONE platform, the solution combines AI visibility, data protection, threat defense, and governance into a single … More → The post Barracuda brings AI security and governance within reach of smaller organizations appeared first on Help Net Security .
Luna-enriched source article · helpnetsecurityNetwork Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure
Network Solutions launched Dark Web Monitoring, which alerts small businesses when information associated with their domain appears in known breach data and provides risk-reduction steps.
Network Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure
Network Solutions launched Dark Web Monitoring, which alerts small businesses when information associated with their domain appears in known breach data and provides risk-reduction steps.
Source published Sep 23, 2026, 1:40 PM UTC · Evidence retrieved Sep 23, 2026, 2:51 PM UTC
What happened
Network Solutions launched Dark Web Monitoring, which alerts small businesses when information associated with their domain appears in known breach data and provides risk-reduction steps. [1]
Why it matters
Stolen credentials and other breach-exposed information can circulate through dark web marketplaces, forums and other sources. [2]
The source characterizes domain-linked exposure as potentially leading to account takeovers, compromised email, impersonation and unauthorized access to sensitive business information. [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Network Solutions has launched Dark Web Monitoring, a new security capability that alerts small businesses when information associated with their domain appears in known breach data and provides steps they can take to reduce risk.
- [2]
Stolen credentials and other information exposed in data breaches can circulate across dark web marketplaces, forums and other sources.
- [3]
For a small business, that exposure can lead to account takeovers, compromised email, impersonation and unauthorized access to sensitive business or … More → The post Network Solutions Dark Web Monitoring alerts small businesses to domain-linked data exposure appeared first on Help Net Security .
Luna-enriched source article · helpnetsecurityPortnox detects and removes unauthorized AI applications from managed devices
Portnox announced capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy by restricting, quarantining, or removing unapproved or risky applications when detected.
Portnox detects and removes unauthorized AI applications from managed devices
Portnox announced capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy by restricting, quarantining, or removing unapproved or risky applications when detected.
Source published Sep 23, 2026, 1:49 PM UTC · Evidence retrieved Sep 23, 2026, 2:51 PM UTC
What happened
Portnox announced capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy by restricting, quarantining, or removing unapproved or risky applications when detected. [1]
Why it matters
The capability addresses shadow AI, including generative AI applications that can act as autonomous agents and access local files, remote resources, and enterprise data using the logged-in user’s permissions. [2]
Known limitations
The supplied material does not specify detection coverage, deployment requirements, enforcement configuration, or performance results. [1] [2] [3]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Portnox has announced new capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy, restricting, quarantining, or removing unapproved or risky applications the moment they’re detected.
- [2]
The capability addresses shadow AI: generative AI applications that increasingly act as autonomous agents, reaching local files, remote resources, and enterprise data with the same permissions as the logged-in user.
- [3]
As this footprint grows faster than most organizations can track, Portnox gives IT … More → The post Portnox detects and removes unauthorized AI applications from managed devices appeared first on Help Net Security .
Luna-enriched source article · securityaffairsShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
ShinyHunters claims it breached FBI recruitment infrastructure using an Oracle PeopleSoft zero-day and stole sensitive data on FBI personnel and applicants; the FBI says it is investigating but has not confirmed a compromise.
ShinyHunters claims FBI breach after alleged PeopleSoft zero-day attack
ShinyHunters claims it breached FBI recruitment infrastructure using an Oracle PeopleSoft zero-day and stole sensitive data on FBI personnel and applicants; the FBI says it is investigating but has not confirmed a compromise.
Source published Sep 23, 2026, 1:56 PM UTC · Evidence retrieved Sep 23, 2026, 2:51 PM UTC
What happened
ShinyHunters claims it breached FBI recruitment infrastructure using an Oracle PeopleSoft zero-day and stole sensitive data on FBI personnel and applicants; the FBI says it is investigating but has not confirmed a compromise. [1] [2] [3] [4] [5]
The group reportedly offered about 5,000 records and claimed the data could include names, contact details, Social Security numbers, assignments and family information. [6] [7]
Reuters partially matched some sample details, including records associated with FBI Director Kash Patel, but could not determine the data’s original source or independently confirm theft from FBI systems. [8] [9] [10] [11]
The alleged intrusion explanation is technically plausible because ShinyHunters was previously linked to exploitation of a PeopleSoft vulnerability, but no public CVE or vendor confirmation exists for the alleged new flaw. [14] [15] [16] [17] [18]
The FBI recruitment website experienced disruption around the claim, but that disruption alone does not prove that wider FBI systems were breached. [19] [20] [21] [22] [23]
Why it matters
If confirmed, exposure of law-enforcement personnel data could enable targeted harassment, social engineering and other abuse involving agents and their families. [12] [13]
Known limitations
The breach, extent of access and origin of the records remain unconfirmed pending the FBI investigation; the ShinyHunters account should therefore remain a claim rather than an established FBI breach. [24] [25] [26]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet.
- [2]
Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants.
- [3]
A person familiar with the matter said that the job descriptions in the data also matched in at least some cases.” The FBI has acknowledged that it is aware of claims involving unauthorized activity affecting FBIjobs.gov and said it is investigating.
- [4]
The agency has not confirmed that its internal systems were compromised or that ShinyHunters obtained the data it claims to possess.
- [5]
The group claims the exploitation of an Oracle PeopleSoft zero-day, reportedly using it to gain remote code execution through infrastructure connected to the FBI’s recruitment services.
- [6]
The claim surfaced on September 22 and quickly drew attention after ShinyHunters said it had obtained data on a large number of current and former FBI personnel.
- [7]
The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details.
- [8]
Reuters was able to partially match some of the sample information with other records, including data associated with FBI Director Kash Patel.
- [9]
However, the news agency could not determine where the information originally came from or independently confirm that it had been stolen from FBI systems.
- [10]
“Reuters was able to partially verify the authenticity of the information by running the details, including the Social Security numbers, against credit bureau records and previously breached data preserved by the dark-web intelligence firm District 4 Labs.” reads the report published by Reuters.
- [11]
“In at least 10 instances — including in the case of FBI Director Kash Patel — Reuters found details that appeared to match.
- [12]
What is already clear is that the incident would be serious if confirmed.
- [13]
Personal information belonging to law enforcement personnel could expose agents and their families to targeted harassment, social engineering and other forms of abuse.
- [14]
The claim is notable because ShinyHunters has already been linked to attacks exploiting a real PeopleSoft zero-day earlier this year.
- [15]
In June, Oracle addressed CVE-2026-35273 , a critical unauthenticated remote code execution vulnerability in PeopleSoft PeopleTools.
- [16]
Google and Mandiant later linked exploitation of that flaw to ShinyHunters activity targeting organizations, particularly in the education sector.
- [17]
That history makes the latest claim technically plausible, but it does not prove that the same group used another PeopleSoft zero-day against the FBI.
- [18]
No public CVE or vendor confirmation currently exists for the alleged new vulnerability.
- [19]
The attackers also reportedly claimed access to several FBI-related services, including human resources systems and a system they referred to as Medlink.
- [20]
They allegedly said that between 2 TB and 3 TB of data had been taken and that the FBI jobs infrastructure had been compromised.
- [21]
Reuters and other media outlets confirmed the recruitment website did experience disruption around the time of the claim.
- [22]
A page that had reportedly been defaced by the attackers later displayed a scheduled-maintenance message.
- [23]
That disruption could be consistent with an intrusion, but it is not by itself proof that the wider FBI systems were breached.
- [24]
For now, however, the FBI investigation remains the missing piece.
- [25]
Until investigators confirm the intrusion, the extent of access and the origin of the leaked records, the ShinyHunters account should remain a claim rather than an established FBI breach.
- [26]
But the available evidence does not yet allow those consequences to be attributed to a confirmed compromise of FBI internal systems.
Luna-enriched source article · helpnetsecurity80,000 relay servers help users in China slip past U.S. AI region bans
Team Cymru reported that more than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U.S. AI models.
80,000 relay servers help users in China slip past U.S. AI region bans
Team Cymru reported that more than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U.S. AI models.
Source published Sep 23, 2026, 1:57 PM UTC · Evidence retrieved Sep 23, 2026, 2:51 PM UTC
What happened
Team Cymru reported that more than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U.S. AI models. [1] [2]
Scott Fisher of Team Cymru said the uncovered activity constitutes an ecosystem designed to break frontier model providers’ terms and conditions and enable fraud and illicit activity. [3]
Why it matters
The article states that CISA, the NSA and the FBI previously warned in a joint advisory about China-based AI firms running large-scale knowledge-related activity; the supplied text is truncated before further detail. [4]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
More than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U.S.
- [2]
AI models, according to Team Cymru.
- [3]
“What we have uncovered is an entire ecosystem designed explicitly to break the frontier model providers’ T&Cs, enabling fraud and illicit activity,” said Scott Fisher, Senior Principal Engineer at Team Cymru.
- [4]
Earlier this month, CISA, the NSA and the FBI warned in a joint advisory that China-based AI firms are running large-scale knowledge … More → The post 80,000 relay servers help users in China slip past U.S.
Luna-enriched source article · helpnetsecurityCofense measures employee readiness against real-world phishing threats
Cofense announced an expansion of its AI-driven Phishing Defense Platform through Cofense Command Center, an orchestration layer for measurement and reporting.
Cofense measures employee readiness against real-world phishing threats
Cofense announced an expansion of its AI-driven Phishing Defense Platform through Cofense Command Center, an orchestration layer for measurement and reporting.
Source published Sep 23, 2026, 2:01 PM UTC · Evidence retrieved Sep 23, 2026, 2:51 PM UTC
What happened
Cofense announced an expansion of its AI-driven Phishing Defense Platform through Cofense Command Center, an orchestration layer for measurement and reporting. [1]
The Competency Dashboard measures how employees recognize, report, and respond to phishing threats. [2]
The measurement advances Secure Behavior Management, described as building competency, tracking behavior, and showing progress across a phishing-defense program. [3]
The Competency Dashboard was described as available now. [4]
Why it matters
The dashboard is intended to give security teams evidence of phishing-program effectiveness rather than only training-completion data. [2]
Cited source evidence
These excerpts support the numbered claims above. They come from one source article and do not establish independent corroboration.
- [1]
Cofense has announced an expansion of its AI-driven Phishing Defense Platform through Cofense Command Center, its orchestration layer for measurement and reporting.
- [2]
The new Competency Dashboard measures how employees recognize, report and respond to phishing threats, giving security teams evidence of program effectiveness rather than training completion.
- [3]
This measurement advances Secure Behavior Management (SBM), an approach that builds competency, tracks behavior, and shows progress across a phishing defense program.
- [4]
The Competency Dashboard, available now, drives … More → The post Cofense measures employee readiness against real-world phishing threats appeared first on Help Net Security .
Additional source records
Material developmentsUAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
Darkreading published a source item for review.
UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
Darkreading published a source item for review.
What happened
Darkreading published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks Darkreading · Published 2026-09-23T16:01:00Z · Retrieved Sep 23, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsSupporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever
Amazon Web Services published a source item for review.
Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever
Amazon Web Services published a source item for review.
What happened
Amazon Web Services published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Supporting ASD’s multi-factor authentication campaign: Why MFA matters more than ever Amazon Web Services · Published 2026-09-23T14:45:44Z · Retrieved Sep 23, 2026, 7:11 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsBurnham announces plan for new UK center to fight disinformation
Therecord Media published a source item for review.
Burnham announces plan for new UK center to fight disinformation
Therecord Media published a source item for review.
What happened
Therecord Media published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Burnham announces plan for new UK center to fight disinformation Therecord Media · Published 2026-09-23T12:30:00Z · Retrieved Sep 23, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsAdobe Patches Critical Flaws in Connect, AEM Forms
Securityweek published a source item for review.
Adobe Patches Critical Flaws in Connect, AEM Forms
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Adobe Patches Critical Flaws in Connect, AEM Forms Securityweek · Published 2026-09-23T11:40:59Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsChrome 154 Patches 108 Vulnerabilities
Securityweek published a source item for review.
Chrome 154 Patches 108 Vulnerabilities
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Chrome 154 Patches 108 Vulnerabilities Securityweek · Published 2026-09-23T10:36:07Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Material developmentsShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
Infosecurity Magazine published a source item for review.
ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day
Infosecurity Magazine published a source item for review.
What happened
Infosecurity Magazine published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- ShinyHunters Claims FBI Hack Via PeopleSoft Zero Day Infosecurity Magazine · Published 2026-09-23T10:00:00Z · Retrieved Sep 23, 2026, 2:52 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsAttackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
Darkreading published a source item for review.
Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
Darkreading published a source item for review.
What happened
Darkreading published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign Darkreading · Published 2026-09-23T14:47:09Z · Retrieved Sep 23, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsDarkMe RAT trades zero-days for plain phishing emails
Helpnetsecurity published a source item for review.
DarkMe RAT trades zero-days for plain phishing emails
Helpnetsecurity published a source item for review.
What happened
Helpnetsecurity published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- DarkMe RAT trades zero-days for plain phishing emails Helpnetsecurity · Published 2026-09-23T13:24:17Z · Retrieved Sep 23, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsArista patches actively exploited VeloCloud Orchestrator zero-day
Bleepingcomputer reports active exploitation in this exact source item.
Arista patches actively exploited VeloCloud Orchestrator zero-day
Bleepingcomputer reports active exploitation in this exact source item.
What happened
Bleepingcomputer reports active exploitation in this exact source item.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Prioritize exposure review and remediation because exploitation is explicitly confirmed.
Evidence
- Arista patches actively exploited VeloCloud Orchestrator zero-day Bleepingcomputer · Published 2026-09-23T12:29:53Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsAI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
Securityweek published a source item for review.
AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- AI-Powered Phishing Platform EvilTokens Disrupted by Microsoft Securityweek · Published 2026-09-23T11:23:30Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsArista Urges Immediate Patching of Exploited VCO Zero-Day
Securityweek published a source item for review.
Arista Urges Immediate Patching of Exploited VCO Zero-Day
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Arista Urges Immediate Patching of Exploited VCO Zero-Day Securityweek · Published 2026-09-23T08:33:06Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
The Hacker News published details for CVE-2026-85046, CVE-2026-85880, CVE-2026-87491.
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
The Hacker News published details for CVE-2026-85046, CVE-2026-85880, CVE-2026-87491.
What happened
The Hacker News published details for CVE-2026-85046, CVE-2026-85880, CVE-2026-87491.
Why it matters
A reviewed impact interpretation has not been published for this record.
Structured associations
Reviewed next steps
- Check asset inventory and patch status for CVE-2026-85046, CVE-2026-85880, CVE-2026-87491.
Evidence
- Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware The Hacker News · Published 2026-09-23T08:29:24Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsFake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools
Securityaffairs published a source item for review.
Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools
Securityaffairs published a source item for review.
What happened
Securityaffairs published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Validate the source-stated mitigation in a controlled environment before rollout.
Evidence
- Fake LastPass on GitHub Led to an Infostealer That Killed 145 Security Tools Securityaffairs · Published 2026-09-23T08:25:27Z · Retrieved Sep 23, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsCVE-2026-87902: how close is your WordPress to remote code execution?
Securityaffairs published details for CVE-2026-87902.
CVE-2026-87902: how close is your WordPress to remote code execution?
Securityaffairs published details for CVE-2026-87902.
What happened
Securityaffairs published details for CVE-2026-87902.
Why it matters
A reviewed impact interpretation has not been published for this record.
Structured associations
Reviewed next steps
- Check asset inventory and patch status for CVE-2026-87902.
Evidence
- CVE-2026-87902: how close is your WordPress to remote code execution? Securityaffairs · Published 2026-09-23T07:36:14Z · Retrieved Sep 23, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsCritical F5 BIG-IP Vulnerability Exploited as Zero-Day
Securityweek published a source item for review.
Critical F5 BIG-IP Vulnerability Exploited as Zero-Day
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Critical F5 BIG-IP Vulnerability Exploited as Zero-Day Securityweek · Published 2026-09-23T07:34:18Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsF5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
Bleepingcomputer published a source item for review.
F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
Bleepingcomputer published a source item for review.
What happened
Bleepingcomputer published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks Bleepingcomputer · Published 2026-09-23T07:17:23Z · Retrieved Sep 23, 2026, 7:23 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Threat and risk signalsCheck Point Patches Exploited Management Server Zero-Day
Securityweek published a source item for review.
Check Point Patches Exploited Management Server Zero-Day
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Check Point Patches Exploited Management Server Zero-Day Securityweek · Published 2026-09-23T06:14:03Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Cloud and infrastructureMicrosoft: September Windows updates break Always On VPN connections
Bleepingcomputer published a source item for review.
Microsoft: September Windows updates break Always On VPN connections
Bleepingcomputer published a source item for review.
What happened
Bleepingcomputer published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Microsoft: September Windows updates break Always On VPN connections Bleepingcomputer · Published 2026-09-23T11:18:13Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureFBI investigating alleged ShinyHunters breach of its jobs site
Therecord Media published a source item for review.
FBI investigating alleged ShinyHunters breach of its jobs site
Therecord Media published a source item for review.
What happened
Therecord Media published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- FBI investigating alleged ShinyHunters breach of its jobs site Therecord Media · Published 2026-09-23T14:22:00Z · Retrieved Sep 23, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureLatvia arrests suspected hacker for electronics repair company breach
Therecord Media published a source item for review.
Latvia arrests suspected hacker for electronics repair company breach
Therecord Media published a source item for review.
What happened
Therecord Media published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Latvia arrests suspected hacker for electronics repair company breach Therecord Media · Published 2026-09-23T12:45:00Z · Retrieved Sep 23, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureRansomware Attacks Reach Record High for 2026
Infosecurity Magazine published a source item for review.
Ransomware Attacks Reach Record High for 2026
Infosecurity Magazine published a source item for review.
What happened
Infosecurity Magazine published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Ransomware Attacks Reach Record High for 2026 Infosecurity Magazine · Published 2026-09-23T12:00:00Z · Retrieved Sep 23, 2026, 2:52 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureEU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response
Infosecurity Magazine published a source item for review.
EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response
Infosecurity Magazine published a source item for review.
What happened
Infosecurity Magazine published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- EU Auditors Warn Information-Sharing Gaps Are Hindering Cyber Incident Response Infosecurity Magazine · Published 2026-09-23T08:30:00Z · Retrieved Sep 23, 2026, 8:52 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureRyuk ransomware member sentenced to 24 months in prison
Bleepingcomputer published a source item for review.
Ryuk ransomware member sentenced to 24 months in prison
Bleepingcomputer published a source item for review.
What happened
Bleepingcomputer published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Ryuk ransomware member sentenced to 24 months in prison Bleepingcomputer · Published 2026-09-23T08:20:05Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
Incidents and exposureShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
Securityweek published a source item for review.
ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- ShinyHunters Claims FBI Hack, Demands Retraction of Threat Report Securityweek · Published 2026-09-23T07:13:49Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityWindows Botnet x47.c Offers AI API Draining, 18 Attack Methods
Infosecurity Magazine published a source item for review.
Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods
Infosecurity Magazine published a source item for review.
What happened
Infosecurity Magazine published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Windows Botnet x47.c Offers AI API Draining, 18 Attack Methods Infosecurity Magazine · Published 2026-09-23T14:00:00Z · Retrieved Sep 23, 2026, 2:52 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityHoneywell: OT Security Teams Embrace AI, but Autonomy Still Rare
Securityweek published a source item for review.
Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Honeywell: OT Security Teams Embrace AI, but Autonomy Still Rare Securityweek · Published 2026-09-23T12:17:28Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityThe president has called for AI leadership. Here’s the mission.
Cyberscoop published a source item for review.
The president has called for AI leadership. Here’s the mission.
Cyberscoop published a source item for review.
What happened
Cyberscoop published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- The president has called for AI leadership. Here’s the mission. Cyberscoop · Published 2026-09-23T12:17:20Z · Retrieved Sep 23, 2026, 2:51 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model reality545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
The Hacker News published a source item for review.
545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
The Hacker News published a source item for review.
What happened
The Hacker News published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- 545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent The Hacker News · Published 2026-09-23T11:47:19Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityAnthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
The Hacker News published a source item for review.
Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
The Hacker News published a source item for review.
What happened
The Hacker News published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests The Hacker News · Published 2026-09-23T11:47:13Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityA Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk
Securityweek published a source item for review.
A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- A Look at AI Doomsday Scenarios That Researchers Say Could Put Humanity at Risk Securityweek · Published 2026-09-23T10:20:36Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityOuterlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm
Securityweek published a source item for review.
Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm
Securityweek published a source item for review.
What happened
Securityweek published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm Securityweek · Published 2026-09-23T10:00:00Z · Retrieved Sep 23, 2026, 1:23 PM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.
AI and model realityNearly two-thirds of tested websites fail every bot test
Helpnetsecurity published a source item for review.
Nearly two-thirds of tested websites fail every bot test
Helpnetsecurity published a source item for review.
What happened
Helpnetsecurity published a source item for review.
Why it matters
A reviewed impact interpretation has not been published for this record.
Reviewed next steps
- Review the exact source item and determine whether it changes exposure or monitoring priorities.
Evidence
- Nearly two-thirds of tested websites fail every bot test Helpnetsecurity · Published 2026-09-23T04:30:37Z · Retrieved Sep 23, 2026, 8:51 AM UTC
Known limitation
This item is supported by one source record and has not been independently corroborated here.