Latest Cybersecurity News and Articles
18 September 2026
Noteworthy stories that might have slipped under the radar: Mandiant's 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited.
The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw appeared first on SecurityWeek.
18 September 2026
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.
The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.
"Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"
18 September 2026
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.
The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek.
18 September 2026
Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access.
The post 23 Million User Records Compromised in Gyazo Data Breach appeared first on SecurityWeek.
18 September 2026

US cybersecurity researchers who conducted hack say ‘scope of what we could theoretically access was huge’Cybersecurity researchers have hacked into OpenAI with the help of Anthropic’s Claude chatbot, in the latest example of security issues at the company.A team at a US-based startup compromised a number of OpenAI employees’ ChatGPT accounts, starting a process that enabled them to access their target’s software cache – and potentially more. Continue reading...
18 September 2026
In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references to hostnames beneath it.
The new owner holds
18 September 2026
A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.
The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no
18 September 2026
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek.
18 September 2026
Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.
The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and
18 September 2026
Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world.
The post NightmareStresser DDoS Service Disrupted in International Operation appeared first on SecurityWeek.
18 September 2026
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
The post Brevo Supply Chain Attack Injects Malware Into 100,000 Websites appeared first on SecurityWeek.
18 September 2026
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.
"The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,"
18 September 2026
CVE-2026-58138 is an unauthenticated remote code execution vulnerability that attackers can exploit via inline workflow definitions.
The post Critical Orkes Conductor Vulnerability Exploited in Attacks appeared first on SecurityWeek.
18 September 2026
The company will use the funding to accelerate platform development and expand its presence in key enterprise markets.
The post MIND Secures $72 Million for AI-Powered DLP appeared first on SecurityWeek.
18 September 2026
Check Point Security Management and Log Servers are affected by a critical vulnerability that can allow remote code execution with root privileges.
The post Check Point, Kaspersky, Tanium Patch Product Vulnerabilities appeared first on SecurityWeek.
18 September 2026
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices.
"Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses
17 September 2026
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network.
The Security Management Server is the system that controls firewall policy and administrator access. Check Point has released a fix through its LivePatch update channel and says it has no indication that the flaw
17 September 2026
Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them.
This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough.
So the threat landscape is not getting cleaner. It is just
17 September 2026
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.
The post Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels appeared first on SecurityWeek.
17 September 2026
OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior.
The post OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training appeared first on SecurityWeek.