<?xml version='1.0' encoding='utf-8'?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>CSOH - Cloud Security News</title>
    <link>https://csoh.org/news.html</link>
    <description>Latest cloud security news curated by Cloud Security Office Hours. Covers AWS, Azure, GCP, Kubernetes vulnerabilities, breaches, and more.</description>
    <language>en-us</language>
    <managingEditor>admin@csoh.org (CSOH)</managingEditor>
    <webMaster>admin@csoh.org (CSOH)</webMaster>
    <lastBuildDate>Wed, 16 Sep 2026 15:13:12 +0000</lastBuildDate>
    <ttl>720</ttl>
    <atom:link href="https://csoh.org/feed.xml" rel="self" type="application/rss+xml" />
    <image>
      <url>https://csoh.org/favicon.png</url>
      <title>CSOH - Cloud Security News</title>
      <link>https://csoh.org/news.html</link>
    </image>
    <item>
      <title>Operation RapidRust: APT36 Deploys RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH</title>
      <link>https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and</link>
      <description>IntroductionIn August 2026, Zscaler ThreatLabz observed new activity by the Pakistan-nexus threat actor APT36 in a campaign we’re tracking as Operation RapidRust. Since our last publication about the group’s activity...</description>
      <source url="https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and">Zscaler ThreatLabz</source>
      <guid isPermaLink="true">https://www.zscaler.com/blogs/security-research/operation-rapidrust-apt36-deploys-rustyshade-rustymove-psnatch-and</guid>
      <pubDate>Wed, 16 Sep 2026 15:13:12 +0000</pubDate>
      <category>Threat Research</category>
    </item>
    <item>
      <title>PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug</title>
      <link>https://www.infosecurity-magazine.com/news/woocommerce-wholesale-lead-capture</link>
      <description>Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells</description>
      <source url="https://www.infosecurity-magazine.com/news/woocommerce-wholesale-lead-capture">Infosecurity Magazine</source>
      <guid isPermaLink="true">https://www.infosecurity-magazine.com/news/woocommerce-wholesale-lead-capture</guid>
      <pubDate>Wed, 16 Sep 2026 15:00:00 +0000</pubDate>
      <category>Vulnerability</category>
      <category>Threat Research</category>
    </item>
    <item>
      <title>Coast Guard, FBI board US-bound foreign ships in order to probe for cyberattacks</title>
      <link>https://cyberscoop.com/coast-guard-fbi-investigate-tanker-cyberattacks</link>
      <description>The agencies issued a joint statement saying the “joint security boardings” came in response to “indications that the networks of both vessels were compromised.” The post Coast Guard, FBI board US-bound foreign ships...</description>
      <source url="https://cyberscoop.com/coast-guard-fbi-investigate-tanker-cyberattacks">CyberScoop</source>
      <guid isPermaLink="true">https://cyberscoop.com/coast-guard-fbi-investigate-tanker-cyberattacks</guid>
      <pubDate>Wed, 16 Sep 2026 14:48:07 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Virtual Event Today: Attack Surface Management Summit</title>
      <link>https://www.securityweek.com/virtual-event-today-attack-surface-management-summit-2</link>
      <description>Join SecurityWeek today for a virtual summit exploring the strategies and tools organizations need to discover, prioritize, and defend their expanding attack surfaces. The post Virtual Event Today: Attack Surface Mana...</description>
      <source url="https://www.securityweek.com/virtual-event-today-attack-surface-management-summit-2">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/virtual-event-today-attack-surface-management-summit-2</guid>
      <pubDate>Wed, 16 Sep 2026 14:35:04 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>EU Chief Warns of AI-Powered Hacking, Moves to Rein In Social Media</title>
      <link>https://www.securityweek.com/eu-chief-warns-of-ai-powered-hacking-moves-to-rein-in-social-media</link>
      <description>Ursula von der Leyen warns that advanced AI could unleash hacking on an unprecedented scale as Europe prepares new protections against social media’s “capture” of children. The post EU Chief Warns of AI-Powered Hackin...</description>
      <source url="https://www.securityweek.com/eu-chief-warns-of-ai-powered-hacking-moves-to-rein-in-social-media">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/eu-chief-warns-of-ai-powered-hacking-moves-to-rein-in-social-media</guid>
      <pubDate>Wed, 16 Sep 2026 14:15:18 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Oracle Critical Security Patch Update, September 2026 Review</title>
      <link>https://blog.qualys.com/vulnerabilities-threat-research/2026/09/16/oracle-critical-security-patch-update-september-2026-review</link>
      <description>Oracle released its September edition of Critical Security Patch Update. The update received patches for 673 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product....</description>
      <source url="https://blog.qualys.com/vulnerabilities-threat-research/2026/09/16/oracle-critical-security-patch-update-september-2026-review">Qualys Blog</source>
      <guid isPermaLink="true">https://blog.qualys.com/vulnerabilities-threat-research/2026/09/16/oracle-critical-security-patch-update-september-2026-review</guid>
      <pubDate>Wed, 16 Sep 2026 14:15:08 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Treasury’s Scott Bessent says no liability exemptions for AI labs</title>
      <link>https://fedscoop.com/treasury-scott-bessent-ai-labs-liability-exemptions</link>
      <description>The secretary told House Financial Services Committee lawmakers that the “best way to guarantee safety” is for AI creators to be held “liable for what they build and generate.” The post Treasury’s Scott Bessent says n...</description>
      <source url="https://fedscoop.com/treasury-scott-bessent-ai-labs-liability-exemptions">CyberScoop</source>
      <guid isPermaLink="true">https://fedscoop.com/treasury-scott-bessent-ai-labs-liability-exemptions</guid>
      <pubDate>Wed, 16 Sep 2026 14:10:19 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>The true cost of a ransomware attack, with and without BCDR</title>
      <link>https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr</link>
      <description>The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can...</description>
      <source url="https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr">BleepingComputer</source>
      <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr</guid>
      <pubDate>Wed, 16 Sep 2026 10:00:10 -0400</pubDate>
      <category>Ransomware</category>
    </item>
    <item>
      <title>CISA and NIST Issue Guidance to Protect Cloud Identity Tokens</title>
      <link>https://www.infosecurity-magazine.com/news/cisa-nist-cloud-identity-token</link>
      <description>CISA and NIST issued final guidance to help protect cloud identity tokens and assertions</description>
      <source url="https://www.infosecurity-magazine.com/news/cisa-nist-cloud-identity-token">Infosecurity Magazine</source>
      <guid isPermaLink="true">https://www.infosecurity-magazine.com/news/cisa-nist-cloud-identity-token</guid>
      <pubDate>Wed, 16 Sep 2026 14:00:00 +0000</pubDate>
      <category>CISA</category>
      <category>Identity</category>
    </item>
    <item>
      <title>AIUC Raises $40 Million to Certify Enterprise AI Agents</title>
      <link>https://www.securityweek.com/aiuc-raises-40-million-to-certify-enterprise-ai-agents</link>
      <description>The company provides a standard for AI systems, testing them against risks such as jailbreaks, prompt injections, and unauthorized actions. The post AIUC Raises $40 Million to Certify Enterprise AI Agents appeared fir...</description>
      <source url="https://www.securityweek.com/aiuc-raises-40-million-to-certify-enterprise-ai-agents">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/aiuc-raises-40-million-to-certify-enterprise-ai-agents</guid>
      <pubDate>Wed, 16 Sep 2026 13:38:36 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories</title>
      <link>https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html</link>
      <description>Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spre...</description>
      <source url="https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html">The Hacker News</source>
      <guid isPermaLink="true">https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html</guid>
      <pubDate>Wed, 16 Sep 2026 19:07:07 +0530</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>EU chief wants joint response to cyberattacks, sabotage</title>
      <link>https://therecord.media/eu-chief-wants-joint-response-to-cyberattacks</link>
      <description>Delivering her annual State of the Union address in Strasbourg, Ursula von der Leyen said threats were “mounting on our soil,” pointing to recent incidents in Denmark, Lithuania and Poland and an attempted drone attac...</description>
      <source url="https://therecord.media/eu-chief-wants-joint-response-to-cyberattacks">The Record</source>
      <guid isPermaLink="true">https://therecord.media/eu-chief-wants-joint-response-to-cyberattacks</guid>
      <pubDate>Wed, 16 Sep 2026 13:14:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Pixel Modem Zero-Day Exploited in Targeted Attacks</title>
      <link>https://www.securityweek.com/pixel-modem-zero-day-exploited-in-targeted-attacks</link>
      <description>Google announced patches for the exploited privilege escalation vulnerability (CVE-2026-58704) on September 15. The post Pixel Modem Zero-Day Exploited in Targeted Attacks appeared first on SecurityWeek .</description>
      <source url="https://www.securityweek.com/pixel-modem-zero-day-exploited-in-targeted-attacks">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/pixel-modem-zero-day-exploited-in-targeted-attacks</guid>
      <pubDate>Wed, 16 Sep 2026 13:10:54 +0000</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>Revolut Data Leak May Trace Back to Compromised Italian Government Accounts</title>
      <link>https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace-back-to-compromised-italian-government-accounts.html</link>
      <description>A suspected compromise of an Italian government PEC account may have allowed threat actors to impersonate law enforcement and obtain sensitive data from hundreds of Revolut customers. The Revolut data exposure may be...</description>
      <source url="https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace-back-to-compromised-italian-government-accounts.html">Security Affairs</source>
      <guid isPermaLink="true">https://securityaffairs.com/199180/data-breach/revolut-data-leak-may-trace-back-to-compromised-italian-government-accounts.html</guid>
      <pubDate>Wed, 16 Sep 2026 13:09:22 +0000</pubDate>
      <category>Breach</category>
      <category>Threat Research</category>
    </item>
    <item>
      <title>Why Is Detection and Response Too Slow for Machine Speed Attacks?</title>
      <link>https://www.aquasec.com/blog/why-is-detection-and-response-too-slow-for-machine-speed-attacks</link>
      <description>TLDR: Runtime security built around detecting activity, correlating signals and then responding assumes there is enough time to act after something malicious happens. Machine speed attacks challenge that assumption be...</description>
      <source url="https://www.aquasec.com/blog/why-is-detection-and-response-too-slow-for-machine-speed-attacks">Aqua Security Blog</source>
      <guid isPermaLink="true">https://www.aquasec.com/blog/why-is-detection-and-response-too-slow-for-machine-speed-attacks</guid>
      <pubDate>Wed, 16 Sep 2026 13:00:09 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Ukraine moves to crack down on scam call centers after corruption scandal</title>
      <link>https://therecord.media/ukraine-call-center-scam-crackdown</link>
      <description>Ukraine’s parliament has approved tougher criminal penalties for involvement in fraudulent call centers and the theft of personal data, following a corruption scandal in which prosecutors were accused of taking bribes...</description>
      <source url="https://therecord.media/ukraine-call-center-scam-crackdown">The Record</source>
      <guid isPermaLink="true">https://therecord.media/ukraine-call-center-scam-crackdown</guid>
      <pubDate>Wed, 16 Sep 2026 12:45:00 +0000</pubDate>
      <category>Scam</category>
    </item>
    <item>
      <title>Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)</title>
      <link>https://www.helpnetsecurity.com/2026/09/16/parallels-desktop-cve-2026-90894-parashells-vulnerability</link>
      <description>A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root privileges on the host system. ParaShells PoC in action (Source:...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/16/parallels-desktop-cve-2026-90894-parashells-vulnerability">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/16/parallels-desktop-cve-2026-90894-parashells-vulnerability</guid>
      <pubDate>Wed, 16 Sep 2026 12:36:30 +0000</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>Webinar: What happens in the first hours of a Google Workspace breach</title>
      <link>https://www.bleepingcomputer.com/news/security/webinar-what-happens-in-the-first-hours-of-a-google-workspace-breach</link>
      <description>The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can ma...</description>
      <source url="https://www.bleepingcomputer.com/news/security/webinar-what-happens-in-the-first-hours-of-a-google-workspace-breach">BleepingComputer</source>
      <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/webinar-what-happens-in-the-first-hours-of-a-google-workspace-breach</guid>
      <pubDate>Wed, 16 Sep 2026 08:11:19 -0400</pubDate>
      <category>Breach</category>
    </item>
    <item>
      <title>US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware</title>
      <link>https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware</link>
      <description>US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&amp;C. The post US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware a...</description>
      <source url="https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/us-uk-dutch-agencies-expose-iranian-chosen-brick-surveillance-malware</guid>
      <pubDate>Wed, 16 Sep 2026 12:00:14 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Spain gets its first taste of AI-aided cyber attack</title>
      <link>https://www.theregister.com/cyber-crime/2026/09/16/spain-gets-its-first-taste-of-ai-aided-cyber-attack/5296844</link>
      <description>Data protection chiefs call for 'immediate review' of data protection models</description>
      <source url="https://www.theregister.com/cyber-crime/2026/09/16/spain-gets-its-first-taste-of-ai-aided-cyber-attack/5296844">The Register - Security</source>
      <guid isPermaLink="true">https://www.theregister.com/cyber-crime/2026/09/16/spain-gets-its-first-taste-of-ai-aided-cyber-attack/5296844</guid>
      <pubDate>Wed, 16 Sep 2026 13:56:55 +0200</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover</title>
      <link>https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover</link>
      <description>Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities. The post Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover appeared first on SecurityWeek .</description>
      <source url="https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/unauthenticated-rce-flaws-could-expose-200000-wordpress-sites-to-takeover</guid>
      <pubDate>Wed, 16 Sep 2026 11:32:53 +0000</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>Self-improving AI should slow down, von der Leyen tells EU lawmakers</title>
      <link>https://www.helpnetsecurity.com/2026/09/16/eu-ursula-von-der-leyen-ai</link>
      <description>European Commission President Ursula von der Leyen wants frontier AI development slowed, and said on Wednesday that she will invite the leading AI labs to discuss how the EU can support their own efforts to do that. I...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/16/eu-ursula-von-der-leyen-ai">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/16/eu-ursula-von-der-leyen-ai</guid>
      <pubDate>Wed, 16 Sep 2026 11:28:45 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Fake CAPTCHA Scams</title>
      <link>https://www.schneier.com/blog/archives/2026/09/fake-captcha-scams.html</link>
      <description>New variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.</description>
      <source url="https://www.schneier.com/blog/archives/2026/09/fake-captcha-scams.html">Schneier on Security</source>
      <guid isPermaLink="true">https://www.schneier.com/blog/archives/2026/09/fake-captcha-scams.html</guid>
      <pubDate>Wed, 16 Sep 2026 11:25:26 +0000</pubDate>
      <category>Scam</category>
    </item>
    <item>
      <title>Threat Intelligence Alone Won't Close the Exploitation Gap</title>
      <link>https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html</link>
      <description>A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attacker...</description>
      <source url="https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html">The Hacker News</source>
      <guid isPermaLink="true">https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html</guid>
      <pubDate>Wed, 16 Sep 2026 16:45:48 +0530</pubDate>
      <category>Vulnerability</category>
      <category>Scam</category>
      <category>Threat Research</category>
    </item>
    <item>
      <title>Critical ScreenConnect flaw now actively exploited in attacks</title>
      <link>https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw</link>
      <description>Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). [...]</description>
      <source url="https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw">BleepingComputer</source>
      <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw</guid>
      <pubDate>Wed, 16 Sep 2026 07:14:28 -0400</pubDate>
      <category>CISA</category>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>Hackuity Raises $19 Million for AI-Powered Vulnerability Management</title>
      <link>https://www.securityweek.com/hackuity-raises-19-million-for-ai-powered-vulnerability-management</link>
      <description>The company will use the new capital to expand its vulnerability operations platform and support international growth. The post Hackuity Raises $19 Million for AI-Powered Vulnerability Management appeared first on Sec...</description>
      <source url="https://www.securityweek.com/hackuity-raises-19-million-for-ai-powered-vulnerability-management">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/hackuity-raises-19-million-for-ai-powered-vulnerability-management</guid>
      <pubDate>Wed, 16 Sep 2026 11:11:23 +0000</pubDate>
      <category>Vulnerability</category>
      <category>AI</category>
    </item>
    <item>
      <title>Cyber-Attacks Cost Organizations $52,000 on Average</title>
      <link>https://www.infosecurity-magazine.com/news/cyberattacks-cost-organizations</link>
      <description>Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000</description>
      <source url="https://www.infosecurity-magazine.com/news/cyberattacks-cost-organizations">Infosecurity Magazine</source>
      <guid isPermaLink="true">https://www.infosecurity-magazine.com/news/cyberattacks-cost-organizations</guid>
      <pubDate>Wed, 16 Sep 2026 11:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Cohesity adds recovery capabilities for AI agents and the data they manage</title>
      <link>https://www.helpnetsecurity.com/2026/09/16/cohesity-agent-resilience-capability</link>
      <description>Cohesity has introduced Cohesity Agent Resilience. This new Cohesity Data Cloud capability will discover, protect, and recover the infrastructure behind enterprise AI agents. A unified view of an agent and the state i...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/16/cohesity-agent-resilience-capability">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/16/cohesity-agent-resilience-capability</guid>
      <pubDate>Wed, 16 Sep 2026 10:58:56 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>NCSC and Allies Warn of Iranian Spyware Campaign</title>
      <link>https://www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen</link>
      <description>The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents</description>
      <source url="https://www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen">Infosecurity Magazine</source>
      <guid isPermaLink="true">https://www.infosecurity-magazine.com/news/ncsc-allies-warn-iranian-chosen</guid>
      <pubDate>Wed, 16 Sep 2026 08:25:00 +0000</pubDate>
      <category>Threat Research</category>
    </item>
    <item>
      <title>Texas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records Stolen</title>
      <link>https://securityaffairs.com/199170/data-breach/texas-utility-centerpoint-energy-confirms-data-breach-after-hacker-claims-7-49m-records-stolen.html</link>
      <description>CenterPoint Energy confirmed a customer data breach after a hacker claimed to leak 7.49M records, including personal and billing information. CenterPoint Energy admitted on Monday that an intruder stole personal infor...</description>
      <source url="https://securityaffairs.com/199170/data-breach/texas-utility-centerpoint-energy-confirms-data-breach-after-hacker-claims-7-49m-records-stolen.html">Security Affairs</source>
      <guid isPermaLink="true">https://securityaffairs.com/199170/data-breach/texas-utility-centerpoint-energy-confirms-data-breach-after-hacker-claims-7-49m-records-stolen.html</guid>
      <pubDate>Wed, 16 Sep 2026 08:19:03 +0000</pubDate>
      <category>Breach</category>
    </item>
    <item>
      <title>CrowdStrike Accelerates Real-Time Data Classification with On-Device AI</title>
      <link>https://www.crowdstrike.com/en-us/blog/crowdstrike-accelerates-real-time-data-classification-with-on-device-ai</link>
      <description />
      <source url="https://www.crowdstrike.com/en-us/blog/crowdstrike-accelerates-real-time-data-classification-with-on-device-ai">CrowdStrike Blog</source>
      <guid isPermaLink="true">https://www.crowdstrike.com/en-us/blog/crowdstrike-accelerates-real-time-data-classification-with-on-device-ai</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 -0500</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>280,000 Impacted by Premier Medical Group Data Breach</title>
      <link>https://www.securityweek.com/280000-impacted-by-premier-medical-group-data-breach/</link>
      <description>In June 2026, hackers accessed files containing patients’ names, contact information, diagnosis details, and health insurance information. The post 280,000 Impacted by Premier Medical Group Data Breach appeared first...</description>
      <source url="https://www.securityweek.com/280000-impacted-by-premier-medical-group-data-breach/">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/280000-impacted-by-premier-medical-group-data-breach/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Breach</category>
    </item>
    <item>
      <title>Rubrik MCP gives AI agents controlled access to security intelligence</title>
      <link>https://www.helpnetsecurity.com/2026/09/16/rubrik-mcp/</link>
      <description>Rubrik has announced Rubrik MCP (Model Context Protocol), giving an organization’s AI agents a secure, programmable path to Rubrik’s data, identity, and application intelligence. Support for MCP expands Rubrik AI, whi...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/16/rubrik-mcp/">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/16/rubrik-mcp/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Identity</category>
      <category>AI</category>
    </item>
    <item>
      <title>Chrome, Firefox Updates Patch 115 Vulnerabilities</title>
      <link>https://www.securityweek.com/chrome-firefox-updates-patch-115-vulnerabilities/</link>
      <description>Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox. The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek .</description>
      <source url="https://www.securityweek.com/chrome-firefox-updates-patch-115-vulnerabilities/">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/chrome-firefox-updates-patch-115-vulnerabilities/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Nozomi Compass helps industrial teams manage OT assets and vulnerabilities</title>
      <link>https://www.helpnetsecurity.com/2026/09/16/nozomi-networks-compass/</link>
      <description>Nozomi Networks announced Nozomi Compass, an OT asset and service management platform designed to help organizations manage industrial assets, vulnerabilities, and exposures. The platform brings asset data, remediatio...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/16/nozomi-networks-compass/">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/16/nozomi-networks-compass/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Citrix adds AI-powered browser activity analysis to SecurAccess</title>
      <link>https://www.helpnetsecurity.com/2026/09/16/citrix-session-insights-capability/</link>
      <description>Citrix has announced Citrix Session Insights, a new AI-powered capability for Citrix SecurAccess with Chrome Enterprise that helps organizations capture, analyze and understand browser activity from users and autonomo...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/16/citrix-session-insights-capability/">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/16/citrix-session-insights-capability/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Securing the unpatchable in an age of AI-driven vulnerabilities</title>
      <link>https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/</link>
      <description>Advances in AI technology will continue to identify vulnerabilities that in some circumstances are difficult, or effectively impossible, to patch. Appropriate network segmentation, rigorous visibility, and the deploym...</description>
      <source url="https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/">Cisco Talos</source>
      <guid isPermaLink="true">https://blog.talosintelligence.com/securing-the-unpatchable-in-an-age-of-ai-driven-vulnerabilities/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Atomic macOS (AMOS) Stealer Activity</title>
      <link>https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/</link>
      <description>Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats. The post Atomic macOS (AMOS) Stealer Activity appeared first on Unit 42 .</description>
      <source url="https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/">Palo Alto Networks Unit 42</source>
      <guid isPermaLink="true">https://unit42.paloaltonetworks.com/atomic-macos-amos-stealer-activity/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Scam</category>
    </item>
    <item>
      <title>Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping</title>
      <link>https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/</link>
      <description>OPSWAT researchers find two zero-days in TP-Link cameras</description>
      <source url="https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/">Infosecurity Magazine</source>
      <guid isPermaLink="true">https://www.infosecurity-magazine.com/news/zeroday-tplink-cameras/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>One runaway AI agent racked up a $50,000 cloud bill</title>
      <link>https://www.helpnetsecurity.com/2026/09/16/google-mandiant-enterprise-ai-security-risks-report/</link>
      <description>Organizations are deploying autonomous AI systems that execute API calls, optimize production configurations, and analyze telemetry across hybrid cloud environments. At the same time, attacks are expanding from direct...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/16/google-mandiant-enterprise-ai-security-risks-report/">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/16/google-mandiant-enterprise-ai-security-risks-report/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program</title>
      <link>https://www.infosecurity-magazine.com/news/cyber-vendors-mitre-uk-testing/</link>
      <description>A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program</description>
      <source url="https://www.infosecurity-magazine.com/news/cyber-vendors-mitre-uk-testing/">Infosecurity Magazine</source>
      <guid isPermaLink="true">https://www.infosecurity-magazine.com/news/cyber-vendors-mitre-uk-testing/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>AI helps scammers build convincing antivirus renewal pages</title>
      <link>https://www.malwarebytes.com/blog/threat-intel/2026/09/ai-helps-scammers-build-convincing-antivirus-renewal-pages</link>
      <description>A fake Avast renewal page shows how AI is helping scammers create more convincing traps with polished designs and fluent copy.</description>
      <source url="https://www.malwarebytes.com/blog/threat-intel/2026/09/ai-helps-scammers-build-convincing-antivirus-renewal-pages">Malwarebytes Labs</source>
      <guid isPermaLink="true">https://www.malwarebytes.com/blog/threat-intel/2026/09/ai-helps-scammers-build-convincing-antivirus-renewal-pages</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
      <category>Scam</category>
    </item>
    <item>
      <title>Enterprises Warned of Attacks Exploiting WSO2 Vulnerability</title>
      <link>https://www.securityweek.com/enterprises-warned-of-attacks-exploiting-wso2-vulnerability/</link>
      <description>The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability appeared first on SecurityWeek .</description>
      <source url="https://www.securityweek.com/enterprises-warned-of-attacks-exploiting-wso2-vulnerability/">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/enterprises-warned-of-attacks-exploiting-wso2-vulnerability/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>What happens when AI agent governance is missing at scale</title>
      <link>https://www.helpnetsecurity.com/2026/09/16/gourab-basu-meshiq-ai-agent-governance/</link>
      <description>In this interview with Help Net Security, Gourab Basu, Global Head of Engineering at meshIQ, discusses governance in AI agent systems. He argues that instructions written into a prompt are not enough to control what a...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/16/gourab-basu-meshiq-ai-agent-governance/">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/16/gourab-basu-meshiq-ai-agent-governance/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Mythos has made 2026 patching hell. It might make 2027 a breeze</title>
      <link>https://www.theregister.com/security/2026/09/16/mythos-has-made-2026-patching-hell-it-might-make-2027-a-breeze/5296747</link>
      <description>Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner</description>
      <source url="https://www.theregister.com/security/2026/09/16/mythos-has-made-2026-patching-hell-it-might-make-2027-a-breeze/5296747">The Register - Security</source>
      <guid isPermaLink="true">https://www.theregister.com/security/2026/09/16/mythos-has-made-2026-patching-hell-it-might-make-2027-a-breeze/5296747</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>DeepZero: Open-source hunting for vulnerable Windows drivers</title>
      <link>https://www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/</link>
      <description>DeepZero is an open-source engine that automates the search for exploitable Windows kernel drivers. You point it at a folder of binaries and it parses them, pulls them apart, scans them, throws most of them away, and...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/16/vulnerable-windows-drivers-deepzero-open-source/</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens</title>
      <link>https://thehackernews.com/2026/09/active-exploitation-attempts-target.html</link>
      <description>A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of impro...</description>
      <source url="https://thehackernews.com/2026/09/active-exploitation-attempts-target.html">The Hacker News</source>
      <guid isPermaLink="true">https://thehackernews.com/2026/09/active-exploitation-attempts-target.html</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>ISC Stormcast For Wednesday, September 16th, 2026 https://isc.sans.edu/podcastdetail/10096, (Wed, Sep 16th)</title>
      <link>https://isc.sans.edu/diary/rss/33342</link>
      <description />
      <source url="https://isc.sans.edu/diary/rss/33342">SANS ISC</source>
      <guid isPermaLink="true">https://isc.sans.edu/diary/rss/33342</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Cyber Op Targets South Korean Media &amp; Automotive Sectors</title>
      <link>https://www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive</link>
      <description>A likely North Korean advanced persistent threat (APT) group used a previously undocumented Linux espionage toolkit to compromise load balancers, gain access to communications, and further exploit networks.</description>
      <source url="https://www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive">Dark Reading</source>
      <guid isPermaLink="true">https://www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability</category>
      <category>Threat Research</category>
    </item>
    <item>
      <title>Mapping out your unknown: A threat hunter’s guide to GitHub</title>
      <link>https://securitylabs.datadoghq.com/articles/mapping-out-your-unknown-threat-hunters-guide-to-github</link>
      <description>In this post, we walk through different threats to GitHub and how to detect them.</description>
      <source url="https://securitylabs.datadoghq.com/articles/mapping-out-your-unknown-threat-hunters-guide-to-github">Datadog Security Labs</source>
      <guid isPermaLink="true">https://securitylabs.datadoghq.com/articles/mapping-out-your-unknown-threat-hunters-guide-to-github</guid>
      <pubDate>Wed, 16 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Before You Patch. Why Patch Reliability Matters for Confident Deployment</title>
      <link>https://blog.qualys.com/product-tech/2026/09/15/before-you-patch-why-patch-reliability-matters-for-confident-deployment</link>
      <description>Executive Summary Microsoft’s September 2026 security updates, KB5124008 and KB5124012, have been linked to USB audio failures on some Windows systems, highlighting the operational risk that can accompany security pat...</description>
      <source url="https://blog.qualys.com/product-tech/2026/09/15/before-you-patch-why-patch-reliability-matters-for-confident-deployment">Qualys Blog</source>
      <guid isPermaLink="true">https://blog.qualys.com/product-tech/2026/09/15/before-you-patch-why-patch-reliability-matters-for-confident-deployment</guid>
      <pubDate>Tue, 15 Sep 2026 18:00:53 +0000</pubDate>
      <category>Azure</category>
    </item>
    <item>
      <title>Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists</title>
      <link>https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html</link>
      <description>Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists arou...</description>
      <source url="https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html">The Hacker News</source>
      <guid isPermaLink="true">https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html</guid>
      <pubDate>Tue, 15 Sep 2026 21:59:51 +0530</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Cisco email security boxes can be rooted by... an email</title>
      <link>https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604</link>
      <description>Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in</description>
      <source url="https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604">The Register - Security</source>
      <guid isPermaLink="true">https://www.theregister.com/security/2026/09/15/cisco-email-security-boxes-can-be-rooted-by-an-email/5296604</guid>
      <pubDate>Tue, 15 Sep 2026 18:01:00 +0200</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>Cisco warns customers of actively exploited zero-day in email gateways</title>
      <link>https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited</link>
      <description>The company confirmed the defect was exploited before it was disclosed and patched, but it did not describe the nature of the attacks or the scope of impact across its customer base. The post Cisco warns customers of...</description>
      <source url="https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited">CyberScoop</source>
      <guid isPermaLink="true">https://cyberscoop.com/cisco-secure-email-gateway-zero-day-exploited</guid>
      <pubDate>Tue, 15 Sep 2026 15:44:41 +0000</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>BambooToken malware controls Windows and Linux systems via MQTT</title>
      <link>https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt</link>
      <description>A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]</description>
      <source url="https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt">BleepingComputer</source>
      <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt</guid>
      <pubDate>Tue, 15 Sep 2026 11:00:00 -0400</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds</title>
      <link>https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html</link>
      <description>With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can...</description>
      <source url="https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html">The Hacker News</source>
      <guid isPermaLink="true">https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html</guid>
      <pubDate>Tue, 15 Sep 2026 17:22:28 +0530</pubDate>
      <category>Vulnerability</category>
      <category>AI</category>
    </item>
    <item>
      <title>Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers</title>
      <link>https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html</link>
      <description>Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development server...</description>
      <source url="https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html">The Hacker News</source>
      <guid isPermaLink="true">https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html</guid>
      <pubDate>Tue, 15 Sep 2026 16:42:32 +0530</pubDate>
      <category>Vulnerability</category>
      <category>Breach</category>
      <category>Scam</category>
    </item>
    <item>
      <title>One Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under Fire</title>
      <link>https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html</link>
      <description>Two China-linked groups ran identical Chrome/Windows zero-day exploits against NGOs, before Chrome’s patch shipped, deploying different backdoors each. Two China-linked threat actors used the same Chrome/Windows zero-...</description>
      <source url="https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html">Security Affairs</source>
      <guid isPermaLink="true">https://securityaffairs.com/199104/apt/one-exploit-chain-two-espionage-campaigns-chrome-and-windows-under-fire.html</guid>
      <pubDate>Tue, 15 Sep 2026 10:17:40 +0000</pubDate>
      <category>Vulnerability</category>
      <category>Threat Research</category>
    </item>
    <item>
      <title>Suspected Black Axe gang leaders face cybercrime charges in the US</title>
      <link>https://www.bleepingcomputer.com/news/security/black-axe-gang-members-extradited-to-us-face-cybercrime-charges</link>
      <description>Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering ch...</description>
      <source url="https://www.bleepingcomputer.com/news/security/black-axe-gang-members-extradited-to-us-face-cybercrime-charges">BleepingComputer</source>
      <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/black-axe-gang-members-extradited-to-us-face-cybercrime-charges</guid>
      <pubDate>Tue, 15 Sep 2026 05:50:25 -0400</pubDate>
      <category>Scam</category>
    </item>
    <item>
      <title>LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server</title>
      <link>https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html</link>
      <description>A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On such servers,...</description>
      <source url="https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html">The Hacker News</source>
      <guid isPermaLink="true">https://thehackernews.com/2026/09/litespeed-enterprise-flaw-could-let-one.html</guid>
      <pubDate>Tue, 15 Sep 2026 12:22:16 +0530</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>Introducing new session management tools with native, granular controls</title>
      <link>https://cloud.google.com/blog/products/identity-security/introducing-new-session-management-tools-with-native-granular-controls</link>
      <description>Google Cloud session management provides flexible options for setting up session controls based on your organization’s security policy needs. To help you improve your security posture and mitigate credential theft and...</description>
      <source url="https://cloud.google.com/blog/products/identity-security/introducing-new-session-management-tools-with-native-granular-controls">Google Cloud Blog</source>
      <guid isPermaLink="true">https://cloud.google.com/blog/products/identity-security/introducing-new-session-management-tools-with-native-granular-controls</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>GCP</category>
      <category>Scam</category>
    </item>
    <item>
      <title>PhantomRaven: An LLM-Generated Information Stealer Developed for Bug Bounty Hunting</title>
      <link>https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/</link>
      <description />
      <source url="https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/">CrowdStrike Blog</source>
      <guid isPermaLink="true">https://www.crowdstrike.com/en-us/blog/phantomraven-llm-generated-information-stealer-for-bug-bounty-hunting/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites</title>
      <link>https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites</link>
      <description>Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden...</description>
      <source url="https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites">BleepingComputer</source>
      <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Threat Research</category>
    </item>
    <item>
      <title>Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints</title>
      <link>https://www.securityweek.com/microsoft-ai-code-of-conduct-sets-cyberattack-boundaries-chain-of-command-safety-constraints/</link>
      <description>The Humanist AI Code of Conduct draws a line between defensive cyber research and operational attack capability. The post Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints...</description>
      <source url="https://www.securityweek.com/microsoft-ai-code-of-conduct-sets-cyberattack-boundaries-chain-of-command-safety-constraints/">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/microsoft-ai-code-of-conduct-sets-cyberattack-boundaries-chain-of-command-safety-constraints/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Azure</category>
      <category>AI</category>
    </item>
    <item>
      <title>AWS STS simplifies session token size limits and adds session token size monitoring</title>
      <link>https://aws.amazon.com/blogs/security/aws-sts-simplifies-session-token-size-limits-and-adds-session-token-size-monitoring/</link>
      <description>AWS Security Token Service (AWS STS) has simplified session token size limits, giving you more room for your session policies and session tags. STS has replaced the packed policy size and the overall session token siz...</description>
      <source url="https://aws.amazon.com/blogs/security/aws-sts-simplifies-session-token-size-limits-and-adds-session-token-size-monitoring/">AWS Security Blog</source>
      <guid isPermaLink="true">https://aws.amazon.com/blogs/security/aws-sts-simplifies-session-token-size-limits-and-adds-session-token-size-monitoring/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AWS</category>
    </item>
    <item>
      <title>The vulnpocalypse rains iBugs down on Apple with record-setting number of patches</title>
      <link>https://www.theregister.com/security/2026/09/15/the-vulnpocalypse-rains-ibugs-down-on-apple-with-record-setting-number-of-patches/5296679</link>
      <description>September Patch Tuesday part 2?</description>
      <source url="https://www.theregister.com/security/2026/09/15/the-vulnpocalypse-rains-ibugs-down-on-apple-with-record-setting-number-of-patches/5296679">The Register - Security</source>
      <guid isPermaLink="true">https://www.theregister.com/security/2026/09/15/the-vulnpocalypse-rains-ibugs-down-on-apple-with-record-setting-number-of-patches/5296679</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Low-quality casino sites conceal highly dangerous threat actors</title>
      <link>https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652</link>
      <description>Security firm Infoblox shines light on malicious infrastructure lurking beneath illegal gambling sites</description>
      <source url="https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652">The Register - Security</source>
      <guid isPermaLink="true">https://www.theregister.com/security/2026/09/15/low-quality-casino-sites-conceal-highly-dangerous-threat-actors/5296652</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Threat Research</category>
    </item>
    <item>
      <title>Who's governing your AI? A trust framework for enterprise agents and models</title>
      <link>https://www.theregister.com/security/2026/09/15/sponsored-whos-governing-your-ai-a-trust-framework-for-enterprise-agents-and-models/5294237</link>
      <description>SPONSORED FEATURE: DigiCert wants to hand every agent a passport, complete with an expiry date and a named human owner</description>
      <source url="https://www.theregister.com/security/2026/09/15/sponsored-whos-governing-your-ai-a-trust-framework-for-enterprise-agents-and-models/5294237">The Register - Security</source>
      <guid isPermaLink="true">https://www.theregister.com/security/2026/09/15/sponsored-whos-governing-your-ai-a-trust-framework-for-enterprise-agents-and-models/5294237</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Swiss court sentences 52-year-old Ukrainian ransomware dev to nearly 13 years in the cooler</title>
      <link>https://www.theregister.com/security/2026/09/15/swiss-court-sentences-52-year-old-ukrainian-ransomware-dev-to-nearly-13-years-in-the-cooler/5296482</link>
      <description>The man allegedly wrote the code that powered the Lockergoga, MegaCortex, and Nefilim operations</description>
      <source url="https://www.theregister.com/security/2026/09/15/swiss-court-sentences-52-year-old-ukrainian-ransomware-dev-to-nearly-13-years-in-the-cooler/5296482">The Register - Security</source>
      <guid isPermaLink="true">https://www.theregister.com/security/2026/09/15/swiss-court-sentences-52-year-old-ukrainian-ransomware-dev-to-nearly-13-years-in-the-cooler/5296482</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Ransomware</category>
    </item>
    <item>
      <title>Google Doc Sidebar Sends Mac and Windows Users Down Different Paths to Malware</title>
      <link>https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows</link>
      <description>A single X DM split into two malware chains: AMOS stealer on Mac, NetSupport Manager on Windows, see the Huntress SOC analyst breakdown.</description>
      <source url="https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows">Huntress Blog</source>
      <guid isPermaLink="true">https://www.huntress.com/blog/google-doc-sidebar-malware-mac-windows</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>The latest AI doomsayer is China’s intelligence boss</title>
      <link>https://www.theregister.com/ai-and-ml/2026/09/15/the-latest-ai-doomsayer-is-chinas-intelligence-boss/5296451</link>
      <description>Beijing’s response is to ‘firmly grasp technological sovereignty’ and broad regulations</description>
      <source url="https://www.theregister.com/ai-and-ml/2026/09/15/the-latest-ai-doomsayer-is-chinas-intelligence-boss/5296451">The Register - Security</source>
      <guid isPermaLink="true">https://www.theregister.com/ai-and-ml/2026/09/15/the-latest-ai-doomsayer-is-chinas-intelligence-boss/5296451</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?</title>
      <link>https://www.securityweek.com/microsoft-commits-to-sweeping-ai-privacy-rules-for-students-will-other-tech-giants-follow/</link>
      <description>Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Othe...</description>
      <source url="https://www.securityweek.com/microsoft-commits-to-sweeping-ai-privacy-rules-for-students-will-other-tech-giants-follow/">SecurityWeek</source>
      <guid isPermaLink="true">https://www.securityweek.com/microsoft-commits-to-sweeping-ai-privacy-rules-for-students-will-other-tech-giants-follow/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Azure</category>
      <category>AI</category>
    </item>
    <item>
      <title>Microsoft Issues Emergency Fixes After Massive Patch Tuesday</title>
      <link>https://www.darkreading.com/application-security/microsoft-emergency-fixes-patch-tuesday</link>
      <description>You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.</description>
      <source url="https://www.darkreading.com/application-security/microsoft-emergency-fixes-patch-tuesday">Dark Reading</source>
      <guid isPermaLink="true">https://www.darkreading.com/application-security/microsoft-emergency-fixes-patch-tuesday</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Azure</category>
    </item>
    <item>
      <title>What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies</title>
      <link>https://cyberscoop.com/whats-next-for-cisas-cdm-program-that-gives-cybersecurity-tools-to-federal-agencies/</link>
      <description>Three feds spoke about future plans for the Continuous Diagnostics and Mitigation program, and lessons they’ve learned. The post What’s next for CISA’s CDM program that gives cybersecurity tools to federal agencies ap...</description>
      <source url="https://cyberscoop.com/whats-next-for-cisas-cdm-program-that-gives-cybersecurity-tools-to-federal-agencies/">CyberScoop</source>
      <guid isPermaLink="true">https://cyberscoop.com/whats-next-for-cisas-cdm-program-that-gives-cybersecurity-tools-to-federal-agencies/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>CISA</category>
    </item>
    <item>
      <title>Black Hat USA 2026 | The 'Breaking' News: The OpenAI-Hugging Face Incident</title>
      <link>https://www.darkreading.com/vulnerabilities-threats/bhusa26huggingfacetalk</link>
      <description>The 'Breaking' News: The OpenAI-Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hug...</description>
      <source url="https://www.darkreading.com/vulnerabilities-threats/bhusa26huggingfacetalk">Dark Reading</source>
      <guid isPermaLink="true">https://www.darkreading.com/vulnerabilities-threats/bhusa26huggingfacetalk</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Architecting resilient authentication with Amazon Cognito multi-Region replication</title>
      <link>https://aws.amazon.com/blogs/security/architecting-resilient-authentication-with-amazon-cognito-multi-region-replication/</link>
      <description>Your consumer identity and access management (CIAM) system is the foundation of your customer experience. It’s how users sign in, access services, and engage with your applications. As your business scales across geog...</description>
      <source url="https://aws.amazon.com/blogs/security/architecting-resilient-authentication-with-amazon-cognito-multi-region-replication/">AWS Security Blog</source>
      <guid isPermaLink="true">https://aws.amazon.com/blogs/security/architecting-resilient-authentication-with-amazon-cognito-multi-region-replication/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AWS</category>
      <category>Identity</category>
    </item>
    <item>
      <title>KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens</title>
      <link>https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html</link>
      <description>Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF93...</description>
      <source url="https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html">The Hacker News</source>
      <guid isPermaLink="true">https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Scam</category>
    </item>
    <item>
      <title>VectraRAT Can Hack Windows Enterprises for $250 per Month</title>
      <link>https://www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises</link>
      <description>The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.</description>
      <source url="https://www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises">Dark Reading</source>
      <guid isPermaLink="true">https://www.darkreading.com/endpoint-security/vectrarat-hack-windows-enterprises</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>September's Windows 11 patch needs an emergency patch of its own</title>
      <link>https://www.theregister.com/on-prem/2026/09/15/septembers-windows-11-patch-needs-an-emergency-patch-of-its-own/5296567</link>
      <description>Microsoft fixes RDP and Hyper-V fallout, but some USB audio stays silent</description>
      <source url="https://www.theregister.com/on-prem/2026/09/15/septembers-windows-11-patch-needs-an-emergency-patch-of-its-own/5296567">The Register - On-Prem</source>
      <guid isPermaLink="true">https://www.theregister.com/on-prem/2026/09/15/septembers-windows-11-patch-needs-an-emergency-patch-of-its-own/5296567</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Azure</category>
    </item>
    <item>
      <title>Operationalizing least privilege: Automate IAM remediation through your CI/CD pipeline</title>
      <link>https://aws.amazon.com/blogs/security/operationalizing-least-privilege-automate-iam-remediation-through-your-ci-cd-pipeline/</link>
      <description>The principle of least privilege is straightforward to articulate but challenging to maintain at scale. When teams first deploy applications to AWS, they often grant broader permissions than strictly necessary; it’s f...</description>
      <source url="https://aws.amazon.com/blogs/security/operationalizing-least-privilege-automate-iam-remediation-through-your-ci-cd-pipeline/">AWS Security Blog</source>
      <guid isPermaLink="true">https://aws.amazon.com/blogs/security/operationalizing-least-privilege-automate-iam-remediation-through-your-ci-cd-pipeline/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AWS</category>
      <category>Identity</category>
    </item>
    <item>
      <title>How to opt out of AI chatbot training</title>
      <link>https://www.malwarebytes.com/blog/how-to/2026/09/how-to-opt-out-of-ai-chatbot-training</link>
      <description>ChatGPT contractors are reviewing real users' conversations. Here’s how to stop AI companies using your chats for model training.</description>
      <source url="https://www.malwarebytes.com/blog/how-to/2026/09/how-to-opt-out-of-ai-chatbot-training">Malwarebytes Labs</source>
      <guid isPermaLink="true">https://www.malwarebytes.com/blog/how-to/2026/09/how-to-opt-out-of-ai-chatbot-training</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Most Fraudulent Hires Receive Credentials Before Detection</title>
      <link>https://www.infosecurity-magazine.com/news/fraudulent-hires-credentials/</link>
      <description>A new report highlights the vast growth in fraudulent candidates, presenting significant insider threat challenges to organizations</description>
      <source url="https://www.infosecurity-magazine.com/news/fraudulent-hires-credentials/">Infosecurity Magazine</source>
      <guid isPermaLink="true">https://www.infosecurity-magazine.com/news/fraudulent-hires-credentials/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Scam</category>
    </item>
    <item>
      <title>Zelensky appoints former police chief to lead Ukraine’s cyber coordination center</title>
      <link>https://therecord.media/ukraine-cyber-coordination-center-ihor-klymenko</link>
      <description>Ihor Klymenko, who has experience in law enforcement and as interior minister, will run Ukraine's National Cybersecurity Coordination Center.</description>
      <source url="https://therecord.media/ukraine-cyber-coordination-center-ihor-klymenko">The Record</source>
      <guid isPermaLink="true">https://therecord.media/ukraine-cyber-coordination-center-ihor-klymenko</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>AI Autonomy: How to Find the Autonomy Your Agents Already Have</title>
      <link>https://blog.gitguardian.com/ai-autonomy/</link>
      <description>AI agents are only as autonomous as the credentials behind them. This article talks about the Cloud Security Alliance's autonomy framework, why an agent's intended boundaries rarely match its actual access, and how Gi...</description>
      <source url="https://blog.gitguardian.com/ai-autonomy/">GitGuardian Blog</source>
      <guid isPermaLink="true">https://blog.gitguardian.com/ai-autonomy/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
      <category>Scam</category>
    </item>
    <item>
      <title>AI coding puts Secure by Design in the spotlight</title>
      <link>https://www.reversinglabs.com/blog/ai-secure-by-design-spotlight</link>
      <description>The software industry is entering the AI era burdened by legacy flaws and weaknesses, making Secure by Design essential.</description>
      <source url="https://www.reversinglabs.com/blog/ai-secure-by-design-spotlight">ReversingLabs Blog</source>
      <guid isPermaLink="true">https://www.reversinglabs.com/blog/ai-secure-by-design-spotlight</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Automate Asset Isolation: Your Last Resort to Meet Remediation Deadlines</title>
      <link>https://blog.qualys.com/product-tech/2026/09/15/automate-asset-isolation-cisa-kev-deadlines</link>
      <description>Executive Summary Remediation deadlines slip for reasons outside your control: a patch does not exist yet, a patch is delayed, or a remediation attempt fails. The outcome is the same either way: the host stays unpatch...</description>
      <source url="https://blog.qualys.com/product-tech/2026/09/15/automate-asset-isolation-cisa-kev-deadlines">Qualys Blog</source>
      <guid isPermaLink="true">https://blog.qualys.com/product-tech/2026/09/15/automate-asset-isolation-cisa-kev-deadlines</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Most Firms Unable to Recover Quickly from Ransomware</title>
      <link>https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/</link>
      <description>Fenix24 found only four of more than 800 clients came close to stated ransomware recovery targets of 24-48 hours</description>
      <source url="https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/">Infosecurity Magazine</source>
      <guid isPermaLink="true">https://www.infosecurity-magazine.com/news/four-of-800-clients-hit-ransomware/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Ransomware</category>
    </item>
    <item>
      <title>Operational Resilience: IT Security Risks with Reduced Staffing | Huntress</title>
      <link>https://www.huntress.com/blog/operational-resilience-reduced-staffing-risks</link>
      <description>Reduced staffing during holidays changes more than headcount. Learn how operational resilience should shape your IT and security change decisions</description>
      <source url="https://www.huntress.com/blog/operational-resilience-reduced-staffing-risks">Huntress Blog</source>
      <guid isPermaLink="true">https://www.huntress.com/blog/operational-resilience-reduced-staffing-risks</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>F5 Bot Defense uses real-time risk scoring to detect fraud and abuse</title>
      <link>https://www.helpnetsecurity.com/2026/09/15/f5-distributed-cloud-bot-defense-enhancements/</link>
      <description>F5 has announced enhancements to F5 Distributed Cloud Bot Defense, introducing new device intelligence capabilities and specialized agentic AI protections. These capabilities bring persistent device context and contin...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/15/f5-distributed-cloud-bot-defense-enhancements/">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/15/f5-distributed-cloud-bot-defense-enhancements/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
      <category>Scam</category>
    </item>
    <item>
      <title>Postman Passport controls API access without exposing credentials</title>
      <link>https://www.helpnetsecurity.com/2026/09/15/postman-passport/</link>
      <description>Postman has announced the general availability of Passport by Postman, marking the company’s expansion into API security with a standalone product that gives organizations a secure way to consume APIs as human and non...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/15/postman-passport/">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/15/postman-passport/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Scam</category>
    </item>
    <item>
      <title>Australia is replacing the Essential Eight with a new cyber framework. Here’s how exposure management can help you get ahead of it.</title>
      <link>https://www.tenable.com/blog/australia-essential-eight-replacement-compliance-exposure-management</link>
      <description>Australia’s move from the Essential Eight to an outcomes-based cybersecurity model will push organizations from conducting periodic point-in-time, checklist compliance assessments to having continuous evidence of a so...</description>
      <source url="https://www.tenable.com/blog/australia-essential-eight-replacement-compliance-exposure-management">Tenable Blog</source>
      <guid isPermaLink="true">https://www.tenable.com/blog/australia-essential-eight-replacement-compliance-exposure-management</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Globalgig expands managed security portfolio to protect enterprise AI</title>
      <link>https://www.helpnetsecurity.com/2026/09/15/globalgig-expands-managed-security-with-ai-protection/</link>
      <description>Globalgig has expanded its managed security portfolio to cover enterprise AI, bringing together services that discover, assess, and protect the AI applications, agents, models, and data enterprises are putting into pr...</description>
      <source url="https://www.helpnetsecurity.com/2026/09/15/globalgig-expands-managed-security-with-ai-protection/">Help Net Security</source>
      <guid isPermaLink="true">https://www.helpnetsecurity.com/2026/09/15/globalgig-expands-managed-security-with-ai-protection/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Have it both ways: stay discoverable in search while disallowing AI training</title>
      <link>https://blog.cloudflare.com/accountable-mixed-use-ai-crawlers/</link>
      <description>Cloudflare is giving site owners a way to stay discoverable while disallowing AI training. New controls and an Accountable designation establish a shared model with Apple, Google, and Microsoft.</description>
      <source url="https://blog.cloudflare.com/accountable-mixed-use-ai-crawlers/">Cloudflare Blog</source>
      <guid isPermaLink="true">https://blog.cloudflare.com/accountable-mixed-use-ai-crawlers/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Azure</category>
      <category>AI</category>
    </item>
    <item>
      <title>AI the Top Priority for New Spend as Cyber Budgets Flatline</title>
      <link>https://www.infosecurity-magazine.com/news/ai-top-priority-new-spend-cyber/</link>
      <description>IANS finds AI is dominating net-new budgets even as overall funding for the function is flat</description>
      <source url="https://www.infosecurity-magazine.com/news/ai-top-priority-new-spend-cyber/">Infosecurity Magazine</source>
      <guid isPermaLink="true">https://www.infosecurity-magazine.com/news/ai-top-priority-new-spend-cyber/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>China spy chief points at US AI models in cyber threat warning</title>
      <link>https://therecord.media/china-spy-chief-warns-of-us-ai-models</link>
      <description>China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerabil...</description>
      <source url="https://therecord.media/china-spy-chief-warns-of-us-ai-models">The Record</source>
      <guid isPermaLink="true">https://therecord.media/china-spy-chief-warns-of-us-ai-models</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Investing Together: Wiz Defend and Google Security Operations</title>
      <link>https://www.wiz.io/blog/wiz-defend-and-google-security-operations</link>
      <description>Continuing to deepen the integration between Wiz Defend and Google Security Operations, helping teams work faster wherever they choose to investigate</description>
      <source url="https://www.wiz.io/blog/wiz-defend-and-google-security-operations">Wiz Blog</source>
      <guid isPermaLink="true">https://www.wiz.io/blog/wiz-defend-and-google-security-operations</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Manhattan DA takes down 12 AI deepfake porn sites</title>
      <link>https://therecord.media/manhattan-da-takes-down-12-ai-deepfake-porn-sites</link>
      <description>Manhattan District Attorney Alvin Bragg held a press conference on Monday touting the takedown of the sites, which hosted AI-generated videos of more than 1,200 people. The sites allowed users to use the faces and bod...</description>
      <source url="https://therecord.media/manhattan-da-takes-down-12-ai-deepfake-porn-sites">The Record</source>
      <guid isPermaLink="true">https://therecord.media/manhattan-da-takes-down-12-ai-deepfake-porn-sites</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>HBO Max’s verified Reddit account hijacked to spread malware</title>
      <link>https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware</link>
      <description>Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.</description>
      <source url="https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware">Malwarebytes Labs</source>
      <guid isPermaLink="true">https://www.malwarebytes.com/blog/news/2026/09/hbo-maxs-verified-reddit-account-hijacked-to-spread-malware</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point</title>
      <link>https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html</link>
      <description>Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this par...</description>
      <source url="https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html">The Hacker News</source>
      <guid isPermaLink="true">https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Phishing</category>
    </item>
    <item>
      <title>The AI Hurricane Is Here</title>
      <link>https://snyk.io/blog/ai-hurricane-is-here/</link>
      <description>AI is accelerating software creation and cyberattacks alike. Leaders must secure agents and code at inception, enforce controls at runtime, and validate defenses independently.</description>
      <source url="https://snyk.io/blog/ai-hurricane-is-here/">Snyk Blog</source>
      <guid isPermaLink="true">https://snyk.io/blog/ai-hurricane-is-here/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>25 Years of Mass Surveillance Is Enough</title>
      <link>https://www.schneier.com/blog/archives/2026/09/25-years-of-mass-surveillance-is-enough.html</link>
      <description>This essay was written with Cindy Cohn, and originally appeared in Lawfare . One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance-such as individual wir...</description>
      <source url="https://www.schneier.com/blog/archives/2026/09/25-years-of-mass-surveillance-is-enough.html">Schneier on Security</source>
      <guid isPermaLink="true">https://www.schneier.com/blog/archives/2026/09/25-years-of-mass-surveillance-is-enough.html</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>1Password's AI patching benchmark is misleading</title>
      <link>https://blog.trailofbits.com/2026/09/15/1passwords-ai-patching-benchmark-is-misleading/</link>
      <description>1Password’s FLAWED report , published on August 6, 2026, gives defenders a misleading picture of AI patching. Its headline says models produced clean fixes only 26% of the time. That figure includes experiments that d...</description>
      <source url="https://blog.trailofbits.com/2026/09/15/1passwords-ai-patching-benchmark-is-misleading/">Trail of Bits Blog</source>
      <guid isPermaLink="true">https://blog.trailofbits.com/2026/09/15/1passwords-ai-patching-benchmark-is-misleading/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Meta AI builds detailed profiles of children from years of family posts</title>
      <link>https://www.malwarebytes.com/blog/family-and-parenting/2026/09/meta-ai-builds-detailed-profiles-of-children-from-years-of-family-posts</link>
      <description>A mother says Meta AI pieced together names, birth details, photos, and location information about her young daughters from years of family posts.</description>
      <source url="https://www.malwarebytes.com/blog/family-and-parenting/2026/09/meta-ai-builds-detailed-profiles-of-children-from-years-of-family-posts">Malwarebytes Labs</source>
      <guid isPermaLink="true">https://www.malwarebytes.com/blog/family-and-parenting/2026/09/meta-ai-builds-detailed-profiles-of-children-from-years-of-family-posts</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>AI</category>
    </item>
    <item>
      <title>Search results are sending people to fake Bitrefill checkouts</title>
      <link>https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts</link>
      <description>Fake Bitrefill checkout pages are appearing in search results and tricking people into sending cryptocurrency directly to scammers.</description>
      <source url="https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts">Malwarebytes Labs</source>
      <guid isPermaLink="true">https://www.malwarebytes.com/blog/threat-intel/2026/09/search-results-are-sending-people-to-fake-bitrefill-checkouts</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Scam</category>
    </item>
    <item>
      <title>Microsoft Releases Emergency Patch to Fix RDS Vulnerability</title>
      <link>https://www.infosecurity-magazine.com/news/microsoft-releases-emergency-patch/</link>
      <description>Microsoft has been forced to issue an out-of-band fix for several issues stemming from this month’s Patch Tuesday</description>
      <source url="https://www.infosecurity-magazine.com/news/microsoft-releases-emergency-patch/">Infosecurity Magazine</source>
      <guid isPermaLink="true">https://www.infosecurity-magazine.com/news/microsoft-releases-emergency-patch/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Azure</category>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>Telegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft Traps</title>
      <link>https://securityaffairs.com/199076/security/telegram-desktop-flaw-could-turn-old-chat-exports-into-data-theft-traps.html</link>
      <description>A Telegram Desktop flaw let bots inject JavaScript into exported chats, enabling data theft and page manipulation. Old HTML exports remain unsafe. A vulnerability in Telegram Desktop could have turned an ordinary chat...</description>
      <source url="https://securityaffairs.com/199076/security/telegram-desktop-flaw-could-turn-old-chat-exports-into-data-theft-traps.html">Security Affairs</source>
      <guid isPermaLink="true">https://securityaffairs.com/199076/security/telegram-desktop-flaw-could-turn-old-chat-exports-into-data-theft-traps.html</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>Non-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at Risk</title>
      <link>https://securityaffairs.com/199090/security/non-zero-day-vpn-flaw-left-japan-government-shared-network-platform-exposed-246000-records-at-risk.html</link>
      <description>Japan ‘s Digital Agency disclosed a VPN breach exposing 246,000 government employee records across 23 ministries. Detected June 25, publicly disclosed September 11. Japan ‘s Digital Agency disclosed that attackers exp...</description>
      <source url="https://securityaffairs.com/199090/security/non-zero-day-vpn-flaw-left-japan-government-shared-network-platform-exposed-246000-records-at-risk.html">Security Affairs</source>
      <guid isPermaLink="true">https://securityaffairs.com/199090/security/non-zero-day-vpn-flaw-left-japan-government-shared-network-platform-exposed-246000-records-at-risk.html</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability</category>
      <category>Breach</category>
    </item>
    <item>
      <title>Supreme Court denies Trump request to allow USPS mail ballot changes</title>
      <link>https://cyberscoop.com/supreme-court-denies-trump-usps-mail-ballot-changes/</link>
      <description>One justice said the attempt to change the rules ahead of the 2026 elections would be "arbitrary and capricious” and violated the Administrative Procedures Act. The post Supreme Court denies Trump request to allow USP...</description>
      <source url="https://cyberscoop.com/supreme-court-denies-trump-usps-mail-ballot-changes/">CyberScoop</source>
      <guid isPermaLink="true">https://cyberscoop.com/supreme-court-denies-trump-usps-mail-ballot-changes/</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group</title>
      <link>https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace</link>
      <description>Analyze Tajin Group's role in phishing and Chinese money laundering. Discover how this Telegram-based vendor exploits payment gateways and adapts its financial fraud operations.</description>
      <source url="https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace">Recorded Future</source>
      <guid isPermaLink="true">https://www.recordedfuture.com/research/tajin-group-gurantee-marketplace</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability</category>
      <category>Phishing</category>
      <category>Scam</category>
    </item>
    <item>
      <title>Announcing the Sovereign Artifacts beta</title>
      <link>https://www.chainguard.dev/unchained/announcing-the-sovereign-artifacts-beta</link>
      <description>Chainguard launches Sovereign Artifacts in beta, giving global organizations an EU-local option for secure container and library artifacts.</description>
      <source url="https://www.chainguard.dev/unchained/announcing-the-sovereign-artifacts-beta">Chainguard Unchained</source>
      <guid isPermaLink="true">https://www.chainguard.dev/unchained/announcing-the-sovereign-artifacts-beta</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>The flood is coming and the pipes were already full</title>
      <link>https://www.chainguard.dev/unchained/the-flood-is-coming-and-the-pipes-were-already-full</link>
      <description>Frontier AI is finding zero-days faster than the industry can fix them. See how Chainguard and Athena are preparing for what comes next.</description>
      <source url="https://www.chainguard.dev/unchained/the-flood-is-coming-and-the-pipes-were-already-full">Chainguard Unchained</source>
      <guid isPermaLink="true">https://www.chainguard.dev/unchained/the-flood-is-coming-and-the-pipes-were-already-full</guid>
      <pubDate>Tue, 15 Sep 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability</category>
      <category>AI</category>
    </item>
    <item>
      <title>HBO Max Reddit account compromised to serve ClickFix attacks</title>
      <link>https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408</link>
      <description>Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware</description>
      <source url="https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408">The Register - Security</source>
      <guid isPermaLink="true">https://www.theregister.com/cyber-crime/2026/09/14/hbo-max-reddit-account-compromised-to-serve-clickfix-attacks/5296408</guid>
      <pubDate>Tue, 15 Sep 2026 00:43:01 +0200</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Maximum Severity GitLab Flaw Puts Supply Chains at Risk</title>
      <link>https://www.darkreading.com/cyberattacks-data-breaches/maximum-severity-gitlab-flaw-supply-chains-risk</link>
      <description>CVE-2026-85706 is a path traversal vulnerability with a 10 out of 10 CVSS score, affecting both GitLab Community Edition and Enterprise Edition instances.</description>
      <source url="https://www.darkreading.com/cyberattacks-data-breaches/maximum-severity-gitlab-flaw-supply-chains-risk">Dark Reading</source>
      <guid isPermaLink="true">https://www.darkreading.com/cyberattacks-data-breaches/maximum-severity-gitlab-flaw-supply-chains-risk</guid>
      <pubDate>Mon, 14 Sep 2026 20:19:22 +0000</pubDate>
      <category>Vulnerability</category>
      <category>Supply Chain</category>
    </item>
    <item>
      <title>Five alleged leaders of Black Axe’s operations in South Africa extradited to US</title>
      <link>https://cyberscoop.com/black-axe-south-africa-leaders-extradited</link>
      <description>Officials said the five individuals concocted various long-running romance scams to trick U.S.-based victims into sending them money. The post Five alleged leaders of Black Axe’s operations in South Africa extradited...</description>
      <source url="https://cyberscoop.com/black-axe-south-africa-leaders-extradited">CyberScoop</source>
      <guid isPermaLink="true">https://cyberscoop.com/black-axe-south-africa-leaders-extradited</guid>
      <pubDate>Mon, 14 Sep 2026 18:37:44 +0000</pubDate>
      <category>Scam</category>
    </item>
    <item>
      <title>AI Changed the Exposure Problem. Validation Needs to Change With It.</title>
      <link>https://thehackernews.com/2026/09/ai-changed-exposure-problem-validation.html</link>
      <description>There's a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening at a much greater scale, whi...</description>
      <source url="https://thehackernews.com/2026/09/ai-changed-exposure-problem-validation.html">The Hacker News</source>
      <guid isPermaLink="true">https://thehackernews.com/2026/09/ai-changed-exposure-problem-validation.html</guid>
      <pubDate>Mon, 14 Sep 2026 17:28:00 +0530</pubDate>
      <category>Vulnerability</category>
      <category>AI</category>
    </item>
    <item>
      <title>Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users</title>
      <link>https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html</link>
      <description>A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named "Twitch Enhanced Viewer...</description>
      <source url="https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html">The Hacker News</source>
      <guid isPermaLink="true">https://thehackernews.com/2026/09/malicious-twitch-browser-extension.html</guid>
      <pubDate>Mon, 14 Sep 2026 12:54:39 +0530</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>CVE-2026-85706: Critical GitLab Path Traversal Exploited in the Wild</title>
      <link>https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/</link>
      <description>Overview On September 10, 2026, GitLab published a critical patch release for GitLab Community Edition (CE) and Enterprise Edition (EE). The release addresses CVE-2026-85706 , a critical path traversal vulnerability (...</description>
      <source url="https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/">Rapid7 Blog</source>
      <guid isPermaLink="true">https://www.rapid7.com/blog/post/etr-cve-2026-85706-critical-gitlab-path-traversal-exploited-in-the-wild/</guid>
      <pubDate>Mon, 14 Sep 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink</title>
      <link>https://www.darkreading.com/cyberattacks-data-breaches/sandworm-chains-cisco-vulnerabilities-cyclops-blink</link>
      <description>The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.</description>
      <source url="https://www.darkreading.com/cyberattacks-data-breaches/sandworm-chains-cisco-vulnerabilities-cyclops-blink">Dark Reading</source>
      <guid isPermaLink="true">https://www.darkreading.com/cyberattacks-data-breaches/sandworm-chains-cisco-vulnerabilities-cyclops-blink</guid>
      <pubDate>Mon, 14 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
    <item>
      <title>Homebrew 7.0.0 gets built-in GUI, better security controls</title>
      <link>https://www.bleepingcomputer.com/news/security/homebrew-700-gets-built-in-gui-better-security-controls</link>
      <description>Homebrew package manager version 7.0.0 has been released with a built-in vulnerability scanner, stronger security controls, and the full release of its native BrewUI graphical interface. [...]</description>
      <source url="https://www.bleepingcomputer.com/news/security/homebrew-700-gets-built-in-gui-better-security-controls">BleepingComputer</source>
      <guid isPermaLink="true">https://www.bleepingcomputer.com/news/security/homebrew-700-gets-built-in-gui-better-security-controls</guid>
      <pubDate>Mon, 14 Sep 2026 00:00:00 +0000</pubDate>
      <category>Vulnerability</category>
    </item>
    <item>
      <title>Apple Updates Everything, (Mon, Sep 14th)</title>
      <link>https://isc.sans.edu/diary/rss/33336</link>
      <description>Today, Apple released its annual update across all its operating systems. With that, Apple not only released new features but also patched 261 different vulnerabilities. This is the most vulnerabilities Apple has ever...</description>
      <source url="https://isc.sans.edu/diary/rss/33336">SANS ISC</source>
      <guid isPermaLink="true">https://isc.sans.edu/diary/rss/33336</guid>
      <pubDate>Mon, 14 Sep 2026 00:00:00 +0000</pubDate>
      <category>Cloud Security</category>
    </item>
  </channel>
</rss>