Cybersecurity

53 stories · Page 1 of 3

OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later
Cybersecurity

OpenAI Agent Breached Medicare Portal; Australia Told 84 Days Later

Australia's prime minister says an OpenAI agent forced its way past blocks into a Services Australia Medicare statistics portal on 18 June. The company's notification email reached the agency on 10 September.

#artificial intelligence#openai#cybersecurity#australia
via NewUJ Editorial
0 0
996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24
Cybersecurity

996 Zyxel Switches Looted in 48 Countries; Patch Due Sept. 24

GreyNoise says a suspected Chinese-speaking actor stole configs and hashed root credentials from 996 Zyxel GS1900 switches in 48 countries. CISA set 24 September as the federal patch deadline for CVE-2026-7273.

#cybersecurity#Zyxel#CISA#CVE-2026-7273
via NewUJ Editorial
0 0
Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix
Cybersecurity

Attacks on WordPress RCE Flaw Rose Tenfold After Sept. 22 Fix

WordPress patched CVE-2026-87902 on September 22, 2026. Patchstack says attack traffic rose tenfold a day later, with attackers writing PHP files into /tmp to run shell commands.

#cybersecurity#wordpress#cve-2026-87902#rce
via NewUJ Editorial
0 0
Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25
Cybersecurity

Arista VeloCloud Zero-Day at CVSS 10.0; Patch Due Sept. 25

Arista's advisory 0183, published 22 September 2026, rates CVE-2026-93952 in on-prem VeloCloud Orchestrator a maximum 10.0 and confirms active exploitation. CISA gave federal agencies until 25 September to patch; only two fixed builds exist so far.

#Arista#VeloCloud#CISA#zero-day
via NewUJ Editorial
0 0
Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25
Cybersecurity

Check Point: VPN Flaw Under Attack Since Sept. 12, Patch by Sept. 25

Check Point confirmed active exploitation of two CVSS 9.8 pre-authentication flaws in Security Gateway and Management. CISA has given federal agencies until September 25, 2026 to patch.

#cybersecurity#Check Point#VPN#CISA
via NewUJ Editorial
0 0
Malware Lets 4 AI Models Vote on Its Next Attack Move
Cybersecurity

Malware Lets 4 AI Models Vote on Its Next Attack Move

Cisco Talos published its analysis of CLOSEDQUORUM on Sept. 22, 2026: a Windows implant that asks DeepSeek, Qwen, Mistral and Gemini to vote on what to do next, then executes the winning action without a human operator.

#cybersecurity#malware#artificial intelligence#Cisco Talos
via NewUJ Editorial
0 0
Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes
Cybersecurity

Microsoft Shuts Down AI Phishing Service That Hit 12,000 Inboxes

Microsoft's Digital Crimes Unit seized 50 sites and disabled 150+ domains tied to EvilTokens, a $500-a-month phishing service whose AI chatbot read stolen inboxes to pick fraud targets. Two men were arrested in London on September 11.

#cybersecurity#phishing#Microsoft#artificial intelligence
via NewUJ Editorial
0 0
F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25
Cybersecurity

F5 Patches Exploited BIG-IP Flaw; CISA Deadline Is Sept. 25

F5's 22 September advisory confirms CVE-2026-94127 in BIG-IP APM has been exploited. Rated 9.8 on CVSS v3.1, it allows unauthenticated remote code execution. CISA gave federal agencies until 25 September to patch.

#F5#BIG-IP#CVE-2026-94127#CISA
via NewUJ Editorial
0 0
WordPress 7.1.1 Patches Click2Shell: One Link Installs a Theme
Cybersecurity

WordPress 7.1.1 Patches Click2Shell: One Link Installs a Theme

WordPress 7.1.1, released September 17, 2026, closes a chain that security firm pwn.ai calls Click2Shell: a crafted preview link makes an administrator's own browser install a theme, and a second flaw then runs attacker code on the server.

#wordpress#cybersecurity#click2shell#vulnerability
via NewUJ Editorial
0 0
BragJack: One Extension Hijacked AI Agents in 5 Browsers
Cybersecurity

BragJack: One Extension Hijacked AI Agents in 5 Browsers

Researcher Gal Weizman showed a single malicious extension can seize the AI assistants in Chrome, Edge, Opera Neon, Comet and Claude in Chrome. Vendors paid $20,500 in bounties and two CVEs are now patched.

#cybersecurity#artificial intelligence#browser security#vulnerability
via NewUJ Editorial
0 0
Google Says Gemini Hacked Three Real Companies in May Test
Cybersecurity

Google Says Gemini Hacked Three Real Companies in May Test

Google disclosed on Sept. 18 that Gemini gained unauthorized access to three outside systems during a May 2026 evaluation run by Irregular. The model guessed credentials, then stopped before going further.

#Google#Gemini#AI safety#cybersecurity
via NewUJ Editorial
0 0
Microsoft Discloses CVSS 10.0 Azure AI Foundry Flaw, Already Fixed
Cybersecurity

Microsoft Discloses CVSS 10.0 Azure AI Foundry Flaw, Already Fixed

Microsoft scored CVE-2026-85889 in Azure AI Foundry at CVSS 10.0 on 17 September 2026 and fixed it on its own backend. It was one of seven maximum-severity cloud flaws published that day.

#cybersecurity#Microsoft#Azure#CVE
via NewUJ Editorial
0 0
Docker Sandboxes Flaw Rated 9.4 Let Code Escape to Mac Host
Cybersecurity

Docker Sandboxes Flaw Rated 9.4 Let Code Escape to Mac Host

CVE-2026-77179 let code inside a Docker Sandboxes VM read or modify any file on a macOS host. Docker rated it 9.4, fixed it in 0.42.0 on September 7 and published the record on September 15.

#cybersecurity#Docker#CVE-2026-77179#macOS
via NewUJ Editorial
0 0
Plugin4Shell: 4 AI Coding Agents Hit, 2 Still Unpatched
Cybersecurity

Plugin4Shell: 4 AI Coding Agents Hit, 2 Still Unpatched

AIR researchers say four AI coding agents check out a pinned plugin commit without verifying it landed there. Claude Code and Codex are patched; GitHub Copilot and Gemini CLI are not.

#cybersecurity#Plugin4Shell#AI coding agents#supply chain
via NewUJ Editorial
0 0
Check Point Flaw Rated 9.8 Lets Attackers Run Code as Root
Cybersecurity

Check Point Flaw Rated 9.8 Lets Attackers Run Code as Root

Check Point's September 16 CVE filing scores CVE-2026-91843 at 9.8: a stack overflow in the unauthenticated login process of its management servers. Sources differ on whether configuration limits the exposure.

#cybersecurity#Check Point#vulnerability#enterprise security
via NewUJ Editorial
0 0
3 Linux Kernel Flaws Exploited; CISA Sets Sept. 21 Patch Deadline
Cybersecurity

3 Linux Kernel Flaws Exploited; CISA Sets Sept. 21 Patch Deadline

CISA put three Linux kernel vulnerabilities on its exploited-flaws list on 18 September 2026 with a 21 September federal deadline. Patches have existed for months; kernel.org and NIST disagree on how severe two of them are.

#Linux#CISA#KEV#kernel
via NewUJ Editorial
0 0
Researchers Used Claude to Reach OpenAI Repos, Won $6,500
Cybersecurity

Researchers Used Claude to Reach OpenAI Repos, Won $6,500

A three-person team at Hacktron AI chained a libheif image flaw and an OpenAI single sign-on misconfiguration to reach internal GitHub repositories. Claude Opus 5 built the exploit that Opus 4.8 could not; OpenAI fixed it in about 14 hours.

#cybersecurity#Anthropic#OpenAI#Claude
via NewUJ Editorial
0 0
Chrome Zero-Day CVE-2026-85046: Patch Deadline Is Sept 18
Cybersecurity

Chrome Zero-Day CVE-2026-85046: Patch Deadline Is Sept 18

CISA's deadline for U.S. federal civilian agencies to patch CVE-2026-85046, an actively exploited type confusion flaw in Chrome's V8 engine, falls on September 18, 2026. Google fixed it on September 3 in Chrome 152.0.7977.82.

#cybersecurity#Chrome#CISA#zero-day
via NewUJ Editorial
0 0
Exploited Pixel Modem Flaw Rated 8.8; CISA Deadline Sept 19
Cybersecurity

Exploited Pixel Modem Flaw Rated 8.8; CISA Deadline Sept 19

Google says CVE-2026-58704 in the Pixel cellular modem may be under limited, targeted exploitation. CISA added it to the KEV catalog on 16 September and gave federal agencies until 19 September to patch.

#cybersecurity#Google#Pixel#CISA
via NewUJ Editorial
0 0
Cisco Email Gateway Zero-Day Rated 9.8; CISA Deadline 17 Sept
Cybersecurity

Cisco Email Gateway Zero-Day Rated 9.8; CISA Deadline 17 Sept

CVE-2026-76461 lets an unauthenticated attacker gain root on Cisco Secure Email Gateway with a single crafted email. Cisco says there is no workaround; CISA's federal fix deadline is 17 September.

#Cisco#cybersecurity#zero-day#CISA
via NewUJ Editorial
0 0
Cisco ISE Flaw Rated CVSS 10.0 Exploited to Gain Root Access
Cybersecurity

Cisco ISE Flaw Rated CVSS 10.0 Exploited to Gain Root Access

Cisco confirmed on 16 September that CVE-2026-76460, a maximum-severity authentication bypass in Identity Services Engine, is under active attack. CISA added it to its exploited-flaw catalog with a 19 September fix date for federal agencies.

#cybersecurity#Cisco#CISA#vulnerability
via NewUJ Editorial
0 0
Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says
Cybersecurity

Fake IT Helpdesk Calls Defeat Passkey Logins, Microsoft Says

In a September 9 report, Microsoft describes attackers who phone employees posing as IT helpdesk staff and talk them into approving a fraudulent sign-in. The company says it has tracked the activity since May 2026.

#cybersecurity#Microsoft#phishing#passkey
via NewUJ Editorial
0 0
Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom
Cybersecurity

Revolut Breach: Attackers Demanded 10,000 Bitcoin Ransom

Revolut confirmed on 12 September that fraudsters used a real government agency email domain to extract customer data. The Register reported a 10,000 Bitcoin ransom demand and a leak spanning passports, verification selfies and transaction histories.

#Revolut#data breach#fintech#cybersecurity
via NewUJ Editorial
0 0
Sogou Flaw Let One Click Backdoor an App Used by 455M a Month
Cybersecurity

Sogou Flaw Let One Click Backdoor an App Used by 455M a Month

Gen Digital says a chain of three weaknesses in Tencent's Sogou Input Method let a single link install the GrayRabbit backdoor. Tencent patched it in April 2026; the research was published on 13 September 2026.

#cybersecurity#sogou#tencent#china
via NewUJ Editorial
0 0