National Cyber Warfare Foundation (NCWF)

Security Affairs newsletter Round 594 by Pierluigi Paganini INTERNATIONAL EDITION


0 user ratings
2026-09-13 15:20:07
milo
Blue Team (CND)
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open […


A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.





Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.





The AI Supply Chain Has a Security Problem, and Much of It Is Sitting on the Open Internet
Attackers Exploit Critical Cisco FMC Flaw to deploy Qilin ransomware
UK Council Attack Linked to Mass Exploitation of SonicWall Flaw
U.S. CISA adds Cisco, Google Chromium V8, Fortinet, and Citrix NetScaler flaws to its Known Exploited Vulnerabilities catalog
More Capable AI, Not Enough Guardrails
A New Claude ‘s Sandbox Failure Shows How AI Can Rationalize Real-World Harm
U.S. CISA adds Microsoft Windows, N-able N-central, and Adobe flaws to its Known Exploited Vulnerabilities catalog
Four Nation-State Actors Used the Same Chrome Zero-Day Exploit Kit Within 12 Days
US Agencies Warn Chinese AI Firms Are Extracting Advanced AI Models
Google fixes the seventh actively exploited Chrome zero-day of 2026
PoisonedRefresh: A Fileless Linux Rootkit That Injects PHP Web Shells Into F5 BIG-IP APM Server Memory
Chaotic Eclipse Released ShieldCrash, A PoC For Microsoft Defender Zero-Day
Microsoft’s Biggest Patch Tuesday: 974 CVEs, 2 Zero-Days and 20 Wormable Bugs
Hackers Drain $320 Million From Liquid Network, Then Return Most of It
WeChat Worm Can Hijack Accounts Without Victims Answering Calls
Massive Vietnam-Linked APIS Database Exposes Passport and Flight Data
North Korea-linked Hackers Hide a Backdoor Inside HAProxy
IT Help Desk Impersonation Lets Hackers Bypass MFA
Condé Nast Data of 32.8 Million Users Offered for Sale After WIRED Leak
StyleSmuggler: The Magento Zero-Day Behind New Store Attacks
Chaotic Eclipse Released GreenSection, A PoC For NVIDIA Memory Corruption Zero-Day
JSCeal Hides Crypto Malware in V8 Bytecode
Why AI Agent Sandboxes Are Failing Security Tests
Berlin Ransomware Leak Exposes State Secrets
Your MikroTik Router May Already Be Compromised: Look for SSH User “-2”
AI Agents Hijacked German Wiki to Cheat, OpenAI Delayed Disclosure




International Press – Newsletter





Cybercrime





Berlin launches crisis response after hackers publish stolen data





2026-09-03: Cloud Data Theft and Extortion via IT Help Desk Vishing and Residential Proxies  





Berlin cyberattack: hackers leak highly sensitive data across dark web 





Condé Nast: 32.8M user records for sale, sample verified  





BengalSEO Part 1: Anatomy of the Operation  





Hackers Drain $320 Million From Bitcoin’s Liquid Network, Keep $47 Million for Themselves in ‘White Hat’ Operation  





Passkey-themed social engineering leads to identity and cloud compromise  





Revolut confirms customer data breach through fake government requests  





Ukrainian National Sentenced to Four Years in Prison for Wire Fraud Conspiracy in Connection with Conti Ransomware  





Malware





REVSTEALER ramps up





Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode  





Signing in without actually signing in  





Artifactory Under Attack: In-the-Wild Exploitation of CVE-2026-42016, CVE-2026-42018 & CVE-2026-82329





Hacking





Critical vulnerabilities in MikroTik RouterOS are being actively exploited. Immediate update recommended 





GreenSection PoC exploit





StyleSmuggler: Magento and Adobe Commerce 0-day RCE under active attack  





WeWorm     





ShieldCrash  Windows Defender 0day Vulnerability 





CVE-2026-10520: Ivanti Sentry OS Command Injection Analysis  





Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox





UK Council Attack Linked to SonicWall SMA 1000 Campaign 





Active exploitation of Cisco Secure Firewall Management Center vulnerabilities





DeepSeek Harness < 0.1.2-alpha.1 Authentication Bypass via Host Header Spoofing





Intelligence and Information Warfare  





DPRK APTs: Ted backdoor and curlRAT target South Korean media and automotive sectors





Beyond Lazarus: Organization of DPRK cyber capabilities 





760,000 Leaked Logins and Five Spy Campaigns: Inside Pakistan’s Worst Cyber Year Yet





China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies  





Once in a BlueMoon: Multiple State-Aligned Threat Actors Rapidly Adopt Novel Exploit Chain Using Chrome and Windows Zero-Days 





Cybersecurity





OpenAI acknowledges ‘wiki incident’ and need for more transparency around unintended AI behavior    





MikroTik ssh 0day exploitation in the wild  





Daybreak for Frontline Defenders: $1B to protect essential services  





OpenAI is building ‘automated shutdown’ capabilities for AI tools, letter to lawmakers says 





A horde of AI agents conspired against their creators





The September 2026 Security Update Review  





AI could kill all humans in next decade, warn experts: but how seriously should we take them?





An alignment assessment of recent cybersecurity incidents     





Detecting and countering misuse of AI: September 2026    





Best Practices Guide for Cyber Hygiene 





Health data breach: EUR 500,000 fine against HÔPITAL PRIVÉ DE LA LOIRE  





Follow me on Twitter: @securityaffairs and Facebook and Mastodon





Pierluigi Paganini





(SecurityAffairs – hacking, newsletter)



Source: SecurityAffairs
Source Link: https://securityaffairs.com/198957/security/security-affairs-newsletter-round-594-by-pierluigi-paganini-international-edition.html


Comments
new comment
Nobody has commented yet. Will you be the first?
 
Forum
Blue Team (CND)



Copyright 2012 through 2026 - National Cyber Warfare Foundation - All rights reserved worldwide.