> IT-Sentinel.com

// Cybersecurity & IT News Aggregator - Real-time Threat Intelligence Feed

NEWS CVE
← messages.back_to_articles

> Security Affairs newsletter Round 597 by Pierluigi Paganini – INTERNATIONAL EDITION

[SOURCE] Security Affairs [AUTHOR: Pierluigi Paganini] [DATE: 27/09/2026 13:40] [LANGUAGE: EN]
A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. OpenAI Agents Accessed US Government Websites Without AuthorizationExploit.in Database Reveals the Roots of Today’s Ransomware EcosystemU.S. CISA adds WordPress flaw to its Known Exploited Vulnerabilities catalogU.S. CISA adds Microsoft SharePoint and Mikrotik RouterOS flaws to its Known Exploited Vulnerabilities catalogCryptocurrency exchange Bitget Says North Korea-Linked Hackers Stole $351.6 MillionClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic StealerAI-Powered CARBONATO Botnet Steals Credentials to Fund Its Own LLM GatewayU.S. CISA adds Adobe and WSO2 flaws to its Known Exploited Vulnerabilities catalogRyuk Member Karen Vardanyan Sentenced to Two Years in U.S. PrisonAI Helps Uncover MikroTrick Attack Chain in MikroTik RouterOSOpenAI Agent Bypassed an Australian Government Health Portal During Internal ResearchCLOSEDQUORUM, the malware that asks four AI models what to do nextU.S. CISA adds Check Point, Arista VeloCloud Orchestrator, and F5 BIG-IP APM flaws to its Known Exploited Vulnerabilities catalogF5 BIG-IP APM Zero-Day Exploited in Zero-Day RCE AttacksShinyHunters claims FBI breach after alleged PeopleSoft zero-day attackEvilTokens made phishing-as-a-service look easy. Then it got taken downFake LastPass on GitHub Led to an Infostealer That Killed 145 Security ToolsCVE-2026-87902: how close is your WordPress to remote code execution?Check Point Fixes a New Actively Exploited Critical Security FlawChaotic Eclipse Released BigDiskBuster, A PoC For Windows Defender Update DoS Zero-DayPublic PoC Exposes Critical Veeam Agent Privilege EscalationU.S. CISA adds Zyxel flaw to its Known Exploited Vulnerabilities catalogContagious Interview: 30,000 devices infected by a fake job interviewGoogle Fined €403 Million Over Location Data PracticesForeign Hackers Target Two Colorado Water UtilitiesChainScript: the RAT that hides its command server inside a blockchain contractA BYD Shark 6 Hack Shows the Risks of Connected CarsThe Target Is No Longer the Model. It’s the Agent.UK Police Data Faces Long-Standing Microsoft Cloud Security ConcernsU.S. CISA adds Linux Kernel flaws to its Known Exploited Vulnerabilities catalogAI Hallucinations Nearly Triggered a US-China Military Confrontation International Press – Newsletter Cybercrime ShinyHunters hacks Clop leak site, threatens to extort ransomware gang Unmasking EvilTokens: Getting to the root of device code phishing Consumer Protection Tuesday: Taking Down Evil Tokens ShinyHunters hackers say they breached FBI, stole data on bureau employees   Tech CEO, Russian National Arrested on Complaint Alleging They Hid Russian Ownership and Development of Software Sold to U.S. Government How Romanian Crime Rings Are Draining U.S. Welfare Accounts   An undercover Google analyst infiltrated a notorious supply-chain hacking gang     Armenian National Extradited to the United States Sentenced to Federal Prison for Ransomware Extortion Scheme      Spraying in the Andes: TeamFiltration Returns to Exploit Forgotten Service Accounts   Exploit.in: inside a Russian hacker forum, 2005 to 2008   Kosovar National Pleads Guilty to Operating Cybercrime Marketplace Offering Tools and Products to Cybercriminals   Malware Threat Intel | One Kit, Forty Companies: How a Malware-as-a-Service Platform Used GitHub as a Distribution Network for its Campaign   Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO   Malicious npm campaign targets developers integrating Twilio Graphalgo campaign spreads to Terraform providers and Go Modules      Inside Corp MDM, the Android spyware targeting logistics companies      ClickFix Malware Report   Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud    Hacking We got a cybersecurity expert to hack this BYD. It was too easy   UPDATE: Active Exploitation CVE-2026-32996 of Veeam Agent   Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity  One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor WordPress 7.1.2 Security Release: Unauthenticated LFI to RCE  Critical F5 BIG-IP Vulnerability Exploited as Zero-Day   MikroTrick: technical analysis, disclosure process, and the use of LLM agents  Top 10 attacks on Claude Code and what each one actually broke Muse, Meta’s extraordinarily privileged AI assistant, has a serious 0-day   Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure Intelligence and Information Warfare   Water Cyberattack Campaign 2026   Exclusive: US military had close call after using AI for false intelligence report, sources say  Foreign hackers breach two more US water utilities, threaten safety of Colorado residents   North Korean “WaterPlum,” commonly referred to as “Contagious Interview,” Cyber Actor Group Targeting IT Professionals; Activities of North Korean IT Workers in Japan, the United States and Europe    Cybersecurity Sensitive UK police data vulnerable to ‘compromise’ by US government and foreign actors   ENISA Threat Landscape 2026 Breadcrumb Home Publications ENISA Threat Landscape 2026   Data Protection Commission fines Google €403 million following Inquiry into Google’s processing of location data   How AI could make it harder for governments to use hacking tools OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files Altman, Amodei Call for Global Cooperation on AI to Boost Safety Follow me on Twitter: @securityaffairs and Facebook and Mastodon Pierluigi Paganini (SecurityAffairs – hacking, newsletter)
[messages.read_original_source] →