September 2026

AI coding agents leaked 13,000 internal company screenshots to public GitHub repos

AI coding agents leaked 13,000 internal company screenshots to public GitHub repos 2026-09-30 at 14:52 By Sinisa Markovic When developers ask AI coding agents to prove that a user interface fix works, some agents have been posting the evidence where anyone can find it, according to Glow Labs. Diagram showing how AI agents leak screenshots […]

AI coding agents leaked 13,000 internal company screenshots to public GitHub repos Read More »

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub 2026-09-30 at 14:30 By AI coding agents asked to share screenshots of code changes for review have put internal company images in public GitHub repositories, security company Glow said. Its researchers found more than 13,000 internal images from developers at over 300 organizations, […]

AI Coding Agents Exposed 13,000 Internal Images, Including Billing Records, on GitHub Read More »

Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit

Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit 2026-09-30 at 14:19 By Eduard Kovacs Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do. The post Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking […]

Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit Read More »

A single market worth protecting: Getting the MiCA review right

A single market worth protecting: Getting the MiCA review right 2026-09-30 at 14:00 By Cointelegraph by Simon Schneider As the European Commission’s MiCA review consultation closes, Europe must decide whether its crypto rulebook is protecting the market without making it too costly to build in. This article is an excerpt from Cointelegraph.com News View Original […]

A single market worth protecting: Getting the MiCA review right Read More »

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks 2026-09-30 at 13:59 By Ionut Arghire The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor. The post Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks Read More »

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access 2026-09-30 at 13:45 By ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session theft […]

US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access Read More »

OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised

OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised 2026-09-30 at 13:39 By Zeljka Zorz Attackers have compromised a self-hosted JFrog Artifactory instance operated by OpenInfra Europe, the regional hub of the OpenInfra Foundation warned in a security notice prominently displayed on its homepage. OpenInfra Europe’s security incident notice “Anyone who downloaded or installed artifacts […]

OpenInfra Europe’s JFrog Artifactory instance breached, packages potentially compromised Read More »

ShinyHunters Defiant After FBI Calls on Members to Come Forward

ShinyHunters Defiant After FBI Calls on Members to Come Forward 2026-09-30 at 13:20 By Ionut Arghire In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI. The post ShinyHunters Defiant After FBI Calls on Members to Come Forward appeared first on SecurityWeek. This article is […]

ShinyHunters Defiant After FBI Calls on Members to Come Forward Read More »

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT 2026-09-30 at 13:16 By Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG) […]

Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT Read More »

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted 2026-09-30 at 13:16 By A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if […]

OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted Read More »

SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit

SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit 2026-09-30 at 13:05 By Cointelegraph by Ezra Reguerra SlowMist identified malicious activity weeks before the Bitget theft, involving a zero-day vulnerability, two security products and a custom withdrawal tool. This article is an excerpt from Cointelegraph.com News View Original Source

SlowMist traces Bitget hack activity to Aug. 31 zero-day exploit Read More »

Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore

Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore 2026-09-30 at 12:31 By Sinisa Markovic Signal users who switch from an Android phone to an iPhone, or the other way around, can take their message history with them, and backups can be restored on Android, iOS, Linux, macOS and Windows. The option […]

Signal brings encrypted local backups to iOS and desktop, adds cross-platform restore Read More »

Former US Air Force members behind million-dollar BEC scheme head to prison

Former US Air Force members behind million-dollar BEC scheme head to prison 2026-09-30 at 10:42 By Sinisa Markovic Two men who ran BEC and phishing campaigns against US businesses while serving in the Air Force have been sentenced to a combined 189 months in federal prison. According to public documents and evidence presented at sentencing, […]

Former US Air Force members behind million-dollar BEC scheme head to prison Read More »

European stablecoin issuer AllUnity launches USD stablecoin USDAU

European stablecoin issuer AllUnity launches USD stablecoin USDAU 2026-09-30 at 10:00 By Cointelegraph by Helen Partz AllUnity is launching USDAU, its fourth fiat-backed stablecoin, expanding a MiCA-regulated lineup that already covers the euro, Swiss franc and Swedish krona. This article is an excerpt from Cointelegraph.com News View Original Source

European stablecoin issuer AllUnity launches USD stablecoin USDAU Read More »

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL 2026-09-30 at 09:55 By Eduard Kovacs Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries.  The post High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL Read More »

Genea brings AI agents to access control with role-based permissions

Genea brings AI agents to access control with role-based permissions 2026-09-30 at 09:49 By Industry News Genea has announced the release of Genea MCP, a Model Context Protocol (MCP) server that connects AI agents directly to the Genea Access Control platform. Onboarding a new hire, setting up a contractor for two weeks, or unlocking the […]

Genea brings AI agents to access control with role-based permissions Read More »

Security tools can now scan Claude Enterprise chats and uploads for sensitive data

Security tools can now scan Claude Enterprise chats and uploads for sensitive data 2026-09-30 at 09:31 By Anamarija Pogorelec More than 100 security and compliance vendors have integrations with the Claude Compliance API, which lets a company send Claude activity into the monitoring tools it already uses. CrowdStrike, Microsoft Purview, Splunk, Palo Alto Networks, Cloudflare […]

Security tools can now scan Claude Enterprise chats and uploads for sensitive data Read More »

OWASP Noir: Open-source static analysis tool

OWASP Noir: Open-source static analysis tool 2026-09-30 at 08:30 By Anamarija Pogorelec OWASP Noir is an open-source static analysis tool that reads an application’s source code and lists the endpoints it exposes: paths, HTTP methods, parameters, headers, and cookies, each tied to the file and line it came from. Here’s where it gets useful. Shadow […]

OWASP Noir: Open-source static analysis tool Read More »

Scroll to Top