PLAINTEXT REPORT Security headlines. Nothing else. Updated 2026-09-17 23:00 UTC. Showing the last 24h. Inspired by brutalist.report, but for infosec news. Proud supporter of the small web. An Intergalactic Robots production. https://intergalacticrobots.app/ THE HACKER NEWS --------------- * [10h] Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html * [11h] Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar https://thehackernews.com/2026/09/can-you-prove-new-cve-is-exploitable.html * [12h] CISO's Expert Guide to Agentic Pentesting for Websites https://thehackernews.com/2026/09/cisos-expert-guide-to-agentic.html * [12h] China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America https://thehackernews.com/2026/09/china-aligned-famoussparrow-deploys.html * [13h] OpenAI Reveals Six Model Incidents Involving Hidden Failures and Unauthorized Uploads https://thehackernews.com/2026/09/openai-reveals-six-model-incidents.html * [14h] BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html * [15h] Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html * [16h] Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html * [17h] U.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS Attacks https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html BLEEPINGCOMPUTER ---------------- * [1h] New RatHat Android malware uses AI to automate device control https://www.bleepingcomputer.com/news/security/new-rathat-android-malware-uses-ai-to-automate-device-control/ * [4h] OpenAI details more cases of AI agents taking unauthorized actions https://www.bleepingcomputer.com/news/security/openai-details-more-cases-of-ai-agents-taking-unauthorized-actions/ * [5h] Brevo supply-chain attack injected ClickFix scripts on customer sites https://www.bleepingcomputer.com/news/security/brevo-supply-chain-attack-injected-clickfix-scripts-on-customer-sites/ * [8h] What Recent AI-Powered Attacks Mean for Your Identity Security https://www.bleepingcomputer.com/news/security/what-recent-ai-powered-attacks-mean-for-your-identity-security/ * [9h] Windows 11 24H2 Home and Pro reach end of support in October https://www.bleepingcomputer.com/news/microsoft/windows-11-24h2-home-and-pro-reach-end-of-support-in-october/ * [11h] US takes down NightmareStresser DDoS-for-hire platform https://www.bleepingcomputer.com/news/security/fbi-seizes-nightmarestresser-service-linked-to-thousands-of-ddos-attacks/ * [14h] Chinese hackers use SparroWocky malware in govt espionage attacks https://www.bleepingcomputer.com/news/security/chinese-hackers-use-sparrowocky-malware-in-govt-espionage-attacks/ * [14h] Microsoft shares workaround for Windows domain login issues https://www.bleepingcomputer.com/news/microsoft/microsoft-releases-workaround-for-windows-domain-login-authentication-issues/ * [15h] Cisco warns of max severity ISE zero-day exploited in attacks https://www.bleepingcomputer.com/news/security/cisco-warns-of-identity-service-engine-zero-day-exploited-in-attacks/ * [22h] Anthropic wants Claude to analyze your bank account and financial data https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-wants-claude-to-analyze-your-bank-account-and-financial-data/ DARK READING ------------ * [now] [Virtual Event] Cybersecurity Outlook 2027 https://www.darkreading.com/events/virtual-event-cybersecurity-outlook-2027 * [now] [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI https://www.darkreading.com/events/virtual-event-what-every-enterprise-know-securing-cloud-2026 * [now] [Virtual Event] Building a Secure AI Strategy for the Enterprise https://www.darkreading.com/events/virtual-event-building-secure-ai-strategy-enterprise-2026 * [1h] CISA Ditches Weekly Vulnerability Roundups for Risk-Based Focus https://www.darkreading.com/cyber-risk/cisa-ditches-weekly-vuln-roundups-risk-based-focus * [3h] China's FamousSparrow APT Spies on US Politics in Latin America https://www.darkreading.com/cyberattacks-data-breaches/china-famoussparrow-spies-latin-america THE RECORD ---------- * [2h] European Commission set to push social media restrictions, safety requirements into law https://therecord.media/european-commission-set-to-push-social-media-kids-restrictions-into-law * [6h] China’s FamousSparrow hackers target Latin America with new backdoor https://therecord.media/china-hackers-latin-america-espionage * [9h] Hackers claim breach of Russian election systems days before parliamentary vote https://therecord.media/russia-election-hackers-breach * [9h] Congress eyes new support for Cyber Command after recent suicide deaths https://therecord.media/congress-eyes-support-for-cyber-command-suicide-deaths * [10h] Israeli contractor BlackCore trained Angolan officials in online influence operations https://therecord.media/angola-israel-influence-operations-blackcore CYBERSCOOP ---------- * [1h] Cisco alerts customers to second actively exploited zero-day in as many days https://cyberscoop.com/cisco-ise-zero-day-cve-2026-76460/ * [3h] The AI hacking apocalypse is not inevitable https://cyberscoop.com/ai-agent-hacking-apocalypse-cybersecurity/ * [9h] Authorities seize popular, long-running DDoS-for-hire service domains https://cyberscoop.com/fbi-seizes-nightmarestresser-ddos-for-hire-domains/ * [13h] America’s cyber strategy overlooks the infrastructure that actually keeps the military moving https://cyberscoop.com/us-cyber-strategy-iranian-threats-infrastructure-op-ed/ SANS ISC -------- * [7h] LausivLoader analysis, or how to pass data between malware stages https://isc.sans.edu/diary/rss/33348 * [21h] ISC Stormcast For Thursday, September 17th, 2026 https://isc.sans.edu/podcastdetail/10098 https://isc.sans.edu/diary/rss/33346 SCHNEIER ON SECURITY -------------------- * [11h] How Candidates Could Use AI for Good https://www.schneier.com/blog/archives/2026/09/how-candidates-could-use-ai-for-good.html MALWAREBYTES LABS ----------------- * [4h] Flock cameras are tracking people as well as cars https://www.malwarebytes.com/blog/privacy/2026/09/flock-cameras-are-tracking-people-as-well-as-cars * [8h] Revolut phishing texts appear days after data breach https://www.malwarebytes.com/blog/threat-intel/2026/09/revolut-phishing-texts-appear-days-after-data-breach * [11h] 12 celebrity deepfake websites seized by Manhattan DA https://www.malwarebytes.com/blog/ai/2026/09/12-celebrity-deepfake-websites-seized-by-manhattan-da * [12h] T-Mobile rewards points expiry texts are a phishing scam https://www.malwarebytes.com/blog/threat-intel/2026/09/t-mobile-rewards-points-expiry-texts-are-a-phishing-scam GRAHAM CLULEY ------------- * [8h] US Coast Guard and FBI board oil tanker to investigate cyber attack https://www.bitdefender.com/en-us/blog/hotforsecurity/us-coast-guard-fbi-board-oil-tanker-investigate-cyber-attack * [23h] Smashing Security podcast #485: These researchers got drunk to hack an LG TV https://grahamcluley.com/smashing-security-podcast-485/ UNIT 42 (PALO ALTO) ------------------- * [59m] Inside the Modern SOC: Defending the Cross-Environment Pivot https://unit42.paloaltonetworks.com/soc-cross-environment-pivot/ CISA ADVISORIES --------------- * [11h] Mitsubishi Electric CC-Link IE TSN Communication Protocol (Update A) https://www.cisa.gov/news-events/ics-advisories/icsa-26-211-07 * [11h] Mitsubishi Electric GX Works3 and Motion Control Settings https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-02 * [11h] Hitachi Energy FACTS Control Platform (FCP) https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-03 * [11h] Bransys ELD https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-01 * [11h] Schneider Electric NetBotz 5 750/755 https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-05 * [11h] Schneider Electric Modicon M340 Controller and Communication Modules https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-04 * [11h] Schneider Electric PowerChute Serial Shutdown https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-07 * [11h] ABB Ability Edgenius https://www.cisa.gov/news-events/ics-advisories/icsa-26-260-06 ZERO DAY INITIATIVE ------------------- * [18h] ZDI-26-714: Samsung rlottie Stack-based Buffer Overflow Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-26-714/ CISCO TALOS ----------- * [4h] Should you care about an “AI slowdown?” https://blog.talosintelligence.com/should-you-care-about-an-ai-slowdown/ * [12h] Ransomware incidents in Japan in the first half of 2026: Investigation of The Gentlemen’s infrastructure and evidence of Qilin's AI use https://blog.talosintelligence.com/ransomware-incidents-in-japan-in-the-first-half-of-2026/