IT Security Newsletter - 9/18/2026
Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
Two oil tankers bound for Texas were boarded by US Coast Guard and FBI personnel last month after cyberattacks disrupted the vessels during their voyage toward the United States, according to a CBS News report citing US officials. One of the ships, the VL Prosperity, is a Liberian-flagged crude tanker that left Egypt on August 1 en route to Galveston, Texas, per vessel-tracking records cited by CBS News. READ MORE...
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched
Four major AI coding agents, Claude Code, Codex, GitHub Copilot and Gemini CLI, all share the same zero-click RCE vulnerability, one that could give an attacker the same reach into a company's systems and data as the employee running the agent, according to AIR. "It is the first supply chain vulnerability of the AI agent ecosystem," the researchers said. "Anyone running a major coding agent that installs plugins from a marketplace is exposed." READ MORE...
Fake parcel delivery messages steal your card and bank details
Parcel delivery phishing campaigns appear around the world under different courier names. In the United States, the messages commonly impersonate USPS and claim that a package has an invalid address or could not be delivered. Similar messages impersonate services in France, Spain, Italy, and the Netherlands. The details vary, but the aim is usually the same: to persuade you to visit a fake courier website and provide personal and financial information. READ MORE...
A fake ChatGPT billing email is after your OpenAI password
A fake ChatGPT billing email is steering users to a copy of the OpenAI login page that keeps whatever username and password they type. Josh Varden of Cofense's Phishing Defense Center traced the email's payment button through a Google redirect to the attacker's page. The lure targets ChatGPT users on work and personal accounts alike, and it copies the kind of bill a subscriber already expects. Credentials entered on the fake page go to the attacker, and the victim is sent on to an error page. READ MORE...
Microsoft fixes bug behind 'Defender Antivirus is turned off' alerts
Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. In a Windows release health dashboard update on Thursday, Microsoft said the issue was fixed in the Microsoft Defender Antivirus update (version 4.18.26080.4) released on September 17. The company acknowledged the bug in late August, even though the issue had affected users since at least June. READ MORE...
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into over 100,000 websites. Brevo was initially hacked on September 10, when a threat actor exploited a vulnerability in Brevo's handling of SAML SSO to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor. The attackers sent phishing emails from six of the accounts and exported the contacts of 43 accounts, Brevo said in an incident notice. READ MORE...
Hackers reveal how Flock cameras really track cars and people
Hackers ripped down a Flock camera above a roadway, made a near-complete copy of the data stored inside it, and shared the files with 404 Media and WIRED, revealing in new detail how exactly Flock Safety's cameras track the movements of both vehicles and people. The hackers say they are also publishing details on how they managed to obtain the software. The breach provides an unprecedented look inside a system that Flock has described as protected by on-device encryption. READ MORE...
Researchers find way to listen in on headphones from afar
Researchers based in China have devised a way to eavesdrop on signals handled by analog components in devices such as headphones, landline handsets, and smart devices by injecting electromagnetic (EM) signals. The technique, referred to as InjectEave, is not simply listening in on a low-frequency analog signal. It's an EM side-channel attack that overcomes one of the longstanding barriers to exploiting EM leakage: the faintness of RF signals in devices like headphones. READ MORE...
New Check Point flaw lets hackers execute code with root privileges
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. Tracked as CVE-2026-91843, this flaw stems from a stack-based buffer overflow weakness in the login process for Security Management Server instances, which manage Security Gateways (firewalls) and monitor network security events. The security issue also affects the company's Log Server. READ MORE...
Microsoft exec called AI scraping the "largest theft of labor in human history"
For years, Microsoft and OpenAI have fought to keep certain information out of the public eye in their fight with news organizations that have accused the AI firms of teaming up to violate copyright laws by stealing tons of news content to train AI. However, now the details that should never have been marked confidential are starting to leak. In a motion for summary judgment that was unsealed Thursday, internal documents are exposed that show exactly how Microsoft and OpenAI viewed the threat. READ MORE...
- ...in 1793, George Washington lays the cornerstone to the United States Capitol building.
- ...in 1927, Columbia Broadcasting System (known today as CBS) first goes on the air.
- ...in 1945, Gen. Douglas MacArthur moves his command headquarters to Tokyo.
- ...in 1971, American cyclist Lance Armstrong is born in Plano, TX.








