<img src="https://secure.ruth8badb.com/159098.png" alt="" style="display:none;">

IT Security Newsletter - 9/22/2026

SHARE

Top News

Meta's Muse AI assistant has a zero-day that can turn it into a Mac backdoor

Mac security researcher Patrick Wardle says it's trivial to turn Muse into "the ultimate backdoor." Increasingly, AI assistants are changing from tools that simply answer questions into agents that can plan tasks, use connected services, and take actions for us. These actions might include booking appointments, filling out forms, creating documents, making purchases, or interacting with email and calendars. READ MORE...

Hacking

China-nexus actor steals thousands of documents in monthslong exploitation campaign

A Chinese-speaking threat actor has engaged in a hacking campaign at least since June, involving the theft of thousands of documents from, at minimum, one Western government, according to a Monday blog post from threat intelligence firm GreyNoise. The hacker targeted critical vulnerabilities in multiple technologies, including WordPress, Zyxel and Ubiquiti, and is suspected of using a large language model to develop custom tools used in the attacks. READ MORE...

Malware

Cybercriminals Are Hiding New Malware in Torrents for Popular Films

Kaspersky's Global Research and Analysis Team (GReAT) has uncovered a sophisticated new multi-stage campaign targeting both individual users and organisations. The campaign relies on a previously unknown malware strain distributed through torrent trackers disguised as popular films, including The Odyssey. One of the popular public archives of torrent files was compromised and was then used to deliver the malicious payload. READ MORE...

Information Security

Gemini's breach of real companies exposes an AI guardrail problem

Google says one of its Gemini models accessed systems belonging to three real companies during a cybersecurity evaluation in May. The model reportedly guessed credentials in one case, while finding exposed credentials in public repositories in two others. Google says Gemini stopped once it recognized that it had reached real infrastructure and that the affected organizations were notified. READ MORE...


The next intellectual property thief may sound like your CEO

Impersonation, phishing and domain-name abuse are the most concerning types of online intellectual property infringement, according to CSC's The State of Online IP Risk 2026 report. Internet and branded content, online marketplaces and paid search were the channels most frequently targeted. CSC surveyed 300 senior executives specializing in intellectual property law during the second quarter of 2026. READ MORE...


Another worry for water systems: infostealer exposure

Nearly two of every 10 U.S. water and wastewater organizations have identity data actively exposed from infostealers harvesting their credentials, according to research published Tuesday. The study from identity risk firm SpyCloud follows months of reports about a wave of cyberattacks hitting targets in the sector, which U.S. government officials suspect are tied to Iran. The company built a database of 66,845 Environmental Protection Agency-registered systems. READ MORE...

Exploits/Vulnerabilities

D-Link warns of max severity zero-day bug in DIR-822A routers

D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. This security flaw stems from a stack-based buffer overflow and improper data handling in the DHCP server component and can be exploited without authentication or user interaction. Attackers without valid credentials on the same local network can send crafted DHCP packets to the device. READ MORE...


Anthropic-linked CVEs pile up, attackers mostly shrug

Despite the concern that advanced AI models' bug-hunting prowess will lead to attackers exploiting more newly uncovered CVEs, fewer than 0.5 percent of the vulnerabilities linked to Anthropic or Project Glasswing are being batttered in the wild, according to VulnCheck security researcher Patrick Garrity. Garrity began tracking CVEs attributed to Project Glasswing, Anthropic's initiative to give select partners access to its Claude Mythos Preview model. READ MORE...

On This Date

  • ...in 1789, the office of United States Postmaster General is established.
  • ...in 1958, rock musician Joan Jett ("I Love Rock 'n' Roll", "Bad Reputation") is born in Wynnewood, PA.
  • ...in 1961, President John F. Kennedy signs legislation establishing the Peace Corps as a permanent government agency.
  • ...in 1991, the Dead Sea Scrolls are made available to the public for the first time.