PLAINTEXT REPORT Security headlines. Nothing else. Updated 2026-09-19 14:00 UTC. Showing the last 24h. Inspired by brutalist.report, but for infosec news. Proud supporter of the small web. An Intergalactic Robots production. https://intergalacticrobots.app/ THE HACKER NEWS --------------- * [3h] Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html * [4h] SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html * [5h] Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html * [6h] Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html * [6h] CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html * [7h] CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html * [19h] Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html * [21h] New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html * [22h] Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html BLEEPINGCOMPUTER ---------------- * [11m] ShinyHunters hacks Clop leak site, threatens to extort ransomware gang https://www.bleepingcomputer.com/news/security/shinyhunters-hacks-clop-leak-site-threatens-to-extort-ransomware-gang/ * [2h] Calling viral AI actress Tilly Norwood? Agree to a face scan first https://www.bleepingcomputer.com/news/security/calling-viral-ai-actress-tilly-norwood-agree-to-a-face-scan-first/ * [21h] Gyazo server flaw exploited to steal 23.6 million user records https://www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-to-steal-236-million-user-records/ * [22h] Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/ DARK READING ------------ * [now] [Virtual Event] Cybersecurity Outlook 2027 https://www.darkreading.com/events/virtual-event-cybersecurity-outlook-2027 * [now] [Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI https://www.darkreading.com/events/virtual-event-what-every-enterprise-know-securing-cloud-2026 * [now] [Virtual Event] Building a Secure AI Strategy for the Enterprise https://www.darkreading.com/events/virtual-event-building-secure-ai-strategy-enterprise-2026 * [17h] Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks https://www.darkreading.com/cyberattacks-data-breaches/vectra-ai-launches-ascent-new-era-ai-driven-attacks * [18h] Cisco Zero-Day Highlights API Endpoint Authentication Issues https://www.darkreading.com/vulnerabilities-threats/cisco-zero-day-api-endpoint-authentication-issues * [18h] EY Survey Finds Autonomous AI Implementation Outpaces Oversight https://www.darkreading.com/cyberattacks-data-breaches/ey-survey-autonomous-ai-implementation-outpaces-oversight * [19h] MFA Won't Save You From OAuth Consent Abuse https://www.darkreading.com/vulnerabilities-threats/mfa-oauth-consent-abuse THE RECORD ---------- * [23h] Nations take action on North Korean IT workers after UN report https://therecord.media/nations-take-action-on-north-korean-it-worker-schemes CYBERSCOOP ---------- * [17h] Early Scattered Spider member pleads guilty to cybercrime spree https://cyberscoop.com/scattered-spider-member-guilty-ahmed-elbadawy/ * [20h] Researchers use AI to find widespread software decoder flaw https://cyberscoop.com/hacktron-ai-heif-heist-vulnerability/ * [22h] International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data https://cyberscoop.com/north-korea-waterplum-job-seeker-crypto-attacks/ SANS ISC -------- * [9h] HTTP QUERY Method: The Grey Zone Between GET And POST. https://isc.sans.edu/diary/rss/33352 SCHNEIER ON SECURITY -------------------- * [16h] Friday Squid Blogging: On Squid Egg Sacs https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-on-squid-egg-sacs.html MALWAREBYTES LABS ----------------- * [22h] New Android malware uses AI to steal bank logins and PINs https://www.malwarebytes.com/blog/news/2026/09/new-android-malware-uses-ai-to-steal-bank-logins-and-pins * [23h] Did an AI really try to break free from human control? https://www.malwarebytes.com/blog/ai/2026/09/did-an-ai-really-try-to-break-free-from-human-control