← Back to Blog
Security News
Security News — 18 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 10 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 18 September 2026 · 27 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Critical CVEs18 Sep
CVSS 9.3 CRITICAL A vulnerability was identified in Totolink A3002MU Hh-B20211125.1046. Affected is the function formWlEncrypt of the file /boafrm/formWlEncrypt. The manipulation of the argument submit-url leads to buffer overflow. It is p…
Read at source →
CVEDatabase - Critical CVEs18 Sep
CVSS 8.6 HIGH A vulnerability was determined in Totolink A3002MU Hh-B20211125.1046. This impacts the function formWlAc of the file /boafrm/formWlAc. Executing a manipulation of the argument submit-url can lead to buffer overflow. The attac…
Read at source →
CVEDatabase - Critical CVEs18 Sep
CVSS 9.3 CRITICAL A flaw was found in the OpenShift console. Unauthenticated access to the `/api/devfile/` and `/api/devfile/samples/` endpoints allows a remote attacker to send crafted devfile payloads. This can lead to Server-Side Reques…
Read at source →
CVEDatabase - Recent CVEs18 Sep
CVSS 2.3 LOW In Vinyl Cache before 9.0,2, workspace buffer overflow vulnerability was found in the .upper() and .lower() string type methods of VCL. This can be used as a remote denial of service (DoS) vector to make the child process segf…
Read at source →
CVEDatabase - Critical CVEs18 Sep
CVSS 8.6 HIGH A vulnerability was found in Totolink A3002MU Hh-B20211125.1046. This affects the function formSchedule of the file /boafrm/formSchedule. Performing a manipulation of the argument webpage results in buffer overflow. The attac…
Read at source →
CVEDatabase - Recent CVEs18 Sep
CVSS 6.5 MEDIUM A flaw was found in Netty's `netty-codec-http` component. A remote attacker could exploit this vulnerability by sending a specially crafted HTTP/1.1 chunk-size token that includes post-digit whitespace. This incorrect parsi…
Read at source →
CVEDatabase - Recent CVEs18 Sep
CVSS 6.5 MEDIUM A flaw was found in Netty's HTTP/1 decoder. Incomplete validation of malformed Transfer-Encoding headers allows a remote attacker to perform HTTP request smuggling. By sending specially crafted HTTP requests, an attacker ca…
Read at source →
CISA Current Activity18 Sep
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-39682 Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability This type…
Read at source →
CISA Current Activity18 Sep
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2025-39964 Linux Kernel Race Condition Vulnerability CVE-2026-53266 Linux Kernel Out-of-Bounds Writ…
Read at source →
Primary Threat Research & Vendor Intelligence
Palo Alto Unit 4218 Sep
Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and…
Read at source →
Independent Investigative Journalism & Breaking News
Dark Reading18 Sep
The new program expands Vectra AI's partner strategy as increasingly complex security environments and the growing use of AI create demand for broader AI expertise, services, and security outcomes.
Read at source →
Dark Reading18 Sep
The authentication bypass flaw CVE-2026-76460 impacts Cisco's Identity Services Engine (ISE) and received a maximum 10 out of 10 CVSS score.
Read at source →
Dark Reading18 Sep
A new survey of senior AI execs shows that while organizations are rapidly deploying AI and autonomous systems, their process and controls are not keeping pace.
Read at source →
Dark Reading18 Sep
MFA is essential, but it cannot replace OAuth governance, least-privilege scopes, consent monitoring, and rapid revocation.
Read at source →
The Hacker News18 Sep
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system…
Read at source →
The Hacker News18 Sep
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory witho…
Read at source →
BleepingComputer18 Sep
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. [...]
Read at source →
The Hacker News18 Sep
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler…
Read at source →
BleepingComputer18 Sep
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. [...]
Read at source →
BleepingComputer18 Sep
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access…
Read at source →
BleepingComputer18 Sep
Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company's security requirements. [...]
Read at source →
The Hacker News18 Sep
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS sco…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)18 Sep
In June 2026 the IETF published RFC 10008[1], defining a new HTTP method: "QUERY". The HTTP protocol faced already by changes (HTTP/2, HTTP/2) but it's the first new standard HTTP verb since "PATCH" in 2010!
Read at source →
SANS Internet Storm Center (Handler Diary)18 Sep
Read at source →
Elastic Security Labs18 Sep
We linked one Elastic Security project to 100 others and ran the full prebuilt detection catalog from the origin, with all the ingest landing in the linked projects. It held up, and where it deliberately does not reach is the interesting p…
Read at source →
Security Executive, Architecture & Policy
Schneier on Security18 Sep
Short essay about squid egg sacs. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Read at source →
Schneier on Security18 Sep
Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude. In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual h…
Read at source →