← Back to Blog
Security News
Security News — 21 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 8 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 21 September 2026 · 12 items.
Government & Critical Vulnerability Advisories
CISA Current Activity21 Sep
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-7273 Zyxel GS1900 Series Switches Stack-Based Buffer Overflow Vulnerability This type of vulnera…
Read at source →
Primary Threat Research & Vendor Intelligence
Palo Alto Unit 4221 Sep
We explore how AWS neutralizes exposed IAM credentials using managed policies, detailing GitHub secret scanning and CloudTrail monitoring strategies. The post From Exposure to Lockdown: How AWS Neutralizes Compromised IAM Credentials throu…
Read at source →
Google Project Zero21 Sep
This short blog post is about abusing a privilege escalation bug that Microsoft recently fixed in Windows, CVE-2026-66804, that I and 14 others reported. This issue is an incomplete fix for CVE-2026-50343, a bug dubbed “Dark Elevator” by C…
Read at source →
Independent Investigative Journalism & Breaking News
Dark Reading21 Sep
Unbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.
Read at source →
Dark Reading21 Sep
ShinyHunters defaced Cl0p's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.
Read at source →
Dark Reading21 Sep
Victims have been identified in Africa, including in Kenya and Uganda.
Read at source →
Dark Reading21 Sep
The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)21 Sep
Microsoft Security Research published an interesting blog post "TerminalFix campaign deploys a reverse tunnel through multistage intrusion" about a malware campaign. The aspect that I want to take a closer look at, is the fact that the thr…
Read at source →
SANS Internet Storm Center (Handler Diary)21 Sep
Read at source →
Elastic Security Labs21 Sep
Cloud threat emulation is more than detonation. A plan-first methodology for cloud detection engineering: scope, victim model, telemetry, coverage, cleanup. Learn how to properly leverage AI to automate your emulations.
Read at source →
Security Executive, Architecture & Policy
Schneier on Security21 Sep
Hackers captured a Flock camera and got a look (alternate link ) at the software: While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered dat…
Read at source →
Daniel Miessler21 Sep
Isometric cutaway of a house at night: the owner asleep upstairs in sienna while four distinct purple people work the lamplit rooms below, one at the front door with a lantern, one sorting his mail into a ledger, one at his computer, one l…
Read at source →