This posting is here to collect cyber security news in September 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
This posting is here to collect cyber security news in September 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
144 Comments
Tomi Engdahl says:
Britney Nguyen / MarketWatch:
Cybersecurity stocks were the top performers in the S&P 500 on Monday amid escalating AI fears; CrowdStrike rose 14%, Palo Alto Networks 13%, and Fortinet 9%
CrowdStrike and Palo Alto Networks lead software stocks to a never-before-seen feat
https://www.morningstar.com/news/marketwatch/20260914261/crowdstrike-and-palo-alto-networks-lead-software-stocks-to-a-never-before-seen-feat
Tomi Engdahl says:
Usb-porttiin kiinnitetty laite teki kymmenistätuhansista televisioista rikoksentekovälineitä
https://www.is.fi/digitoday/tietoturva/art-2000012267876.html
Tietoturvayhtiö Bitsight havaitsi kymmeniä tuhansia halpoja Android-tv-tikkuja, jotka olivat vaarallisia jo tehtaalta lähtiessään.
Laitteisiin oli asennettu valmiiksi kiinalaisen yhtiön sovelluksia, jotka ohjasivat liikennettä käyttäjän yhteyden kautta ja tekivät mainospetoksia.
Noin 38 000 haitallista tikkua tuotti mainospetoksilla arviolta lähes 43 000 euroa päivässä.
Tietoturvayhtiö F-Securen asiantuntija Joel Latto kehottaa kuluttajia pysyttelemään luotetuissa ja sertifioiduissa laitteissa.
Halvoilla Android-pohjaisilla tv-tikuilla eli mediatoistimilla voi olla pimeä puoli. Tietoturvayhtiö Bitsight havaitsi kymmeniätuhansia tällaisia televisioihin kytkettyjä laitteita, jotka olivat vaarallisia jo tehtaalta lähtiessään.
Laitteisiin oli asennettu valmiiksi kaksi kiinalaisen yhtiön sovellusta, joiden avulla tv-tikut pystyivät tekemään katalia asioita käyttäjänsä selän takana. Tv:n ollessa päällä tikut ohjasivat internet-liikennettä käyttäjän kotiyhteyden kautta. Maksua vastaan tarjottu palvelu voi olla houkuttava rikollisille.
Kun television sulki, tikut alkoivat takoa rahaa mainospetoksilla. Tikut ottivat yhteyttä tekoälyllä luotuihin verkkosivuihin ja tekeytyivät tunnettujen brändien puhelimiksi. Automatisoidut ohjelmat eli botit klikkasivat näillä verkkosivuilla olevia mainoksia näyttökertojen kerryttämiseksi eli rahan tekemiseksi.
Latton mukaan tekoäly tekee tällaisesta toiminnasta entistä automaattisempaa ja laajamittaisempaa. Näin aivan tavallisista nettiin kytketyistä laitteista voi tulla osa paljon suurempaa rikollista operaatiota.
– Kuluttajien tulisi pysytellä luotetuissa ja sertifioiduissa laitteissa, jotka saavat säännöllisesti tietoturvakorjauksia, Latto neuvoo.
Tomi Engdahl says:
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-kb5002914-security-update-breaks-excel-copy-and-paste/?fbclid=IwdGRjcAUWC3RwZG9mBWV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHggTK0rW8bhbzLqYUKdwGet0IqqakxKvzBdSgC2BDy7RWuoWBNaRoRNCJUt5_aem_YRva5h3NsOiHdG7x01RiEQ
Tomi Engdahl says:
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/?fbclid=IwdGRjcAUWOOBwZG9mBWV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHq4Rvoeo4jl6sj4dWHV4FLcoJAzWF4QJiBbKZ47HVahBJHFG2GYYy2FrlMEq_aem_mi2IG07iCy1pUjFanYKQsg
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.
Broadcom addressed the security flaw (tracked as CVE-2026-59310) on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code.
The company also warned customers in a supplemental FAQ at the time to treat fixing CVE-2026-59310 as an emergency and install patches as soon as possible.
Tomi Engdahl says:
Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers.
https://www.securityweek.com/microsoft-commits-to-sweeping-ai-privacy-rules-for-students-will-other-tech-giants-follow/
Tomi Engdahl says:
CISO Strategy
“We Think the Security Control Is Working” Is No Longer Good Enough
Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today.
https://www.securityweek.com/we-think-the-security-control-is-working-is-no-longer-good-enough/
Security, risk, and control assessments are typically done for the sake of compliance: tools deployed, audits passed, workflows completed, boxes checked. That’s no longer enough for boards, customers, and regulators, who all want an answer to a harder question: ‘can you prove your controls are working right now?’
I often ask CISOs a version of that question, and the honest answer is usually some form of “we think so.” It’s not because they’re careless. Most control checks still happen the way a dentist visit does. When your dentist asks whether you brush and floss every day, you could fib and say yes, but one look at your x-ray tells the real story.
Security works the same way. An annual audit captures what you told the auditor, or what looked true on the day someone checked. But it may not be the ground truth.
Tomi Engdahl says:
Vulnerabilities
$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws
AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage.
https://www.securityweek.com/1-million-sandbox-challenge-uncovers-linux-kernel-flaws/
Linux
A two-week focused sandbox bug-bounty program resulted in 1,285 filings, but none that could access customer data.
The Vercel sandbox, a Firecracker‑based microVM environment, is an isolation tool for untrusted AI‑agent code. For two weeks (August 18 until September 1), Vercel operated a focused bug-bounty program with a $1 million reward pot. It called the program a ‘challenge’ – a challenge to HackerOne hackers (black box targeting) and Trail of Bits engineers (white box targeting) to escape the sandbox.
Time is up, and the results have been published. Vercel received 1,285 reports in two weeks, demonstrating the modern power and speed of researchers working with AI-assistance. “Report triage runs until October 1, but so far we have validated 1 Critical, 7 High, 15 Medium, 49 Low, 19 Informative. ~$325k in committed payouts,” says the firm. None of the reports showed anyone being able to access a real customer’s data – but many have allowed Vercel to improve the product.
Tomi Engdahl says:
Artificial Intelligence
OpenAI Investigates Report Linking AI Agents to RubyGems Attack
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity
https://www.securityweek.com/openai-investigates-report-linking-ai-agents-to-rubygems-attack/
Tomi Engdahl says:
Suomalaisten luottamus digimaailmaan vahvistui huijauksista huolimatta
Kahdeksan kymmenestä kertoo kuitenkin kohdanneensa digihuijauksen tai sen yrityksen viimeisen vuoden aikana.
https://yle.fi/a/74-20246485
Tomi Engdahl says:
Ison ihmisjoukon tilinumerot ja henkilötunnukset vuotivat vääriin käsiin – Uutta tietoa julki
Holmaston mukaan heidän järjestelmistään löydettiin haavoittuvuus.
https://www.iltalehti.fi/digiuutiset/a/a2a71772-bc45-4263-b601-da135d27bbc5
Rahaliike Holmaston järjestelmistä on löydetty haavoittuvuus, kertoo yhtiö sähköpostitse.
– Asiakashakumme rajapinnassa havaittiin haavoittuvuus, jonka kautta ulkopuolinen automaattinen järjestelmä pääsi hakemaan osan asiakasrekisterimme tiedoista, vastaa Holmaston yrittäjä Erika von Schantz sähköpostiviestissä Iltalehden haastattelupyyntöön.
Holmastoon tehtiin sunnuntaina 30. elokuuta tietomurto. Myöhemmin paljastui, että vuodossa vääriin käsiin päätyi yhteystietojen lisäksi myös henkilötunnuksia ja tilinumeroita.
Tietoturvaloukkauksen kerrotaan koskevan noin 70 prosenttia yrityksen asiakkaista.
Iltalehti pyysi haastattelua puhelimitse, mutta yritys suostui antamaan vastaukset kysymyksiin sähköpostitse.
Holmaston mukaan yhtiö on käynyt yhdessä palveluntarjoajan kanssa heidän käyttämänsä järjestelmät läpi, ja havaitut puutteet on korjattu.
– Haavoittuvuus korjattiin välittömästi havaitsemisen jälkeen, ja järjestelmän tietojenhakua on rajoitettu.
Tomi Engdahl says:
New York Times:
European Commission President Ursula von der Leyen unveils the EU Kids Act during her SOTU address, proposing a blanket ban on social media for kids under 13 — A proposed law would bar children under 13 from using social media across the 27-nation bloc. — The European Union outlined plans …
https://www.nytimes.com/2026/09/16/business/european-union-social-media-ban.html
Tomi Engdahl says:
Wall Street Journal:
AWS facilities in Abu Dhabi and Bahrain remain mostly offline after Iranian drones hit them in March, testing the region’s pitch for AI and data processing
The Gulf’s AI Nightmare Came Courtesy of an Iranian Drone
Amazon data centers are still offline months after being hit, testing the region’s multibillion-dollar ambitions
https://www.wsj.com/world/middle-east/the-gulfs-ai-nightmare-came-courtesy-of-an-iranian-drone-3f313cb3?st=bKp1un&reflink=desktopwebshare_permalink
DUBAI—The day after the U.S. and Israel launched their opening strikes on Iran, the Islamic Republic shot back with swarms of drones aimed at the Gulf’s newest high-value targets: American data centers.
More than six months after the barrage, a damaged Amazon Web Services facility in Abu Dhabi and another one in Bahrain are still mostly offline. The company has told clients to move their data to other regions while it repairs the sites and hasn’t given a date for completing the work.
The attacks and lasting damage are complicating the pitch by Gulf states like the United Arab Emirates to become world-leading data processors for industries such as artificial intelligence. They add a huge new risk for U.S. companies weighing investments that can cost tens of billions of dollars.
The U.A.E. put years of diplomatic muscle into persuading U.S. officials to sell it top-of-the-line AI chips, ultimately swaying the Trump administration to give it the same access as European countries. In a May 2025 visit to Abu Dhabi, President Trump watched as the Emirates’ leaders unveiled plans for a data-center complex requiring 5 gigawatts of power, the equivalent of more than two Hoover Dams.
Emirati and U.S. officials boasted that OpenAI had agreed to be the inaugural tenant at the complex, with plans to ultimately take 20% of its capacity. That deal now appears to be stalled. OpenAI still hasn’t signed a lease for the project, people familiar with the matter said. OpenAI didn’t respond to a request for comment. News Corp, owner of The Wall Street Journal, has a content-licensing partnership with OpenAI.
Tomi Engdahl says:
Lentomatkustajiin iskee ovela huijaus – tuhansia valetilejä paljastui
Huijarit väijyvät lentoyhtiöiden valituksia ja esiintyvät asiakaspalvelijoina.
https://www.is.fi/digitoday/art-2000012277911.html
Tomi Engdahl says:
Suomi.fi-varoitus annettu
Suomalaisia varoitetaan vaarallisista sähköposteista, jotka vaikuttavat aidoilta Suomi.fi-ilmoituksilta.
https://www.iltalehti.fi/digiuutiset/a/8b69dfb8-482f-4dff-af73-12f0a8267de1
Tomi Engdahl says:
Suomen turvallisuustilanne on muuttunut nopeasti, ja kansalaisten on oltava henkisesti varauduttava uusiin sabotaasi-iskuihin. Näin painottaa tasavallan presidentti Alexander Stubb MTV:n Asian ytimessä -ohjelman tuoreessa haastattelussa. https://www.mtvuutiset.fi/artikkeli/varautukaa-sabotaasi-iskuihin-stubb-neuvoo-suomalaisia-mtv-n-erikoishaastattelussa/9393650
Tomi Engdahl says:
https://www.facebook.com/share/1FdGbJ5YNK/
A new app called Zuckoff lets you detect nearby Meta smart glasses via Bluetooth.
As smart glasses become increasingly popular, so do public concerns about surreptitious recording. In response, 30-year-old Polish software developer Paweł Szydłowski has created ‘Zuckoff,’ a new mobile app designed to detect nearby smart wearables like the Ray-Ban Meta glasses.
By scanning the surrounding environment for specific Bluetooth fingerprints and signatures, the app estimates the distance of compatible smart glasses, offering a digital early-warning system for privacy-conscious individuals.
Since its launch on Apple’s App Store, the app has quickly gained over 5,000 users who are looking for ways to protect their personal space from invisible lenses.
While Zuckoff can identify when compatible glasses are nearby, it cannot determine whether the devices are actively recording. Nevertheless, the app’s growing popularity underscores a widening divide between tech giants pushing wearable AI and a public wary of constant surveillance. The app arrives at a tense moment: Meta recently had to disable thousands of smart glasses after discovering users were tampering with the built-in recording indicator LEDs to film people covertly. While Meta continues to defend its devices’ privacy guardrails, tools like Zuckoff suggest that consumers are increasingly eager to take privacy enforcement into their own hands.
source: Business Insider. (2026). Zuckoff App Can Detect Meta Smart Glasses Recording Nearby.
Tomi Engdahl says:
“My Cybercab held me hostage for an hour.” https://trib.al/tytrXyR
Tomi Engdahl says:
Does this really solve anything? https://trib.al/7keY6By
Webcam Off
Zuckerberg’s Pervert Glasses Have Been So Publicly Shamed That Meta’s Reportedly Now Working on a Version With No Camera
Does this really solve anything?
https://futurism.com/future-society/zuckerberg-pervert-glasses-shamed-meta-no-camera?fbclid=IwdGRjcAUYVtBjbGNrBRhWuXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEei_mftG1fqOf9sbKhjVfXm5VdXXs9VlGD16ggk7yNCTh6wfnmAk7Ok_QOd-Q_aem_pss2_cggCx62inzhfulI6Q
Tomi Engdahl says:
CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.
https://www.securityweek.com/cisa-releases-guidance-on-deploying-cyber-decoys/
The US Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance on deploying decoy systems for robust cyber defenses within critical infrastructure organizations.
Cyber decoys, the agency says, complement Zero Trust models, which continuously verify all access, by assuming an adversary has gained some level of access to an enterprise environment.
“Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI),” CISA notes.
They enable organizations to identify, observe, and block malicious activity early, gather and analyze CTI, and allocate resources more effectively.
“Decoy techniques are incremental, cost-effective, and scalable, allowing organizations to introduce them without major architectural changes,” CISA’s guidance (PDF) reads.
To expose adversary activity, organizations should place decoys where users rarely or never interact with them, and should configure them to produce high-fidelity alerts.
They should be designed to divert attackers to decoy data, to produce a misleading understanding of the environment during adversary reconnaissance, and lure threat actors into downloading large amounts of non-sensitive or meaningless data.
Additionally, they should direct adversaries to controlled environments where their real-world-like operations can be observed, and CTI can be collected more efficiently.
“CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data,” CISA notes.
https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf
Tomi Engdahl says:
One hijacked AI coding session helped spread Shai-Hulud across about 100 internal repositories.
A poisoned PyPI package installed an infostealer, GitHub OAuth tokens were stolen, and a compromised package in the company’s own namespace caused a second infection.
Read: https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html
Tomi Engdahl says:
Rikolliset myyvät pääsyä kaupallisiin kielimalleihin
https://etn.fi/index.php/13-news/19309-rikolliset-myyvaet-paeaesyae-kaupallisiin-kielimalleihin
Tomi Engdahl says:
Kvanttiturvallista ohjausta FPGA-piirillä
https://etn.fi/index.php/13-news/19308-kvanttiturvallista-ohjausta-fpga-piirillae
Lattice Semiconductor tuo markkinoille Mach-N2-FPGA-perheen järjestelmien ohjaukseen ja suojaukseen. Piireihin yhdistyvät integroitu flash-muisti, laitteistopohjainen Root of Trust ja CNSA 2.0 -vaatimusten mukainen post-kvanttisalaus.
Mach-N2 perustuu Latticen Nexus 2 -FPGA-alustaan ja on tarkoitettu erityisesti palvelin-, tietoliikenne- ja teollisuusjärjestelmien jatkuvasti toimiviin ohjaus- ja turvatoimintoihin. Uusi perhe tarjoaa jopa kaksinkertaisen logiikkatiheyden sekä aiempaa enemmän SERDES-kaistaa.
Post-kvanttiturvaa varten Mach-N2 tukee ML-DSA-, LMS- ja XMSS-algoritmeja autentikointiin sekä ML-KEM-algoritmia avaintenvaihtoon. Salausalgoritmit voidaan päivittää kentällä, ja anti-rollback-suojaus estää palaamisen vanhempaan ohjelmistoversioon.
Tomi Engdahl says:
https://www.makeuseof.com/i-switched-dns-providers-and-finally-escaped-us-surveillance-law/?link_source=ta_first_comment&taid=6aaab609964d6b00018948db&utm_campaign=trueanthem&utm_medium=social&utm_source=facebook&fbclid=IwdGRjcAUYz29jbGNrBRjPaHBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEe4L_3LQ1z9mGXYe0pdMxAZ2YU99eklAEUf9RNBS6EMjrlTxY5Ulmrv66IiPI_aem_TU-WYHnw4cuzHkpSgqBO_Q
Tomi Engdahl says:
They’re hitting a nerve. https://trib.al/vTuDwWO
Hitting Them Where It Hurts
Iran Drone Strikes on Amazon Data Centers Are Permanently Deleting Customer Data
They’re hitting a nerve.
https://futurism.com/artificial-intelligence/iran-drone-strikes-data-centers-deleting-customer-data?fbclid=IwdGRjcAUZGbljbGNrBRkZn3Bkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeoVtU5gmY7XRV0cUFXzwh5mA8FdXgv362HF9x_g8JbnuwFSU9JGgTN9mahk8_aem_skj0ArysEBkycLqTjJRYrg
As the USA’s war with Iran shows no signs of letting up, strikes on data centers are putting not just human lives in peril, but even customer data.
According to a September 15 Amazon Web Services update, Iranian drone strikes left some of the tech giant’s data centers in the United Arab Emirates and Bahrain in tatters. The company admitted that it was “unable to restore access to the resources and data hosted” on local data centers. The damage extended across several “availability zones,” which are clusters of one or more data centers in the same region.
“The damage to our infrastructure spanned multiple Availability Zones and exceeded what our regional and multi-AZ services are designed to withstand,” Amazon admitted.
As the company points out, the drone strikes first began in March, first highlighting how critical digital infrastructure near an active warzone has quickly become a major vulnerability, giving Iranian forces a key target and plenty of leverage.
Tomi Engdahl says:
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/
Customer engagement platform Brevo fell victim to a supply chain attack that resulted in malicious code being injected into over 100,000 websites.
Brevo was initially hacked on September 10, when a threat actor exploited a vulnerability in Brevo’s handling of SAML SSO to access 138 accounts, including one belonging to cryptocurrency storage provider Trezor.
The attackers sent phishing emails from six of the accounts and exported the contacts of 43 accounts, Brevo said in an incident notice.
The company closed the unauthorized access, but the attackers returned on September 14, when they used a compromised long-lived Cloudflare API key to deploy a worker.
That worker injected malicious scripts into brevo.com and sibforms.com, and into three JavaScript files that Brevo’s customers embed into their websites, the company said in a post-mortem.
“The script showed selected visitors a fake ‘Cloudflare, verify you are human’ page that instructed them to paste and run a command on their computer, a social-engineering technique known as ClickFix,” Brevo explains.
Tomi Engdahl says:
Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels
The Coast Guard confirmed evidence of malicious cyber activity on the VL Prosperity, but has not attributed the attack to Iran.
https://www.securityweek.com/cyberattacks-on-two-oil-tankers-prompt-coast-guard-fbi-to-board-vessels/
Two oil tankers bound for Texas were boarded by US Coast Guard and FBI personnel last month after cyberattacks disrupted the vessels during their voyage toward the United States, according to a CBS News report citing US officials.
One of the ships, the VL Prosperity, is a Liberian-flagged crude tanker that left Egypt on August 1 en route to Galveston, Texas, per vessel-tracking records cited by CBS News.
Iran’s Mehr News Agency reported on August 20 that the cyberattack had allegedly occurred on August 7 as the tanker passed through the Strait of Gibraltar. Citing a crew member, the Iranian outlet said the intrusion reached the engine room, with hackers slowing coolant flow, raising engine speed and interfering with fuel delivery.
Tomi Engdahl says:
OpenAI Says Its Models Searched GitHub for Leaked API Keys During Training
OpenAI published a framework for disclosing model misalignment alongside six reports describing problematic behavior.
https://www.securityweek.com/openai-says-its-models-hunted-github-for-leaked-api-keys-during-training/
Tomi Engdahl says:
CISA Retires Weekly Vulnerability Bulletin in Risk-Based Pivot
The decision follows BOD 26-04, which directs federal organizations to prioritize vulnerabilities based on real-world risk.
https://www.securityweek.com/cisa-retires-weekly-vulnerability-bulletin-in-risk-based-pivot/
Tomi Engdahl says:
https://www.facebook.com/share/1D9TtqCxSF/
US law enforcement agencies are increasingly concerned that Meta’s smart glasses could be used to secretly record police officers and sensitive facilities. The glasses contain cameras and are designed to look like ordinary eyewear, making covert recording difficult to detect.
A New York Police Department memo warned that people could potentially record sensitive areas such as jail layouts and officer patrol routines. Videos reportedly recorded inside detention facilities have already appeared on social media, increasing security concerns.
Police agencies from several states have warned that the glasses could also be used for criminal reconnaissance or other security threats. Some federal agencies, including ICE, have subsequently restricted the use of smart glasses in their workplaces.
The concerns also highlight a broader privacy debate surrounding wearable cameras, AI and facial-recognition technology. Privacy advocates argue that the situation raises questions about why surveillance technology can be widely used by authorities while similar technology used to monitor authorities is treated as a security threat.
Sources:
New York Times
The Guardian
Tomi Engdahl says:
There is no cloud and redundancy, it’s only someone else’s computers/racks.
Customer Data Permanently Lost in Iran Strikes on Amazon Data Centers
Amazon Web Services didn’t design its data centers to withstand war, and now the company admits it can’t recover what’s been lost.
https://www.wired.com/story/customer-data-permanently-lost-in-iran-strikes-on-amazon-data-centers/?utm_brand=wired&utm_campaign=aud-dev&utm_medium=social&utm_social-type=owned&utm_source=facebook&fbclid=IwdGRjcAUbjntwZG9mBWV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHr7m-pJtYTI1-5-v1cQhbRJgUxEVaPjMlei3A2me7PImepJ3bP7qT-_b3OCx_aem_HLlKLWvwvqRobJx4NvoDQw
Tomi Engdahl says:
Game over. https://trib.al/Snfskww
Spy vs Spy
New App Detects the Radio Fingerprint of Smart Glasses and Warns You When Someone Is Using Them Nearby
“Covert recording is a lot about power.”
https://futurism.com/robots-and-machines/app-smart-glasses-bluetooth?fbclid=IwdGRjcAUbj-ljbGNrBRuP1XBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeh8e56AENFAjJqb91_RmKOrCrmynoY4TU18eeXrY_a1V6kywWlQq3jM9q4lI_aem_yi0kY7xJ5cIY_LtVlcXVTQ
Tomi Engdahl says:
Devastating. https://trib.al/toEV6wT
Hitting Them Where It Hurts
Iran Drone Strikes on Amazon Data Centers Are Permanently Deleting Customer Data
They’re hitting a nerve.
https://futurism.com/artificial-intelligence/iran-drone-strikes-data-centers-deleting-customer-data?fbclid=IwdGRjcAUcUi5jbGNrBRxSIHBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeUquohxpTU8MsipYRjs62NZEKnz5SMBMVYqLhRtn5gkSbSlFkIaIg1u2exKI_aem_VQZD7nLsYNkv6RI3eTOuyQ
Tomi Engdahl says:
“The damage to our infrastructure spanned multiple Availability Zones and exceeded what our regional and multi-AZ services are designed to withstand,” Amazon admitted.
As the company points out, the drone strikes first began in March, first highlighting how critical digital infrastructure near an active warzone has quickly become a major vulnerability, giving Iranian forces a key target and plenty of leverage.
https://futurism.com/artificial-intelligence/iran-drone-strikes-data-centers-deleting-customer-data?fbclid=IwdGRjcAUcUnpjbGNrBRxSIHBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeUquohxpTU8MsipYRjs62NZEKnz5SMBMVYqLhRtn5gkSbSlFkIaIg1u2exKI_aem_VQZD7nLsYNkv6RI3eTOuyQ
Tomi Engdahl says:
https://edition.cnn.com/2026/09/18/politics/us-military-ai-false-intelligence-china-ship
Tomi Engdahl says:
“Take another selfie to get back into your account.” https://trib.al/i9982a8
Ear to Ear
Google Now Asking For Users’ Video Selfies to Verify Their Identities
“Take another selfie to get back into your account.”
https://futurism.com/artificial-intelligence/google-asks-video-selfies?fbclid=IwdGRjcAUdP41jbGNrBR0_fnBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEezHIeBQ3nnL4bORrZBCuB4WB5kREB31rbRJ8tgUsOBQLpy3E2ctFKZxi4xSg_aem_xKAJ9IkH9dK4HKCS5LcozA
Tomi Engdahl says:
CrowdSec Confirms Source Code Stolen in Supply Chain Attack
The cybersecurity firm believes the data breach was the result of the May 2026 TanStack supply chain attack.
https://www.securityweek.com/crowdsec-confirms-source-code-stolen-in-supply-chain-attack/
Tomi Engdahl says:
Colorado Water Utilities Hit by Cyberattacks Targeting OT Systems
The hackers changed equipment settings, disabled remote access and alarms, and altered pumping cycles, officials said.
https://www.securityweek.com/colorado-water-utilities-hit-by-cyberattacks-targeting-ot-systems/
Tomi Engdahl says:
Google Confirms Gemini AI Breached Three Firms
Google is the latest AI giant to confirm that its models escaped a testing environment and hacked real companies.
https://www.securityweek.com/google-confirms-gemini-ai-breached-three-firms/
Tomi Engdahl says:
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.
https://www.securityweek.com/ai-built-exploit-and-sign-in-flaw-opened-path-to-internal-openai-code/
Tomi Engdahl says:
Microsoft Patches 18 Vulnerabilities in AI, Cloud Products
Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority.
https://www.securityweek.com/microsoft-patches-18-vulnerabilities-in-ai-cloud-products/
Tomi Engdahl says:
NightmareStresser DDoS Service Disrupted in International Operation
Active since at least 2022, NightmareStresser was one of the longest-running DDoS-for-hire services in the world.
https://www.securityweek.com/nightmarestresser-ddos-service-disrupted-in-international-operation/
Tomi Engdahl says:
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Hackers used a compromised API key to deploy a Cloudflare worker that injected malicious scripts.
https://www.securityweek.com/brevo-supply-chain-attack-injects-malware-into-100000-websites/
Tomi Engdahl says:
“We Think the Security Control Is Working” Is No Longer Good Enough
Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today.
https://www.securityweek.com/we-think-the-security-control-is-working-is-no-longer-good-enough/
Tomi Engdahl says:
Olivia Fletcher / Bloomberg:
Ireland’s DPC fines Google €403M over how it processed location data after complaints from European consumer rights groups, and gives it six months to comply
https://www.bloomberg.com/news/articles/2026-09-21/google-fined-by-irish-watchdog-for-location-data-rule-breach