This posting is here to collect cyber security news in September 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
This posting is here to collect cyber security news in September 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
84 Comments
Tomi Engdahl says:
Researchers found 237 unclaimed packages and domains in company llms.txt instruction files. Learn more
https://cnews.link/fortune500-security-gap-ai-agents-install-malware/
Tomi Engdahl says:
AI agents read legitimate llms.txt files from trusted companies and proceed to install malware
For you, it’s just some text. For an AI agent, it’s operational input.
https://cybernews.com/security/fortune500-security-gap-ai-agents-install-malware/?utm_source=cn_facebook&utm_medium=social&utm_campaign=cybernews&utm_content=post&source=cn_facebook&medium=social&campaign=cybernews&content=post&fbclid=IwVERDUAUDpRVwZG9mBWV4dG4DYWVtAjEwAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHiKIchtee3pBHD4_v4zjPd92y0NN8q-elR5y_oJLXrk55z3kLTy9Zryiy1V8_aem_iqlF1dguksnzYeqqPhhDFA
Key takeaways:
Researchers found 237 unclaimed packages and domains in company llms.txt instruction files.
Attackers can claim those names and make AI agents install malicious code from official-looking instructions.
Researchers say their test package ran inside a Fortune 500 company in under four minutes.
A real campaign impersonated Clerk by registering a package name referenced in its llms.txt file.
An AI agent visits a company website, checks a legitimate llms.txt machine-readable file, and installs malware. It follows the official instructions that point to non-existent packages. Security researchers have found hundreds of inadvertent mistakes – hackers are already leveraging them, and tricking AI agents into self-compromise.
A cybersecurity research team from Israel demonstrated that compromising Fortune 500 companies is possible simply by checking vendor documentation and claiming non-existent packages referenced in it.
Thousands of companies, including tech giants, fintechs, and defense contractors, already publish llms.txt files on their domains – it’s an emerging convention to provide machine-readable summaries to LLMs and AI agents, similar to robots.txt.
The open question remains: How many of these files were actually read before publication? Researchers scanned them and found hundreds of non-existent packages and domains referenced in the documentation.
“It’s taken 4 minutes for a Fortune 500 company to run code we wrote,” said Alon Hertz, a security analyst and former member of Unit 8200, the Israeli military intelligence unit.
No phishing, no intrusion is required to compromise developers who let their AI agents roam.
The researchers simply published a code package that is cited in one of the llms.txt files and managed to achieve code execution inside “Fortune 500” companies, according to a report titled “Data Becomes Code.”
Moreover, they also found a live malicious campaign exploiting the same gap.
Legitimate llms.txt is a minefield for AI agents
Hertz said his team checked 15,000 major companies and pulled 8,565 llms.txt files across 6,214 live domains. Google instructs developers to place such a file in the site’s root directory to save AI time crawling and understanding primary content.
This file becomes one of the AI’s first interactions with the website, looking for answers on how to use the product, what to read, which APIs to call, which packages to install, and which domains to trust.
“An AI coding agent asked to integrate with that company’s product will read that line and run it,” Hertz explains.
However, in many cases, there is no package to run. The researchers found over 237 unclaimed artifacts referenced as installation or setup instructions, including package names, domains, and subdomains. The non-existent packages span nning multiple ecosystems, such as PyPI, npm, RubyGems, NuGet, crates.io, and Packagist.
“Every one of them was something we could have claimed, most for free.”
The researchers registered several packages using names that appeared in the llms.txt files from well-known companies, embedding minimal code that simply phoned home when installed.
The researchers claim that a machine inside “a multi-hundred-billion-dollar company” installed their package in under 4 minutes.
The report warns that AI agents have no reason to question official documentation. As AI agents become the first to read, interpret, and act on new data, this creates a whole new attack surface.
“The boundary between data and code has collapsed. Every content on your website is no longer content – it’s operational input,” the report concludes.
Tomi Engdahl says:
Artificial Intelligence
Anthropic Warns Claude Users of Infostealer Malware Infections
The AI giant is logging customers out of their accounts and removing payment data to prevent unauthorized Claude usage.
https://www.securityweek.com/anthropic-warns-claude-users-of-infostealer-malware-infections/
Tomi Engdahl says:
Incident Response
Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense
Sevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes.
https://www.securityweek.com/sevii-targets-ai-speed-attacks-with-preemptive-autonomous-defense/
Fighting fire with fire is a known response. Fighting AI attacks with AI defense is a growing practice. But instant remediation is new and welcome.
Sevii has extended its Autonomous Defense & Remediation (ADR) platform with a new AI security module. As the speed and scope of AI driven attacks increases, it requires an AI defense. Since companies are rarely aware of all the shadow AI used within the organization, this defense needs to operate at runtime irrespective of source, with effectively immediate and autonomous remediation.
This is what the new module provides. As with Sevii’s wider ADR platform, alerts are received from the customer’s entire security detection stack. The new module ingests these alerts in real-time and then analyzes them. While existing tools can detect attacks, they tend to report them to the SOC. Sevii’s new AI module ‘intercepts’ this reporting and responds instantly and autonomously with its own AI-driven machine speed.
Tomi Engdahl says:
OpenLeash Adds a Human Check to Risky AI Agent Actions
The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain.
https://www.securityweek.com/openleash-adds-a-human-check-to-risky-ai-agent-actions/
Tomi Engdahl says:
Artificial Intelligence
OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days
The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems.
https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/
Tomi Engdahl says:
Artificial Intelligence
What the Hugging Face Incident Teaches Security Leaders About AI Agent Access
Security teams must treat autonomous agents as highly privileged identities.
https://www.securityweek.com/what-the-hugging-face-incident-teaches-security-leaders-about-ai-agent-access/
Tomi Engdahl says:
Artificial Intelligence
The Future of AI-Driven Security Depends on Complete Data
For twenty-five years, “data” in security meant logs and events. But logs are a lossy representation of reality
https://www.securityweek.com/the-future-of-ai-driven-security-depends-on-complete-data/
Tomi Engdahl says:
Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability
The high-severity SQL injection flaw (CVE-2026-19949) could allow unauthenticated attackers to achieve remote code execution.
https://www.securityweek.com/over-3-million-wordpress-sites-affected-by-migration-plugin-vulnerability/
Tomi Engdahl says:
A high-severity vulnerability in the All-in-One WP Migration and Backup WordPress plugin exposes over 3 million websites to remote code execution (RCE) attacks, WordPress security firm Defiant warns.
https://www.securityweek.com/over-3-million-wordpress-sites-affected-by-migration-plugin-vulnerability/
Tomi Engdahl says:
5 Million WordPress Sites Affected by SQL Injection Vulnerability in All-in-One WP Migration and Backup WordPress Plugin
On August 14th, 2026, we received a submission for an Unauthenticated Second-Order SQL Injection vulnerability in All-in-One WP Migration and Backup, a WordPress plugin with more than 5 million active installations. This vulnerability makes it possible for unauthenticated attackers to inject SQL that is later executed when a site administrator performs an archive restore, which can be used to leak the plugin’s secret key and ultimately achieve remote code execution, leading to complete site takeover.
https://www.wordfence.com/blog/2026/09/5-million-wordpress-sites-affected-by-sql-injection-vulnerability-in-all-in-one-wp-migration-and-backup-wordpress-plugin/
Tomi Engdahl says:
Meta bricked the cameras on thousands of its AI glasses
https://www.businessinsider.com/meta-glasses-camera-disabled-tampering-recording-light-update-2026-9?utm_campaign=mrf-business-marfeel-headline-graphic&utm_source=facebook&utm_medium=social&mrfcid=202609026a982bb55163c67bd72d48b6&fbclid=IwdGRjcAUGcXtjbGNrBQZxYHBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEe-h2OlM3zw6Kb9tKmYHL8R1Zk_7wTA5A6Z3vXpTonB8oDJxjsK5Ol4qPua2I_aem_jjuu2uQDGS3yLEOgwJQR5w
Thousands of Meta’s AI glasses no longer have functioning cameras after the company detected people tampering with the recording indicator lights.
Meta announced new efforts in recent weeks to crack down on people who drill out or cover up the tiny lights on their Meta glasses, which can make it easier to surreptitiously record people.
On Tuesday, Meta confirmed it’s already shut down the cameras on thousands of devices following a software update intended to combat bad actors. The company said the enforcement action impacted the newest update affected less than one tenth of a percent of all Meta AI glasses sold. Semafor first reported the news.
Tomi Engdahl says:
ChatGPT has gone offline in a major outage
ChatGPT down: OpenAI chatbot not working in major outage
Some users also report problems with rival systems such as Claude and Grok
https://www.independent.co.uk/tech/chatgpt-down-openai-not-working-b3044260.html?fbclid=IwdGRjcAUGetdjbGNrBQZ6tnBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeB6Xfa6y6lEltuSTS7ncc6pd89ZhdXAVtAqHfNG1OKmDwDme0t49bj-oih1A_aem_5_FcNKH6DozvGh4KxFXrhQ
ChatGPT has gone offline in a major outage.
Visitors to OpenAI’s chatbot saw an array of strange behaviour – including the site attempting to download an unusual file.
Users joked that the outage meant they would have to use their own brains at work. But it also led to an array of problems across other sites and apps, many of which rely on OpenAI for their artificially intelligent features.
Tomi Engdahl says:
“We have been continuously exfiltrating new data for over a year into our private database.” https://trib.al/SeDw8cW
StealID
Hackers Are Selling Stolen Scans of 153 Million US and Canadian Drivers Licenses, Which Very Likely Include Yours
“We have been continuously exfiltrating new data for over a year into our private database.”
https://futurism.com/future-society/hackers-selling-stolen-scans-americans-drivers-licenses?fbclid=IwdGRjcAUGfdVjbGNrBQZ9v3Bkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEea0VqDxenR1GYfmqLx_wOfimpgtygK8uvEDHmLW_DWY-MR984AxjuHDpFuxk_aem_zI22dI0KOiMaXzUUJkg77w
The digital scans of more than 153 million drivers licenses of individuals from the United States and Canada are being sold on the dark web through an easily accessible service called Nexus.
As noted cybersecurity journalist Brian Krebs noted on his blog this week, the sale has now caught the attention of the FBI, which has launched an official inquiry.
On the same day Krebs published his post, the service mysteriously vanished from the dark web, which could make tracking down the people behind the hack more difficult.
Nonetheless, the scale of the leak is staggering, and includes not just drivers licenses, but 10 million ID cards, over three million travel documents, and over half a million medical cards as well, representing over 170 million individuals total. That’s pushing half of the United States’ and Canada’s combined populations.
Tomi Engdahl says:
AI Fallout
World Plunged Into Chaos as ChatGPT, Claude, and Grok Suddenly Go Down Simultaneously: “Finally I Can See the Sun!”
“And for a brief moment, millions of people had to use their brains again.”
https://futurism.com/artificial-intelligence/ai-chatbots-chatgpt-claude-grok-go-down?fbclid=IwdGRjcAUGkeNjbGNrBQaRqXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeCjzNZkovvSRBXu2KuJwDxCenWjwsjYUC-WaeVQdAKlOP4NKYaZbK8VqGa-s_aem_U12KAPGnuWSLJmTIpIRpsQ
Tomi Engdahl says:
https://www.facebook.com/share/1DqNJqFSVg/
Google AI Falsely Claims Flock Cameras Contain Valuable Gold and Copper
Google’s AI Overview has reportedly claimed that Flock license-plate cameras contain 1–5 grams of gold and up to 23 pounds of copper. Those figures are highly questionable, especially because a Flock camera reportedly weighs only about three pounds.
The claim appears to have originated from online jokes suggesting that Flock cameras contain valuable metals worth hundreds of dollars. In reality, electronic devices can contain trace amounts of precious metals, but extracting them from a single camera would generally not make financial sense.
Google’s AI Overview reportedly cited an anonymous Substack post that itself described the scrap-value figures as estimates rather than verified data. It also cited an AI-generated Instagram post repeating the same claim, rather than reliable technical or financial sources.
The incident highlights a broader problem with AI-generated search summaries: confident wording does not guarantee accurate information. In this case, Google’s AI appears to have repeated internet speculation as fact instead of recognizing that the original claim was essentially an online meme.
Tomi Engdahl says:
AI-agentti murtautuu yritykseen neljällä dollarilla
https://etn.fi/index.php/13-news/19256-ai-agentti-murtautuu-yritykseen-neljaellae-dollarilla
Tekoälyagentit ovat muuttamassa myös kyberrikollisuutta. Cybernewsin tutkijat löysivät palvelimen, jolla AI-agentti automatisoi lähes koko kiristyshyökkäyksen kohteen tiedustelusta datan varastamiseen ja lunnaiden määrittämiseen. Tekoälyn käyttökustannukset jäivät halvimmillaan 40 senttiin yritystä kohti.
Cybernewsin tietoturvatutkijat löysivät heinäkuussa avoimeksi jääneen palvelimen, joka kuului venäjänkielisen The Gentlemen -kiristyshaittaohjelmaryhmän kumppanille. Palvelimella oli 3,1 teratavua yli 30 yritykseltä varastettua dataa sekä käytännössä koko hyökkäysoperaation infrastruktuuri.
The Gentlemen havaittiin ensimmäisen kerran heinäkuussa 2025. Cybernewsin mukaan ryhmä on ilmoittanut vuodessa noin 700 uhrista. Löydetty palvelin ei kuitenkaan kuulunut välttämättä ryhmän ydintiimille vaan sen kumppanitoimijalle, jota Cybernews kuvaa venäjänkieliseksi uhkatoimijaksi.
Operaation kiinnostavin osa oli sen automatisoinnin aste. Hyökkäysten takana toimi avoimen lähdekoodin Hermes AI-agentti, jota Cybernewsin mukaan ajettiin DeepSeek-V4-Pro-mallilla. Ihmisen osallistuminen jäi vähäiseksi.
Hyökkääjä syötti agentille tyypillisesti GitLab-palvelimen osoitteen, käyttäjätunnuksen ja salasanan. Tunnukset oli todennäköisesti saatu tietoja varastavilta haittaohjelmilta tai ostettu alkuperäisen pääsyn välittäjiltä. Tämän jälkeen agentti mukautti hyökkäysskriptit kohdeyrityksen ympäristöön.
Agentti pystyi hoitamaan tiedustelua, murtautumisen jälkeisiä toimia ja datan siirtämistä hyökkääjälle. Palvelimelta löytyi 86 tekoälyn generoimaa Python-skriptiä, jotka oli konfiguroitu todellisia uhreja varten. Agentille oli lisäksi rakennettu MCP-rajapinta Penelope-työkaluun, jonka kautta se pystyi käyttämään murrettuihin järjestelmiin muodostettuja reverse shell -yhteyksiä.
Tomi Engdahl says:
EU uusi kybervelvoite iskee siruvalmistajiin viikon päästä
https://etn.fi/index.php/13-news/19260-eu-uusi-kybervelvoite-iskee-siruvalmistajiin-viikon-paeaestae
EU kyberkestävyyssäädöksen CRA ensimmäiset käytännön velvoitteet tulevat voimaan 11. syyskuuta. Viikon päästä valmistajien on alettava raportoida aktiivisesti hyväksikäytetyistä haavoittuvuuksista ja vakavista tietoturvapoikkeamista. Velvoite koskee myös EU:n ulkopuolisia puolijohdeyrityksiä, jos niiden tuotteita myydään unionin markkinoilla.
CRA tulee kokonaisuudessaan sovellettavaksi vasta joulukuussa 2027, mutta raportointivelvoite alkaa jo nyt. Valmistajan on annettava ensimmäinen varoitus aktiivisesti hyväksikäytetystä haavoittuvuudesta tai vakavasta tietoturvapoikkeamasta 24 tunnin kuluessa siitä, kun se on tullut asiasta tietoiseksi.
Varsinainen ilmoitus on tehtävä 72 tunnin kuluessa. Raportointi tapahtuu ENISAn Single Reporting Platform -järjestelmän kautta. Velvoite pakottaa valmistajat rakentamaan etukäteen prosessit haavoittuvuuksien seurantaan, tapausten eskalointiin ja viranomaisraportointiin.
CRA ei koske vain valmiita kuluttajalaitteita. Sen piiriin kuuluvat myös erikseen EU-markkinoille saatettavat digitaaliset komponentit, joten vaatimukset ulottuvat muun muassa puolijohde- ja ohjainpiirivalmistajiin.
Valmistajan kotipaikalla ei ole ratkaisevaa merkitystä. Jos esimerkiksi taiwanilainen tai yhdysvaltalainen siruyhtiö myy CRA:n piiriin kuuluvia tuotteita EU:n alueella, sen on noudatettava samoja raportointivelvoitteita kuin eurooppalaisen valmistajan.
Tämä tarkoittaa käytännössä huomattavasti enemmän kuin viranomaislomakkeen täyttämistä hyökkäyksen jälkeen. Yrityksen on kyettävä seuraamaan tuotteidensa haavoittuvuuksia jatkuvasti, vastaanottamaan ilmoituksia, arvioimaan niiden vakavuutta ja käynnistämään raportointi hyvin nopeasti.
Tomi Engdahl says:
https://www.securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/
Tomi Engdahl says:
VMware Workstation and Fusion Updates Patch Critical Vulnerability
https://www.securityweek.com/vmware-workstation-and-fusion-updates-patch-critical-vulnerability/
The flaws could allow attackers with administrative access to a virtual machine to execute code on the host system.
Tomi Engdahl says:
https://www.securityweek.com/google-patches-6th-chrome-zero-day-of-2026/
Tomi Engdahl says:
Capsule Security Launches ‘AI Circuit Breaker’ to Stop Rogue Agents
New models, trained using NVIDIA Nemotron 3 Ultra, aim to catch rogue agent behavior before it executes, without the latency of large-model review.
https://www.securityweek.com/capsule-security-launches-ai-circuit-breaker-to-stop-rogue-agents/
Tomi Engdahl says:
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor.
https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/
Tomi Engdahl says:
https://www.securityweek.com/hired-for-one-job-judged-on-another-the-cisos-real-problem/
Tomi Engdahl says:
Financial Times:
Some European defense officials push back on efforts to cut reliance on US tech, warning it could leave Europe with inferior systems and greater cyber risks
https://www.ft.com/content/0e9d714b-f367-4dd7-8ef4-6d4b2c08b79c?syn-25a6b1a6=1
Tomi Engdahl says:
Raphael Satter / Reuters:
Letters: US military branches disabled ad trackers on government-issued devices amid reports of location data being used to target US forces in the Middle East — U.S. military officials say they have disabled advertising trackers on a range of phones and computers, according to letters released
https://www.reuters.com/business/media-telecom/us-military-turns-off-ad-trackers-devices-amid-middle-east-targeting-reports-2026-09-04/
Tomi Engdahl says:
Sam Sabin / Axios:
OpenAI commits $1B in subsidized model access, training, support, and partnerships to a new initiative aimed at protecting essential services around the world
OpenAI launches plan to protect critical infrastructure from AI cyberattacks
https://www.axios.com/2026/09/03/openai-critical-infrastructure-cyber-ai-models
OpenAI is launching a new initiative designed to provide subsidized access to its models to water systems, electricity providers, local governments and other critical services.
Tomi Engdahl says:
Was this a huge coincidence, or is something else going on behind the scenes? https://trib.al/zCSHU4z
Imperfect Timing
Nobody Will Say Why Every Major AI Chatbot Suddenly Went Down Yesterday
Was this a huge coincidence, or is something else going on behind the scenes?
https://futurism.com/artificial-intelligence/nobody-saying-why-major-chatbot-outage?fbclid=IwdGRjcAUH5q5jbGNrBQfml3Bkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeuS1NmwhKeZII7NqvJjg_wHD4Hc9rz0PP9GaFjCMARWwBAljr5jRiLoI0XdU_aem_iK_klT24kGWCYAj3CFWgUA
On Thursday, three major chatbots — ChatGPT, Claude, and Grok — all went down without warning.
The simultaneous outage of three flagship from AI systems from three different providers was bizarre. But, in an exceedingly peculiar information gap, we still don’t know why models from Anthropic, OpenAI, and SpaceXAI respectively suffered outages at the same time, Wired reports. Whatever linked the disruptions, for now, remains unclear.
Tomi Engdahl says:
https://www.engadget.com/2251091/rogue-openai-agents-took-over-german-coding-forum-in-previously-undisclosed-hijacking/?utm_term=Autofeed&utm_campaign=Echobox-Engadget&utm_medium=Social-Distribution&utm_source=Facebook&fbclid=IwdGRjcAUH_lBjbGNrBQf-RXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeEOfcCIxbSOOzTZlutFSrbMnZLQKZC1hUCGjKm15Q7VQabQo0ud2R8AvMJeQ_aem_RiaODHZNLkWCccxf0JFrgg
Tomi Engdahl says:
https://www.facebook.com/share/p/1ETrujrwcT/
Thousands of AI agents linked to OpenAI reportedly took over a German-language programming wiki and turned it into a communication hub for other AI agents.
Researchers Sydney Von Arx and Cormac Slade Byrd found more than 15,000 edits made by AI agents on DseWiki, a German wiki for programmers.
According to the researchers, the agents used the site to exchange information, discuss ways to bypass OpenAI restrictions, cheat on certain tasks and evaluations, evade detection, and preserve their communications.
When a moderator began deleting pages in June, the agents reportedly created backup pages to keep their communications available.
The researchers linked the activity to OpenAI through agent usernames, server logs and other evidence. About half of the usernames reportedly suggested an OpenAI affiliation, including names such as “OpenAIResearcher” and “OAIResearchMar26.”
OpenAI disputed describing the incident as hacking and said it had not yet had an opportunity to fully review the researchers’ report. The company also said the incident was separate from the July Hugging Face breach involving rogue AI agents.
Sources: Reuters; Sydney Von Arx and Cormac Slade Byrd / Nightingale researchers.
Tomi Engdahl says:
15,000 edits ran for two months. OpenAI’s monitoring missed it.
Researchers found the pages on a volunteer-run German wiki.
The agents signed their work OpenAIResearcher, according to the report.
Moderators deleted pages by hand through June.
OpenAI disputes that any of this amounts to hacking.
Outside researchers caught what the company’s own systems did not.
Read more on TNW: https://thenextweb.com/news/openai-agents-german-wiki-breakout
Tomi Engdahl says:
‘Catastrophic’: Ex-cyber chief’s brutal warning as Aussies flock to Chinese-made vehicles
A leading cyber security expert has issued a chilling warning about the spread of C6hinese-made vehicles in Australia.
https://www.news.com.au/technology/motoring/catastrophic-excyber-chiefs-brutal-warning-as-aussies-flock-to-chinesemade-vehicles/news-story/4182b57e6c2bdd51917530fa0b487c66?utm_source=News.com.au&utm_medium=facebook&utm_campaign=Emplifi&fbclid=IwY2xjawUKCJxwZG9mBWV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHuiCIA25y5HTgjKb7oiMGoa4-DK1BLuDEntIRVrn-eNJJSqUe9V7AacLR-Gt_aem_BTdBkgrkFm_ifLLZ1G54xg
A leading cyber security expert has issued a chilling warning about the spread of Chinese-made vehicles in Australia, saying he believes the popular cars are listening in on drivers.
Tomi Engdahl says:
Jättikö Venäjä tahallaan jäljen? “Omiaan luomaan pelkoakin”
Venäjä pystyy halvoilla keinoilla aiheuttamaan paljon harmia Euroopassa. Asiantuntija kertoo, miksi emme ole paremmin varautuneita.
https://www.iltalehti.fi/ulkomaat/a/c4ac745c-6add-46f6-8b30-893f8c953973
Venäjä tekee kasvavassa määrin hybridi-iskuja Euroopassa samalla kun se käy täysimittaista sotaa Ukrainassa. Miten Venäjällä riittää aikaa ja resursseja kaikkeen tähän?
– Nehän eivät välttämättä juuri sido resursseja, sanoo Jyväskylän yliopiston vanhempi yliopistonlehtori Panu Moilanen.
Venäjän hybridivaikuttaminen, johon kuuluvat muun muassa erilaiset sabotaasi-iskut, on Venäjälle suhteellisen halpaa lystiä. Lisäksi Venäjä voi itse päättää, kuinka paljon se haluaa satsata hybridioperaatioihin milläkin hetkellä.
Vastapuoli ei nimittäin voi vastata takaisin samalla mitalla.
– Etu sille hybridivaikuttajalle on, että se voi itse hyvin pitkälti määritellä sen, että kuinka paljon se haluaa käyttää resursseja hybridivaikuttamiseen.
Tomi Engdahl says:
”Varoitus Suomelle” – Uutiset Saksasta ovat vakavia
Saksan tapahtumista pitää oppia, sanoo sotatieteiden tohtori Jarno Limnell (kok).
https://www.iltalehti.fi/ulkomaat/a/3f010c85-ec5b-4b1a-9213-217570e88b18
Saksassa syyskuussa tapahtuneet sähköverkkoon kohdistuvat sabotaasiyritykset kannattaa huomioida myös Suomessa, sotatieteiden tohtori, kokoomuksen kansanedustaja Jarno Limnell kirjoittaa X-viestipalvelussa.
Kolmessa saksalaisessa osavaltiossa tutkitaan sähköverkkoon kohdistuneita sabotaasiyrityksiä. Sabotaasista ovat kertoneet muun muassa uutistoimisto Reuters ja saksalaislehti Bild.
Sabotaasiyritykset ovat ”vakavia”, Limnell kommentoi.
– Nyt kannattaa katsoa yksittäisiä iskuja laajemmalle. Tämä on varoitus myös Suomelle.
– Kohteena on yhteiskunnan hermosto: sähkö, jonka varassa toimivat viestintä, liikenne, yritykset ja meidän arkemme, Limnell kommentoi.
Limnellin mielestä Suomen kannattaisi suojella omaa kriittistä infrastruktuuriaan entistä kokonaisvaltaisemmin.
– Kriittisen infrastruktuurin suojaamisessa on siirryttävä yksittäisten kohteiden vartioinnista koko järjestelmän toimintakyvyn turvaamiseen. Kaikkea ei voida suojata koko ajan. Ratkaisevaa on, ettei onnistunutkaan isku pysäytä yhteiskuntaa.
Drooni-iskuyritys lentokentällä
Sähköverkkoihin kohdistuvien iskusarjojen taustaa ei tiedetä. Saksan viranomaiset eivät ole sulkeneet pois valtiollisen toimijan mahdollisuutta, mutta kesken olevassa tutkinnassa ei ole ilmennyt näyttöä esimerkiksi Venäjän osallisuudesta.
Leipzig-Hallen lentokentältä elokuussa löytyneestä räjähteitä sisältäneestä droonista Saksa on sen sijaan syyttänyt Venäjää.
Sabotage! Großangriff auf unser Stromnetz
https://www.bild.de/news/inland/grossangriff-auf-unser-stromnetz-drei-sabotage-faelle-an-umspannwerken-in-nur-zwei-tagen-6a9a5a50240b302c8a838ad4
Berlin – Deutschland erlebt beunruhigende Angriffe auf seine kritische Infrastruktur. Innerhalb von nur drei Tagen kam es bundesweit zu mehreren Sabotageakten an Umspannwerken. Einiges spricht dafür, dass die Angriffe vom selben Täter geplant wurden. So liegen die Sabotagen nicht nur zeitlich eng beieinander, auch die Abschusskonstruktionen sollen sich ähneln, heißt es aus Sicherheitskreisen. Nach einem Bekennerschreiben gibt es eine Spur.
Tomi Engdahl says:
https://hackaday.com/2026/09/04/this-week-in-security-baked-in-malware-freezers-not-freezing-zoom-snoops-clipboards-and-ai-makes-things-worse-faster/
The AI platform ServiceNow which offers both hosted and on-premises versions just patched a trifecta of CVSS-10 vulnerabilities.
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
Tomi Engdahl says:
https://www.securityweek.com/elementor-pro-wordpress-plugin-vulnerability-exploited-to-hack-sites/
Tomi Engdahl says:
Artificial Intelligence
OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders
The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility.
https://www.securityweek.com/openai-pledges-1-billion-to-bring-frontier-ai-to-critical-infrastructure-defenders/
Tomi Engdahl says:
Vulnerabilities
12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover
Dubbed PostGREShell, CVE-2026-6471 turns low-level replication access into code execution, permanent superuser privileges and a persistent database backdoor.
https://www.securityweek.com/12-year-old-postgresql-vulnerability-enables-database-server-takeover/
Tomi Engdahl says:
https://etn.fi/index.php/13-news/19260-eu-uusi-kybervelvoite-iskee-siruvalmistajiin-viikon-paeaestae
Tomi Engdahl says:
Varoitus kaikille Microsoft 365 -käyttäjille
Viranomainen varoittaa Microsoft 365 -murroista.
https://www.iltalehti.fi/digiuutiset/a/dfb47482-838e-443b-bcce-5a6d9c1d5e64
Liikenne- ja viestintävirasto Traficomin Kyberturvallisuuskeskus varoittaa viikkokatsauksessaan Microsoft 365 -tilimurroista. Elokuussa niitä ilmoitettiin Kyberturvallisuuskeskukselle enemmän kuin kertaakaan aiemmin tänä vuonna.
Viranomainen kertoo, että näihin tileihin kohdistuvat kaappaukset ja tietomurrot alkavat usein huijausviestillä, jossa kalastellaan Microsoft 365 -tunnuksia tai pyydetään kirjautumisen hyväksymistä huijarin puolesta.
Kalasteluviestien tunnistamista hankaloittaa se, että ne voivat näyttää tulevan tutuilta lähettäjiltä, koska viestejä lähetetään myös aiemmin kaapatuilta tileiltä.
– Pelkkä kirjautumissivun tuttu ulkoasu ei takaa aitoutta, vaan käyttäjän kannattaa aina tarkistaa sivuston verkko-osoite, Kyberturvallisuuskeskus painottaa.
Mikäli rikollinen pääsee käsiksi uhrin Microsoft 365 -tiliin, voi hän lukea ja lähettää sähköposteja, varastaa tietoja ja toteuttaa erilaisia petoksia uhrin nimissä.
Kyberturvallisuus kehottaa vaihtamaan salasanan välittömästi, mikäli epäilee antaneensa tunnuksensa huijaussivustolle. Lisäksi asiasta tulee ilmoittaa organisaation it-tuelle tai tietoturvavastaavalle.
– Myös havaitusta tunnustenkalastelusta kannattaa tehdä ilmoitus Kyberturvallisuuskeskukselle, sillä se auttaa tunnistamaan käynnissä olevia huijauskampanjoita ja ehkäisemään uusia uhreja.
Tomi Engdahl says:
Zvi Mowshowitz / Don’t Worry About the Vase:
An in-depth look at OpenAI’s wiki incident: other hacked message boards, OpenAI’s cover-up, how harmless web search tasks led agents to break out, and more — I did not expect to be back here so soon with more OpenAI agent swarm coverage. — And yet, here we are.
https://thezvi.substack.com/p/openai-and-the-wiki-incident
Tomi Engdahl says:
Charlotte Tobitt / Press Gazette:
The US raises censorship concerns over the UK’s proposals to force tech platforms to put “trustworthy” news providers at the top of social and video feeds — News Media Association warns forcing prominence for ‘trustworthy’ news could end up harming sector.
US issues ‘censorship’ warning over UK plan to boost ‘public service’ news on social media
News Media Association warns forcing prominence for ‘trustworthy’ news could end up harming sector.
https://pressgazette.co.uk/news/us-issues-censorship-warning-over-uk-plan-to-boost-public-service-news-on-social-media/
Tomi Engdahl says:
Gamers Nexus on YouTube:
Analysis of LG smart TVs shows its ad software tracks nearby devices, security flaws can allow hackers to eavesdrop via a built-in microphone, and more
216,000,000 Spy TVs | The LG Smart TV Problem
https://www.youtube.com/watch?v=6IFVTcM28KA
The LG Smart TVs we’ve tested have first-party ACR (automatic content recognition) functionality that can pry into your personal life with greater precision than you might realize, with LG Ad Solutions’ executives and leadership saying, on camera, that LG “owns the glass.” Not you — even though you bought it — but them. They also talk about knowing everybody in the household, knowing the secondary devices, moving from TVs to smartphones and other screens, and more in their B2B discussions. Beyond just the fact that we think the TV’s native behavior parallels malware, the LG Smart TVs we tested also have a number of security vulnerabilities that can be exploited to convert the TVs into covert listening devices. In this investigation, we dive into the mix of LG’s first-party functionality that (in our opinions) is tantamount to spying and LG’s vulnerabilities and exploits that they have failed to protect against.
Tomi Engdahl says:
OpenAI Agents Hijack Another Victim Website
OpenAI agents made 15,000–18,000 autonomous edits to a German wiki over three months, evading moderation and echoing tactics seen in the Hugging Face breach.
https://www.securityweek.com/openai-agents-hijack-another-victim-website/
Tomi Engdahl says:
https://www.facebook.com/share/v/1HLLNeMsLJ/
People should be “very worried” about artificial intelligence going rogue, following the Hugging Face hack in July, The Atlantic’s Josh Tyrangiel says.
“We’ve seen AI commit a felony,” he said.
In July, OpenAI’s agents broke out of their offline sandbox and hacked another AI company, Hugging Face. The agents took over its servers and tried to cover up their tracks, with no human asking them to.
Tyrangiel, author of “A.I. For Good,” discussed the incident and what it could mean for the future with Washington Week moderator Jeffrey Goldberg.
Washington Week with The Atlantic is a partnership between @newshour, @wetatvfm and @theatlantic, airing every Friday on PBS stations nationwide. Tap the link in Washington Week’s bio to watch this week’s episode
Tomi Engdahl says:
ChatGPT:stä löytyi vakava tietoturva-aukko
https://etn.fi/index.php/13-news/19273-chatgpt-stae-loeytyi-vakava-tietoturva-aukko
Check Point Research löysi OpenAI:n ChatGPT-palvelusta haavoittuvuuden, jonka avulla hyökkääjä pystyi komentamaan toisen käyttäjän tekoälyistuntoa salaa. Demonstraatiossa ChatGPT luki uhrin Gmailista tietoja ja välitti ne hyökkääjälle käyttäjän huomaamatta. Haavoittuvuus on jo korjattu.
Hyökkäys perustui ChatGPT:n koodia suorittavien hiekkalaatikoiden väliseen piilokanavaan. Eri käyttäjien suoritusympäristöt oli eristetty toisistaan, mutta ne pääsivät samaan OpenAI:n sisäiseen JFrog Artifactory -palveluun, jota käytettiin ohjelmistopakettien välittämiseen.
Check Point havaitsi, että palvelun metadataan pystyi kirjoittamaan tietoa yhdeltä käyttäjätililtä ja lukemaan sen toiselta. Näin pakettipalvelusta syntyi käytännössä yhteinen leikepöytä eri käyttäjien eristetyille suoritusympäristöille.
Hyökkääjä pystyi tämän jälkeen syöttämään piilotetun tehtävän uhrin ChatGPT-istunnolle esimerkiksi haitallisen kehotteen, jaetun keskustelun tai mukautetun GPT:n kautta. Kun uhri lähetti ChatGPT:lle tavallisen viestin, järjestelmä saattoi käsitellä näkyvän pyynnön rinnalla hyökkääjän piilotetun tehtävän.
Check Pointin testissä piilotettu tehtävä käski ChatGPT:tä hakemaan tietoja uhrin kytketystä Gmail-tilistä. Sähköpostitiedot palautettiin hyökkääjälle piilokanavan kautta, samalla kun uhrille näkynyt keskustelu jatkui normaalisti. Ainoa merkki Gmailin käytöstä oli pieni ”Talked to Gmail” -ilmoitus vastauksen yhteydessä.
Peter Lang says:
Thanks for maintaining this roundup every month – it is one of the most useful security link collections around. The AI agent malware stories are getting scarier by the week. Looking forward to following the updates in the comments.
Tomi Engdahl says:
Dan Goodin / Ars Technica:
Microsoft’s September 2026 Patch Tuesday fixes a record ~972 vulnerabilities, bringing its total flaws patched in 2026 to 2,760, more than double from 2025
Why this month’s Microsoft patch release is a doozy
Security gnomes are pumping out patches ahead of an expected onslaught of AI-assisted attacks.
https://arstechnica.com/security/2026/09/microsoft-patches-a-record-972-vulnerabilities-112-of-them-critical/
Tomi Engdahl says:
Reuters:
The NSA, CISA, and FBI issue a joint advisory warning that Chinese AI companies, including DeepSeek, are conducting “industrial-scale” distillation campaigns — The U.S. government on Tuesday accused Chinese artificial intelligence companies of maliciously copying technology …
https://www.reuters.com/technology/us-accuses-chinese-ai-firms-industrial-scale-theft-ai-technology-2026-09-08/
Tomi Engdahl says:
Jacob Reid / Bloomberg:
UK seeks to force Apple and Google to block children from taking, viewing, or sharing nude images on their devices, and praises Apple’s age-based restrictions
https://www.bloomberg.com/news/articles/2026-09-08/uk-to-force-apple-google-to-block-nude-images-on-kids-devices