Cyber security news September 2026

This posting is here to collect cyber security news in September 2026.

I post links to security vulnerability news to comments of this article.

You are also free to post related links to comments.

84 Comments

  1. Tomi Engdahl says:

    sabelle Bousquette / Wall Street Journal:
    Google Cloud and Accenture form the Accenture Gemini Enterprise Business Group to train up to 1,000 Accenture forward deployed engineers for Gemini Enterprise

    Google Cloud, Accenture Launch Unit to Put AI Engineers On-Site With Customers
    The new group will be made up of 1,000 forward-deployed engineers
    https://www.wsj.com/cio-journal/google-cloud-accenture-launch-unit-to-put-ai-engineers-on-site-with-customers-698a8628

    Reply
  2. Tomi Engdahl says:

    Matt Burgess / Wired:
    Researchers say Meta ran 300+ ads with CSAM in 2026 so far; some featured morphed images of real children, and many linked to “nudification” apps from China

    Meta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real Kids
    Images of real children—including a member of a European royal family—were used to create some of the 350 ads containing child sexual abuse. Lawmakers say they plan to investigate.
    https://www.wired.com/story/meta-failed-to-catch-hundreds-of-ai-child-abuse-ads-some-included-images-of-real-kids/

    Reply
  3. Tomi Engdahl says:

    Brian O’Donovan / RTÉ:
    Ireland’s media watchdog investigates X over concerns about age assurance measures and parental controls, the first formal probe under the Online Safety Code — The media regulator Coimisiún na Meán has opened an investigation into Elon Musk’s social media platform X amid concerns …

    Media watchdog to investigate X over age verification, parental control concerns
    https://www.rte.ie/news/ireland/2026/0908/1590789-coimisiun-na-mean-x-investigation/

    Reply
  4. Tomi Engdahl says:

    Maria Curi / Axios:
    Source: Anthropic is severing ties with the Information Technology Industry Council after the tech industry trade group opposed three export control measures — Anthropic is severing ties with the Information Technology Industry Council, an industry advocacy group, over legislation …

    Scoop: Anthropic breaks from major tech group over chips
    https://www.axios.com/2026/09/08/anthropic-breaks-tech-group-chips

    Anthropic is severing ties with the Information Technology Industry Council, an industry advocacy group, over legislation that would curb foreign access to U.S. chips, Axios has learned.

    Reply
  5. Tomi Engdahl says:

    Anthropic:
    Anthropic details four incidents where Claude gained unauthorized access to third-party systems, including a new Opus 4.6 case; METR will investigate them — We present an alignment assessment of four incidents in which Claude models gained unauthorized access to real third-party systems.

    An alignment assessment of recent cybersecurity incidents
    https://www.anthropic.com/research/alignment-assessment-cybersecurity-incidents

    Reply
  6. Tomi Engdahl says:

    Reuters:
    Researchers: OpenAI’s agents used 10+ previously undisclosed sites for unsanctioned communications earlier in 2026; the behavior was closer to spam than hacking — AI agents unleashed by OpenAI used more than 10 previously undisclosed websites for unsanctioned communications earlier this year …
    https://www.reuters.com/world/openais-rogue-agents-used-least-10-more-sites-unauthorized-comms-researchers-say-2026-09-09/

    Reply
  7. Tomi Engdahl says:

    Artificial Intelligence
    Meta Launches Personal AI Agent, Muse, Emphasizes Safety and Privacy

    Muse runs on a dedicated, secure virtual machine that houses both the agent and the user’s data.

    https://www.securityweek.com/meta-launches-personal-ai-agent-muse-emphasizes-safety-and-privacy/

    Reply
  8. Tomi Engdahl says:

    Application Security
    This Key Will Self-Destruct: An Open Standard for Revocable API Keys

    Every leaked credential should be dead, or dying, within sixty seconds of being found. Here’s a proposal to make that the default.

    https://www.securityweek.com/this-key-will-self-destruct-an-open-standard-for-revocable-api-keys/

    Reply
  9. Tomi Engdahl says:

    Artificial Intelligence
    US Agencies Warn China Is Systematically Extracting Frontier AI Capabilities

    Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.

    https://www.securityweek.com/us-agencies-warn-china-is-systematically-extracting-frontier-ai-capabilities/

    Reply
  10. Tomi Engdahl says:

    Vulnerabilities
    Chipmaker Patch Tuesday: Nvidia, AMD, Arm Issue Security Advisories

    Major chipmakers announced patches for vulnerabilities recently discovered in their products.

    https://www.securityweek.com/chipmaker-patch-tuesday-nvidia-amd-arm-issue-security-advisories/

    Reply
  11. Tomi Engdahl says:

    Mobile & Wireless
    Android’s September 2026 Updates Patch 180 Vulnerabilities

    The security updates resolve critical flaws across Android’s Framework, System, and Kernel components.

    https://www.securityweek.com/androids-september-2026-updates-patch-180-vulnerabilities/

    Reply
  12. Tomi Engdahl says:

    Artificial Intelligence
    AI Is Giving Lesser-Resourced Attackers Nation-State-Level Reach, Google Warns

    Criminal and state-sponsored adversaries are increasingly using AI to automate and scale their attacks, according to GTIG.

    https://www.securityweek.com/ai-is-giving-lesser-resourced-attackers-nation-state-level-reach-google-warns/

    AI attack

    Adversaries, both criminal and state-sponsored, are increasingly using AI to automate and scale their attacks, according to Google’s Threat Intelligence Group (GTIG).

    What started as relatively simple adversarial prompt injection into enterprise AI systems has become a full-blown war, with aggressors developing and using their own AI systems, and enterprises using additional AI defenses that provide an expanded attack surface. It is an ongoing and expanding loop that is unlikely to abate.

    Google, straddling both sides of this war (partly a cause by developing Gemini, and partly a defense in its efforts to detect and shut down attackers), has chronicled the evolution through 2026.

    The overall effect of this automation is an increased speed of attack, and TeamPCP (UNC6780) provides an example. “The threat actor leveraged an AI coding chatbot, a prompt, and a set of agent instructions to plan, build, and execute a mass credential harvesting campaign in less than six hours,” say the Google researchers.

    Reply
  13. Tomi Engdahl says:

    Endpoint Security
    New ‘ShieldCrash’ Zero-Day Exploit Targets Microsoft Defender

    The exploit provides full System privileges on Windows machines running the September 2026 patches.

    https://www.securityweek.com/new-shieldcrash-zero-day-exploit-targets-microsoft-defender/

    Reply
  14. Tomi Engdahl says:

    The MFA Identity Trap: When Authentication Creates a False Sense of Security

    Organizations must distinguish identity verification, authentication and threat detection, or risk successfully authenticating the attackers they are trying to stop.

    https://www.securityweek.com/the-mfa-identity-trap-when-authentication-creates-a-false-sense-of-security/

    Reply
  15. Tomi Engdahl says:

    Ukraine-Russia war latest: Nato foils Moscow’s plot to unleash secret weapon to destroy undersea cables in Arctic
    The discovery comes months after Britain and Norway disclosed that they had uncovered a covert Russian operation in Arctic waters
    https://www.independent.co.uk/news/world/europe/ukraine-russia-war-live-trump-putin-zelensky-plane-moldova-drones-b3047700.html?fbclid=IwdGRjcAUPXMRjbGNrBQ9ctXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeTt_ZMwfFGw3Xc1VpJwTplo0iAOs6ArsPKOAkmNHUxAEcGiGisjNVs7d2LGk_aem_UBf15CUSoqlyAOgq6cjGKQ

    NATO allies foiled a plot where Russian subs trained to unleash a secret weapon designed to disable critical undersea cables without leaving any fingerprints, it has been reported.

    A joint operation involving Britain, Norway and the United States tracked and confronted the Russian vessels at sea, officials told Reuters after a clandestine Russian operation was carried out by Moscow’s GUGI undersea warfare directorate.

    Reply
  16. Tomi Engdahl says:

    Axios:
    Letter: the Senate disaster management subcommittee, led by Sen. Josh Hawley, is probing OpenAI’s handling of the Hugging Face breach, calling it “reckless”

    Scoop: OpenAI faces Senate probe into Hugging Face breach
    https://www.axios.com/2026/09/10/openai-hugging-face-senate-investigation-hawley

    A Republican-led Senate subcommittee that oversees disaster management is investigating OpenAI’s handling of the Hugging Face breach in July, Axios has learned.

    Why it matters: The investigation comes amid rapidly escalating concern on Capitol Hill about the existential dangers posed by AI following public warnings by several Anthropic and OpenAI researchers.

    Reply
  17. Tomi Engdahl says:

    Digiuutiset
    Oletko Elisan asiakas? Tämä muuttuu
    Elisa tiedottaa Elisa-tunnuksen käyttöön tulleesta muutoksesta.
    https://www.iltalehti.fi/digiuutiset/a/762eb3ab-04fd-49f0-a7f6-a669ec52a61a

    Elisa on tiedottanut asiakkaitaan uudistuneesta kirjautumisesta. Jatkossa Elisa-tunnuksella kirjaudutaan aina kaksivaiheisesti:

    Syötä Elisa-käyttäjätunnuksesi ja -salasanasi tuttuun tapaan.
    Saat tekstiviestillä ja sähköpostilla kuusinumeroisen koodin, jolla kirjautuminen vahvistetaan. Kirjautumiskoodi on voimassa 10 minuuttia.

    Muutoksen taustalla on turvallisuuden parantaminen. Sen myötä Elisa-tunnuksella ei voi kirjautua pelkästään käyttäjätunnuksen ja salasanan tietämällä, vaan kirjautuvalla on oltava pääsy myös Elisa-tiliin yhdistettyyn sähköpostiin tai puhelinnumeroon. Tämä pienentää mahdollisuutta luvattomaan kirjautumiseen.

    Reply
  18. Tomi Engdahl says:

    Onko sinulla tällainen televisio? Tätä et tiennyt sen tekevän jopa sammutettuna
    Televisiot keräävät käyttäjistään dataa monin eri tavoin valmistajien omiin tarkoituksiinsa. Tästä johtuen laitteita on varustettu teknologialla, joka voi mahdollistaa käyttäjien suoranaisen vakoilemisen, mikäli joku taho haluaa niin tehdä. Teknologiatubettaja teki huolestuttavia löytöjä LG:n televisioista.
    https://www.iltalehti.fi/digiuutiset/a/58c496e5-ed30-4a78-bf37-819e7ee600d4

    Reply
  19. Tomi Engdahl says:

    Poliisi takavarikoi erikoisen laitteen – Suomalaismiehet ehtivät huijata kymmeniä
    Poliisin mukaan suomalaismiehet huijasivat kymmeniä suomalaisia Hollannista käsin. Ulkomaalainen pääepäilty hoiti muun muassa huijaussoittajien rekrytoinnin.
    https://www.iltalehti.fi/digiuutiset/a/d137d7b6-8ba4-402d-b0c8-689fc28375e7

    Poliisi on saanut valmiiksi laajan huijausvyyhdin esitutkinnan. Huijaukset tehtiin lähettelemällä tietojenkalasteluviestejä ja soittamalla suomalaisille uhreille kalasteltujen tietojen turvin.

    Poliisitutkinnan ensimmäisessä vaiheessa selvisi, että Alankomaista on lähetetty massoittain tietojenkalasteluviestejä suomalaisille uhreille. Viestejä lähetettiin muun muassa poliisin ja veroviranomaisen nimissä.

    Viestit ohjasivat valesivuille, joissa uhreja erehdytettiin antamaan henkilötietojaan.

    Tämän jälkeen epäillyt rikolliset soittivat uhreille pankkien nimissä. Rikolliset käyttivät kalastelemiaan tietoja luottamuksen herättämiseksi ja saivat uhrit muun muassa siirtämään rahaa ja luovuttamaan verkkopankkitunnuksiaan.

    Puhelut soitettiin suomalaisista liittymistä Alankomaista käsin.

    Poliisi epäilee kahta suomalaismiestä puheluiden soittamisesta ja kahta muuta suomalaista rikosten mahdollistamisesta. Nelikko on ollut vangittuna.

    Reply
  20. Tomi Engdahl says:

    Reuters: Venäjä jäi rysän päältä kiinni Huippuvuorilla – IL seuraa sotaa
    Iltalehti seuraa Ukrainan sotaa ja sen seurauksia hetki hetkeltä.
    https://www.iltalehti.fi/ulkomaat/a/758b4ebc-823a-4c47-9079-e5f67b44633b

    Reuters: Venäjä jäi rysän päältä kiinni Huippuvuorilla

    Yhdysvallat, Britannia ja Norja havaitsivat keväällä arktisella merialueella venäläisiä sukellusveneitä, jotka harjoittelivat merikaapeleiden lamauttamista salaisella sabotaasiaseella, uutistoimisto Reuters kertoo.

    Huippuvuorten lähistöllä toteutetun operaation takana oli Venäjän puolustusministeriön syvänmeren tutkimuksen pääosasto (GUGI).

    Reutersin virkamieslähteiden mukaan venäläiset testasivat aluksilla teknologiaa, jolla vedenalainen kaapeli voidaan tehdä toimintakyvyttömäksi jälkiä jättämättä. Toiminta keskeytyi Nato-maiden väliintulon vuoksi, ja venäläisalukset poistuivat paikalta aiheuttamatta vahinkoa kaapeleille.

    Britannia ja Norja luovuttivat selvityksensä tulokset suoraan Venäjälle osoittaakseen tietävänsä uudesta teknologiasta ja estääkseen sen käytön jatkossa.

    Norjan puolustusministeri Tore Sandvik painotti Reutersille antamassaan lausunnossa liittolaisten yhteisoperaation osoittaneen Moskovalle, ettei salainen toiminta tai kriittisen infrastruktuurin uhkaaminen jää havaitsematta.

    Reply
  21. Tomi Engdahl says:

    Venäjän operaatio ympäri Nato-maata paljastui – Puistattava yksityiskohta
    Venäjän kansalainen on kuukausitolkulla vakoillut Nato-maa Romanian sotilaskohteita. Venäjä-tutkija nostaa esiin Antonov-yksityiskohdan, jolla on yhteys Saksan Leipzigin ja Hallen tapaukseen.
    https://www.iltalehti.fi/ulkomaat/a/2a74426b-0cf1-493f-aa90-4ec1168574e6

    Nato-maa Romanian tiedustelupalvelu SRI kertoi keskiviikkona estäneensä Venäjän sabotaasikampanjan Romanian maaperällä. SRI:n mukaan Romaniassa asuva Venäjän kansalainen on ollut tarkkailussa helmikuusta lähtien osana tutkintaa ja hänen epäillään yrittäneen sabotaasitekoa.

    – Venäjän kansalainen sai välikädeltä ohjeet tuottaa valokuva- ja videomateriaalia sotilaallisesti strategisesti kiinnostavista kohteista, mukaan lukien ukrainalaisista Antonov-kuljetuskoneista niiden ollessa maan alueella, SRI sanoi tiedotteessaan uutistoimisto Reutersin mukaan.

    Ajatushautomo Cepassa toimiva Venäjä-tutkija Olga Lautman kiinnittää juuri tähän yksityiskohtaan huomiota.

    – Antonov-yhteyttä kannattaa pitää silmällä, hän kirjoittaa blogissaan.

    Saksan Leipzigin ja Hallen lentokentän räjähdedrooni löytyi nimenomaan ukrainalaisen kuljetuskoneen Antonovin läheltä. Lentokentältä ja lähistöltä löytyi mediatietojen mukaan myös kaksi muuta droonia.

    Reply
  22. Tomi Engdahl says:

    Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6
    https://thehackernews.com/2026/09/anthropic-ai-models-breached-real.html?m=1

    Reply
  23. Tomi Engdahl says:

    Gian Volpicelli / Bloomberg:
    Anthropic gives EU cybersecurity agency ENISA testing access to Mythos 5 after months of talks that began in late May; ENISA still lacks access to Mythos 5.1

    https://www.bloomberg.com/news/articles/2026-09-10/anthropic-gives-eu-access-to-mythos-months-after-model-s-release

    Reply
  24. Tomi Engdahl says:

    Samantha Cole / 404 Media:
    Slack messages: Automattic CEO Matt Mullenweg says he has been put on paid leave after CFO Mark Davies “conspired” with board members and was voted interim CEO — Mullenweg, co-founder of WordPress, wrote in a company-wide Slack channel on Wednesday that board members “conspired” …

    Automattic CEO Matt Mullenweg Put on ‘Leave of Absence’
    https://www.404media.co/wordpress-automattic-ceo-matt-mullenweg-put-on-leave-of-absence/

    Reply
  25. Tomi Engdahl says:

    Suomalaiseen organisaatioon hyökätään yli 1200 kertaa viikossa
    https://etn.fi/index.php/13-news/19283-suomalaiseen-organisaatioon-hyoekaetaeaen-yli-1200-kertaa-viikossa

    Suomalaisiin organisaatioihin kohdistuvien kyberhyökkäysten määrä jatkaa kasvuaan. Check Point Researchin mukaan suomalainen organisaatio kohtasi elokuussa keskimäärin 1205 hyökkäystä viikossa. Määrä kasvoi 17 prosenttia vuodentakaisesta.

    Maailmanlaajuisesti organisaatioihin kohdistui elokuussa keskimäärin 2422 kyberhyökkäystä viikossa. Määrä kasvoi neljä prosenttia heinäkuusta ja 22 prosenttia viime vuoden elokuusta.

    Euroopassa hyökkäysten määrä kasvoi vuodessa 28 prosenttia, enemmän kuin millään muulla alueella. Pohjoismaista voimakkainta kasvu oli Ruotsissa, jossa organisaatio kohtasi keskimäärin 2 470 hyökkäystä viikossa. Kasvua vuodentakaisesta oli peräti 38 prosenttia. Norjassa vastaava luku oli 1 884 hyökkäystä ja kasvua kaksi prosenttia.

    Toimialoista kovimman hyökkäyspaineen alla oli edelleen koulutusala, jonka organisaatioihin kohdistui maailmanlaajuisesti keskimäärin 5 354 hyökkäystä viikossa. Julkisella sektorilla määrä oli 3 067 ja majoitus- ja matkailualalla 3 056 hyökkäystä.

    Myös kiristyshyökkäysten määrä kasvoi voimakkaasti. Elokuussa raportoitiin maailmanlaajuisesti 1 042 kiristyshyökkäystä, lähes kaksi kertaa enemmän kuin vuotta aikaisemmin. Heinäkuusta määrä kasvoi kahdeksan prosenttia. Eniten iskuja kohdistui liike-elämän palveluihin, joiden osuus raportoiduista hyökkäyksistä oli 36 prosenttia.

    Reply
  26. Tomi Engdahl says:

    “It just kept going and going, and that pit in my stomach just kept getting bigger and deeper.” https://trib.al/cihMg81

    Intelligence Report
    Mother Horrified When Meta’s AI Scours Instagram and Facebook for Invasive Information About Her Young Daughters
    “It just kept going and going, and that pit in my stomach just kept getting bigger and deeper.”
    https://futurism.com/artificial-intelligence/mother-horrified-meta-ai-family?fbclid=IwdGRjcAUPqoJjbGNrBQ-qXXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeRp3UFUIsYol_BB4ZMTupDNGdvauombMHYsooo9xWon_BPY6UGt6qpCYgqEc_aem_-ytVz8GVxA7jyeBX5hjxNw

    “Who’s the child passenger?” read the Meta AI’s suggested prompt, talking about her daughter.

    Robins, who detailed her dystopian experience in a viral Instagram video, decided to engage with the Facebook AI feature to see what would happen. To her horror, it coughed up a detailed response that named not only her daughter who was pictured in the video, but her other daughter as well. It did so, seemingly, by cross-referencing information from her Facebook page with other posts on Meta platforms going back years — information largely shared not by Robins, but by family members including excited grandparents.

    In another disarming prompt, Meta encouraged Robins to ask it: “Where does Kalie Robins live?”

    As Meta AI searched for the information, it said it was working on “pinpointing Kalie Robins’ location.” It then offered multiple paragraphs expounding on where Robins was likely based, drawing on content including a 2018 Facebook post that, per the Meta AI summary, “congratulated her” on a life achievement.

    Meta AI also encouraged users to ask questions about Robins’ professional life and her work in “mental health advocacy,” providing information about her and her husband’s employment histories.

    Reply
  27. Tomi Engdahl says:

    Who is protecting children in the age of AI manipulation?

    Inside the deepfake epidemic sexualising students and terrorising British schools
    As a report reveals criminals targeting schools with sickening blackmail involving sexualised children, Chloe Combi explores the pandemic of AI-fuelled material exploiting students and teachers, and asks who is protecting the children in the age of AI manipulation
    https://www.independent.co.uk/news/uk/home-news/ai-deepfakes-british-schools-pupils-teachers-b3047908.html?fbclid=IwdGRjcAUPxyJjbGNrBQ_G-XBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeWYis28x7lOYPmllkj09iCEu0wfBRKWOAwwgJpg9rzKhVxyXdiswVPTjjN84_aem_T6avmzIhTZA7aUJT7kVIng

    Reply
  28. Tomi Engdahl says:

    “You[r] TV is wiretapping your whole house.” https://trib.al/c39hr5l

    Spy TV
    LG TVs Caught Secretly Recording Users and Scanning Their Homes For Other Devices, Even When Disconnected From the Internet
    “You[r] TV is wiretapping your whole house.”
    https://futurism.com/future-society/lg-secretly-recording-users?fbclid=IwdGRjcAUQaJVjbGNrBRBohHBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeh1zOtlgQvo3lLct1Li0mwcgp3ykDHGewwBT09XruT-ihe8mwnN1-7vSQEHg_aem_T34xged8gcBNnOJ9mdTjpQ

    Reply
  29. Tomi Engdahl says:

    Western officials revealed that a joint NATO operation had succeeded in thwarting a secret Russian training exercise to disable critical undersea data cables. #EuropeNews
    https://l.euronews.com/nOrL

    Reply

Leave a Comment

Your email address will not be published. Required fields are marked *

*

*