This posting is here to collect cyber security news in September 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
This posting is here to collect cyber security news in September 2026.
I post links to security vulnerability news to comments of this article.
You are also free to post related links to comments.
124 Comments
Tomi Engdahl says:
Britney Nguyen / MarketWatch:
Cybersecurity stocks were the top performers in the S&P 500 on Monday amid escalating AI fears; CrowdStrike rose 14%, Palo Alto Networks 13%, and Fortinet 9%
CrowdStrike and Palo Alto Networks lead software stocks to a never-before-seen feat
https://www.morningstar.com/news/marketwatch/20260914261/crowdstrike-and-palo-alto-networks-lead-software-stocks-to-a-never-before-seen-feat
Tomi Engdahl says:
Usb-porttiin kiinnitetty laite teki kymmenistätuhansista televisioista rikoksentekovälineitä
https://www.is.fi/digitoday/tietoturva/art-2000012267876.html
Tietoturvayhtiö Bitsight havaitsi kymmeniä tuhansia halpoja Android-tv-tikkuja, jotka olivat vaarallisia jo tehtaalta lähtiessään.
Laitteisiin oli asennettu valmiiksi kiinalaisen yhtiön sovelluksia, jotka ohjasivat liikennettä käyttäjän yhteyden kautta ja tekivät mainospetoksia.
Noin 38 000 haitallista tikkua tuotti mainospetoksilla arviolta lähes 43 000 euroa päivässä.
Tietoturvayhtiö F-Securen asiantuntija Joel Latto kehottaa kuluttajia pysyttelemään luotetuissa ja sertifioiduissa laitteissa.
Halvoilla Android-pohjaisilla tv-tikuilla eli mediatoistimilla voi olla pimeä puoli. Tietoturvayhtiö Bitsight havaitsi kymmeniätuhansia tällaisia televisioihin kytkettyjä laitteita, jotka olivat vaarallisia jo tehtaalta lähtiessään.
Laitteisiin oli asennettu valmiiksi kaksi kiinalaisen yhtiön sovellusta, joiden avulla tv-tikut pystyivät tekemään katalia asioita käyttäjänsä selän takana. Tv:n ollessa päällä tikut ohjasivat internet-liikennettä käyttäjän kotiyhteyden kautta. Maksua vastaan tarjottu palvelu voi olla houkuttava rikollisille.
Kun television sulki, tikut alkoivat takoa rahaa mainospetoksilla. Tikut ottivat yhteyttä tekoälyllä luotuihin verkkosivuihin ja tekeytyivät tunnettujen brändien puhelimiksi. Automatisoidut ohjelmat eli botit klikkasivat näillä verkkosivuilla olevia mainoksia näyttökertojen kerryttämiseksi eli rahan tekemiseksi.
Latton mukaan tekoäly tekee tällaisesta toiminnasta entistä automaattisempaa ja laajamittaisempaa. Näin aivan tavallisista nettiin kytketyistä laitteista voi tulla osa paljon suurempaa rikollista operaatiota.
– Kuluttajien tulisi pysytellä luotetuissa ja sertifioiduissa laitteissa, jotka saavat säännöllisesti tietoturvakorjauksia, Latto neuvoo.
Tomi Engdahl says:
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-kb5002914-security-update-breaks-excel-copy-and-paste/?fbclid=IwdGRjcAUWC3RwZG9mBWV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHggTK0rW8bhbzLqYUKdwGet0IqqakxKvzBdSgC2BDy7RWuoWBNaRoRNCJUt5_aem_YRva5h3NsOiHdG7x01RiEQ
Tomi Engdahl says:
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/?fbclid=IwdGRjcAUWOOBwZG9mBWV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHq4Rvoeo4jl6sj4dWHV4FLcoJAzWF4QJiBbKZ47HVahBJHFG2GYYy2FrlMEq_aem_mi2IG07iCy1pUjFanYKQsg
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.
Broadcom addressed the security flaw (tracked as CVE-2026-59310) on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code.
The company also warned customers in a supplemental FAQ at the time to treat fixing CVE-2026-59310 as an emergency and install patches as soon as possible.
Tomi Engdahl says:
Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers.
https://www.securityweek.com/microsoft-commits-to-sweeping-ai-privacy-rules-for-students-will-other-tech-giants-follow/
Tomi Engdahl says:
CISO Strategy
“We Think the Security Control Is Working” Is No Longer Good Enough
Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today.
https://www.securityweek.com/we-think-the-security-control-is-working-is-no-longer-good-enough/
Security, risk, and control assessments are typically done for the sake of compliance: tools deployed, audits passed, workflows completed, boxes checked. That’s no longer enough for boards, customers, and regulators, who all want an answer to a harder question: ‘can you prove your controls are working right now?’
I often ask CISOs a version of that question, and the honest answer is usually some form of “we think so.” It’s not because they’re careless. Most control checks still happen the way a dentist visit does. When your dentist asks whether you brush and floss every day, you could fib and say yes, but one look at your x-ray tells the real story.
Security works the same way. An annual audit captures what you told the auditor, or what looked true on the day someone checked. But it may not be the ground truth.
Tomi Engdahl says:
Vulnerabilities
$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws
AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage.
https://www.securityweek.com/1-million-sandbox-challenge-uncovers-linux-kernel-flaws/
Linux
A two-week focused sandbox bug-bounty program resulted in 1,285 filings, but none that could access customer data.
The Vercel sandbox, a Firecracker‑based microVM environment, is an isolation tool for untrusted AI‑agent code. For two weeks (August 18 until September 1), Vercel operated a focused bug-bounty program with a $1 million reward pot. It called the program a ‘challenge’ – a challenge to HackerOne hackers (black box targeting) and Trail of Bits engineers (white box targeting) to escape the sandbox.
Time is up, and the results have been published. Vercel received 1,285 reports in two weeks, demonstrating the modern power and speed of researchers working with AI-assistance. “Report triage runs until October 1, but so far we have validated 1 Critical, 7 High, 15 Medium, 49 Low, 19 Informative. ~$325k in committed payouts,” says the firm. None of the reports showed anyone being able to access a real customer’s data – but many have allowed Vercel to improve the product.
Tomi Engdahl says:
Artificial Intelligence
OpenAI Investigates Report Linking AI Agents to RubyGems Attack
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity
https://www.securityweek.com/openai-investigates-report-linking-ai-agents-to-rubygems-attack/
Tomi Engdahl says:
Suomalaisten luottamus digimaailmaan vahvistui huijauksista huolimatta
Kahdeksan kymmenestä kertoo kuitenkin kohdanneensa digihuijauksen tai sen yrityksen viimeisen vuoden aikana.
https://yle.fi/a/74-20246485
Tomi Engdahl says:
Ison ihmisjoukon tilinumerot ja henkilötunnukset vuotivat vääriin käsiin – Uutta tietoa julki
Holmaston mukaan heidän järjestelmistään löydettiin haavoittuvuus.
https://www.iltalehti.fi/digiuutiset/a/a2a71772-bc45-4263-b601-da135d27bbc5
Rahaliike Holmaston järjestelmistä on löydetty haavoittuvuus, kertoo yhtiö sähköpostitse.
– Asiakashakumme rajapinnassa havaittiin haavoittuvuus, jonka kautta ulkopuolinen automaattinen järjestelmä pääsi hakemaan osan asiakasrekisterimme tiedoista, vastaa Holmaston yrittäjä Erika von Schantz sähköpostiviestissä Iltalehden haastattelupyyntöön.
Holmastoon tehtiin sunnuntaina 30. elokuuta tietomurto. Myöhemmin paljastui, että vuodossa vääriin käsiin päätyi yhteystietojen lisäksi myös henkilötunnuksia ja tilinumeroita.
Tietoturvaloukkauksen kerrotaan koskevan noin 70 prosenttia yrityksen asiakkaista.
Iltalehti pyysi haastattelua puhelimitse, mutta yritys suostui antamaan vastaukset kysymyksiin sähköpostitse.
Holmaston mukaan yhtiö on käynyt yhdessä palveluntarjoajan kanssa heidän käyttämänsä järjestelmät läpi, ja havaitut puutteet on korjattu.
– Haavoittuvuus korjattiin välittömästi havaitsemisen jälkeen, ja järjestelmän tietojenhakua on rajoitettu.
Tomi Engdahl says:
New York Times:
European Commission President Ursula von der Leyen unveils the EU Kids Act during her SOTU address, proposing a blanket ban on social media for kids under 13 — A proposed law would bar children under 13 from using social media across the 27-nation bloc. — The European Union outlined plans …
https://www.nytimes.com/2026/09/16/business/european-union-social-media-ban.html
Tomi Engdahl says:
Wall Street Journal:
AWS facilities in Abu Dhabi and Bahrain remain mostly offline after Iranian drones hit them in March, testing the region’s pitch for AI and data processing
The Gulf’s AI Nightmare Came Courtesy of an Iranian Drone
Amazon data centers are still offline months after being hit, testing the region’s multibillion-dollar ambitions
https://www.wsj.com/world/middle-east/the-gulfs-ai-nightmare-came-courtesy-of-an-iranian-drone-3f313cb3?st=bKp1un&reflink=desktopwebshare_permalink
DUBAI—The day after the U.S. and Israel launched their opening strikes on Iran, the Islamic Republic shot back with swarms of drones aimed at the Gulf’s newest high-value targets: American data centers.
More than six months after the barrage, a damaged Amazon Web Services facility in Abu Dhabi and another one in Bahrain are still mostly offline. The company has told clients to move their data to other regions while it repairs the sites and hasn’t given a date for completing the work.
The attacks and lasting damage are complicating the pitch by Gulf states like the United Arab Emirates to become world-leading data processors for industries such as artificial intelligence. They add a huge new risk for U.S. companies weighing investments that can cost tens of billions of dollars.
The U.A.E. put years of diplomatic muscle into persuading U.S. officials to sell it top-of-the-line AI chips, ultimately swaying the Trump administration to give it the same access as European countries. In a May 2025 visit to Abu Dhabi, President Trump watched as the Emirates’ leaders unveiled plans for a data-center complex requiring 5 gigawatts of power, the equivalent of more than two Hoover Dams.
Emirati and U.S. officials boasted that OpenAI had agreed to be the inaugural tenant at the complex, with plans to ultimately take 20% of its capacity. That deal now appears to be stalled. OpenAI still hasn’t signed a lease for the project, people familiar with the matter said. OpenAI didn’t respond to a request for comment. News Corp, owner of The Wall Street Journal, has a content-licensing partnership with OpenAI.
Tomi Engdahl says:
Lentomatkustajiin iskee ovela huijaus – tuhansia valetilejä paljastui
Huijarit väijyvät lentoyhtiöiden valituksia ja esiintyvät asiakaspalvelijoina.
https://www.is.fi/digitoday/art-2000012277911.html
Tomi Engdahl says:
Suomi.fi-varoitus annettu
Suomalaisia varoitetaan vaarallisista sähköposteista, jotka vaikuttavat aidoilta Suomi.fi-ilmoituksilta.
https://www.iltalehti.fi/digiuutiset/a/8b69dfb8-482f-4dff-af73-12f0a8267de1
Tomi Engdahl says:
Suomen turvallisuustilanne on muuttunut nopeasti, ja kansalaisten on oltava henkisesti varauduttava uusiin sabotaasi-iskuihin. Näin painottaa tasavallan presidentti Alexander Stubb MTV:n Asian ytimessä -ohjelman tuoreessa haastattelussa. https://www.mtvuutiset.fi/artikkeli/varautukaa-sabotaasi-iskuihin-stubb-neuvoo-suomalaisia-mtv-n-erikoishaastattelussa/9393650
Tomi Engdahl says:
https://www.facebook.com/share/1FdGbJ5YNK/
A new app called Zuckoff lets you detect nearby Meta smart glasses via Bluetooth.
As smart glasses become increasingly popular, so do public concerns about surreptitious recording. In response, 30-year-old Polish software developer Paweł Szydłowski has created ‘Zuckoff,’ a new mobile app designed to detect nearby smart wearables like the Ray-Ban Meta glasses.
By scanning the surrounding environment for specific Bluetooth fingerprints and signatures, the app estimates the distance of compatible smart glasses, offering a digital early-warning system for privacy-conscious individuals.
Since its launch on Apple’s App Store, the app has quickly gained over 5,000 users who are looking for ways to protect their personal space from invisible lenses.
While Zuckoff can identify when compatible glasses are nearby, it cannot determine whether the devices are actively recording. Nevertheless, the app’s growing popularity underscores a widening divide between tech giants pushing wearable AI and a public wary of constant surveillance. The app arrives at a tense moment: Meta recently had to disable thousands of smart glasses after discovering users were tampering with the built-in recording indicator LEDs to film people covertly. While Meta continues to defend its devices’ privacy guardrails, tools like Zuckoff suggest that consumers are increasingly eager to take privacy enforcement into their own hands.
source: Business Insider. (2026). Zuckoff App Can Detect Meta Smart Glasses Recording Nearby.
Tomi Engdahl says:
“My Cybercab held me hostage for an hour.” https://trib.al/tytrXyR
Tomi Engdahl says:
Does this really solve anything? https://trib.al/7keY6By
Webcam Off
Zuckerberg’s Pervert Glasses Have Been So Publicly Shamed That Meta’s Reportedly Now Working on a Version With No Camera
Does this really solve anything?
https://futurism.com/future-society/zuckerberg-pervert-glasses-shamed-meta-no-camera?fbclid=IwdGRjcAUYVtBjbGNrBRhWuXBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEei_mftG1fqOf9sbKhjVfXm5VdXXs9VlGD16ggk7yNCTh6wfnmAk7Ok_QOd-Q_aem_pss2_cggCx62inzhfulI6Q
Tomi Engdahl says:
CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses
Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.
https://www.securityweek.com/cisa-releases-guidance-on-deploying-cyber-decoys/
The US Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance on deploying decoy systems for robust cyber defenses within critical infrastructure organizations.
Cyber decoys, the agency says, complement Zero Trust models, which continuously verify all access, by assuming an adversary has gained some level of access to an enterprise environment.
“Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI),” CISA notes.
They enable organizations to identify, observe, and block malicious activity early, gather and analyze CTI, and allocate resources more effectively.
“Decoy techniques are incremental, cost-effective, and scalable, allowing organizations to introduce them without major architectural changes,” CISA’s guidance (PDF) reads.
To expose adversary activity, organizations should place decoys where users rarely or never interact with them, and should configure them to produce high-fidelity alerts.
They should be designed to divert attackers to decoy data, to produce a misleading understanding of the environment during adversary reconnaissance, and lure threat actors into downloading large amounts of non-sensitive or meaningless data.
Additionally, they should direct adversaries to controlled environments where their real-world-like operations can be observed, and CTI can be collected more efficiently.
“CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data,” CISA notes.
https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf
Tomi Engdahl says:
One hijacked AI coding session helped spread Shai-Hulud across about 100 internal repositories.
A poisoned PyPI package installed an infostealer, GitHub OAuth tokens were stolen, and a compromised package in the company’s own namespace caused a second infection.
Read: https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html
Tomi Engdahl says:
Rikolliset myyvät pääsyä kaupallisiin kielimalleihin
https://etn.fi/index.php/13-news/19309-rikolliset-myyvaet-paeaesyae-kaupallisiin-kielimalleihin
Tomi Engdahl says:
Kvanttiturvallista ohjausta FPGA-piirillä
https://etn.fi/index.php/13-news/19308-kvanttiturvallista-ohjausta-fpga-piirillae
Lattice Semiconductor tuo markkinoille Mach-N2-FPGA-perheen järjestelmien ohjaukseen ja suojaukseen. Piireihin yhdistyvät integroitu flash-muisti, laitteistopohjainen Root of Trust ja CNSA 2.0 -vaatimusten mukainen post-kvanttisalaus.
Mach-N2 perustuu Latticen Nexus 2 -FPGA-alustaan ja on tarkoitettu erityisesti palvelin-, tietoliikenne- ja teollisuusjärjestelmien jatkuvasti toimiviin ohjaus- ja turvatoimintoihin. Uusi perhe tarjoaa jopa kaksinkertaisen logiikkatiheyden sekä aiempaa enemmän SERDES-kaistaa.
Post-kvanttiturvaa varten Mach-N2 tukee ML-DSA-, LMS- ja XMSS-algoritmeja autentikointiin sekä ML-KEM-algoritmia avaintenvaihtoon. Salausalgoritmit voidaan päivittää kentällä, ja anti-rollback-suojaus estää palaamisen vanhempaan ohjelmistoversioon.
Tomi Engdahl says:
https://www.makeuseof.com/i-switched-dns-providers-and-finally-escaped-us-surveillance-law/?link_source=ta_first_comment&taid=6aaab609964d6b00018948db&utm_campaign=trueanthem&utm_medium=social&utm_source=facebook&fbclid=IwdGRjcAUYz29jbGNrBRjPaHBkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEe4L_3LQ1z9mGXYe0pdMxAZ2YU99eklAEUf9RNBS6EMjrlTxY5Ulmrv66IiPI_aem_TU-WYHnw4cuzHkpSgqBO_Q
Tomi Engdahl says:
They’re hitting a nerve. https://trib.al/vTuDwWO
Hitting Them Where It Hurts
Iran Drone Strikes on Amazon Data Centers Are Permanently Deleting Customer Data
They’re hitting a nerve.
https://futurism.com/artificial-intelligence/iran-drone-strikes-data-centers-deleting-customer-data?fbclid=IwdGRjcAUZGbljbGNrBRkZn3Bkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeoVtU5gmY7XRV0cUFXzwh5mA8FdXgv362HF9x_g8JbnuwFSU9JGgTN9mahk8_aem_skj0ArysEBkycLqTjJRYrg
As the USA’s war with Iran shows no signs of letting up, strikes on data centers are putting not just human lives in peril, but even customer data.
According to a September 15 Amazon Web Services update, Iranian drone strikes left some of the tech giant’s data centers in the United Arab Emirates and Bahrain in tatters. The company admitted that it was “unable to restore access to the resources and data hosted” on local data centers. The damage extended across several “availability zones,” which are clusters of one or more data centers in the same region.
“The damage to our infrastructure spanned multiple Availability Zones and exceeded what our regional and multi-AZ services are designed to withstand,” Amazon admitted.
As the company points out, the drone strikes first began in March, first highlighting how critical digital infrastructure near an active warzone has quickly become a major vulnerability, giving Iranian forces a key target and plenty of leverage.