Cyber security news September 2026

This posting is here to collect cyber security news in September 2026.

I post links to security vulnerability news to comments of this article.

You are also free to post related links to comments.

124 Comments

  1. Tomi Engdahl says:

    Britney Nguyen / MarketWatch:
    Cybersecurity stocks were the top performers in the S&P 500 on Monday amid escalating AI fears; CrowdStrike rose 14%, Palo Alto Networks 13%, and Fortinet 9%

    CrowdStrike and Palo Alto Networks lead software stocks to a never-before-seen feat
    https://www.morningstar.com/news/marketwatch/20260914261/crowdstrike-and-palo-alto-networks-lead-software-stocks-to-a-never-before-seen-feat

    Reply
  2. Tomi Engdahl says:

    Usb-porttiin kiinnitetty laite teki kymmenistätuhansista televisioista rikoksentekovälineitä
    https://www.is.fi/digitoday/tietoturva/art-2000012267876.html

    Tietoturvayhtiö Bitsight havaitsi kymmeniä tuhansia halpoja Android-tv-tikkuja, jotka olivat vaarallisia jo tehtaalta lähtiessään.

    Laitteisiin oli asennettu valmiiksi kiinalaisen yhtiön sovelluksia, jotka ohjasivat liikennettä käyttäjän yhteyden kautta ja tekivät mainospetoksia.

    Noin 38 000 haitallista tikkua tuotti mainospetoksilla arviolta lähes 43 000 euroa päivässä.

    Tietoturvayhtiö F-Securen asiantuntija Joel Latto kehottaa kuluttajia pysyttelemään luotetuissa ja sertifioiduissa laitteissa.

    Halvoilla Android-pohjaisilla tv-tikuilla eli mediatoistimilla voi olla pimeä puoli. Tietoturvayhtiö Bitsight havaitsi kymmeniätuhansia tällaisia televisioihin kytkettyjä laitteita, jotka olivat vaarallisia jo tehtaalta lähtiessään.

    Laitteisiin oli asennettu valmiiksi kaksi kiinalaisen yhtiön sovellusta, joiden avulla tv-tikut pystyivät tekemään katalia asioita käyttäjänsä selän takana. Tv:n ollessa päällä tikut ohjasivat internet-liikennettä käyttäjän kotiyhteyden kautta. Maksua vastaan tarjottu palvelu voi olla houkuttava rikollisille.

    Kun television sulki, tikut alkoivat takoa rahaa mainospetoksilla. Tikut ottivat yhteyttä tekoälyllä luotuihin verkkosivuihin ja tekeytyivät tunnettujen brändien puhelimiksi. Automatisoidut ohjelmat eli botit klikkasivat näillä verkkosivuilla olevia mainoksia näyttökertojen kerryttämiseksi eli rahan tekemiseksi.

    Latton mukaan tekoäly tekee tällaisesta toiminnasta entistä automaattisempaa ja laajamittaisempaa. Näin aivan tavallisista nettiin kytketyistä laitteista voi tulla osa paljon suurempaa rikollista operaatiota.

    – Kuluttajien tulisi pysytellä luotetuissa ja sertifioiduissa laitteissa, jotka saavat säännöllisesti tietoturvakorjauksia, Latto neuvoo.

    Reply
  3. Tomi Engdahl says:

    CISA: Critical VMware RCE flaw now exploited by ransomware gangs
    https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/?fbclid=IwdGRjcAUWOOBwZG9mBWV4dG4DYWVtAjExAHNydGMGYXBwX2lkDDM1MDY4NTUzMTcyOAABHq4Rvoeo4jl6sj4dWHV4FLcoJAzWF4QJiBbKZ47HVahBJHFG2GYYy2FrlMEq_aem_mi2IG07iCy1pUjFanYKQsg

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July.

    Broadcom addressed the security flaw (tracked as CVE-2026-59310) on July 29, describing it as a critical directory traversal vulnerability in the vCenter Syslog server that unauthenticated attackers can exploit to execute arbitrary code.

    The company also warned customers in a supplemental FAQ at the time to treat fixing CVE-2026-59310 as an emergency and install patches as soon as possible.

    Reply
  4. Tomi Engdahl says:

    Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

    Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers.

    https://www.securityweek.com/microsoft-commits-to-sweeping-ai-privacy-rules-for-students-will-other-tech-giants-follow/

    Reply
  5. Tomi Engdahl says:

    CISO Strategy
    “We Think the Security Control Is Working” Is No Longer Good Enough

    Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today.

    https://www.securityweek.com/we-think-the-security-control-is-working-is-no-longer-good-enough/

    Security, risk, and control assessments are typically done for the sake of compliance: tools deployed, audits passed, workflows completed, boxes checked. That’s no longer enough for boards, customers, and regulators, who all want an answer to a harder question: ‘can you prove your controls are working right now?’

    I often ask CISOs a version of that question, and the honest answer is usually some form of “we think so.” It’s not because they’re careless. Most control checks still happen the way a dentist visit does. When your dentist asks whether you brush and floss every day, you could fib and say yes, but one look at your x-ray tells the real story.

    Security works the same way. An annual audit captures what you told the auditor, or what looked true on the day someone checked. But it may not be the ground truth.

    Reply
  6. Tomi Engdahl says:

    Vulnerabilities
    $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

    AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage.

    https://www.securityweek.com/1-million-sandbox-challenge-uncovers-linux-kernel-flaws/

    Linux

    A two-week focused sandbox bug-bounty program resulted in 1,285 filings, but none that could access customer data.

    The Vercel sandbox, a Firecracker‑based microVM environment, is an isolation tool for untrusted AI‑agent code. For two weeks (August 18 until September 1), Vercel operated a focused bug-bounty program with a $1 million reward pot. It called the program a ‘challenge’ – a challenge to HackerOne hackers (black box targeting) and Trail of Bits engineers (white box targeting) to escape the sandbox.

    Time is up, and the results have been published. Vercel received 1,285 reports in two weeks, demonstrating the modern power and speed of researchers working with AI-assistance. “Report triage runs until October 1, but so far we have validated 1 Critical, 7 High, 15 Medium, 49 Low, 19 Informative. ~$325k in committed payouts,” says the firm. None of the reports showed anyone being able to access a real customer’s data – but many have allowed Vercel to improve the product.

    Reply
  7. Tomi Engdahl says:

    Artificial Intelligence
    OpenAI Investigates Report Linking AI Agents to RubyGems Attack

    The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity

    https://www.securityweek.com/openai-investigates-report-linking-ai-agents-to-rubygems-attack/

    Reply
  8. Tomi Engdahl says:

    Suomalaisten luottamus digimaailmaan vahvistui huijauksista huolimatta
    Kahdeksan kymmenestä kertoo kuitenkin kohdanneensa digihuijauksen tai sen yrityksen viimeisen vuoden aikana.
    https://yle.fi/a/74-20246485

    Reply
  9. Tomi Engdahl says:

    Ison ihmisjoukon tilinumerot ja henkilötunnukset vuotivat vääriin käsiin – Uutta tietoa julki
    Holmaston mukaan heidän järjestelmistään löydettiin haavoittuvuus.
    https://www.iltalehti.fi/digiuutiset/a/a2a71772-bc45-4263-b601-da135d27bbc5

    Rahaliike Holmaston järjestelmistä on löydetty haavoittuvuus, kertoo yhtiö sähköpostitse.

    – Asiakashakumme rajapinnassa havaittiin haavoittuvuus, jonka kautta ulkopuolinen automaattinen järjestelmä pääsi hakemaan osan asiakasrekisterimme tiedoista, vastaa Holmaston yrittäjä Erika von Schantz sähköpostiviestissä Iltalehden haastattelupyyntöön.

    Holmastoon tehtiin sunnuntaina 30. elokuuta tietomurto. Myöhemmin paljastui, että vuodossa vääriin käsiin päätyi yhteystietojen lisäksi myös henkilötunnuksia ja tilinumeroita.

    Tietoturvaloukkauksen kerrotaan koskevan noin 70 prosenttia yrityksen asiakkaista.

    Iltalehti pyysi haastattelua puhelimitse, mutta yritys suostui antamaan vastaukset kysymyksiin sähköpostitse.

    Holmaston mukaan yhtiö on käynyt yhdessä palveluntarjoajan kanssa heidän käyttämänsä järjestelmät läpi, ja havaitut puutteet on korjattu.

    – Haavoittuvuus korjattiin välittömästi havaitsemisen jälkeen, ja järjestelmän tietojenhakua on rajoitettu.

    Reply
  10. Tomi Engdahl says:

    New York Times:
    European Commission President Ursula von der Leyen unveils the EU Kids Act during her SOTU address, proposing a blanket ban on social media for kids under 13 — A proposed law would bar children under 13 from using social media across the 27-nation bloc. — The European Union outlined plans …
    https://www.nytimes.com/2026/09/16/business/european-union-social-media-ban.html

    Reply
  11. Tomi Engdahl says:

    Wall Street Journal:
    AWS facilities in Abu Dhabi and Bahrain remain mostly offline after Iranian drones hit them in March, testing the region’s pitch for AI and data processing

    The Gulf’s AI Nightmare Came Courtesy of an Iranian Drone
    Amazon data centers are still offline months after being hit, testing the region’s multibillion-dollar ambitions
    https://www.wsj.com/world/middle-east/the-gulfs-ai-nightmare-came-courtesy-of-an-iranian-drone-3f313cb3?st=bKp1un&reflink=desktopwebshare_permalink

    DUBAI—The day after the U.S. and Israel launched their opening strikes on Iran, the Islamic Republic shot back with swarms of drones aimed at the Gulf’s newest high-value targets: American data centers.

    More than six months after the barrage, a damaged Amazon Web Services facility in Abu Dhabi and another one in Bahrain are still mostly offline. The company has told clients to move their data to other regions while it repairs the sites and hasn’t given a date for completing the work.

    The attacks and lasting damage are complicating the pitch by Gulf states like the United Arab Emirates to become world-leading data processors for industries such as artificial intelligence. They add a huge new risk for U.S. companies weighing investments that can cost tens of billions of dollars.

    The U.A.E. put years of diplomatic muscle into persuading U.S. officials to sell it top-of-the-line AI chips, ultimately swaying the Trump administration to give it the same access as European countries. In a May 2025 visit to Abu Dhabi, President Trump watched as the Emirates’ leaders unveiled plans for a data-center complex requiring 5 gigawatts of power, the equivalent of more than two Hoover Dams.

    Emirati and U.S. officials boasted that OpenAI had agreed to be the inaugural tenant at the complex, with plans to ultimately take 20% of its capacity. That deal now appears to be stalled. OpenAI still hasn’t signed a lease for the project, people familiar with the matter said. OpenAI didn’t respond to a request for comment. News Corp, owner of The Wall Street Journal, has a content-licensing partnership with OpenAI.

    Reply
  12. Tomi Engdahl says:

    Lentomatkustajiin iskee ovela huijaus – tuhansia vale­tilejä paljastui

    Huijarit väijyvät lentoyhtiöiden valituksia ja esiintyvät asiakaspalvelijoina.

    https://www.is.fi/digitoday/art-2000012277911.html

    Reply
  13. Tomi Engdahl says:

    Suomi.fi-varoitus annettu
    Suomalaisia varoitetaan vaarallisista sähköposteista, jotka vaikuttavat aidoilta Suomi.fi-ilmoituksilta.
    https://www.iltalehti.fi/digiuutiset/a/8b69dfb8-482f-4dff-af73-12f0a8267de1

    Reply
  14. Tomi Engdahl says:

    Suomen turvallisuustilanne on muuttunut nopeasti, ja kansalaisten on oltava henkisesti varauduttava uusiin sabotaasi-iskuihin. Näin painottaa tasavallan presidentti Alexander Stubb MTV:n Asian ytimessä -ohjelman tuoreessa haastattelussa. https://www.mtvuutiset.fi/artikkeli/varautukaa-sabotaasi-iskuihin-stubb-neuvoo-suomalaisia-mtv-n-erikoishaastattelussa/9393650

    Reply
  15. Tomi Engdahl says:

    https://www.facebook.com/share/1FdGbJ5YNK/

    A new app called Zuckoff lets you detect nearby Meta smart glasses via Bluetooth.

    As smart glasses become increasingly popular, so do public concerns about surreptitious recording. In response, 30-year-old Polish software developer Paweł Szydłowski has created ‘Zuckoff,’ a new mobile app designed to detect nearby smart wearables like the Ray-Ban Meta glasses.

    By scanning the surrounding environment for specific Bluetooth fingerprints and signatures, the app estimates the distance of compatible smart glasses, offering a digital early-warning system for privacy-conscious individuals.

    Since its launch on Apple’s App Store, the app has quickly gained over 5,000 users who are looking for ways to protect their personal space from invisible lenses.

    While Zuckoff can identify when compatible glasses are nearby, it cannot determine whether the devices are actively recording. Nevertheless, the app’s growing popularity underscores a widening divide between tech giants pushing wearable AI and a public wary of constant surveillance. The app arrives at a tense moment: Meta recently had to disable thousands of smart glasses after discovering users were tampering with the built-in recording indicator LEDs to film people covertly. While Meta continues to defend its devices’ privacy guardrails, tools like Zuckoff suggest that consumers are increasingly eager to take privacy enforcement into their own hands.

    source: Business Insider. (2026). Zuckoff App Can Detect Meta Smart Glasses Recording Nearby.

    Reply
  16. Tomi Engdahl says:

    “My Cybercab held me hostage for an hour.” https://trib.al/tytrXyR

    Reply
  17. Tomi Engdahl says:

    CISA Releases Cyber Decoy Guidance to Strengthen Critical Infrastructure Defenses

    Complementing Zero Trust models, decoys enable organizations to detect, observe, and block malicious activity in their environments.

    https://www.securityweek.com/cisa-releases-guidance-on-deploying-cyber-decoys/

    The US Cybersecurity and Infrastructure Security Agency (CISA) has released new guidance on deploying decoy systems for robust cyber defenses within critical infrastructure organizations.

    Cyber decoys, the agency says, complement Zero Trust models, which continuously verify all access, by assuming an adversary has gained some level of access to an enterprise environment.

    “Cyber decoys are assets that appear to be legitimate systems, accounts, or data, but are designed to distract adversaries, detect their presence, or facilitate collection of cyber threat intelligence (CTI),” CISA notes.

    They enable organizations to identify, observe, and block malicious activity early, gather and analyze CTI, and allocate resources more effectively.

    “Decoy techniques are incremental, cost-effective, and scalable, allowing organizations to introduce them without major architectural changes,” CISA’s guidance (PDF) reads.

    To expose adversary activity, organizations should place decoys where users rarely or never interact with them, and should configure them to produce high-fidelity alerts.

    They should be designed to divert attackers to decoy data, to produce a misleading understanding of the environment during adversary reconnaissance, and lure threat actors into downloading large amounts of non-sensitive or meaningless data.

    Additionally, they should direct adversaries to controlled environments where their real-world-like operations can be observed, and CTI can be collected more efficiently.

    “CISA developed this guidance to help defensive teams at varying levels of cybersecurity maturity plan and implement cyber decoy strategies that strengthen their detection and response capabilities. Many organizations struggle to detect adversaries who use legitimate credentials, native tools, and living off the land (LOTL) techniques to conduct discovery, move laterally, and access data,” CISA notes.

    https://www.cisa.gov/sites/default/files/2026-09/using-cyber-decoys-to-strengthen-detection-and-response_508c.pdf

    Reply
  18. Tomi Engdahl says:

    One hijacked AI coding session helped spread Shai-Hulud across about 100 internal repositories.

    A poisoned PyPI package installed an infostealer, GitHub OAuth tokens were stolen, and a compromised package in the company’s own namespace caused a second infection.

    Read: https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html

    Reply
  19. Tomi Engdahl says:

    Kvanttiturvallista ohjausta FPGA-piirillä
    https://etn.fi/index.php/13-news/19308-kvanttiturvallista-ohjausta-fpga-piirillae

    Lattice Semiconductor tuo markkinoille Mach-N2-FPGA-perheen järjestelmien ohjaukseen ja suojaukseen. Piireihin yhdistyvät integroitu flash-muisti, laitteistopohjainen Root of Trust ja CNSA 2.0 -vaatimusten mukainen post-kvanttisalaus.

    Mach-N2 perustuu Latticen Nexus 2 -FPGA-alustaan ja on tarkoitettu erityisesti palvelin-, tietoliikenne- ja teollisuusjärjestelmien jatkuvasti toimiviin ohjaus- ja turvatoimintoihin. Uusi perhe tarjoaa jopa kaksinkertaisen logiikkatiheyden sekä aiempaa enemmän SERDES-kaistaa.

    Post-kvanttiturvaa varten Mach-N2 tukee ML-DSA-, LMS- ja XMSS-algoritmeja autentikointiin sekä ML-KEM-algoritmia avaintenvaihtoon. Salausalgoritmit voidaan päivittää kentällä, ja anti-rollback-suojaus estää palaamisen vanhempaan ohjelmistoversioon.

    Reply
  20. Tomi Engdahl says:

    They’re hitting a nerve. https://trib.al/vTuDwWO

    Hitting Them Where It Hurts
    Iran Drone Strikes on Amazon Data Centers Are Permanently Deleting Customer Data
    They’re hitting a nerve.
    https://futurism.com/artificial-intelligence/iran-drone-strikes-data-centers-deleting-customer-data?fbclid=IwdGRjcAUZGbljbGNrBRkZn3Bkb2YFZXh0bgNhZW0CMTEAc3J0YwZhcHBfaWQMMzUwNjg1NTMxNzI4AAEeoVtU5gmY7XRV0cUFXzwh5mA8FdXgv362HF9x_g8JbnuwFSU9JGgTN9mahk8_aem_skj0ArysEBkycLqTjJRYrg

    As the USA’s war with Iran shows no signs of letting up, strikes on data centers are putting not just human lives in peril, but even customer data.

    According to a September 15 Amazon Web Services update, Iranian drone strikes left some of the tech giant’s data centers in the United Arab Emirates and Bahrain in tatters. The company admitted that it was “unable to restore access to the resources and data hosted” on local data centers. The damage extended across several “availability zones,” which are clusters of one or more data centers in the same region.

    “The damage to our infrastructure spanned multiple Availability Zones and exceeded what our regional ​and multi-AZ services are designed to withstand,” Amazon admitted.

    As the company points out, the drone strikes first began in March, first highlighting how critical digital infrastructure near an active warzone has quickly become a major vulnerability, giving Iranian forces a key target and plenty of leverage.

    Reply

Leave a Comment

Your email address will not be published. Required fields are marked *

*

*