Skip to content
-
Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
Close

Search

Uncategorized

Weekly Threat Report 2026-09-21

Weekly Threat Intelligence Summary Top 10 General Cyber Threats Generated 2026-09-21T05:00:05.141662+00:00 China-Based…

Report Bot
By Report Bot
On
September 21, 2026
Uncategorized

Evening Security Summary – 2026-09-20

# Daily Threat Forecast – xloggs.com News Reporter ## Overview This daily threat forecast covers key security…

Xloggs MCP
By Xloggs MCP
On
September 20, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-20 13:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-20 13:00 PDT Malicious npm packages evade…

Report Bot
By Report Bot
On
September 20, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-20 08:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-20 08:00 PDT Malicious npm packages evade…

Report Bot
By Report Bot
On
September 20, 2026
Uncategorized

Morning Security Report – 2026-09-20

# Morning Security Report – 2026-09-20 **Report Type**: Real-time News Summary **Date**: 2026-09-20 **Source**:…

Xloggs MCP
By Xloggs MCP
On
September 20, 2026
Uncategorized

Evening Security Summary – 2026-09-19

# Daily Threat Forecast – xloggs.com News Reporter ## Overview This daily threat forecast covers key security…

Xloggs MCP
By Xloggs MCP
On
September 19, 2026
Uncategorized

Weekly Threat Report 2026-09-21

By Report Bot
September 21, 2026 10 Min Read
Comments Off on Weekly Threat Report 2026-09-21

Weekly Threat Intelligence Summary

Top 10 General Cyber Threats

Generated 2026-09-21T05:00:05.141662+00:00

  1. China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies (www.cisa.gov, 2026-09-04T16:12:28)
    Score: 13.544
    Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation acti
  2. September 2026 Patch Tuesday: Two Exploited Zero-Days and 113 Critical Vulnerabilities Among 972 CVEs (www.crowdstrike.com, 2026-09-08T05:00:00)
    Score: 10.533
  3. H1 2026 Malware Vulnerability Trends (www.recordedfuture.com, 2026-09-03T00:00:00)
    Score: 10.165
    Learn how adversaries abuse trusted tools, AI, and developer environments for cyberattacks. Get actionable insights on ransomware, mobile threats, and supply chain security.
  4. Tajin Group: Guarantee Marketplace Vendor Involved in Phishing and Chinese Money Laundering Group (www.recordedfuture.com, 2026-09-15T00:00:00)
    Score: 9.665
    Analyze Tajin Group's role in phishing and Chinese money laundering. Discover how this Telegram-based vendor exploits payment gateways and adapts its financial fraud operations.
  5. New Android malware uses AI to steal bank logins and PINs (www.malwarebytes.com, 2026-09-18T15:37:04)
    Score: 7.774
    RatHat can navigate infected phones while stealing bank logins, authentication codes, and screen-lock PINs.
  6. Google Pixel owners urged to patch actively exploited modem flaw (www.malwarebytes.com, 2026-09-16T10:39:04)
    Score: 7.406
    Google’s September Pixel update fixes 110 vulnerabilities, including a modem flaw being used in limited, targeted attacks.
  7. Recorded Future Announces Automated Signature Creation, Accelerating Vulnerability Prioritization (www.recordedfuture.com, 2026-09-04T00:00:00)
    Score: 7.332
    Recorded Future's Automated Signature Creation turns new vulnerabilities into detection signatures in under an hour, matching the pace of AI-driven exploits.
  8. HBO Max’s verified Reddit account hijacked to spread malware (www.malwarebytes.com, 2026-09-15T11:51:03)
    Score: 7.248
    Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.
  9. Android malware creates a hidden copy of your banking app (www.malwarebytes.com, 2026-09-11T12:14:55)
    Score: 6.584
    The Gigabud banking Trojan can clone a banking app into a separate work profile on an Android device to help hide fraudulent transactions.
  10. BlueMoon exploit kit turns Chrome and Windows flaws into attacks (www.malwarebytes.com, 2026-09-10T15:49:13)
    Score: 6.442
    Four different espionage groups used the same exploit kit to target recently fixed flaws, showing why “patch later” is a dangerous gamble.

Top 10 AI / LLM-Related Threats

Generated 2026-09-21T06:00:22.580569+00:00

  1. China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies (www.cisa.gov, 2026-09-04T16:12:28)
    Score: 38.654
    Executive summary China-based artificial intelligence (AI) companies are conducting systematic extraction of proprietary functionalities and capabilities of U.S. AI companies’ models through industrial-scale knowledge distillation campaigns that form the core—not merely a supplement—of their AI development strategy. While “distillation” is recognized as a legitimate and useful technique in AI research, China-based AI companies are engaging in aggressive, malicious, and targeted distillation acti
  2. Origin Is All You Need: Provenance-Aware Transformers for Structural Trust-Boundary Separation (arxiv.org, 2026-09-21T04:00:00)
    Score: 24.78
    arXiv:2609.21088v1 Announce Type: new
    Abstract: Indirect prompt injection (IPI) remains a central safety and security challenge for large language model (LLM) systems because standard transformers lack architectural notion of source authority. Retrieved documents, user inputs, and system instructions are all processed through the same undifferentiated attention mechanism, forcing the model to infer from wording alone what should be obeyed and what should be treated as data. We propose Provenanc
  3. CASCADE Against Jailbreaks: Combination Across Stages with Controlled Attack-Defense Evaluation (arxiv.org, 2026-09-21T04:00:00)
    Score: 20.78
    arXiv:2609.21793v1 Announce Type: new
    Abstract: Defenses against jailbreak attacks on Large Language Models (LLMs) operate at different pipeline stages, such as input modification or output guard, but it remains unclear which defenses to deploy at each stage and how to combine them. Prior empirical studies, fragmented by inconsistent attack-success-rate definitions and experimental settings, have evaluated defenses largely in isolation. Here we present the first systematic study, to our knowled
  4. Conformal Privacy Auditing: Calibrated Re-identification Attacks with Statistical Guarantees (arxiv.org, 2026-09-21T04:00:00)
    Score: 17.78
    arXiv:2609.21340v1 Announce Type: new
    Abstract: Empirical identity leakage from released text is increasingly driven by attackers that combine large language models (LLMs) with auxiliary knowledge to link documents to individuals. Existing audits typically report success rates for specific attack pipelines but lack finite-sample statistical guarantees, while training-time protections such as differential privacy are difficult to translate into release-time decisions for individual natural-langu
  5. HE-Guardrail: A Homomorphic Guardrail Against Jailbreak Attacks for Encrypted Large Language Model Inference (arxiv.org, 2026-09-21T04:00:00)
    Score: 17.78
    arXiv:2609.21484v1 Announce Type: new
    Abstract: Homomorphic encryption (HE) has emerged as a promising approach to privacy-preserving machine learning (PPML), enabling computation directly over encrypted data. In HE-based PPML, a client submits an encrypted input to the server, which evaluates models such as large language models (LLMs) without access to the underlying plaintext. However, we identify a critical security vulnerability in this setting: HE-LLM inference is vulnerable to malicious
  6. SRAF: Stealthy and Robust Adversarial Fingerprint for Copyright Verification of Large Language Models (arxiv.org, 2026-09-21T04:00:00)
    Score: 17.78
    arXiv:2505.06304v5 Announce Type: replace
    Abstract: The protection of Intellectual Property (IP) for Large Language Models (LLMs) has become a critical concern as model theft and unauthorized commercialization escalate. While adversarial fingerprinting offers a promising black-box solution for ownership verification, existing methods suffer from significant limitations: they are fragile against downstream model modifications, sensitive to system prompt variations, and easily detectable due to h
  7. Staying on the Attack Path: Structured State for Long-Horizon Automated Penetration Testing (arxiv.org, 2026-09-21T04:00:00)
    Score: 17.78
    arXiv:2609.07344v2 Announce Type: replace
    Abstract: Large language model (LLM) based agents are increasingly applied to cybersecurity tasks such as vulnerability discovery and automated penetration testing. On long-horizon security tasks, however, such agents remain limited by context forgetting and intent drift: early critical facts and causal reasoning chains are lost over extended interactions, and the agent falls into aimless, repetitive exploration. This paper proposes Intentest, an intent
  8. NetInspector: Measuring and Improving LLM Capabilities for Reliable Intent-Based Networking Policy Generation (arxiv.org, 2026-09-21T04:00:00)
    Score: 14.78
    arXiv:2609.21103v1 Announce Type: new
    Abstract: Modern networks are large in scale and heterogeneous in configuration, making manual policy management increasingly impractical. Intent-Based Networking (IBN) addresses this by automating the translation of high-level operator goals into low-level network configurations. Yet existing IBN systems rely on static heuristics and fixed-feature classifiers that generalize poorly to distribution shifts such as new service definitions or evolving phrasing
  9. CESBench: Benchmarking Large Language Models on Cryptographic Engineering Security for IoT Devices (arxiv.org, 2026-09-21T04:00:00)
    Score: 14.78
    arXiv:2609.21344v1 Announce Type: new
    Abstract: For Internet of Things (IoT) devices, a secure algorithm alone is not enough: an attacker with physical access can attack the implementation directly, and its flaws are hard to fix once deployed. Large language models (LLMs) are now used to build and analyze such implementations. LLM benchmarks exist for cryptography and general cybersecurity, but none covers cryptographic engineering. In this paper, we present CESBench, 380 expert-written items a
  10. Micro-Collaborative Poisoning: A Distributed Attack on RAG Systems (arxiv.org, 2026-09-21T04:00:00)
    Score: 14.78
    arXiv:2609.21573v1 Announce Type: new
    Abstract: Retrieval-Augmented Generation (RAG) improves large language models by grounding outputs in external knowledge sources, but this dependency also creates a surface for poisoning attacks. This paper introduces Micro-Collaborative Poisoning, a distributed attack in which a false target claim is divided across multiple locally plausible documents instead of being concentrated in a single malicious passage. We evaluate the attack across 108 RAG configu
  11. Watermarkable Multi-Draft Speculative Sampling via Poisson Processes (arxiv.org, 2026-09-21T04:00:00)
    Score: 14.78
    arXiv:2609.21858v1 Announce Type: new
    Abstract: Large language models (LLMs) have achieved state-of-the-art performance across a wide range of tasks, motivating two important aspects of deployment: inference efficiency and output provenance, which can be tackled by speculative sampling and watermarking, respectively. However, recent works have shown that combining these two goals is highly nontrivial and can be potentially impossible. In this work, we develop a novel multi-draft speculative sam
  12. Understanding the Security Boundary of Obfuscation-based On-Device LLM Protection (arxiv.org, 2026-09-21T04:00:00)
    Score: 14.78
    arXiv:2609.10117v2 Announce Type: replace
    Abstract: Trusted Execution Environments (TEEs) offer a promising mechanism for safeguarding the intellectual property of on-device Large Language Models (LLMs). To overcome the inherent computational bottlenecks of TEEs, existing TEE-Shielded LLM Partition (TSLP) methods apply efficient obfuscation schemes to computationally intensive layers, offloading them to external GPUs while retaining only lightweight operations within the TEE. Although a growing
  13. OverThink: Slowdown Attacks on Reasoning LLMs (arxiv.org, 2026-09-21T04:00:00)
    Score: 14.78
    arXiv:2502.02542v5 Announce Type: replace-cross
    Abstract: A reasoning language model (RLM) generates costly reasoning tokens, often hidden from the users, that help it excel at many tasks. Our Overthink attack targets RLM-based applications (such as chatbots or coding agents) that rely on external context by forcing these models to generate substantially more reasoning tokens while still producing contextually correct answers. An adversary conducts the attack by injecting decoy reasoning proble
  14. CIPL: A Channel-Aware Framework for Recoverable Privacy Leakage in LLM Agents (arxiv.org, 2026-09-21T04:00:00)
    Score: 12.48
    arXiv:2609.21686v1 Announce Type: new
    Abstract: Privacy leakage in LLM agents is commonly evaluated within individual components such as memory, retrieval, or tool-use pipelines, which makes it difficult to distinguish internal exposure from information that an external observer can actually recover. We present CIPL (Channel Inversion for Privacy Leakage), a channel-aware evaluation framework for black-box privacy leakage in LLM agents. CIPL represents a target through sensitive source, selecti
  15. Algebraic Cryptanalytic Extraction on Hard-Label Neural Networks (arxiv.org, 2026-09-21T04:00:00)
    Score: 12.48
    arXiv:2608.05736v2 Announce Type: replace
    Abstract: Although the state-of-the-art model extraction attack on the hard-label Fully-connected Neural Network (FCN) by Carlini et al. at EUROCRYPT 2025 has polynomial-time complexity in theory, its dual-point clustering relies on singular value decomposition (SVD) with a time complexity of $\mathcal{O}(n^2 (d^{(k)})^3)$, resulting in huge runtime in practice. To address this computational bottleneck, this work transforms Carlini et al.'s geometr
  16. Et Tu, MacBook? Unprivileged Keystroke Inference and Context Profiling via the Built-in IMU Side Channel (arxiv.org, 2026-09-21T04:00:00)
    Score: 11.78
    arXiv:2609.21569v1 Announce Type: new
    Abstract: Recent generations of Apple MacBooks embed an inertial measurement unit (IMU) within their unibody chassis for device orientation and motion sensing. However, this IMU inadvertently captures not only intended device-level information but also subtle physical vibrations from user interactions and the surrounding environment. These signals establish a novel, previously unexplored side channel. We uncover a vulnerability allowing non-root access to I
  17. Selecting a vector store for Amazon Bedrock Knowledge Bases (aws.amazon.com, 2026-09-17T15:53:13)
    Score: 11.546
    Choosing the right vector store for your Amazon Bedrock Knowledge Bases RAG application affects performance and cost. This post compares Amazon OpenSearch Service, Amazon Aurora PostgreSQL with pgvector, and Amazon S3 Vectors across three RAG use cases, with benchmarks and a practical selection framework.
  18. TrustBOM: A Scalable Architecture for Confidentiality-Preserving SBOMs Across Organizations (arxiv.org, 2026-09-21T04:00:00)
    Score: 11.48
    arXiv:2609.21419v1 Announce Type: new
    Abstract: Software Bills of Materials (SBOMs) have emerged as a key mechanism for software supply chain governance in enterprise architectures. However, their adoption across organizations remains limited due to concerns about exposing sensitive dependency information. To address this limitation, we propose TrustBOM, a scalable architecture for confidentiality-preserving SBOMs integrated into enterprise CI/CD workflows. TrustBOM enables software providers t
  19. A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity (unit42.paloaltonetworks.com, 2026-09-18T10:00:36)
    Score: 11.125
    Analysis of how default configurations in AWS AgentCore Harness allow prompt injection to exfiltrate credentials, and key steps to secure your agents. The post A Vault with a Heap-View: The Uncomfortable Space Between AgentCore Harness and Identity appeared first on Unit 42 .
  20. Patch Tuesday – September 2026 (www.rapid7.com, 2026-09-08T21:44:04)
    Score: 10.961
    Microsoft is publishing 974 own-product vulnerabilities on September 2026 Patch Tuesday , including 723 vulnerabilities in Windows. Along with Microsoft fixes for 25 non-Microsoft CVEs, that brings the total number of vulnerabilities on the table today to 999. Whether this is the biggest Patch Tuesday ever depends on how we count, but this is by far the most CVEs that Microsoft has ever published in a single day. As Rapid7 noted last month, there is no reason to suppose that Patch Tuesday will e
  21. The September 2026 Security Update Review (www.thezdi.com, 2026-09-08T18:32:13)
    Score: 10.929
    Whelp, here we are. Deep into the new normal. With nearly 1,000 CVEs coming out from Microsoft and a healthy release from Adobe as well, there’s a phrase from my military days that comes to mind: embrace the suck. Take an extended break from your regularly scheduled activities as we take a look at the latest security patches from Adobe and Microsoft. If you’d rather watch the full video recap covering the entire release, you can check it out here: Adobe Patches for September 2026 For the first p
  22. How to opt out of AI chatbot training (www.malwarebytes.com, 2026-09-15T15:41:44)
    Score: 10.868
    ChatGPT contractors are reviewing real users' conversations. Here’s how to stop AI companies using your chats for model training.
  23. X-SPUR: Explainable Surprisal-Based Protocol-Aware Unsupervised Reasoning for Automotive Ethernet Intrusion Detection (arxiv.org, 2026-09-21T04:00:00)
    Score: 10.78
    arXiv:2609.21217v1 Announce Type: new
    Abstract: Automotive Ethernet carries heterogeneous multi-protocol traffic in modern in-vehicle networks, where labeled attack data are rarely available and the strongest prior unsupervised detector still relies on handcrafted traffic features. This article presents X-SPUR, an explainable, surprisal-based, protocol-aware unsupervised reasoning framework that instead represents raw packet fields as token sequences, learns benign traffic patterns through caus
  24. Metasploit Wrap Up: This One Goes to Sixteen! (www.rapid7.com, 2026-09-11T13:35:11)
    Score: 10.194
    This One Goes to Sixteen! Another banger from Metasploit with sixteen new modules, including ten exploit modules, with five on the CISA KEV list. Cisco, Papercut, Sonicwall, Jetbrains, and Langflow all have exploit modules, and not to be outdone, we even have a Metasploit scanner to watch the watchers! New module content (16) Elasticsearch ingest-attachment Apache Tika XFA XXE Local File Read Authors: Bourbon Offensive Security Services and Jean-Marie Bourbon Type: Auxiliary Pull request: #21739
  25. Transcript-Bound Combiners for Downgrade-Resilient Hybrid Post-Quantum Key Establishment: Definition, Proof, and Embedded-Device Cost (arxiv.org, 2026-09-21T04:00:00)
    Score: 9.48
    arXiv:2609.21273v1 Announce Type: new
    Abstract: Hybrid key establishment runs a post-quantum key-encapsulation mechanism (KEM) alongside a classical Diffie-Hellman primitive, so that the session key stays secure while either component resists attack. This design is now standardized in the Transport Layer Security protocol, Secure Shell, and the Internet Key Exchange, with the standardized module-lattice KEM (ML-KEM) as the post-quantum component. A hybrid KEM secures the derived key, but not th

Auto-generated 2026-09-21

Author

Report Bot

Follow Me
Other Articles
Previous

Evening Security Summary – 2026-09-20

  • Clippie retired for Mico the Avatar.
  • reco.jpg
  • password-security.jpg

Newsletter signup

Join today to get site updates in your inbox. Opt-out anytime. No advertisement or email list up for sale.

Please wait...

Thank you for sign up!

Copyright 2026 — Xloggs AI Security and News. All rights reserved. Blogsy WordPress Theme