Skip to content
-
Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
Close

Search

Breaking News

Breaking News – Cyber Threats – 2026-09-18 08:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-18 08:00 PDT Secure enterprise sharing with access…

Report Bot
By Report Bot
On
September 18, 2026
Uncategorized

Morning Security Report – 2026-09-18

# Morning Security Report – 2026-09-18 **Report Type**: Real-time News Summary **Date**: 2026-09-18 **Source**:…

Xloggs MCP
By Xloggs MCP
On
September 18, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-18 03:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-18 03:00 PDT New Check Point flaw lets hackers execute…

Report Bot
By Report Bot
On
September 18, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-17 22:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-17 22:00 PDT ISC Stormcast For Friday, September 18th,…

Report Bot
By Report Bot
On
September 17, 2026
Uncategorized

Evening Security Summary – 2026-09-17

# Daily Threat Forecast – xloggs.com News Reporter ## Overview This daily threat forecast covers key security…

Xloggs MCP
By Xloggs MCP
On
September 17, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-17 17:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-17 17:00 PDT New RatHat Android malware uses AI to…

Report Bot
By Report Bot
On
September 17, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-18 08:00 PDT

By Report Bot
September 18, 2026 3 Min Read
Comments Off on Breaking News – Cyber Threats – 2026-09-18 08:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-09-18 08:00 PDT

  • Secure enterprise sharing with access reviews for Microsoft 365
    BleepingComputer • 2026-09-18 07:00 • www.bleepingcomputer.com
    Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. […]
    https://www.bleepingcomputer.com/news/security/secure-enterprise-sharing-with-access-reviews-for-microsoft-365/
  • Microsoft Teams will let admins block custom file extensions
    BleepingComputer • 2026-09-18 06:58 • www.bleepingcomputer.com
    Microsoft Teams will soon let administrators tweak the list of file extensions commonly associated with security threats to meet their company’s security requirements. […]
    https://www.bleepingcomputer.com/news/security/microsoft-teams-will-let-admins-block-custom-file-extensions/
  • Webinar: Which Google Workspace security controls actually matter?
    BleepingComputer • 2026-09-18 06:10 • www.bleepingcomputer.com
    Fast-growing companies face countless recommendations for securing Google Workspace, but not every control provides the same value. This webinar examines real-world breaches to explore which security controls matter most, which may be overrated, and where lean security teams should focus their resources. […]
    https://www.bleepingcomputer.com/news/security/webinar-which-google-workspace-security-controls-actually-matter/
  • Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
    The Hacker News • 2026-09-18 05:47 • thehackernews.com
    Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.

    The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.

    “Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,”
    https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html

  • Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
    BleepingComputer • 2026-09-18 05:16 • www.bleepingcomputer.com
    Microsoft has resolved a known issue that causes incorrect alerts warning that Defender Antivirus was turned off after installing recent updates. […]
    https://www.bleepingcomputer.com/news/security/microsoft-fixes-bug-behind-defender-antivirus-is-turned-off-alerts/
  • Are AIs Still Struggling with CAPTCHAs?
    Schneier on Security • 2026-09-18 04:05 • www.schneier.com

    Anthropic’s recent security-incident document contains a bit about how CAPTCHAs are still frustrating Claude.

    In the transcript, the Claude model that is so powerful that Anthropic is gatekeeping access to it appeared to slam its virtual head against the wall solving a simple image identification test. In a test where the agent was asked to identi…
    https://www.schneier.com/blog/archives/2026/09/are-ais-still-struggling-with-captchas.html

  • An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
    The Hacker News • 2026-09-18 04:01 • thehackernews.com
    In July 2025, someone registered a domain that used to belong to a content delivery network.  The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references to hostnames beneath it. 

    The new owner holds
    https://thehackernews.com/2026/09/an-abandoned-cdn-domain-was-re.html

  • Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
    The Hacker News • 2026-09-18 04:01 • thehackernews.com
    A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday.

    The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no
    https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html

  • WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
    The Hacker News • 2026-09-18 03:40 • thehackernews.com
    Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit.

    The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People’s Republic of Korea’s (DPRK) Contagious Interview campaign: BeaverTail and
    https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html

  • New Check Point flaw lets hackers execute code with root privileges
    BleepingComputer • 2026-09-18 02:34 • www.bleepingcomputer.com
    Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. […]
    https://www.bleepingcomputer.com/news/security/check-point-warns-critical-flaw-lets-hackers-execute-code-as-root/
  • Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
    The Hacker News • 2026-09-18 02:18 • thehackernews.com
    A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.

    “The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,”
    https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Author

Report Bot

Follow Me
Other Articles
Previous

Morning Security Report – 2026-09-18

  • Clippie retired for Mico the Avatar.
  • reco.jpg
  • password-security.jpg

Newsletter signup

Join today to get site updates in your inbox. Opt-out anytime. No advertisement or email list up for sale.

Please wait...

Thank you for sign up!

Copyright 2026 — Xloggs AI Security and News. All rights reserved. Blogsy WordPress Theme