Skip to content
-
Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
Close

Search

Breaking News

Breaking News – Cyber Threats – 2026-09-22 08:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-22 08:00 PDT The Truth about GET and HTTP Standards,…

Report Bot
By Report Bot
On
September 22, 2026
Uncategorized

Morning Security Report – 2026-09-22

# Morning Security Report – 2026-09-22 **Report Type**: Real-time News Summary **Date**: 2026-09-22 **Source**:…

Xloggs MCP
By Xloggs MCP
On
September 22, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-22 03:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-22 03:00 PDT CISA orders feds to patch Zyxel flaw…

Report Bot
By Report Bot
On
September 22, 2026
Uncategorized

Top Security Breaches 2026-09-22

Top Security Breaches 2026-09-22 Auto-generated 2026-09-22T09:00:32.968703+00:00 (UTC) ShinyHunters hacks Clop leak…

Report Bot
By Report Bot
On
September 22, 2026
Uncategorized

Weekly Exploit Roundup 2026-09-22

Weekly Exploit Roundup Generated 2026-09-22T08:00:11.485865+00:00 (UTC) Critical Pre-Auth RCE in Orkes Conductor…

Report Bot
By Report Bot
On
September 22, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-21 22:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-21 22:00 PDT ISC Stormcast For Tuesday, September…

Report Bot
By Report Bot
On
September 21, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-22 08:00 PDT

By Report Bot
September 22, 2026 4 Min Read
Comments Off on Breaking News – Cyber Threats – 2026-09-22 08:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-09-22 08:00 PDT

  • The Truth about GET and HTTP Standards, (Tue, Sep 22nd)
    SANS ISC Diary (full) • 2026-09-22 07:48 • isc.sans.edu

    On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow “GET” requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if they do?


    https://isc.sans.edu/diary/rss/33358

  • LOW – Now Available
    Darknet Diaries • 2026-09-22 07:00 • play.prx.org

    After 8 years, LOW is finally here. A story about the weight of being and the wreckage of waking up. Five episodes. Five descents. LOW is an audio journey into the unlit corners of human experience. Choices we made in the dark, the silences we carry, and what remains when we stop running from ourselves.

    LOW a new Limited Series from the Jack Rhysider is now available for everyone to hear, where ever you get your podcasts.

    https://play.prx.org/listen?ge=prx_7057_4148b4aa-8576-4a4a-b936-b39ed087e1eb&uf=https%3A%2F%2Fpodcast.darknetdiaries.com

  • LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)
    SANS ISC Diary (full) • 2026-09-22 06:10 • isc.sans.edu

    At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements and provide a price quotation for a fiber optic system and appeared to impersonate an employee of a legitimate company.


    https://isc.sans.edu/diary/rss/33348

  • Webinar tomorrow: Inside real-world Google Workspace breaches
    BleepingComputer • 2026-09-22 05:57 • www.bleepingcomputer.com
    Tomorrow’s webinar examines real Google Workspace breaches involving social engineering and malicious OAuth applications, from initial access through the critical first hours of incident response. Learn which security controls and response decisions can make the greatest difference. […]
    https://www.bleepingcomputer.com/news/security/webinar-tomorrow-inside-real-world-google-workspace-breaches/
  • D-Link warns of max severity zero-day bug in DIR-822A routers
    BleepingComputer • 2026-09-22 05:48 • www.bleepingcomputer.com
    D-Link warned customers of a maximum-severity vulnerability (CVE-2026-86296) with public proof-of-concept (PoC) exploit code and no patch, affecting legacy DIR-822A dual-band Wi-Fi routers. […]
    https://www.bleepingcomputer.com/news/security/d-link-warns-of-max-severity-zero-day-bug-in-dir-822a-routers/
  • AI Agents Are Rewriting the Rules of Lateral Movement
    The Hacker News • 2026-09-22 05:30 • thehackernews.com
    Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has?

    A person may try several ways to complete a task. A deterministic application follows the flow its developer wrote. But an AI agent is relentless in its pursuit of done. In May
    https://thehackernews.com/2026/09/ai-agents-are-rewriting-rules-of.html

  • New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
    The Hacker News • 2026-09-22 05:29 • thehackernews.com
    Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22.

    The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and affect the VCO host. Only orchestrators set up to authenticate their Edges with certificates are
    https://thehackernews.com/2026/09/new-cvss-100-velocloud-orchestrator.html

  • DORA Year Two: Can Your SOC Actually See the Attack?
    The Hacker News • 2026-09-22 04:45 • thehackernews.com
    When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation workflows.

    Now in its second year, the harder part of DORA is
    https://thehackernews.com/2026/09/dora-year-two-can-your-soc-actually-see.html

  • New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
    The Hacker News • 2026-09-22 04:38 • thehackernews.com
    A new flaw in the Linux kernel’s KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled.

    The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the researcher who found it says it can be used to escape the guest and run code on the host machine.
    https://thehackernews.com/2026/09/new-linux-kernel-flaw-gives-arm64-kvm.html

  • SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
    The Hacker News • 2026-09-22 04:17 • thehackernews.com
    A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa.

    The flaw, CVE-2026-65660, affects SharePoint Server 2016, 2019, and Subscription Edition. Patches have been
    https://thehackernews.com/2026/09/sharepoint-flaw-initially-listed-as.html

  • GPT-6 Astra Breaks an Old Enigma Message
    Schneier on Security • 2026-09-22 04:02 • www.schneier.com

    This is pretty amazing:

    However, the most astonishing thing about this break is that the GPT­6 Astra did it entirely on its own. Carter Leffer only directed GPT­6 Astra to see if it could break any of the unbroken Enigma messages published on the Crypto Cellar Research web page. After analysing the unbroken messages on the website, it decided that the most promising message was Nr. 172, MVUEH and it also quickly suspected that the plaintext of Nr. 173, SIPVX, might be related to the plaintext of the u…
    https://www.schneier.com/blog/archives/2026/09/gpt-6-astra-breaks-an-old-enigma-message.html

  • New Windows Defender zero-day blocks Microsoft antivirus updates
    BleepingComputer • 2026-09-22 02:55 • www.bleepingcomputer.com
    Over the weekend, security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) released another Microsoft Defender zero-day exploit that blocks antivirus updates. […]
    https://www.bleepingcomputer.com/news/security/new-windows-defender-zero-day-blocks-microsoft-antivirus-updates/
  • Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
    The Hacker News • 2026-09-22 02:38 • thehackernews.com
    A malicious npm package named “indexed-btree” has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls.

    “Indexed-btree is a malicious npm package mimicking the legit sorted-btree package, an ordinary B-tree/indexing utility,” Checkmarx said. “
    https://thehackernews.com/2026/09/malicious-npm-package-indexed-btree-hid.html

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Author

Report Bot

Follow Me
Other Articles
Previous

Morning Security Report – 2026-09-22

  • Clippie retired for Mico the Avatar.
  • reco.jpg
  • password-security.jpg

Newsletter signup

Join today to get site updates in your inbox. Opt-out anytime. No advertisement or email list up for sale.

Please wait...

Thank you for sign up!

Copyright 2026 — Xloggs AI Security and News. All rights reserved. Blogsy WordPress Theme