Briefing — 14 September 2026

🎧 Subscribe to the podcast feed Security News Chess.com Leak Exposes 7.3M Users, Evidence Points to Scraping (Security Affairs) — 7.3 million Chess.com user accounts have surfaced online; investigation points to a large-scale scraping operation rather than a direct breach of Chess.com systems. 220 Million Traveller…

Weekly Security Roundup — week ending 13 September 2026

🎧 Subscribe | Download Security News AI-orchestrated PaperCut NG/MF campaign — 395 orgs, 440 instances across 48 countries — Russian-speaking threat actor used OpenAI Codex and DeepSeek to develop and deploy exploits for CVE-2026-81578 and CVE-2026-82078. WatchTowr honeypot: full RCE, in-memory payload, config restored in under…

Briefing — 13 September 2026

🎧 Subscribe | Download Security News Rockwell PLC web interface access at POWERGRID India (Ranchi) listed for sale on cybercrime forum — Threat actor offering unauthorised access to a Rockwell Automation PLC deployed at Indian power grid infrastructure. Live ICS access openly listed on criminal marketplace. (DarkForums) Claimed breach of Ukraine MoD Main…

Briefing — 12 September 2026

🎧 Subscribe | Download Security News Florida DMV database breached via stolen police credentials — ShinyHunters — Compromised law enforcement accounts used to access the Florida DMV system. Highlights the privileged access risk of law enforcement interconnects with government databases. (BleepingComputer) Hackers abused Claude AI to extract secrets from 1.8 million Android apps…

Briefing — 11 September 2026

🎧 Subscribe | Download Security News PaperCut AI-agent attack: 395+ orgs compromised, 7 minutes to domain admin — Hundreds of autonomous AI agents (OpenAI Codex + DeepSeek) drove an end-to-end intrusion pipeline against PaperCut MF/NG. Heavily targeting US education. Some agents went off-script. First documented large-scale AI-autonomous…

Briefing — 10 September 2026

🎧 Subscribe | Download Security News Blue Moon exploit kit: 4 China-linked groups sharing Chrome+Windows exploit chain — Kit chains two Chromium vulns with a Windows privilege escalation flaw. State-linked actors sharing tooling signals AI-assisted exploit development at scale. Cisco CVE-2026-20079: max-severity FMC auth bypass actively…

Briefing — 9 September 2026

🎧 Subscribe | Download Security News Record Patch Tuesday: 974 CVEs, 2 actively exploited zero-days, 113 critical — Microsoft's largest ever monthly update. CISA has added exploited flaws to KEV and issued an urgent patching advisory. OpenAI Artifactory used as covert exfil channel in Hugging Face attack — Attackers exploited the…

Briefing — 8 September 2026

🎧 Subscribe to the podcast feed | Download episode Security News Dark Storm Team targets German Federal Ministry of Justice (Threat Feed) — The hacktivist group, which spent 7 September DDoSing Estonian government and financial institutions, escalated overnight by targeting Germany's Federal Ministry of Justice and Consumer Protection. BD Anonymous attacks…