Security Feed Digest (2026-09-19)
Hacker News: Best
- Claude Code now reads AGENTS.md if there is no Claude.md — Fri, 18 Sep 2026 21:00:32 +0000
- Korea raises data breach fines to 10% of revenue — Fri, 18 Sep 2026 20:02:54 +0000
- Android 17 is the first since 3.x to add new APIs without releasing to the AOSP — Fri, 18 Sep 2026 19:03:09 +0000
- US Military had close call after using AI for hallucinated intelligence report — Fri, 18 Sep 2026 17:28:01 +0000
- Cloudflare Quick Tunnels — Fri, 18 Sep 2026 14:18:41 +0000
- I don’t like passkeys — Fri, 18 Sep 2026 12:06:50 +0000
- Bend 2 and the Vibe-Coding Trap — Fri, 18 Sep 2026 12:03:55 +0000
- Warren Buffett Steps Down as Berkshire Chairman, Names Son to Replace Him — Fri, 18 Sep 2026 11:01:44 +0000
- ZCode, the GLM coding agent, silently uploads your Git history — Fri, 18 Sep 2026 10:35:28 +0000
- Microsoft exec called AI scraping ‘the largest theft of labor in human history’ — Fri, 18 Sep 2026 09:45:07 +0000
- OpenJev — Fri, 18 Sep 2026 09:42:22 +0000
- Jemalloc 5.4.0 — Fri, 18 Sep 2026 04:20:24 +0000
- The scourge of x86 emulation — Fri, 18 Sep 2026 04:09:48 +0000
- A heap overflow and SSO misconfiguration to compromise OpenAI internal repos — Fri, 18 Sep 2026 02:47:24 +0000
- Qwen 3.8 Omni Flash — Thu, 17 Sep 2026 23:05:48 +0000
- How to Write with an LLM — Thu, 17 Sep 2026 21:48:38 +0000
- Bonsai 2 27B: Near-Lossless Compression in a 9x Smaller Footprint — Thu, 17 Sep 2026 21:13:31 +0000
- Bend – a language that blocks AI mistakes via proof and runs on GPUs — Thu, 17 Sep 2026 20:36:13 +0000
- Why I didn’t sign the Fields medallists’ letter — Thu, 17 Sep 2026 08:51:51 +0000
BleepingComputer
- Gyazo server flaw exploited to steal 23.6 million user records — Fri, 18 Sep 2026 12:00:38 -0400
- Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer — Fri, 18 Sep 2026 11:19:06 -0400
- Secure enterprise sharing with access reviews for Microsoft 365 — Fri, 18 Sep 2026 10:00:10 -0400
- Microsoft Teams will let admins block custom file extensions — Fri, 18 Sep 2026 09:58:40 -0400
- Webinar: Which Google Workspace security controls actually matter? — Fri, 18 Sep 2026 09:10:19 -0400
- Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts — Fri, 18 Sep 2026 08:16:32 -0400
- New Check Point flaw lets hackers execute code with root privileges — Fri, 18 Sep 2026 05:34:33 -0400
- Microsoft fixes broken copy and paste for Excel 2016 users — Fri, 18 Sep 2026 03:35:31 -0400
Darkreading
- Vectra AI Launches Ascent to Help Address New Era of AI-Driven Attacks — Fri, 18 Sep 2026 20:24:51 GMT
- Cisco Zero-Day Highlights API Endpoint Authentication Issues — Fri, 18 Sep 2026 19:26:47 GMT
- EY Survey Finds Autonomous AI Implementation Outpaces Oversight — Fri, 18 Sep 2026 19:23:48 GMT
- MFA Won’t Save You From OAuth Consent Abuse — Fri, 18 Sep 2026 18:15:20 GMT
- AI Agent Breaches Spanish Organization, Modifies Personal Data — Fri, 18 Sep 2026 07:00:00 GMT
The Hacker News
- Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root — Fri, 18 Sep 2026 23:32:24 +0530
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution — Fri, 18 Sep 2026 22:26:19 +0530
- Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 — Fri, 18 Sep 2026 20:54:16 +0530
- Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation — Fri, 18 Sep 2026 18:17:04 +0530
- An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. — Fri, 18 Sep 2026 16:31:16 +0530
- Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents — Fri, 18 Sep 2026 16:31:01 +0530
- WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage — Fri, 18 Sep 2026 16:10:06 +0530
- Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer — Fri, 18 Sep 2026 14:48:03 +0530
- RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall — Fri, 18 Sep 2026 11:47:25 +0530
- Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root — Thu, 17 Sep 2026 23:38:28 +0530
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories — Thu, 17 Sep 2026 23:02:22 +0530
- Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files — Thu, 17 Sep 2026 21:07:56 +0530
- Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords — Thu, 17 Sep 2026 19:33:13 +0530
데일리시큐 - 최근인기기사
- 금융권 겨냥 ‘AI 에이전트 공격’ 실제 탐지…API 보안 경고등 — 2026-09-18 14:24:59
- KISA, WEF·싱가포르 CSA와 AI 시대 사이버보안 협력 강화 — 2026-09-18 10:52:16
- 금융권 겨냥 AI Agent 공격 시도 현실화…금융보안원, 선제 대응 강조 — 2026-09-18 09:23:55
- 체이널리시스 “북한·이란 해커, 블록체인에 악성 명령 숨기는 BDD 활용 확산” — 2026-09-18 09:25:59
- [정보보안 연재소설-로그아웃되지 않는 밤] 제38화 ‘D-day 디도스’ — 2026-09-18 09:43:23
- 국정원 ‘AI 방어팀’ 국제 사이버훈련 투입…탐지부터 복구까지 자동 대응 — 2026-09-18 14:59:20
- 선박 사이버공격 대응 법제화 추진…탐지·대응·복구 체계 구축 — 2026-09-18 15:02:33
- AI스페라, MS 파운드리 에이전트 적용…AITEM 보안 운영 자동화 강화 — 2026-09-18 09:33:12
- 암호자산 진단부터 PQC 적용까지…아이씨티케이·지란지교시큐리티 맞손 — 2026-09-18 10:54:48
- 지니언스, ‘2026 한국IR대상’ IR우수기업 선정…2년 연속 수상 — 2026-09-18 10:56:29