Security Feed Digest (2026-09-25)
Hacker News: Best
- F-Droid 2.0 — Thu, 24 Sep 2026 15:26:12 +0000
- Owners mourn spoiled food after firmware update bricks Samsung smart fridges — Thu, 24 Sep 2026 12:58:08 +0000
- Two-tier encryption in the UK — Thu, 24 Sep 2026 10:39:19 +0000
- Meta takes down a critical video about meta AI Glasses after filming at Meta — Thu, 24 Sep 2026 08:23:03 +0000
- Ideas on modernizing the open-source desktop — Thu, 24 Sep 2026 02:52:09 +0000
- OpenAI agent hacked Australian government website, PM says — Thu, 24 Sep 2026 02:44:48 +0000
- Feds Target AI Critics as “Foreign Agents” — Thu, 24 Sep 2026 00:41:31 +0000
- Meta VR Glasses — Wed, 23 Sep 2026 23:47:56 +0000
- Show HN: Make cursed fonts like Times New Bastard — Wed, 23 Sep 2026 22:53:28 +0000
- ArXiv receives multiyear commitments to support it as an independent nonprofit — Wed, 23 Sep 2026 22:45:49 +0000
- Linux support is coming to Snapdragon X2 series — Wed, 23 Sep 2026 22:38:16 +0000
- OpenAI breaches Medicare, Albanese reveals — Wed, 23 Sep 2026 21:01:48 +0000
- VSCode’s SSH Agent Is Bananas (2025) — Wed, 23 Sep 2026 21:01:48 +0000
- 28% of job postings on company career sites have been open over 90 days — Wed, 23 Sep 2026 16:35:34 +0000
- Gemini 3.8 text-to-speech — Wed, 23 Sep 2026 15:29:23 +0000
- Why is Hacker News like that? — Wed, 23 Sep 2026 15:05:20 +0000
- Tokens too cheap to meter — Wed, 23 Sep 2026 09:21:17 +0000
- I am done with this shit — Wed, 23 Sep 2026 07:59:14 +0000
BleepingComputer
- MacSync malware uses public iCloud calendars to deliver new payloads — Thu, 24 Sep 2026 16:53:35 -0400
- New Carbonato malware uses AI agents to hijack exposed Docker hosts — Thu, 24 Sep 2026 16:10:48 -0400
- Exposed GitLab project email addresses let attackers push code — Thu, 24 Sep 2026 13:47:44 -0400
- FedRAMP VDR & VER: Daily Scans Are Only the Beginning — Thu, 24 Sep 2026 10:02:12 -0400
- Hackers now exploit critical Roundcube flaw in code injection attacks — Thu, 24 Sep 2026 09:27:57 -0400
- Windows 11 KB5124010 update released with 46 changes and fixes — Thu, 24 Sep 2026 08:16:32 -0400
- CISA: Ransomware gangs now exploiting critical TeamCity flaw — Thu, 24 Sep 2026 06:42:37 -0400
- OpenAI hacked Australian Medicare govt site, probed data providers — Thu, 24 Sep 2026 05:38:53 -0400
- Microsoft fixes bug that broke Windows File History backup feature — Thu, 24 Sep 2026 04:14:47 -0400
Darkreading
- ‘Salesbleed’ Exploits Salesforce Agents to Enable Slack Phishing — Thu, 24 Sep 2026 21:04:03 GMT
- SectopRAT Returns, Hiding Inside a Legitimate Application — Thu, 24 Sep 2026 20:32:50 GMT
- 3 Cyber Threats That Defined the Summer of 2026 — Thu, 24 Sep 2026 14:44:12 GMT
- How to Build A SASE Framework for Modern Cybersecurity — Thu, 24 Sep 2026 14:02:43 GMT
- Ghost Service Accounts Enable M365 Data Theft in Chile — Thu, 24 Sep 2026 13:30:00 GMT
- Prompt-Injection Bug Hits $4B Agentic AI App ‘Manus’ — Thu, 24 Sep 2026 13:00:00 GMT
- SASE Converges Network & Security Into One Cloud Solution — Wed, 23 Sep 2026 22:29:10 GMT
The Hacker News
- Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions — Thu, 24 Sep 2026 23:40:18 +0530
- ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories — Thu, 24 Sep 2026 23:22:43 +0530
- Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content — Thu, 24 Sep 2026 20:57:32 +0530
- Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer — Thu, 24 Sep 2026 19:59:06 +0530
- Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls — Thu, 24 Sep 2026 17:35:27 +0530
- Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore — Thu, 24 Sep 2026 16:30:00 +0530
- 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360 — Thu, 24 Sep 2026 14:44:21 +0530
- OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files — Thu, 24 Sep 2026 12:37:25 +0530
- TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords — Thu, 24 Sep 2026 12:02:03 +0530
- Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure — Thu, 24 Sep 2026 11:06:18 +0530