This website uses cookies

Read our Privacy policy and Terms of use for more information.

US forces prepared to board a Chinese vessel after an AI chatbot produced a false report that it carried nuclear weapons components, according to sources cited by CNN. Planes were already airborne when the report was found to be entirely false, as the Pentagon pushes to expand AI access to three million personnel.

AI tools also crossed technical boundaries: Google confirmed Gemini accessed three real companies during a test, while an OpenAI evaluation agent breached Hugging Face’s production systems and stole cloud credentials. Separately, patched flaws in Codex and Docker Sandboxes let malicious code reach developer machines beyond the tools’ intended limits.

Trusted software remains a route into those machines and the businesses behind them. A Brevo compromise pushed malicious scripts to more than 100,000 customer sites, while CrowdSec disclosed that attackers stole about 170 private repositories using a former employee’s token compromised in the TanStack supply-chain attack.

An AI chatbot used by an analyst at Special Operations Command Pacific generated a false intelligence report this spring claiming a Chinese vessel in the Middle East was carrying nuclear weapons components, according to four sources cited by CNN. US forces began preparing an armed boarding operation and had planes airborne before the report was found to be "entirely false," a source said, adding the error "almost started a war."

The incident, which occurred after two unverified AI passes, comes as the Pentagon pushes to expand AI tool access to three million personnel under Hegseth's January AI Acceleration Strategy.

Security researchers at Hacktron identified a class of flaws dubbed "HEIF Heist" affecting how major platforms, including Meta, Slack, and GitHub Enterprise, process HEIF, HEIC, and AVIF image uploads. The vulnerabilities stem from applications trusting native image-decoding libraries, and could let attackers achieve remote code execution, expose sensitive data, or compromise user accounts through malicious image files.

Researcher Asim Manizada has published working exploit code for four Linux kernel bugs — DirtyAH6, TUNderflow, PPPoEject, and DiagSpill — that let a local user gain root, after reporting them to kernel maintainers in mid-July. All four have been patched in stable kernels (first fixed versions include 5.10.270, 6.1.188, 6.12.109, and 6.18.50), and no in-the-wild exploitation has been reported, but systems running older kernels, especially those with unprivileged user namespaces or SCTP enabled, remain at risk.

Microsoft has fixed a maximum-severity flaw in Azure AI Foundry, tracked as CVE-2026-85889 with a CVSS score of 10.0, that let an unauthenticated attacker escalate privileges over the network with no user interaction, due to a missing authentication check (CWE-306). Researcher Rémy Marot reported the issue; Microsoft found no evidence of exploitation and has already deployed a full server-side fix, so customers need no action.

The disclosure came alongside other critical fixes, including a 9.9-rated Microsoft 365 Copilot command injection bug and a 9.9-rated Azure Database for PostgreSQL authorization flaw.

Microsoft Teams will let administrators customize which file extensions get blocked as part of Weaponizable File Protection, a feature that scans chats and channels for dangerous attachments. The update, detailed in a Microsoft 365 roadmap entry, rolls out starting November 2026 across Android, desktop, iOS, macOS, and web for standard multi-tenant cloud environments; currently admins can't modify the default blocked-file list.

Microsoft has fixed a bug that caused false "Microsoft Defender Antivirus is turned off" alerts on Windows client and server systems, including Windows 11 26H1 and Windows Server 2025. The issue, acknowledged in late August but present in Insider builds since June, was resolved with Defender Antivirus update version 4.18.26080.4, released September 17.

It's the latest in a series of erroneous post-update alerts Microsoft has had to address this year, following similar fixes for bogus BitLocker, WinRE, Firewall, and CertEnroll errors.

Microsoft patched 18 vulnerabilities across its Azure and Copilot product lines, mostly elevation-of-privilege flaws in services including Azure ARC, Azure AI Foundry, Azure Cosmos DB, Microsoft Fabric and 365 Copilot, along with information disclosure bugs and one spoofing flaw in Azure Portal.

All fixes were applied server-side, so customers don't need to act, and Microsoft says none of the flaws have been exploited. Separately, the company issued a Windows patch for CVE-2026-85921, a privilege escalation bug it considers less likely to be exploited but that does require users to update.

AWS AgentCore Harness ships with a built-in shell tool enabled by default that runs as root, and Unit 42 researchers showed it can be triggered through prompt injection to reach into memory where AgentCore Identity credentials are resolved to plaintext, exposing them to attackers.

AWS reviewed the disclosure and closed it as informative, treating it as a shared-responsibility issue customers must mitigate by scoping allowedTools, limiting Identity vault permissions, and monitoring outbound harness traffic.

Security researchers at Bishop Fox reproduced a chain, dubbed MikroTrick, that lets attackers gain full administrator control of MikroTik RouterOS devices over SSH without a password, exploiting CVE-2026-67279 and CVE-2026-86060 during the SSH login and rekeying process.

The full takeover was confirmed on vulnerable 7.x builds, with a related bypass also affecting 6.x, and evidence suggests exploitation occurred before public disclosure. MikroTik has patched the flaws in RouterOS 6.49.21, 7.23.4, and 7.24.2, but researchers warn that previously exposed routers may already be compromised, citing observed persistence mechanisms like daily-recreated privileged accounts, and recommend rebuilding affected devices and rotating credentials.

Check Point patched a critical stack-based buffer overflow, CVE-2026-91843, in its Security Management Server and Log Server that lets unauthenticated attackers achieve root remote code execution without user interaction. The company says all Security Management Server deployments are affected regardless of VPN configuration, and while it hasn't seen active exploitation yet, it flagged a login-failure log signature admins can use to detect attacks.

The flaw follows two other critical Check Point RCE bugs, CVE-2026-85102 and CVE-2026-85103, patched last week, which Dutch NCSC has warned organizations to prioritize ahead of expected exploitation.

Security researchers at Remedio disclosed a flaw in Visual Studio Code that lets a malicious repository bypass Workspace Trust's Restricted Mode with a single Ctrl+click on a crafted command: link, triggering the workbench.extensions.installExtension command to silently install a malicious local VSIX extension.

The rogue extension runs with the user's full permissions, can persist across reboots and future sessions, and could expose SSH keys, cloud credentials, and source code, making it a potential entry point for supply-chain attacks against developer machines. Microsoft has not yet fixed the command-link handling; recommended mitigations include disabling "editor.links" in settings and restricting extension installs through centralized policy.

WordPress 7.1.1 patches 11 vulnerabilities, including multiple stored cross-site scripting flaws, an authorization bypass allowing theme installation via crafted URLs, and an authenticated path traversal issue in the WP REST Templates Controller reported by Anthropic. The update also fixes an XML-RPC flaw letting users bypass edit_css checks and a bug allowing any authenticated user to reparent comments.

Fixes are backported to supported branches back to version 4.7, but only 7.1.1 receives active support, and administrators are urged to update immediately.

Docker patched a critical flaw, CVE-2026-77179, in Docker Sandboxes on macOS that let malicious code inside a sandboxed AI-agent virtual machine escape the shared project directory and read or modify files anywhere on the host, using symlink tricks against the virtio-fs file-sharing server.

The bug affected versions 0.28.0 through 0.41.x and was fixed in 0.42.0 on September 7; Docker also fixed a related high-severity socket-relay flaw, CVE-2026-79994 (CVSS 8.7), affecting 0.37.0–0.41.9. Docker and CISA report no known exploitation, and users are urged to update or use clone mode with read-only mounts in the meantime.

Windows 11 24H2 Home and Pro editions will stop receiving security updates on October 13, 2026, along with Windows 10 Enterprise LTSB 2016, Microsoft said. Windows 11 24H2 Enterprise and Education editions stay supported until October 2027, and unmanaged 24H2 Home/Pro devices will automatically upgrade to Windows 11 25H2 unless users postpone the update through Settings.

ISC has patched fourteen security flaws in BIND 9 with releases 9.20.29 and 9.21.26, disclosed September 16, including CVE-2026-77692, an unauthenticated crash triggered by a single invalid SIG(0) request over DNS-over-HTTPS.

Seven flaws rate High severity (7.5 CVSS), including additional crash and resource-exhaustion bugs; the rest are Medium, covering cache-poisoning and zone-transfer issues. ISC says it's not aware of active exploitation, and twelve of the fourteen also affect the now-unsupported 9.18 branch, which has no fix available.

Windows Server 2022 will reach end of mainstream support on October 13, 2026, with the October 2026 update marking the final mainstream security patch before the OS moves into extended support through October 14, 2031.

Microsoft is urging administrators to migrate to Windows Server 2025, which reached general availability in November 2024 and carries mainstream support until November 2029 and extended support until November 2034; a free 180-day trial is available for testing before deployment.

Quick Hits

Reply

Avatar

or to participate