Infosec bits for 2026 week 38
Zoya Vilakazi
| Sept. 18, 2026, 2:22 p.m.
Cybersecurity News:
CISA Urges Critical Infrastructure to Plant Decoys Inside Networks [Alessandro Mascellino, Infosecurity Magazine]
Abandoned IoT apps keep sending sensitive data to broken servers [Sinisa Markovic, Help Net Security]
Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? [Associated Press, Security Week]
Core introduces new AI-powered Microsoft Surface devices in SA [The Core Computer Business, IT Web]
Vulnerabilities & Patches:
Maximum Severity GitLab Flaw Puts Supply Chains at Risk [Rob Wright, Dark Reading]
Cisco patches max-severity ISE flaw, the second critical zero-day this week [Lucian Constantin, CSO Online]
Google Pixel owners urged to patch actively exploited modem flaw [Pieter Arntz, Malwarebytes]
Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases [Ionut Arghire, Security Week]
Brevo supply-chain attack injected ClickFix scripts on customer sites [Bill Toulas, Bleeping Computer]
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root [Swati Khandelwal, The Hacker News]
Attacks & Threats:
RatHat Turns Android Accessibility Into an Attack Weapon [Pierluigi Paganini, Security Affairs]
Zero-click RCE vulnerability hit four major AI coding agents, two remain unpatched [Sinisa Markovic, Help Net Security]
MikroTrick Attack Lets Hackers Gain Full Admin Control of MikroTik Routers Without Login [Tushar Subhra Dutta, Cyber Security News]
AI-Powered Malware Rewrites Itself Every Hour to Evade Signature-Based Detection [Tushar Subhra Dutta, Cyber Security News]