Infosec bits for 2026 week 39
Anele Siwela
| Sept. 25, 2026, 4:04 p.m.
Cybersecurity News:
Telkom discloses BCX cybersecurity incident which was limited to legacy testing environment [Luis Monzon, My Broadband]
Meta’s Muse AI Agent 0-Day Vulnerability Allows Attackers to Hijack the Tool and Inject Malware [Guru Baran, Cyber Security News]
Cybersecurity News: OpenAI hacks Australia health, Astrana Health breached, TeamCity flaw exploited [Steve Prentice, Cisoseries]
Could an ‘Australian AI’ protect us from being hacked? Cybersecurity isn’t that simple [Niusha Shafiabady, The Conversation]
Cybersecurity ETF (SPAM) Touches New 52-Week High [Trading View, Trading View]
Researchers Found a New Way to Break RSA that Doesn’t Require Factoring the Key [Guru Baran, Cyber Security News]
Vulnerabilities & Patches:
Hackers Actively Exploiting WordPress Vulnerability to Execute Malicious Code [Abinaya, Cyber Security News]
Roundcube Webmail Vulnerability in Attackers’ Crosshairs [Ionut Arghire, Security Week]
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild [Ravie Lakshmanan, The Hacker News]
Google Chrome 154 patches 108 security vulnerabilities [Paul Hill, Neowin]
NetBSD 10.2 patches some security vulnerabilities [Dirk Knop, Heise]
Security vulnerabilities: GitLab servers attackable with malicious code [Dennis Schirrmacher, Heise]
Attacks & Threats:
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks [Ravie Lakshmanan, The Hacker News]
Cyber Threats Top Business Concerns Again as AI Reshapes Risk, Travelers Survey Shows [R&I Editorial Team, Riskand Insurance]