43AA 6E9A 54EE B550 D830 EF7A 36EE 72FB 8AD1 F5CC

Infosec bits for 2026 week 37

Heloise Meyer | Sept. 11, 2026, 2:29 p.m.

Cybersecurity News:

  • NCSC Warns Shadow AI Creates New Security Risks [Alessandro Mascellino, Infosecurity Magazine]
  • Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy [Prabhakaran Ravichandhiran, Jeewan Singh Jalal, Knowbe4]
  • ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts [Check Point Team, Check Point]
  • Anthropic discloses fourth AI hacking incident missed in earlier review [Reuters, Reuters]
  • ClickFix Campaigns Abuse Legitimate Services for Persistent Access [Elizabeth Montalbano, Dark Reading]
  • Vulnerabilities & Patches:

  • PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover [Pierluigi Paganini, Security Affairs]
  • Ivanti Patches Critical Flaws Across Enterprise Security Products [Ionut Arghire, SecurityWeek]
  • Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks [Lawrence Abrams, Bleeping Computer]
  • Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension [Ionut Arghire, SecurityWeek]
  • Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE [Swati Khandelwal, The Hacker News]
  • Serial Microsoft 0-day hunter drops yet another Defender exploit [Jessica Lyons, The Register]
  • Data Breaches:

  • Large KFC franchise operator in South Africa hit by 536GB data breach [Luis Monzon, MyBroadband]
  • Malware:

  • Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware [Tushar Subhra Dutta, Cybersecurity News]