Infosec bits for 2026 week 37
Heloise Meyer
| Sept. 11, 2026, 2:29 p.m.
Cybersecurity News:
NCSC Warns Shadow AI Creates New Security Risks [Alessandro Mascellino, Infosecurity Magazine]
Bypassing the Gatekeepers: How a Global Phishing Campaign Turns Google's Infrastructure into a Trust Proxy [Prabhakaran Ravichandhiran, Jeewan Singh Jalal, Knowbe4]
ChatGPT Let Attackers Read Victims’ Gmail Through a Hidden Channel Between Accounts [Check Point Team, Check Point]
Anthropic discloses fourth AI hacking incident missed in earlier review [Reuters, Reuters]
ClickFix Campaigns Abuse Legitimate Services for Persistent Access [Elizabeth Montalbano, Dark Reading]
Vulnerabilities & Patches:
PostgreSQL Hit by 12-Year-Old Vulnerability Allowing Server Takeover [Pierluigi Paganini, Security Affairs]
Ivanti Patches Critical Flaws Across Enterprise Security Products [Ionut Arghire, SecurityWeek]
Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks [Lawrence Abrams, Bleeping Computer]
Fortinet Patches Critical Vulnerabilities in FortiMonitorOnSight, Chrome Extension [Ionut Arghire, SecurityWeek]
Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE [Swati Khandelwal, The Hacker News]
Serial Microsoft 0-day hunter drops yet another Defender exploit [Jessica Lyons, The Register]
Data Breaches:
Large KFC franchise operator in South Africa hit by 536GB data breach [Luis Monzon, MyBroadband]
Malware:
Hackers Use Fake GTA 6 Downloads to Deploy RATs, Infostealers and Data-Wiping Malware [Tushar Subhra Dutta, Cybersecurity News]