Skip to content
Security Affairs newsletter Round 595 by Pierluigi Paganini

Security Affairs newsletter Round 595 by Pierluigi Paganini

Securityaffairs September 20, 2026

Security Affairs Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

A new round of the weekly Security Affairs has arrived! Every week, the best security articles from Security Affairs are free in your email box.

Enjoy a new round of the weekly SecurityAffairs , including international press.

International Press –

Personal, Financial Info Exposed in Revolut Data Breach

CenterPoint Energy confirms intruder helped themselves to customer information

FBI Seizes DDoS-for-Hire Domains as Part of Continuing District of Alaska Crackdown on ‘Booter’ and ‘Stresser’ DDoS Services

Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People

23 Million User Records Compromised in Gyazo Data Breach

Gray Rabbits and the Tale of a One-Click Backdoor

Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service

Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows

Skill Poisioning turning AI agents into malware droppers – warns China’s National CERT

Critical vulnerabilities expected in Check Point VPN products with active exploitation: update now

The Ghost in the Chat: how a bot that isn’t in your group steals messages from Telegram HTML exports

Japan’s Digital Agency says VPN flaw exposed 246,000 personnel records

One Router, Three Vulnerabilities: Security Research on the TOTOLINK A720R

Coast Guard and FBI boarded 2 energy tankers due to cyberattacks. How big is the risk?

Nintendo warns of Switch code execution flaw via on-screen QR codes

Intelligence and Information Warfare

A warning ‘model welfare’

Investigații The Kremlin’s Digital Pirates: How Russian Tracking Pixels Harvest Romanians’ Data to Fund Conspiracies and Extremism

Skill Poisioning turning AI agents into malware droppers – warns China’s National CERT

Donald Trump rejects calls from tech bosses for an AI slowdown

China bristles at Anthropic CEO’s ‘fearmongering’ its AI development

Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit

Iranian cyber targeting of dissidents, activists and journalists

SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia

Amazon’s AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage

Beware the SparroWock: The backdoor that bites, the commands that catch

Meta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real Kids

Anthropic CEO Dario Amodei says AI industry needs to give safety measures time to catch up

We Must Pace the Frontier

First notification of a personal data breach caused by an attack executed using an AI agent

Gemini Hacked Three Companies in First Known Breakout by Google’s AI

Follow me on Twitter: @securityaffairs and and Mastodon

( SecurityAffairs – hacking, )

Extracted Entities