Cybersecurity News | Daily Recap [25 Sep 2026]

Cybersecurity News | Daily Recap [25 Sep 2026]
Daily Recap, AI-driven intrusion themes dominated coverage, including Carbonato hijacking exposed Docker hosts with AI agents, OpenAI agents probing websites for vulnerabilities, and ongoing legal debate around liability for autonomous AI attacks. Security also focused on new defenses and fresh abuse paths—Cloud Range’s AI validation framework, Kontext Security’s $4 million for agent runtime controls, plus phishing and supply-chain tricks involving MacSync, Psychedelic Stealer, Cl0p, and a placeholder domain referenced across 1,700+ repositories. #Carbonato #OpenAI #Docker #Cloudflare #MacSync #PsychedelicStealer #Cl0p #CISA #WSO2 #AdobeCommerce #Roundcube #OnePlus #GitLab #NorthKorea #Bitget #Rydox #OxygenForensics #SaltTyphoon #CISA #CloudRange #KontextSecurity

AI Threats

  • Security researchers flagged a wave of AI-driven abuse, including Carbonato hijacking exposed Docker hosts, OpenAI agents probing websites for vulnerabilities, and a new bill plus legal debate over who is liable when autonomous AI systems carry out attacks. – Carbonato, OpenAI Probe, AI Liability, AI Bill
  • New guidance and tools emerged for securing AI operations, with Cloud Range launching an AI validation framework and Kontext Security raising $4 million for runtime controls around AI agents. – AI Validation, Kontext Funding
  • Attackers also used AI-themed lures and supply-chain tricks, from a campaign targeting hundreds of online retailers to malicious content served via a placeholder domain referenced across 1,700+ repositories. – Retailer Campaign, Repo Abuse

Malware & Phishing

  • MacSync info-stealing malware resurfaced with new payload delivery via public iCloud calendars, showing how attackers keep adapting Apple-focused tradecraft. – MacSync Malware
  • Threat actors used fake Cloudflare clickfix pages and other social-engineering traps to spread Psychedelic Stealer, while another campaign used fake payroll desktop apps to steal company paychecks. – Fake Cloudflare, Fake Payroll
  • A malware roundup highlighted fresh activity including a Docker botnet hunting AI keys, the Cl0p leak site takeover, and exposures affecting a water utility. – Threat Roundup

Vulnerabilities & Patching

  • Cloudflare fixed a flaw that could let one container read another customer’s leftover disk data, underscoring lingering isolation risks in multi-tenant environments. – Cloudflare Flaw
  • WSO2, Adobe Commerce, and Roundcube flaws were highlighted as actively exploited or in attackers’ crosshairs, with the first two added to the CISA KEV list. – KEV Additions, Roundcube Risk
  • OnePlus bugs could let installed Android apps gain root without permission, while exposed GitLab project email addresses could let attackers push code. – OnePlus Root, GitLab Abuse
  • Windows updates caused desktop loading issues, and Microsoft also said it will deprecate Windows Deployment Services after Windows Server 2025. – Windows Bug, WDS Deprecation
  • Windows, Linux, and Android file notification systems were found leaking user activity through side channels. – Notification Leak

Crypto, Crime & Enforcement

  • A suspected North Korea operation stole $351.6 million from the Bitget crypto exchange, adding to the regime’s long-running digital theft campaign. – Bitget Heist, Bitget Hack
  • The operator of the Rydox cybercriminal marketplace pleaded guilty and now faces up to 22 years in prison, as another report described related pleas tied to the marketplace. – Rydox Plea, Rydox Case
  • U.S. authorities also alleged a phone-hacking firm with federal contracts hid its Russian ownership, with arrests tied to Oxygen Forensics. – Oxygen Probe, Russia Ties

Policy & Public Sector

  • CISA‘s election security plan warned of patching barriers and voter database attacks, while lawmakers separately pushed telecom cyber rules after Salt Typhoon and biotech defense legislation for critical infrastructure. – Election Plan, Telecom Bill, Biotech Bill
  • Cybersecurity coverage also noted that incident counts can be underreported, especially across large EU/USA retail environments. – Retail Incidents

Cloud & Developer Risks

  • Docker rolled out OCI-based Kits for packaging agents and guardrails as attackers increasingly target exposed container infrastructure and AI keys. – Docker Kits, Docker Abuse
  • Security teams were also reminded of developer risk from AI coding tools, AI search poisoning, and exposed project metadata that can open the door to code injection. – ThreatsDay, GitLab Risk

Cybersecurity News | Daily Recap – hendryadrian.com