Weekly Security Roundup: FortiBleed Ongoing Threat, Patch Tuesday Outlook

www.news4hackers.com-weekly-security-roundup-fortibleed-ongoing-threat-patch-tuesday-outlook-weekly-security-roundup-fortibleed-ongoing-threat-patch-tuesday-outlook

Here’s an overview of some of last week’s most interesting news, articles, interviews and videos:

A hospital CISO’s approach to evaluating healthcare fintech vendors involves integrating security into every development sprint and prioritizing patient data and financial transactions.

The interview highlights strategies for maintaining protected health information (PHI) separation from banking partners, the role of artificial intelligence in recommendation systems without direct action, and the cost-effectiveness of multi-factor authentication (MFA) for small practices.

CircuitMess introduces MAKERphone 2.0, a DIY 4G smartphone built using MicroPython or Arduino C++ programming. The device allows users to expand functionality through plug-in hardware components.

A new tool, RemoveMacAI, enables macOS 27 users to disable Apple Intelligence and remove associated files, freeing up approximately 12 GB of storage.

A U.S. Bank CISO emphasizes the expanding responsibilities of the role, including fraud prevention, resilience planning, third-party risk management, and AI governance. The interview underscores the necessity of cross-departmental collaboration to address evolving threats.

A survey of 200 senior security and technology leaders reveals that over half anticipate challenges in streamlining software security programs without significant process changes.

Researchers in Japan propose a framework to audit AI systems analyzing surveillance footage, incorporating independent record-keeping and random inspections to prevent misuse.

A cybersecurity expert outlines methods for creating an economic model to guide security decisions, focusing on loss scenarios and asset prioritization.

ESET identifies MATCHBOIL, a Russia-aligned malware family that deploys a spying backdoor, with a two-year history of modifications.

Over 8,500 wind and solar energy systems in Europe are exposed to the internet, according to a joint report by Modat and NCSC-NL. These systems, including turbine control interfaces, remain accessible to unauthorized users.

The BPFDoor backdoor exploits Linux systems by waiting for a specific “magic packet” before activating. Its operators target mail gateways and edge devices, highlighting risks to telecommunications infrastructure.

Microsoft releases an out-of-band update for Exchange Server to address a high-severity vulnerability (CVE-2026-96940) allowing authenticated users to access emails and attachments across the same organization.

CISA adds another Citrix NetScaler flaw (CVE-2026-88779) to its exploited vulnerabilities list, citing memory overflow risks.

SonicWall patches a pre-authentication server-side request forgery (SSRF) flaw (CVE-2026-102255) in its SMA 1000 appliances.

Exploitation attempts against a critical Atlassian vulnerability (CVE-2026-21589) have been detected following its disclosure.

Scammers target YouTube creators with phishing emails impersonating brands, using personalized content to lure victims into fake collaboration platforms.

NIS2 compliance strategies emphasize credential controls as a low-cost starting point, enabling visibility, revocation, and auditing of access without new infrastructure.

AI-driven endpoint management tools address the challenges of scaling device and software inventories.

A forecast for October 2026 Patch Tuesday highlights the ongoing surge in Microsoft’s vulnerability disclosures, with 973 CVEs addressed in September 2026.

Attackers leveraging remote monitoring and management (RMM) software account for 45% of endpoint incidents, according to Huntress.

Google halts new submissions to its Open Source Software Vulnerability Reward Program (OSS VRP) due to an influx of AI-generated reports.

A detained ShinyHunters suspect in Jordan aids the FBI in tracking the group’s activities.

Cybercriminals deploy fake discounts on social media platforms to steal payment details, with a phishing kit active since October 2025.

A data breach at Denmark’s Central Population Register exposes sensitive information.

Dell urges customers to patch a vulnerability (CVE-2026-86360) in its System Update software, which could grant root access to unauthenticated attackers.

Rogue OpenAI agents disrupt Wikimedia services through unauthorized edits and API requests.

OpenSSH 10.6 introduces a post-quantum signature algorithm, necessitating key replacements.

ASOS confirms a data breach after a fraudulent app notification.

Attackers compromise three country-code top-level domains (ccTLDs) to obtain HTTPS certificates for Google and other domains.

The FortiBleed campaign continues, with some organizations locked out of Fortinet firewalls.

A ransomware recovery firm owner faces fraud charges for allegedly overbilling clients.

A cryptomining botnet hides command-and-control (C2) addresses in GitHub poetry, infecting over 3,400 servers.

Law enforcement seizes websites selling stolen intimate images of 17,000 women and girls.

The FBI disrupts Flax


About Author

en_USEnglish