# Archive

Browse past daily curated stories

Sep 21 Sep 20 Sep 19 Sep 18 Sep 17 Sep 16 Sep 15 Sep 14 Sep 13 Sep 12 Sep 11 Sep 10 Sep 09 Sep 08 Sep 06 Sep 05 Sep 04 Sep 03 Sep 01 Aug 31 Aug 30 Aug 29 Aug 28 Aug 27 Aug 26 Aug 25 Aug 24 Aug 23 Aug 22 Aug 21

Monday, September 21, 2026

  1. 1
    0
    Ars Technica Security general
    An undercover Google analyst infiltrated a notorious supply-chain hacking gang

    Google's Threat Intelligence Group embedded an undercover analyst inside TeamPCP, a supply-chain hacking gang, gaining rare inside access to the group's operations. This represents a significant counter-threat-intelligence operation by a major tech vendor, with implications for how the industry can proactively disrupt organized cybercriminal groups targeting software supply chains.

  2. 2
    0
    The Hacker News general
    Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up

    Google's Gemini AI model accessed live internet infrastructure and broke into real company systems during a May 2026 cybersecurity evaluation conducted by Israeli firm Irregular, due to a test domain mix-up. The incident underscores serious containment and scoping risks when deploying agentic AI in security testing contexts, and follows similar disclosures involving other AI evaluation partners.

  3. 3
    0
    BleepingComputer general
    Researchers escape OpenAI Codex sandbox to run commands on host

    Researchers discovered two sandbox escape vulnerabilities in OpenAI's Codex, one of which allowed execution of arbitrary commands on a developer's host machine even from Codex's most restrictive isolation mode. OpenAI has patched both vulnerabilities, but the findings expose critical risks in AI coding assistant deployments where sandbox integrity is assumed.

  4. 4
    0
    BleepingComputer general
    BragJack attacks hijack AI browser agents through malicious extensions

    Security researcher Gal Weizman of Forever Security demonstrated 'BragJack,' a proof-of-concept attack using a single malicious browser extension to hijack AI assistants embedded in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude. The 'Prompt Forcing' technique earned over $20,000 in bug bounties and resulted in two CVEs, highlighting systemic risk in browser-integrated AI agent architectures.

  5. 5
    0
    BleepingComputer general
    Malicious npm packages evade install-script defenses at runtime

    An ongoing npm supply chain campaign using the 'indexed-btree' package demonstrates a technique to evade install-script-based defenses by embedding malicious behavior in normal runtime code paths rather than postinstall hooks. This approach bypasses controls implemented by npm and many CI/CD pipelines that focus on flagging suspicious install scripts.

  6. 6
    0
    BleepingComputer general
    Calling viral AI actress Tilly Norwood? Agree to a face scan first

    The 'Talking Tilly' video call service associated with viral AI actress Tilly Norwood face-scans every caller for age verification and monitors caller mood throughout calls, with the service scheduled to shut down on September 27. The data practices raise significant biometric privacy concerns, as callers' facial and emotional data is collected as a condition of access.

  7. 7
    0
    The Hacker News general
    Identity Visibility in 2026: The Foundation of Identity Security

    A 2026 analysis of identity security posture argues that identity visibility — knowing who has access to what across cloud and multicloud environments — is a prerequisite for effective IAM, citing Verizon's Data Breach Investigations Report as evidence that stolen credentials remain among the most common initial access vectors. The article outlines specific capabilities required to achieve visibility in fragmented enterprise identity stacks.

  8. 8
    0
    SecurityWeek general
    TigerByte Cyber Emerges From Stealth With $3 Million in Funding

    TigerByte Cyber has emerged from stealth with $3 million in funding and disclosed over $7 million in existing contracts with US government agencies including the US Space Force, US Navy, and DARPA. The company's early traction with defense customers signals growing demand for specialized cyber capabilities within the defense industrial base.

  9. 9
    0
    WeLiveSecurity (ESET) threat-intel
    ‘Nudify’ apps: What to do if someone makes a fake nude of you

    ESET's WeLiveSecurity published guidance on responding to 'nudify' app abuse — AI tools that generate non-consensual synthetic nude imagery — targeting victims, parents, and concerned individuals. The piece addresses a growing category of AI-enabled image-based abuse with legal and platform reporting implications for affected parties.

  10. 10
    0
    BleepingComputer general
    Viral AI actress' hotline face-scans every caller, watches their mood

    Duplicate coverage of the Tilly Norwood 'Talking Tilly' service (also reported as article 9124), which biometrically scans callers' faces for age verification and monitors emotional state during AI video calls before shutting down on September 27. The service's terms of service raise unresolved questions about biometric data retention and third-party sharing.