Security Affairs newsletter Round 595 by Pierluigi Paganini – INTERNATIONAL EDITION

Wait 5 sec.

A new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box.Enjoy a new round of the weekly SecurityAffairs newsletter, including international press.Google Gemini also Broke Out of Its Test EnvironmentAI Helps Hackers Hijack OpenAI Staff Accounts Through a ForumBrevo Supply-Chain Attack Infected Over 100,000 WebsitesGyazo Data Breach Exposes 23 Million User RecordsRatHat Turns Android Accessibility Into an Attack WeaponCheck Point Fixes Critical CVE-2026-91843 Allowing Root Code ExecutionOpenAI admits its models lie to cover their own mistakesCyberattacks on Oil Tankers Put Maritime Critical Infrastructure at RiskSilkParasite Infrastructure Links SpiceRAT to Central Asian TargetsNightmareStresser Goes Offline in Global DDoS-for-Hire CrackdownU.S. CISA adds Acronis Backup, Cisco ISE, and Google Pixel flaws to its Known Exploited Vulnerabilities catalogChosen Brick, Iran’s Surveillance MalwareBambooToken: The Malware That Speaks MQTT to Stay Under the RadarGoogle Patches Pixel Modem Zero-Day Exploited in Targeted AttacksRevolut Data Leak May Trace Back to Compromised Italian Government AccountsTexas Utility CenterPoint Energy Confirms Data Breach After Hacker Claims 7.49M Records StolenU.S. CISA adds Cisco Secure Email Gateway flaw to its Known Exploited Vulnerabilities catalogCisco Warns of Ongoing Exploitation of Critical Email Gateway Zero-DayShared Hosting at Risk: LiteSpeed Enterprise Bug Can Grant Root from a Single TenantOne Exploit Chain, Two Espionage Campaigns: Chrome and Windows Under FireTelegram Desktop Flaw Could Turn Old Chat Exports Into Data Theft TrapsNon-Zero-Day VPN Flaw Left Japan ‘s Government Shared Network Platform Exposed: 246,000 Records at RiskENISA: Frontier AI Is Changing the Speed of Cyberattacks. Europe Needs to Catch UpChina Calls Amodei’s AI Proposal a New Cold War PlaybookU.S. CISA adds GitLab, JFrog Artifactory, and ConnectWise ScreenConnect flaws to its Known Exploited Vulnerabilities catalogDutch NCSC Warns: Critical Check Point VPN Flaws Put Networks at RiskAnthropic CEO Calls for an AI Slowdown. Is It Possible?GitLab CVE-2026-85706: One HTTP Request, No Authentication, Full File Read – Exploited Within 24 HoursConti Hacker Who Built Malware and Attacked Victims Gets Four-Year SentenceInternational Press – NewsletterCybercrimePersonal, Financial Info Exposed in Revolut Data Breach CenterPoint Energy confirms intruder helped themselves to customer informationFBI Seizes DDoS-for-Hire Domains as Part of Continuing District of Alaska Crackdown on ‘Booter’ and ‘Stresser’ DDoS Services  Hackers Stole Flock’s Camera Software, Revealing How the Company Tracks Cars and People  23 Million User Records Compromised in Gyazo Data Breach  MalwareGray Rabbits and the Tale of a One-Click Backdoor  Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot Service  Mind the (Patch) Gap: Multiple Chinese Threat Actors Chain 0-day Exploits in Chrome & Windows  Skill Poisioning turning AI agents into malware droppers – warns China’s National CERT  HackingCritical vulnerabilities expected in Check Point VPN products with active exploitation: update now  The Ghost in the Chat: how a bot that isn’t in your group steals messages from Telegram HTML exports Japan’s Digital Agency says VPN flaw exposed 246,000 personnel recordsOne Router, Three Vulnerabilities: Security Research on the TOTOLINK A720R Coast Guard and FBI boarded 2 energy tankers due to cyberattacks. How big is the risk?  Nintendo warns of Switch code execution flaw via on-screen QR codes  Hacking OpenAI  Intelligence and Information Warfare  A warning about ‘model welfare’  Investigații The Kremlin’s Digital Pirates: How Russian Tracking Pixels Harvest Romanians’ Data to Fund Conspiracies and Extremism  Skill Poisioning turning AI agents into malware droppers – warns China’s National CERT  Donald Trump rejects calls from tech bosses for an AI slowdownChina bristles at Anthropic CEO’s ‘fearmongering’ about its AI development  Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit  Iranian cyber targeting of dissidents, activists and journalists  SilkParasite Infrastructure: SpiceRAT Servers Tied to Energy and Government Targets Across Central Asia Amazon’s AWS is unable to restore access to Bahrain, one UAE cloud data zone after war damage  Beware the SparroWock: The backdoor that bites, the commands that catch  CybersecurityMeta Failed to Catch Hundreds of AI Child Abuse Ads. Some Included Images of Real Kids  Anthropic CEO Dario Amodei says AI industry needs to give safety measures time to catch upWe Must Pace the Frontier First notification of a personal data breach caused by an attack executed using an AI agent  Gemini Hacked Three Companies in First Known Breakout by Google’s AI Follow me on Twitter: @securityaffairs and Facebook and MastodonPierluigi Paganini(SecurityAffairs – hacking, newsletter)