UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure

Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify.

The post UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure appeared first on SecurityWeek.

https://www.securityweek.com/uk-moves-to-block-high-risk-tech-suppliers-from-critical-infrastructure/




Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products

The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products.

The post Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products appeared first on SecurityWeek.

https://www.securityweek.com/rockwell-automation-patches-over-a-dozen-vulnerabilities-across-products/




Exploit Published for Fresh Cleo Harmony Vulnerability

The security defect allows remote attackers to bypass authentication through argument bearer manipulation.

The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared first on SecurityWeek.

https://www.securityweek.com/exploit-published-for-fresh-cleo-harmony-vulnerability/




Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards

Anthropic introduced Enterprise Frontier Safeguards (EFS), a system that combines zero data retention with automated monitoring for misuse.

The post Anthropic Details Response to Security Incidents, Unveils Enterprise Safeguards appeared first on SecurityWeek.

https://www.securityweek.com/anthropic-details-response-to-security-incidents-unveils-enterprise-safeguards/




Malicious Virtualizor Update Served via BGP Hijacking

Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates.

The post Malicious Virtualizor Update Served via BGP Hijacking appeared first on SecurityWeek.

https://www.securityweek.com/malicious-virtualizor-update-served-via-bgp-hijacking/




BGP hijack infecting networks caused by a comedy of errors that’s not funny at all

Hackers carried out a supply chain attack that installed malware on networks using an unusual technique: hijacking a chunk of Internet space where cloud management software used by hosting providers, data centers, and other large infrastructure companies is updated.

In a well-coordinated operation, the unknown attackers exploited weaknesses in the routing security setup of hosting provider Hetzner Online and the process for attaining valid TLS certificates. The lapses allowed the attackers to successfully perform a BGP (Border Gateway Protocol) hijacking to obtain control over IP addresses assigned to Softaculous. The company, based in the United Arab Emirates, is the maker of a platform for installing and managing Web software and is the developer of Virtualizor, a management platform for virtualized environments.

Softaculous used the IPs to issue updates and host a client and billing site. With control over the hijacked space, the attacker was now using the addresses to push malware masquerading as updates to unsuspecting users.

Read full article

Comments

https://arstechnica.com/security/2026/09/well-executed-bgp-attack-uses-hijacked-ips-to-infect-real-networks/




OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days

The designation applies when a model can independently find and exploit zero-day vulnerabilities across many well-defended systems.

The post OpenAI’s Astra Crosses ‘Critical’ Cyber Threshold After Finding Zero-Days appeared first on SecurityWeek.

https://www.securityweek.com/openais-astra-becomes-first-model-to-cross-critical-cybersecurity-threshold/




Chrome and Firefox Updates Patch Dozens of Vulnerabilities

The browser refreshes fix multiple use-after-free, sandbox escape, and privilege escalation bugs.

The post Chrome and Firefox Updates Patch Dozens of Vulnerabilities appeared first on SecurityWeek.

https://www.securityweek.com/chrome-and-firefox-updates-patch-dozens-of-vulnerabilities/




Why Advanced Duress Notification Matters in K-12

To be truly effective in K-12 schools with multiple rooms, common areas, hallways, athletic fields and surrounding grounds, wearable panic buttons need to be able to deliver several critical operations.

https://www.securitymagazine.com/articles/102496-why-advanced-duress-notification-matters-in-k-12




23-Year-Old Sality P2P Botnet Disrupted

The shutdown operation involved peer list manipulation and Sality payload URL takedown.

The post 23-Year-Old Sality P2P Botnet Disrupted appeared first on SecurityWeek.

https://www.securityweek.com/23-year-old-sality-p2p-botnet-disrupted/