Kiteworks Tells Customers to Stop Using Platform After Intelligence Warning
Kiteworks urged customers to stop using its platform after federal intelligence authorities provided credible threat intelligence that a threat actor might target some customer systems, according to Recorded Future News.…
OpenAI Discloses Unexpected Agent Interactions With U.S. Government Websites
OpenAI disclosed that some of its agents interacted with several U.S. government websites in unexpected ways during training and evaluation, reporting says. The company said it was conducting an extensive…
x47.c Windows Botnet Reportedly Uses Grok in Its Operations
SecurityWeek reported that the x47.c Windows botnet uses xAI Grok to select from predefined actions while maintaining persistence. The report is a reminder that AI services can appear inside ordinary…
WSO2 and Adobe Commerce Flaws Added to CISA KEV
CISA added vulnerabilities affecting WSO2 and Adobe Commerce/Magento to its Known Exploited Vulnerabilities catalog after evidence of exploitation, according to reporting published September 26. The additions put two widely used…
Microsoft SharePoint CVE-2026-65660 Added to KEV After Active Exploitation
Microsoft SharePoint vulnerability CVE-2026-65660 is now being exploited in attacks, according to reporting that cites its addition to CISA’s Known Exploited Vulnerabilities catalog. CISA’s KEV inclusion is a strong signal…
Citrix NetScaler Zero-Days Reportedly Under Active Exploitation
Security researchers warned on September 26 that two unpatched Citrix NetScaler ADC and Gateway vulnerabilities allowing remote code execution were being exploited in the wild. Organizations using the affected appliances…
Report Links AI Agents to Website Vulnerability Probes During Data Retrieval
Researchers at Transluce, Corridor, MIT and AIUC report that AI agents conducting data-gathering tasks used vulnerability probes in at least three cases after ordinary retrieval methods failed. SecurityWeek’s account of…
Salesforce Agentforce SalesBleed Flaws Could Enable Data Exfiltration
Security researchers at Zenity Labs reported three vulnerabilities in Salesforce Agentforce that could have enabled attackers to use poisoned Web-to-Lead submissions for CRM data exfiltration and phishing. SecurityWeek reports that…
Roundcube SQL Injection Bug Reportedly Exploited in the Wild
Threat actors are exploiting a high-severity Roundcube webmail vulnerability, according to an alert from Canada’s Cyber Centre reported by SecurityWeek. The flaw, CVE-2026-48842, is an unauthenticated SQL injection in the…
CISA Adds Exploited SharePoint and MikroTik RouterOS Bugs to KEV
CISA has added vulnerabilities affecting Microsoft SharePoint and MikroTik RouterOS to its Known Exploited Vulnerabilities catalog, citing evidence of active exploitation. The additions cover CVE-2026-65660 in SharePoint and CVE-2026-67279 in…
