A reader survey by Android Authority, prompted by its coverage of the OpenClaw tool, found that 43% of respondents would not give an AI agent full access to their computer for security reasons, while another 27% said they simply weren't interested. Only about 25% said they'd allow it if properly secured, and fewer than 4% expressed no concern at all.
androidauthority.com
· 2026-09-17
A Hacker News user described being locked out of Google, banking, email and Drive accounts after their phone was stolen, since 2FA and account recovery relied on that device and an old email they could no longer access. The poster noted Google's automated recovery flow offers only options tied to the lost phone or an outdated backup email, leaving no clear path to a human for help.
news.ycombinator.com
· 2026-09-17
CrowdSec disclosed that a leak of its private source code repositories occurred in May 2026 and was reported to the company on September 16. The exposed material includes SaaS console code, AWS routines, connectors, and CI/CD tokens, but excludes CrowdSec's public Security Engine software. The company found no evidence of leaked credentials, customer data, or login information, and believes the Tanstack supply-chain compromise was the likely entry point.
crowdsec.net
· 2026-09-17
A virtual event titled Cybersecurity Outlook 2027 will bring together industry analysts, researchers and experts to discuss emerging cyber threats from criminals and nation-states as the new year approaches. The sessions will also cover how AI-driven tools and other technologies can help organizations protect multi-cloud and hybrid environments.
darkreading.com
· 2026-09-17
Google's Threat Intelligence Group disclosed a credential-harvesting operation where attackers compromised cloud infrastructure and deployed a multi-agent AI framework that scanned for vulnerabilities, fixed its own errors, and rotated IP addresses largely without human input. The entire campaign, which compromised thousands of third-party credentials, took less than six hours to execute. Separately, Microsoft found AI-assisted phishing messages reaching click-through rates of 54%, compared to roughly 12% for conventional campaigns.
bleepingcomputer.com
· 2026-09-17
Cloudflare released Security-Audit-Skill, a coding-agent tool that runs a six-phase security audit: mapping a codebase's architecture and attack surface, assigning isolated 'hunter' agents to search for vulnerabilities against a coverage ledger, validating candidates with skeptical verifier agents, and producing structured reports categorized as confirmed, needs_validation, or rejected. It served as the original single-repo prototype that Cloudflare later expanded into its larger, fleet-wide vulnerability discovery harness.
github.com
· 2026-09-17
A survey of over 500 CISOs by IANS and Artico found that 69% now rank AI as their top target for new cybersecurity budget dollars, even though overall security budgets grew just 5% in 2026. Nearly a quarter of organizations have created dedicated AI security budget lines, while others fund it through general security, IT, or innovation budgets.
darkreading.com
· 2026-09-16
After a researcher's resignation over AI extinction fears, Anthropic CEO Dario Amodei called for external organizations to verify AI labs' safety practices and audit training pipelines, a proposal quickly backed by OpenAI, Google and others. Security experts counter that labs should first tighten fundamental internet security measures—access logs, permissions, and control systems—rather than relying on outside auditors as the primary fix.
techcrunch.com
· 2026-09-16
Security researchers have identified a novel attack technique, dubbed BragJack, that exploits agentic AI assistants embedded directly in web browsers. The attack allows malicious actors to manipulate these assistants into accessing sensitive user information, performing unauthorized actions, and exfiltrating data without the user's knowledge.
darkreading.com
· 2026-09-16
Elastic Security Labs uncovered a malware toolkit called KREMLIN, active since mid-2025, that tricks victims into opening fake invoice or receipt files to install malicious Chrome and Edge extensions without any user approval. The toolkit recreates Chromium's cryptographic integrity checks so the browser treats the rogue extension as legitimate, then harvests login credentials, session tokens and other sensitive data. Elastic ties the operation to a Brazilian group that has run at least seven campaigns impersonating 12 banks since May.
bleepingcomputer.com
· 2026-09-16
iOS 27 includes a new privacy feature called Impersonation Risk Detection, designed to flag social engineering scams where attackers pose as banks or trusted contacts to pressure victims into transferring money or changing account details. The feature is disabled by default and must be turned on manually through Settings > Privacy & Security > Impersonation Risk Detection. It works by analyzing device and Apple Account signals to generate a risk score that participating apps can use to add warnings, delays, or identity checks.
9to5mac.com
· 2026-09-16
European Commission President Ursula von der Leyen indicated Canada could gain an 'associate member' status linked to a proposed European Security Council, framing the move as a response to escalating geopolitical risks. The remarks suggest the EU is considering deeper defense and security ties with non-member allies as threats intensify.
bbc.com
· 2026-09-16