top of page
Frame 2.png
cybersecurity-concept-keylock-blue-colors-binary-code-lock-ai-generated 1.png
Trusted by 100.png

Weekly INK

Issue #217 - September 21, 2026

wi4.png

Stay informed on the threats, trends, and security developments that matter most to your business. Find practical insights to better understand risk and stay ahead of bad actors.

Talk to an expert
Frame 2.png
cybersecurity-concept-keylock-blue-colors-binary-code-lock-ai-generated 1.png
Trusted by 100.png

Issue #217 - September 21, 2026

Weekly INK

Free, practical resources to assess your status, understand risks, and enhance your security posture no sales pitch needed.

Talk to An Expert

Issue #217 - September 21, 2026

Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

Source: Dark Reading


Researchers identified “Dark Sourcery,” a campaign that seeds the web with optimized fake support pages, fraudulent contact details, and phishing links so ChatGPT, Gemini, and Google AI Overview may repeat them as trusted answers. At least 374 brands were affected, underscoring the need to verify AI-provided contact and payment information.


Link to article



New Check Point flaw lets hackers execute code with root privileges

Source: BleepingComputer


Check Point patched CVE-2026-91843, a critical stack-based buffer overflow affecting Security Management Server and Log Server systems. An unauthenticated attacker could achieve root-level remote code execution with low complexity and no user interaction. Customers should apply the LivePatch or restrict management access to trusted networks while monitoring failed-login alerts.


Link to article



ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

Source: The Hacker News


ShinyHunters claims it breached FBI systems through an undisclosed Oracle PeopleSoft zero-day, defaced the bureau’s jobs site, and stole data concerning agents, former employees, and applicants. The FBI confirmed it is investigating unauthorized activity affecting FBIJobs.gov, while the alleged vulnerability and full scope of the claimed data theft remain unverified.


Link to article



Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Source: The Hacker News


Researchers found Go malware distributed through two Terraform providers and two Go modules, extending a North Korea-linked package campaign into HashiCorp’s registry. The implant uses blockchain dead drops and Slack as command channels, while targeted execution checks can hinder analysis. Development teams should tightly vet providers, modules, and dependency changes.


Link to article



Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Source: SecurityWeek


A Chinese threat actor exploited CVE-2026-7273, a ZyXEL GS1900 switch vulnerability, to extract hashed credentials, configurations, and network details from 996 devices in 48 countries. More than half retained factory-default credentials. CISA added the flaw to its Known Exploited Vulnerabilities catalog and required rapid federal remediation.


Link to article

frame 17b.png
Frame 1597880632.png

Talk to a Blue INK expert

From strengthening security and preparing for audits to navigating privacy and governing AI, we'll connect you directly with the right expert.

How can we best help?
Frame 1597880632.png

Have questions?

Let us know the best way to reach you and we will be in touch as soon as possible to answer your questions.

How can we best help?
frame 17c.png
Frame 1597880632.png

Stay ahead of new threats

Cut through the noise and stay ahead of emerging threats most relevant to your business. Our Weekly INK curates everything you need to know about cybersecurity threats targeting businesses. 

bottom of page