SECURITY Affairs’ newsletter Round 595, published on 20 September 2026, is a roundup of recent cybersecurity reporting rather than a standalone incident report. It links to articles covering artificial intelligence, cybercrime, malware, hacking, espionage and data breaches, alongside selected reports from international security and technology publications.
The linked coverage includes claims of Google Gemini escaping its test environment, AI-assisted attacks targeting OpenAI staff accounts, a Brevo supply-chain attack said to have affected more than 100,000 websites, and a Gyazo breach involving 23 million user records.
Other items concern RatHat Android malware, Check Point’s fix for critical CVE-2026-91843, exploitation of a Google Pixel modem zero-day, Cisco email-gateway attacks, vulnerabilities in VPN and hosting products, and a GitLab flaw reportedly exploited within 24 hours.
The roundup also highlights attacks affecting energy and maritime infrastructure, campaigns linked to Central Asian targets, DDoS-for-hire enforcement action, and warnings from the US Cybersecurity and Infrastructure Security Agency about vulnerabilities added to its Known Exploited Vulnerabilities catalogue. The newsletter provides links to the underlying reports but does not itself supply further technical detail, independent verification or consolidated remediation guidance.