{"id":5501,"date":"2025-09-19T23:00:00","date_gmt":"2025-09-19T11:00:00","guid":{"rendered":"https:\/\/ostermanresearch.com\/?p=5501"},"modified":"2025-09-19T18:00:24","modified_gmt":"2025-09-19T06:00:24","slug":"news20250919","status":"publish","type":"post","link":"https:\/\/ostermanresearch.com\/2025\/09\/19\/news20250919\/","title":{"rendered":"News &#8211; September 19, 2025"},"content":{"rendered":"\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"326\" data-attachment-id=\"5513\" data-permalink=\"https:\/\/ostermanresearch.com\/2025\/09\/19\/news20250919\/news20250919-2\/\" data-orig-file=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/09\/news20250919.jpg?fit=1100%2C350&amp;ssl=1\" data-orig-size=\"1100,350\" data-comments-opened=\"0\" data-image-meta=\"{&quot;aperture&quot;:&quot;0&quot;,&quot;credit&quot;:&quot;&quot;,&quot;camera&quot;:&quot;&quot;,&quot;caption&quot;:&quot;&quot;,&quot;created_timestamp&quot;:&quot;0&quot;,&quot;copyright&quot;:&quot;&quot;,&quot;focal_length&quot;:&quot;0&quot;,&quot;iso&quot;:&quot;0&quot;,&quot;shutter_speed&quot;:&quot;0&quot;,&quot;title&quot;:&quot;&quot;,&quot;orientation&quot;:&quot;0&quot;}\" data-image-title=\"news20250919\" data-image-description=\"\" data-image-caption=\"\" data-medium-file=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/09\/news20250919.jpg?fit=300%2C95&amp;ssl=1\" data-large-file=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/09\/news20250919.jpg?fit=1024%2C326&amp;ssl=1\" src=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/09\/news20250919.jpg?resize=1024%2C326&#038;ssl=1\" alt=\"\" class=\"wp-image-5513\" srcset=\"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/09\/news20250919.jpg?resize=1024%2C326&amp;ssl=1 1024w, https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/09\/news20250919.jpg?resize=300%2C95&amp;ssl=1 300w, https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/09\/news20250919.jpg?resize=768%2C244&amp;ssl=1 768w, https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/09\/news20250919.jpg?w=1100&amp;ssl=1 1100w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><\/figure>\n\n\n\n<p>News for today:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Vulnerability in ChatGPT<\/strong>. After letting OpenAI know first (the responsible disclosure obligation), Radware announced its discovery of ShadowLeak, a previously unknown zero-click vulnerability in ChatGPT Deep Research. The flaw <em>allows attackers to exfiltrate sensitive information from users without any clicks, prompts or visible signs of compromise on the network or endpoint<\/em>. POC was sending an email to a target user, which resulted in sensitive information being returned to the sender without the user even having to open the email. <em>ShadowLeak operates independently and leaves no network level evidence, making these threats nearly impossible to detect from the perspective of the ChatGPT business customer<\/em>. Ouch. <a href=\"https:\/\/www.radware.com\/newsevents\/pressreleases\/2025\/radware-uncovers-first-zero-click-service-side-vulnerability-in-chatgpt\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Radware<\/a><\/li>\n\n\n\n<li><strong>GreyNoise introduced its MCP Server<\/strong>. GreyNoise introduced its Model Context Protocol Server to provide structured access for LLMs and agents to its threat intelligence service. <em>The GreyNoise MCP Server provides AI models and agents with access to accurate, real-time threat intelligence, so they can remain grounded in trusted, up-to-date data as they reason about security issues. Through MCP, agents can query GreyNoise in real-time to determine whether an IP is benign, malicious, suspicious, or unknown, and to identify vulnerabilities actively being exploited in the wild<\/em>. <a href=\"https:\/\/www.greynoise.io\/press\/greynoise-intelligence-launches-model-context-protocol-mcp-server-power-future-of-agentic-soc\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">GreyNoise<\/a><\/li>\n\n\n\n<li><strong>Netwrix on cyberattacks in healthcare<\/strong>. The healthcare sector is under sustained attack, per the new Netwrix 2025 Cybersecurity Trends Report. 48% experienced at least one incident over the past 12 months. Compromised identities are a key root cause: <em>Phishing, ransomware, and user account compromise were the most common attack types reported \u2014 threats that frequently begin with stolen credentials. Nearly one-third of respondents (31%) said their organizations had incidents involving compromised user or admin accounts<\/em>.  <a href=\"https:\/\/www.netwrix.com\/healthcare-cyberattack-losses-above-200000-dollars-nearly-quadruple-in-12-months-netwrix-survey-finds.html\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Netwrix<\/a><\/li>\n\n\n\n<li><strong>Falcon Next-Gen Identity Security<\/strong>. CrowdStrike added new capabilities to its Falcon Next-Gen Identity Security solution. New stuff: FalconID via the Falcon for Mobile app (phishing-resistant, passwordless MFA), enhanced privileged access, and identity-driven case management. <em>Falcon Next-Gen Identity Security was purpose-built with unified initial access, modern privileged access management, identity threat detection and response (ITDR), SaaS identity security, and agentic identity protection to stop identity-driven breaches across domains<\/em>. <a href=\"https:\/\/www.crowdstrike.com\/en-us\/press-releases\/falcon-next-gen-identity-security-innovations-expand-unified-protection-for-every-identity\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">CrowdStrike<\/a> <\/li>\n\n\n\n<li><strong>OPSWAT in London<\/strong>. OPSWAT opened its new international briefing center and cybersecurity lab in London. In addition to catering for a growing number of employees, <em>the London office will also serve as a hub to train and certify the next generation of critical national infrastructure (CNI) cybersecurity professionals through\u00a0OPSWAT Academy<\/em>.\u00a0<a href=\"https:\/\/www.opswat.com\/blog\/opswat-establishes-international-briefing-center-in-london-to-tackle-escalating-cybersecurity-threats\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">OPSWAT<\/a><\/li>\n\n\n\n<li><strong>Tenable Exposure Management Leadership Council<\/strong>. Tenable said its formed a new council to focus on maturing exposure management disciplines. Various CISOs and other cybersecurity leaders have been invited to join. The council has released its first report, too. <a href=\"https:\/\/www.tenable.com\/press-releases\/tenable-unites-top-cisos-to-forge-exposure-management-framework-for-proactive-risk-management\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Tenable<\/a> <\/li>\n\n\n\n<li><strong>New Cato PoP in Oslo<\/strong>. Cato opened a new datacenter in Oslo, to extend Cato&#8217;s AI-powered network security platform to locations and customers in Norway and the wider Nordics region. <a href=\"https:\/\/www.catonetworks.com\/news\/cato-expands-sase-ai-platform-in-nordics-with-new-oslo-datacenter\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cato Networks<\/a><\/li>\n<\/ul>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>News for September 19: ChatGPT vulnerability, GreyNoise MCP Server, Netwrix research, and more.<\/p>\n","protected":false},"author":384585,"featured_media":5513,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_coblocks_attr":"","_coblocks_dimensions":"","_coblocks_responsive_height":"","_coblocks_accordion_ie_support":"","advanced_seo_description":"","jetpack_seo_html_title":"","jetpack_seo_noindex":false,"jetpack_post_was_ever_published":false,"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":true,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2}},"categories":[712027501],"tags":[712027517],"class_list":["post-5501","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news-roundup","tag-news-roundup"],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"https:\/\/i0.wp.com\/ostermanresearch.com\/wp-content\/uploads\/2025\/09\/news20250919.jpg?fit=1100%2C350&ssl=1","jetpack_likes_enabled":true,"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pcHAk4-1qJ","_links":{"self":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/5501","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/users\/384585"}],"replies":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/comments?post=5501"}],"version-history":[{"count":15,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/5501\/revisions"}],"predecessor-version":[{"id":5517,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/posts\/5501\/revisions\/5517"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media\/5513"}],"wp:attachment":[{"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/media?parent=5501"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/categories?post=5501"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/ostermanresearch.com\/wp-json\/wp\/v2\/tags?post=5501"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}