Several cybersecurity companies have released new products and updates. Netscout has enhanced its DDoS protection to mitigate outbound attacks, helping service providers prevent compromised devices from disrupting networks. F5 has improved its AI Gateway to better control AI costs, access, and security through policy enforcement. Intezer has introduced a native automation builder for security workflows, eliminating the need for separate SOAR tools. Tufin has updated its orchestration suite with AI-driven segmentation analysis and multi-vendor automation capabilities.

Several cybersecurity vendors have announced new product releases and enhancements this week, focusing on areas such as AI security, DDoS protection, security automation, and network segmentation. F5 Networks, Intezer, Netscout, and Tufin have all introduced updates to their respective platforms.
F5 Networks has enhanced its AI Gateway, integrating it into the F5 AI Security Platform. This update aims to provide a unified control plane for enterprises to manage access and usage of AI models, agents, and tools. The enhanced gateway is designed to enforce policies on every AI request, helping organizations optimize the economics of AI at scale while controlling costs and ensuring security. A dashboard called F5 AI Guardrails is part of this solution.
Netscout has expanded its Adaptive DDoS Protection (ADP) solution to include outbound attack mitigation. This extension allows service providers to automatically detect and mitigate DDoS attack traffic originating from within their networks. By shifting protection towards the source of attacks, Netscout intends to help operators prevent compromised subscriber devices from consuming network capacity, disrupting their own operations, and launching attacks against other organizations and customers across the internet.
Intezer has introduced "Workflows," a native automation and response builder integrated directly into its platform. This feature enables security teams to create and customize response workflows within the same environment where alerts are triaged and investigated. The goal is to allow organizations to automate post-investigation actions without the need for a separate Security Orchestration, Automation, and Response (SOAR) system.
Tufin has released Tufin Orchestration Suite (TOS) 5.3, which aims to simplify security operations and maintain consistent control across complex multi-vendor, hybrid environments. Alongside this platform update, Tufin also launched its AI-powered Segmentation Intelligence solution. This new solution continuously analyzes an organization’s segmentation policies to understand their intent, identify policy gaps and drift, and recommend actions to address these issues.

OpenAI has announced a $1 billion commitment to provide subsidized access to its Daybreak AI cybersecurity tools for under-resourced critical infrastructure defenders. The initiative, named Daybreak for Frontline Defenders, will offer AI models, training, and technical support over the next six months, prioritizing water and wastewater utilities, electric grid operators, and local government entities. This move aims to equip organizations with limited budgets and staff against increasingly sophisticated cyber threats.
A weakness has been identified in Tenda CP3 27.5.57.101. This issue affects some unknown processing of the file Net/NetCheckPing.cpp. This manipulation of the argument interface_name/host causes os command injection. The attack can be initiated remotely.
A security flaw has been discovered in Tenda CP3 27.5.57.101. This vulnerability affects the function SystemAsh of the file Apis/system.c of the component Kylin. The manipulation of the argument AlarmVoiceURL results in os command injection. It is possible to launch the attack remotely.

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on September 4. "Sansec is publishing early
In BPF instructions that load/store a value from/to a scratch memory register the register index is an unsigned 32-bit integer and must not exceed 15, but libpcap BPF interpreter does not validate the value. In particular uncommon use cases a crafted filter program can cause the interpreter to try reading and writing the OS process memory in the 16GiB starting at the current stack frame on 64-bit architectures and in the entire address space on 32-bit architectures.

Attackers are exploiting two new PaperCut flaws to steal credentials and gain privileged access in education-sector attacks across the U.S. and Europe. Attackers are exploiting two recelty disclosed PaperCut flaws, CVE-2026-81578 and CVE-2026-82078, in attacks targeting schools and other education organizations in the U.S. and Europe, as reported by TheHackerNews. Arctic Wolf researchers observed