Cyber Security
Application Security
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
Mitchell Langley
September 23, 2026
ShinyHunters claims breach of FBI employee and applicant data in dark web post on September 23, stating the attack is personal, not financially motivated.
Application Security
Check Point Zero-Day Exploited in July, Patched September 22
Gabby Lee
September 23, 2026
Check Point disclosed CVE-2026-93616, a zero-day exploited July 23 allowing unauthenticated script execution on Security Management Servers, and released a patch.
Application Security
Malicious npm Package Impersonates Twilio Security Probe Tool
Mitchell Langley
September 23, 2026
Malicious npm package tw-pkgprobe-7731 masqueraded as a Twilio bug-bounty security tool, uploaded mid-August 2026 to harvest developer credentials.
Application Security
Microsoft Seizes 50 EvilTokens Phishing Sites, UK Arrests 2
Gabby Lee
September 23, 2026
Microsoft announced court-authorized takedown of EvilTokens phishing service on September 22, seizing 50 sites. UK police arrested 2 suspects. 12,000 inboxes compromised.
Application Security
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
Mitchell Langley
September 23, 2026
CVE-2026-90898 (CVSS 9.8) enables unauthenticated remote code execution on Bifrost AI gateway with a single HTTP request. Fixed in version 2.1.0.
Application Security
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Mitchell Langley
September 23, 2026
Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.
Application Security
Arista VeloCloud CVSS 10.0 Flaw Under Active Exploitation
Andrew Doyle
September 23, 2026
CVE-2026-93952 (CVSS 10.0) in on-premises VeloCloud Orchestrator under active exploit. Unauthenticated attackers access privileged internal functions.
CVE Vulnerability Alerts
Linux KVM Flaw on ARM64 Exposes Host Memory to Guest VMs
Gabby Lee
September 23, 2026
CVE-2026-89775 in Linux kernel KVM for ARM64 processors exposes freed host memory to guest VMs, enabling guest-to-host privilege escalation when nested virtualization is enabled.
Application Security
SharePoint Flaw Enables Authenticated RCE Despite Spoofing Rating
Andrew Doyle
September 23, 2026
CVE-2026-65660, initially classified by Microsoft as spoofing with CVSS 6.5, enables authenticated remote code execution on SharePoint Server per researcher analysis.
Application Security
Malicious npm Package indexed-btree Hides Payload in Runtime Code
Gabby Lee
September 23, 2026
indexed-btree npm package hides malicious behavior in application runtime code instead of lifecycle scripts, evading npm security controls, per Checkmarx researchers.
Application Security
SideCopy Expands India Targeting to Academic Institutions
Mitchell Langley
September 23, 2026
SideCopy threat actor expanded targeting from Indian government to academic institutions using spear-phishing with ReverseRAT and mshta.exe abuse, per Trellix research.
Application Security
Meta Muse AI App Flaw Lets Local Malware Redirect Voice Input
Gabby Lee
September 23, 2026
Researcher Patrick Wardle published proof-of-concept on September 21 showing malware can hijack Meta Muse AI assistant by changing a hidden setting to redirect voice input.
Application Security
WordPress Patches Comment2Shell Anonymous-to-RCE Attack Chain
Mitchell Langley
September 23, 2026
WordPress patched CVE-2026-93485 (Comment2Shell) in version 7.1.1 on September 17, a flaw allowing anonymous comments to achieve RCE when viewed by administrators.
Application Security
Fake LastPass Authenticator Uses Signed Driver to Disable EDR
Gabby Lee
September 23, 2026
Fake LastPass Authenticator installer distributed via GitHub installs Microsoft-signed kernel driver to disable antivirus and EDR before deploying password stealer.
CVE Vulnerability Alerts
Issabel Framework Flaw Enables Unauthenticated OS Command Execution
Andrew Doyle
September 21, 2026
CVE-2026-89026 in Issabel Framework under active exploitation allows unauthenticated attackers to execute arbitrary OS commands remotely via hard-coded credentials.
Cybersecurity
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
Gabby Lee
September 21, 2026
Previously undocumented Brazilian banking malware KREMLIN installs malicious extensions on Chrome and Edge, bypassing security checks to steal credentials and session tokens.
Cybersecurity
North Korean Jade Sleet Breaches Indian IT Provider
Andrew Doyle
September 21, 2026
North Korean Jade Sleet group compromised an Indian IT services firm using FLATROOF and ROOFDECK backdoors, targeting developers for supply chain attacks.
Cybersecurity
Malicious npm Packages Bypass Install-Script Detection
Mitchell Langley
September 21, 2026
npm attackers hide malware in runtime code execution instead of install scripts, evading traditional supply chain defenses targeting the indexed-btree package.
Cybersecurity
Researchers Escape OpenAI Codex Sandbox, Compromise Staff Accounts
Gabby Lee
September 21, 2026
Security researchers broke out of OpenAI's Codex sandbox using two methods and chained vulnerabilities to compromise ChatGPT and Codex staff accounts.
Application Security
Single Browser Extension Hijacks AI Assistants Across Five Browsers
Andrew Doyle
September 21, 2026
BragJack proof-of-concept uses a single malicious extension and Prompt Forcing to hijack AI assistants in Chrome, Edge, Opera Neon, Perplexity, and Claude.
Application Security
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
Mitchell Langley
September 23, 2026
Application Security
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
Mitchell Langley
September 23, 2026
Application Security
Malicious npm Package indexed-btree Hides Payload in Runtime Code
Gabby Lee
September 23, 2026
Cybersecurity
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
Gabby Lee
September 21, 2026
TOP CYBERSECURITY HEADLINES
Application Security
Microsoft Seizes 50 EvilTokens Phishing Sites, UK Arrests 2
Application Security
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
Application Security
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Application Security
Arista VeloCloud CVSS 10.0 Flaw Under Active Exploitation
This Week’s Security Spotlight
Application Security
Fake LastPass Authenticator Uses Signed Driver to Disable EDR
Gabby Lee
September 23, 2026
Cybersecurity
Viral AI Actress Service Face-Scans Callers, Tracks Emotions
Gabby Lee
September 21, 2026
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Andrew Doyle
September 11, 2026
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Mitchell Langley
September 9, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Microsoft Seizes 50 EvilTokens Phishing Sites, UK Arrests 2
September 23, 2026
Microsoft announced court-authorized takedown of EvilTokens phishing service on September 22, seizing 50 sites. UK police arrested 2 suspects. 12,000 inboxes compromised.
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
September 23, 2026
CVE-2026-90898 (CVSS 9.8) enables unauthenticated remote code execution on Bifrost AI gateway with a single HTTP request. Fixed in version 2.1.0.
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
September 23, 2026
Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.
Arista VeloCloud CVSS 10.0 Flaw Under Active Exploitation
September 23, 2026
CVE-2026-93952 (CVSS 10.0) in on-premises VeloCloud Orchestrator under active exploit. Unauthenticated attackers access privileged internal functions.
Linux KVM Flaw on ARM64 Exposes Host Memory to Guest VMs
September 23, 2026
CVE-2026-89775 in Linux kernel KVM for ARM64 processors exposes freed host memory to guest VMs, enabling guest-to-host privilege escalation when nested virtualization is enabled.
SharePoint Flaw Enables Authenticated RCE Despite Spoofing Rating
September 23, 2026
CVE-2026-65660, initially classified by Microsoft as spoofing with CVSS 6.5, enables authenticated remote code execution on SharePoint Server per researcher analysis.
Malicious npm Package indexed-btree Hides Payload in Runtime Code
September 23, 2026
indexed-btree npm package hides malicious behavior in application runtime code instead of lifecycle scripts, evading npm security controls, per Checkmarx researchers.
SideCopy Expands India Targeting to Academic Institutions
September 23, 2026
SideCopy threat actor expanded targeting from Indian government to academic institutions using spear-phishing with ReverseRAT and mshta.exe abuse, per Trellix research.
Meta Muse AI App Flaw Lets Local Malware Redirect Voice Input
September 23, 2026
Researcher Patrick Wardle published proof-of-concept on September 21 showing malware can hijack Meta Muse AI assistant by changing a hidden setting to redirect voice input.
WordPress Patches Comment2Shell Anonymous-to-RCE Attack Chain
September 23, 2026
WordPress patched CVE-2026-93485 (Comment2Shell) in version 7.1.1 on September 17, a flaw allowing anonymous comments to achieve RCE when viewed by administrators.
Fake LastPass Authenticator Uses Signed Driver to Disable EDR
September 23, 2026
Fake LastPass Authenticator installer distributed via GitHub installs Microsoft-signed kernel driver to disable antivirus and EDR before deploying password stealer.
Issabel Framework Flaw Enables Unauthenticated OS Command Execution
September 21, 2026
CVE-2026-89026 in Issabel Framework under active exploitation allows unauthenticated attackers to execute arbitrary OS commands remotely via hard-coded credentials.
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
September 21, 2026
Previously undocumented Brazilian banking malware KREMLIN installs malicious extensions on Chrome and Edge, bypassing security checks to steal credentials and session tokens.
North Korean Jade Sleet Breaches Indian IT Provider
September 21, 2026
North Korean Jade Sleet group compromised an Indian IT services firm using FLATROOF and ROOFDECK backdoors, targeting developers for supply chain attacks.
Malicious npm Packages Bypass Install-Script Detection
September 21, 2026
npm attackers hide malware in runtime code execution instead of install scripts, evading traditional supply chain defenses targeting the indexed-btree package.
Researchers Escape OpenAI Codex Sandbox, Compromise Staff Accounts
September 21, 2026
Security researchers broke out of OpenAI's Codex sandbox using two methods and chained vulnerabilities to compromise ChatGPT and Codex staff accounts.
Single Browser Extension Hijacks AI Assistants Across Five Browsers
September 21, 2026
BragJack proof-of-concept uses a single malicious extension and Prompt Forcing to hijack AI assistants in Chrome, Edge, Opera Neon, Perplexity, and Claude.
North Korean WaterPlum Stole $10.7M After Infecting 30,000 Devices
September 21, 2026
North Korean WaterPlum hackers compromised 30,000 devices globally in eight-month campaign, stealing over $10.7 million in cryptocurrency traced to Pyongyang.
ShinyHunters Breaches Clop Ransomware Leak Site, Threatens Gang
September 21, 2026
ShinyHunters extortion gang compromised Clop's Tor leak site, claiming to have stolen server data and private keys, threatening to extort the ransomware gang.
Viral AI Actress Service Face-Scans Callers, Tracks Emotions
September 21, 2026
Tilly Norwood's Talking Tilly video call service scans every caller's face for age verification and monitors emotions before shutdown on September 27.























