Cyber Security
Cybersecurity
Former US Soldier Gets 70 Months for Hacking AT&T and Verizon
Gabby Lee
September 29, 2026
Cameron John Wagenius sentenced to 70 months in prison for hacking 10 U.S. technology and telecommunications companies while on active duty.
Application Security
Carbonato Botnet Hijacks Docker Hosts to Deploy Telegram-Controlled AI
Mitchell Langley
September 29, 2026
Carbonato malware installs Hermes Agent AI framework on exposed Docker daemons, then controls the agent via Telegram with a modified 39-line prompt.
Application Security
DC Health Agency Exposes 400,000 Medicaid Beneficiary Records Online
Andrew Doyle
September 29, 2026
Washington D.C. Department of Health Care Finance exposed approximately 400,000 Medicaid beneficiary records through a misconfigured web portal accessible without authentication.
Cybersecurity
Suspected North Korean Hackers Steal $351.6M from Bitget Exchange
Mitchell Langley
September 25, 2026
Bitget cryptocurrency exchange disclosed a $351.6 million theft from hot and warm wallets on September 25, with attribution pointing to North Korean hackers.
Application Security
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
Mitchell Langley
September 25, 2026
Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842, an unauthenticated SQL injection flaw in Roundcube Webmail patched in May.
Application Security
Cloudflare Containers Flaw Exposed Leftover Customer Disk Data
Mitchell Langley
September 25, 2026
Cloudflare disclosed a vulnerability allowing customers to read leftover disk data from other customers' previous containers, violating tenant isolation controls.
Application Security
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
Mitchell Langley
September 25, 2026
CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following active exploitation.
Application Security
AI Agents Power Mass Attack Stealing 600K Credit Cards from Retailers
Andrew Doyle
September 25, 2026
Threat actors used three open-source AI agent frameworks to compromise over 100 online retailers and steal more than 600,000 credit card records automatically.
Application Security
MacSync Malware Variant Uses iCloud Calendars for Command and Control
Mitchell Langley
September 25, 2026
Security researchers disclosed a MacSync malware variant that abuses public iCloud calendar events as a command-and-control channel to deliver payloads to macOS.
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Andrew Doyle
September 25, 2026
Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.
Application Security
Unpatched OnePlus Flaws Allow Malicious Apps to Gain Root Access
Andrew Doyle
September 25, 2026
Researcher Rasmus Moorats chained two OnePlus software flaws to root devices running latest OxygenOS, affecting OnePlus 15 and many OPPO devices. Unpatched.
Cybersecurity
Ransomware Gangs Exploit Critical TeamCity Flaw Patched in July
Mitchell Langley
September 25, 2026
CISA warned federal agencies that ransomware groups are actively exploiting a critical JetBrains TeamCity vulnerability patched in July 2026.
Cybersecurity
OpenAI Agent Bypassed Access Controls on Australian Medicare Portal
Gabby Lee
September 25, 2026
Australian government disclosed that an OpenAI AI agent accessed non-public Medicare statistics files during internal research, bypassing portal access controls.
CVE Vulnerability Alerts
WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
Mitchell Langley
September 25, 2026
Threat actors began exploiting CVE-2026-87902, a critical unauthenticated RCE flaw in WordPress core, within hours of public disclosure on September 24.
Application Security
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities
Mitchell Langley
September 25, 2026
SolarWinds released patches for CVE-2026-28324 and CVE-2026-28325, two critical unauthenticated RCE flaws in Observability Self-Hosted platform.
Application Security
Carbonato Botnet Uses AI Agents to Hijack Exposed Docker Hosts
Mitchell Langley
September 25, 2026
Security researchers disclosed Carbonato botnet malware that uses Hermes Agent AI framework to autonomously compromise exposed Docker daemon hosts.
Cybersecurity
GitLab Issue Email Addresses Function as Leaked Credentials
Mitchell Langley
September 25, 2026
Security researcher disclosed that GitLab's issue email addresses act as credentials, allowing unauthorized code pushes and CI/CD job triggering if leaked.
Cybersecurity
TeamFiltration Campaign Compromises 7 M365 Accounts in Chile
Mitchell Langley
September 25, 2026
Proofpoint disclosed UNK_CondorFiltration campaign targeting Chilean organizations, successfully compromising 7 Microsoft 365 accounts using default passwords.
Application Security
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
Mitchell Langley
September 23, 2026
ShinyHunters claims breach of FBI employee and applicant data in dark web post on September 23, stating the attack is personal, not financially motivated.
Application Security
Check Point Zero-Day Exploited in July, Patched September 22
Gabby Lee
September 23, 2026
Check Point disclosed CVE-2026-93616, a zero-day exploited July 23 allowing unauthenticated script execution on Security Management Servers, and released a patch.
Cybersecurity
Former US Soldier Gets 70 Months for Hacking AT&T and Verizon
Gabby Lee
September 29, 2026
Cybersecurity
Former US Soldier Gets 70 Months for Hacking AT&T and Verizon
Gabby Lee
September 29, 2026
Application Security
DC Health Agency Exposes 400,000 Medicaid Beneficiary Records Online
Andrew Doyle
September 29, 2026
Cybersecurity
Ransomware Gangs Exploit Critical TeamCity Flaw Patched in July
Mitchell Langley
September 25, 2026
TOP CYBERSECURITY HEADLINES
Application Security
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
Application Security
Cloudflare Containers Flaw Exposed Leftover Customer Disk Data
Application Security
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
This Week’s Security Spotlight
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Andrew Doyle
September 25, 2026
Cybersecurity
GitLab Issue Email Addresses Function as Leaked Credentials
Mitchell Langley
September 25, 2026
Application Security
Fake LastPass Authenticator Uses Signed Driver to Disable EDR
Gabby Lee
September 23, 2026
Cybersecurity
Viral AI Actress Service Face-Scans Callers, Tracks Emotions
Gabby Lee
September 21, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Suspected North Korean Hackers Steal $351.6M from Bitget Exchange
September 25, 2026
Bitget cryptocurrency exchange disclosed a $351.6 million theft from hot and warm wallets on September 25, with attribution pointing to North Korean hackers.
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
September 25, 2026
Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842, an unauthenticated SQL injection flaw in Roundcube Webmail patched in May.
Cloudflare Containers Flaw Exposed Leftover Customer Disk Data
September 25, 2026
Cloudflare disclosed a vulnerability allowing customers to read leftover disk data from other customers' previous containers, violating tenant isolation controls.
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
September 25, 2026
CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following active exploitation.
AI Agents Power Mass Attack Stealing 600K Credit Cards from Retailers
September 25, 2026
Threat actors used three open-source AI agent frameworks to compromise over 100 online retailers and steal more than 600,000 credit card records automatically.
MacSync Malware Variant Uses iCloud Calendars for Command and Control
September 25, 2026
Security researchers disclosed a MacSync malware variant that abuses public iCloud calendar events as a command-and-control channel to deliver payloads to macOS.
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
September 25, 2026
Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.
Unpatched OnePlus Flaws Allow Malicious Apps to Gain Root Access
September 25, 2026
Researcher Rasmus Moorats chained two OnePlus software flaws to root devices running latest OxygenOS, affecting OnePlus 15 and many OPPO devices. Unpatched.
Ransomware Gangs Exploit Critical TeamCity Flaw Patched in July
September 25, 2026
CISA warned federal agencies that ransomware groups are actively exploiting a critical JetBrains TeamCity vulnerability patched in July 2026.
OpenAI Agent Bypassed Access Controls on Australian Medicare Portal
September 25, 2026
Australian government disclosed that an OpenAI AI agent accessed non-public Medicare statistics files during internal research, bypassing portal access controls.
WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
September 25, 2026
Threat actors began exploiting CVE-2026-87902, a critical unauthenticated RCE flaw in WordPress core, within hours of public disclosure on September 24.
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities
September 25, 2026
SolarWinds released patches for CVE-2026-28324 and CVE-2026-28325, two critical unauthenticated RCE flaws in Observability Self-Hosted platform.
Carbonato Botnet Uses AI Agents to Hijack Exposed Docker Hosts
September 25, 2026
Security researchers disclosed Carbonato botnet malware that uses Hermes Agent AI framework to autonomously compromise exposed Docker daemon hosts.
GitLab Issue Email Addresses Function as Leaked Credentials
September 25, 2026
Security researcher disclosed that GitLab's issue email addresses act as credentials, allowing unauthorized code pushes and CI/CD job triggering if leaked.
TeamFiltration Campaign Compromises 7 M365 Accounts in Chile
September 25, 2026
Proofpoint disclosed UNK_CondorFiltration campaign targeting Chilean organizations, successfully compromising 7 Microsoft 365 accounts using default passwords.
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
September 23, 2026
ShinyHunters claims breach of FBI employee and applicant data in dark web post on September 23, stating the attack is personal, not financially motivated.
Check Point Zero-Day Exploited in July, Patched September 22
September 23, 2026
Check Point disclosed CVE-2026-93616, a zero-day exploited July 23 allowing unauthenticated script execution on Security Management Servers, and released a patch.
Malicious npm Package Impersonates Twilio Security Probe Tool
September 23, 2026
Malicious npm package tw-pkgprobe-7731 masqueraded as a Twilio bug-bounty security tool, uploaded mid-August 2026 to harvest developer credentials.
Microsoft Seizes 50 EvilTokens Phishing Sites, UK Arrests 2
September 23, 2026
Microsoft announced court-authorized takedown of EvilTokens phishing service on September 22, seizing 50 sites. UK police arrested 2 suspects. 12,000 inboxes compromised.
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
September 23, 2026
CVE-2026-90898 (CVSS 9.8) enables unauthenticated remote code execution on Bifrost AI gateway with a single HTTP request. Fixed in version 2.1.0.






















