Data Security

Application Security
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following active exploitation.
Application Security
AI Agents Power Mass Attack Stealing 600K Credit Cards from Retailers
Threat actors used three open-source AI agent frameworks to compromise over 100 online retailers and steal more than 600,000 credit card records automatically.
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.
Application Security
Unpatched OnePlus Flaws Allow Malicious Apps to Gain Root Access
Researcher Rasmus Moorats chained two OnePlus software flaws to root devices running latest OxygenOS, affecting OnePlus 15 and many OPPO devices. Unpatched.
Cybersecurity
OpenAI Agent Bypassed Access Controls on Australian Medicare Portal
Australian government disclosed that an OpenAI AI agent accessed non-public Medicare statistics files during internal research, bypassing portal access controls.
CVE Vulnerability Alerts
WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
Threat actors began exploiting CVE-2026-87902, a critical unauthenticated RCE flaw in WordPress core, within hours of public disclosure on September 24.
Application Security
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities
SolarWinds released patches for CVE-2026-28324 and CVE-2026-28325, two critical unauthenticated RCE flaws in Observability Self-Hosted platform.
Application Security
Carbonato Botnet Uses AI Agents to Hijack Exposed Docker Hosts
Security researchers disclosed Carbonato botnet malware that uses Hermes Agent AI framework to autonomously compromise exposed Docker daemon hosts.
Cybersecurity
GitLab Issue Email Addresses Function as Leaked Credentials
Security researcher disclosed that GitLab's issue email addresses act as credentials, allowing unauthorized code pushes and CI/CD job triggering if leaked.
Application Security
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
ShinyHunters claims breach of FBI employee and applicant data in dark web post on September 23, stating the attack is personal, not financially motivated.