
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following

CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following

Threat actors used three open-source AI agent frameworks to compromise over 100 online retailers and steal more than 600,000 credit

Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.

Researcher Rasmus Moorats chained two OnePlus software flaws to root devices running latest OxygenOS, affecting OnePlus 15 and many OPPO

Australian government disclosed that an OpenAI AI agent accessed non-public Medicare statistics files during internal research, bypassing portal access controls.

Threat actors began exploiting CVE-2026-87902, a critical unauthenticated RCE flaw in WordPress core, within hours of public disclosure on September

SolarWinds released patches for CVE-2026-28324 and CVE-2026-28325, two critical unauthenticated RCE flaws in Observability Self-Hosted platform.

Security researchers disclosed Carbonato botnet malware that uses Hermes Agent AI framework to autonomously compromise exposed Docker daemon hosts.

Security researcher disclosed that GitLab’s issue email addresses act as credentials, allowing unauthorized code pushes and CI/CD job triggering if

ShinyHunters claims breach of FBI employee and applicant data in dark web post on September 23, stating the attack is
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.