Endpoint Security

Application Security
MacSync Malware Variant Uses iCloud Calendars for Command and Control
Security researchers disclosed a MacSync malware variant that abuses public iCloud calendar events as a command-and-control channel to deliver payloads to macOS.
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.
Application Security
Unpatched OnePlus Flaws Allow Malicious Apps to Gain Root Access
Researcher Rasmus Moorats chained two OnePlus software flaws to root devices running latest OxygenOS, affecting OnePlus 15 and many OPPO devices. Unpatched.
Cybersecurity
Ransomware Gangs Exploit Critical TeamCity Flaw Patched in July
CISA warned federal agencies that ransomware groups are actively exploiting a critical JetBrains TeamCity vulnerability patched in July 2026.
CVE Vulnerability Alerts
WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
Threat actors began exploiting CVE-2026-87902, a critical unauthenticated RCE flaw in WordPress core, within hours of public disclosure on September 24.
Application Security
Carbonato Botnet Uses AI Agents to Hijack Exposed Docker Hosts
Security researchers disclosed Carbonato botnet malware that uses Hermes Agent AI framework to autonomously compromise exposed Docker daemon hosts.
Malicious npm Package Impersonates Twilio Security Probe Tool
Application Security
Malicious npm Package Impersonates Twilio Security Probe Tool
Malicious npm package tw-pkgprobe-7731 masqueraded as a Twilio bug-bounty security tool, uploaded mid-August 2026 to harvest developer credentials.
Application Security
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.
Application Security
Malicious npm Package indexed-btree Hides Payload in Runtime Code
indexed-btree npm package hides malicious behavior in application runtime code instead of lifecycle scripts, evading npm security controls, per Checkmarx researchers.
Application Security
SideCopy Expands India Targeting to Academic Institutions
SideCopy threat actor expanded targeting from Indian government to academic institutions using spear-phishing with ReverseRAT and mshta.exe abuse, per Trellix research.