News

CVE Vulnerability Alerts
WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
Threat actors began exploiting CVE-2026-87902, a critical unauthenticated RCE flaw in WordPress core, within hours of public disclosure on September 24.
Application Security
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities
SolarWinds released patches for CVE-2026-28324 and CVE-2026-28325, two critical unauthenticated RCE flaws in Observability Self-Hosted platform.
Application Security
Carbonato Botnet Uses AI Agents to Hijack Exposed Docker Hosts
Security researchers disclosed Carbonato botnet malware that uses Hermes Agent AI framework to autonomously compromise exposed Docker daemon hosts.
Cybersecurity
GitLab Issue Email Addresses Function as Leaked Credentials
Security researcher disclosed that GitLab's issue email addresses act as credentials, allowing unauthorized code pushes and CI/CD job triggering if leaked.
Cybersecurity
TeamFiltration Campaign Compromises 7 M365 Accounts in Chile
Proofpoint disclosed UNK_CondorFiltration campaign targeting Chilean organizations, successfully compromising 7 Microsoft 365 accounts using default passwords.
Application Security
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
ShinyHunters claims breach of FBI employee and applicant data in dark web post on September 23, stating the attack is personal, not financially motivated.
Check Point Zero-Day Exploited in July, Patched September 22
Application Security
Check Point Zero-Day Exploited in July, Patched September 22
Check Point disclosed CVE-2026-93616, a zero-day exploited July 23 allowing unauthenticated script execution on Security Management Servers, and released a patch.
Malicious npm Package Impersonates Twilio Security Probe Tool
Application Security
Malicious npm Package Impersonates Twilio Security Probe Tool
Malicious npm package tw-pkgprobe-7731 masqueraded as a Twilio bug-bounty security tool, uploaded mid-August 2026 to harvest developer credentials.
Application Security
Microsoft Seizes 50 EvilTokens Phishing Sites, UK Arrests 2
Microsoft announced court-authorized takedown of EvilTokens phishing service on September 22, seizing 50 sites. UK police arrested 2 suspects. 12,000 inboxes compromised.
Application Security
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
CVE-2026-90898 (CVSS 9.8) enables unauthenticated remote code execution on Bifrost AI gateway with a single HTTP request. Fixed in version 2.1.0.