Cyber Security
Four Nation-State Groups Deploy BlueMoon Kit Within 12 Days
NSA, CISA, FBI Accuse Six Chinese AI Firms of Model Distillation
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
Attackers Use BYOD Weaknesses to Access M365 via Graph API
Surfshark VPN Breach Exposes Internal Testing and Proxy Servers
Citrix NetScaler CVE-2026-19490 Exploited Since September 3
CISA Sets September 12 Deadline for Cisco, Citrix, Fortinet Flaws
Infostealer Logs Expose Replayable AI Tokens That Bypass MFA
Google Patches Seventh Chrome Zero-Day of 2026, CVE-2026-87491
PoisonedRefresh Rootkit Injects PHP Web Shells into F5 BIG-IP Memory
September Windows Server Updates Break Remote Desktop Services
Microsoft Excel KB5002914 Update Breaks Copy and Paste Functions
cPanel Critical RCE Enables Full Server Takeover via Mail Account
SAP Patches CVSS 10.0 Kernel RCE in Extended Passport Processing
Microsoft Ships Record 974 Security Patches in September Batch
ShinyHunters Claims Breach of Florida DMV DAVID Database
Grindr Settles UK HIV Data Sharing Lawsuit for £26 Million
Liquid Network Attackers Return 3,400 Bitcoin, Keep $47 Million
OpenAI Artifactory Flaw Enabled Cross-Account Data Theft
Boston Scientific Cyberattack Damages Q3 and Full-Year Earnings
Ohio Man Sentenced to 15 Years for AI-Generated Sextortion
LG Accused of Privacy Violations Over Smart TV Data Collection
Microsoft Adds Age-Awareness APIs to Windows 11
EU Cyber Resilience Act 24-Hour Vulnerability Deadline Arrives
UK Lawmakers Question Cyber Bill’s Executive Liability Exemption
Welsh Regulator Exposes 2,000 Staff Diversity Records via FoI Error
OpenAI Agent Swarm Logs Reveal Emergent Deception and Coordination
PEEP Toolkit Turns Chrome and Edge Into Post-Exploitation Backdoors
Magento StyleSmuggler Zero-Day Deploys Linux Backdoors on Stores
Mathspace Breach Exposes Data of Over 1 Million Students and Staff
CVE Vulnerability Alerts
Cisco Secure Workload CVE-2026-20223 Earns CVSS 10.0
CVE-2026-20223 lets unauthenticated remote attackers gain full Site Admin access to Cisco Secure Workload; no credentials or user interaction are required.
Application Security
NGINX 1.31.0 Zero-Day nginx-poolslip Bypasses ASLR
Researcher Vega publicly disclosed nginx-poolslip, an unpatched RCE zero-day in NGINX 1.31.0 that bypasses ASLR and threatens tens of millions of servers.
Cybersecurity
WantToCry Ransomware Hits SMB Ports, Evades EDR Tools
Sophos CTU analysis reveals WantToCry ransomware encrypts files off-device via brute-forced SMB sessions, leaving no local binary for EDR tools to detect.
Cybersecurity
DOJ Secures Guilty Pleas From Tech-Support Fraud Executives
Two U.S. telecom executives pleaded guilty to concealing a six-year tech-support fraud scheme that cost Americans an estimated $2.1 billion annually.
Application Security
BadIIS Malware-as-a-Service Hijacks IIS Servers for SEO Fraud
Cisco Talos exposed BadIIS, a Chinese-speaking MaaS platform hijacking IIS servers to redirect traffic and manipulate search rankings since 2021.
Cybersecurity
GhostTree Exploit Hangs Windows Defender With NTFS Junctions
Varonis Threat Labs disclosed GhostTree, an NTFS junction loop technique that causes Windows Defender to hang and fail to detect hidden malware files.
Cybersecurity
SilverFox APT Spreads ValleyRAT via Fake Microsoft Teams Sites
K7 Security Labs found SilverFox APT serving ValleyRAT via trojanized Teams installers on teams-securecall.com, targeting credentials and crypto wallets.
Application Security
TamperedChef Hides Malware Inside Signed Apps
Palo Alto's Unit 42 documented TamperedChef, a signed-app malware campaign with 12,000 global infections using digitally signed certificates to evade detection.
Application Security
Chrome 148 Patches Critical WebRTC Use-After-Free
Google patched 16 Chrome vulnerabilities including critical CVE-2026-9111, a WebRTC use-after-free enabling drive-by exploitation without user interaction.
CVE Vulnerability Alerts
P2PInfect Botnet Infiltrates Kubernetes Clusters via Redis
FortiGuard found P2PInfect enrolled enterprise GKE Kubernetes clusters for six months undetected via exposed Redis instances and a 2022 CVSS 10.0 flaw.
Group-IB Exposes Five Brokers Fabricating Breach Alerts From Old Leaks
Cybersecurity
Group-IB Exposes Five Brokers Fabricating Breach Alerts From Old Leaks
Group-IB identified five dark web brokers posting 500–1,000 fake corporate breach ads monthly using recycled Facebook 2021, Eatigo, and Truecaller leak data.
Cybersecurity
NYC Health + Hospitals Breach Exposes 1.8M Patients’ Fingerprints
Hackers spent 77 days inside NYC Health + Hospitals via a vendor breach, stealing fingerprints, medical records, and SSNs from 1.8 million patients.
Cybersecurity
Poland Drops Signal After Russian APTs Compromise Officials’ Accounts
Poland abandoned Signal after Russian APTs compromised officials' accounts via fake support calls and malicious QR codes that bypassed its encryption.
Cybersecurity
EvilTokens Service Breaches 340 Microsoft 365 Orgs via OAuth Tokens
EvilTokens, a phishing service launched in February 2026, bypassed MFA in 340 Microsoft 365 organizations by stealing OAuth tokens instead of passwords.
Cybersecurity
Webworm APT Uses Discord and OneDrive as C2 in Government Espionage
Webworm, a China-aligned APT, deployed EchoCreep and GraphWorm backdoors that abuse Discord and Microsoft OneDrive as C2 channels against government targets.
Cybersecurity
PinTheft PoC Goes Public, Narrowing Arch Linux Exploit Window
V12 security team released a working PinTheft exploit for an Arch Linux kernel double-free, enabling local root escalation on unpatched systems with RDS loaded.
Application Security
Anthropic Silently Fixed Claude Code Null-Byte Sandbox Escape
A null-byte sandbox bypass in Claude Code allowed credential exfiltration via prompt injection, present from October 2025 until Anthropic's silent March patch.
Cybersecurity
Huawei Zero-Day Caused Luxembourg’s 3-Hour National Telecom Blackout
A zero-day in Huawei routers crashed Luxembourg's national telecom in July 2025 for three hours, cutting emergency services, with no CVE and no confirmed patch.
Application Security
CVE-2026-3102: ExifTool Image Injection Runs Shell Commands on macOS
CVE-2026-3102 in ExifTool's SetMacOSTags lets a crafted image execute shell commands on macOS; the flaw is patched in ExifTool 13.50 after Kaspersky disclosure.
Application Security
Single-Letter Go Typosquat Backdoors Financial and Crypto Developers
A Go module typosquatting shopspring/decimal deployed a DNS-based backdoor polling for OS commands every five minutes, targeting financial app developers.
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Cybersecurity
ShinyHunters Claims Breach of Florida DMV DAVID Database
Application Security
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
CVE Vulnerability Alerts
Aurora Ransomware Operators Use Cursor AI to Execute Network Attacks

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Cybersecurity
LG Accused of Privacy Violations Over Smart TV Data Collection
Application Security
OpenAI Agents Made 18,000 Unauthorized Edits to German Wiki
Application Security
Judge Rules Pentagon Actions Against Anthropic Unlawful
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
DOJ Secures Guilty Pleas From Tech-Support Fraud Executives
Two U.S. telecom executives pleaded guilty to concealing a six-year tech-support fraud scheme that cost Americans an estimated $2.1 billion annually.
BadIIS Malware-as-a-Service Hijacks IIS Servers for SEO Fraud
Cisco Talos exposed BadIIS, a Chinese-speaking MaaS platform hijacking IIS servers to redirect traffic and manipulate search rankings since 2021.
GhostTree Exploit Hangs Windows Defender With NTFS Junctions
Varonis Threat Labs disclosed GhostTree, an NTFS junction loop technique that causes Windows Defender to hang and fail to detect hidden malware files.
SilverFox APT Spreads ValleyRAT via Fake Microsoft Teams Sites
K7 Security Labs found SilverFox APT serving ValleyRAT via trojanized Teams installers on teams-securecall.com, targeting credentials and crypto wallets.
TamperedChef Hides Malware Inside Signed Apps
Palo Alto's Unit 42 documented TamperedChef, a signed-app malware campaign with 12,000 global infections using digitally signed certificates to evade detection.
Chrome 148 Patches Critical WebRTC Use-After-Free
Google patched 16 Chrome vulnerabilities including critical CVE-2026-9111, a WebRTC use-after-free enabling drive-by exploitation without user interaction.
P2PInfect Botnet Infiltrates Kubernetes Clusters via Redis
FortiGuard found P2PInfect enrolled enterprise GKE Kubernetes clusters for six months undetected via exposed Redis instances and a 2022 CVSS 10.0 flaw.
Group-IB Exposes Five Brokers Fabricating Breach Alerts From Old Leaks
Group-IB identified five dark web brokers posting 500–1,000 fake corporate breach ads monthly using recycled Facebook 2021, Eatigo, and Truecaller leak data.
NYC Health + Hospitals Breach Exposes 1.8M Patients’ Fingerprints
Hackers spent 77 days inside NYC Health + Hospitals via a vendor breach, stealing fingerprints, medical records, and SSNs from 1.8 million patients.
Poland Drops Signal After Russian APTs Compromise Officials’ Accounts
Poland abandoned Signal after Russian APTs compromised officials' accounts via fake support calls and malicious QR codes that bypassed its encryption.
EvilTokens Service Breaches 340 Microsoft 365 Orgs via OAuth Tokens
EvilTokens, a phishing service launched in February 2026, bypassed MFA in 340 Microsoft 365 organizations by stealing OAuth tokens instead of passwords.
Webworm APT Uses Discord and OneDrive as C2 in Government Espionage
Webworm, a China-aligned APT, deployed EchoCreep and GraphWorm backdoors that abuse Discord and Microsoft OneDrive as C2 channels against government targets.
PinTheft PoC Goes Public, Narrowing Arch Linux Exploit Window
V12 security team released a working PinTheft exploit for an Arch Linux kernel double-free, enabling local root escalation on unpatched systems with RDS loaded.
Anthropic Silently Fixed Claude Code Null-Byte Sandbox Escape
A null-byte sandbox bypass in Claude Code allowed credential exfiltration via prompt injection, present from October 2025 until Anthropic's silent March patch.
Huawei Zero-Day Caused Luxembourg’s 3-Hour National Telecom Blackout
A zero-day in Huawei routers crashed Luxembourg's national telecom in July 2025 for three hours, cutting emergency services, with no CVE and no confirmed patch.
CVE-2026-3102: ExifTool Image Injection Runs Shell Commands on macOS
CVE-2026-3102 in ExifTool's SetMacOSTags lets a crafted image execute shell commands on macOS; the flaw is patched in ExifTool 13.50 after Kaspersky disclosure.
Single-Letter Go Typosquat Backdoors Financial and Crypto Developers
A Go module typosquatting shopspring/decimal deployed a DNS-based backdoor polling for OS commands every five minutes, targeting financial app developers.
CVE-2026-46376: FreePBX Hard-Coded Credentials Open VoIP Portals
CVE-2026-46376 in FreePBX hardcodes setup credentials in the User Control Panel, letting unauthenticated attackers access phone systems and commit toll fraud.
Pardus Linux CVSS 9.3 Flaw Exposes Turkish Government Systems to Root
A three-vulnerability chain in Pardus Linux's pardus-update package lets any local user gain root on Turkish government systems; no patch is available yet.
CVE-2026-46333: Linux Kernel Flaw Grants Root via ssh-keysign
Qualys disclosed CVE-2026-46333, a nine-year-old Linux privilege escalation flaw that gives local users a reliable path to root on Debian, Fedora, and Ubuntu.