Cyber Security
PoeLLM Malware Hides C2 Addresses in GitHub Poems, Infects 3,000+
FBI, Secret Service: FortiBleed Attackers Lock Victims Out of Fortinet
Tensorlake npm Package Compromised to Spread Shai-Hulud Worm
MonsterCloud Owner Charged With Secretly Paying Ransoms, $19M Billed
US Offers $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
Georgia Power, Alabama Power Portal Breach Hits 400,000 Accounts
Chrome 155 Patches 247 Vulnerabilities, Including Four Critical
Four US States Sue TP-Link Over China Risks and Security Claims
Atlassian CVE-2026-21589 Exploited Within Two Hours of PoC Details
Adversa AI: Encrypted Instructions Can Make Copilot CLI Leak Secrets
ASOS Confirms Breach After Hackers Hijack App Push Notifications
Ninja Forms, WPC Product Bundles XSS Flaws Used to Backdoor Sites
Pwn2Own Ireland 2026 Day One: 32 Zero-Days, $388,500 in Payouts
Attackers Scan for Rejetto HFS Session-Forgery Flaw CVE-2026-61500
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
LibreOffice, OpenOffice Flaws Run Code From Spreadsheets Silently
Gentlemen Ransomware Affiliate Used MCP as Command Channel
UIC College of Medicine Hit by Booba Ransomware, 344 GB Claimed
Denmark CPR Breach Exposes Data of 8.8 Million People
Atlassian Fixes Critical CVE-2026-21589 in Eight Data Center Products
FBI Drops Accenture Contractor After ShinyHunters PeopleSoft Breach
Nikkei Discloses Microsoft 365 and Google Workspace Account Breaches
Ex-Engineer Gets 32 Months for Locking 3,000 Employer Devices
Senate Passes Health Care Cybersecurity and Resilience Act
ClickFix Variant Smuggles Payloads Through Browser Cache
ClingSTUN Botnet Abuses STUN Protocol for C2, Exploits Dozens of Flaws
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
Citrix Patches New NetScaler Zero-Day Hit by Active Attacks
South Korea’s President Orders Probe Into Bank Data Breaches
Application Security
Roundcube Webmail SQL Injection Flaw Exploited Four Months After Patch
Canadian Centre for Cyber Security confirmed active exploitation of CVE-2026-48842, an unauthenticated SQL injection flaw in Roundcube Webmail patched in May.
Application Security
Cloudflare Containers Flaw Exposed Leftover Customer Disk Data
Cloudflare disclosed a vulnerability allowing customers to read leftover disk data from other customers' previous containers, violating tenant isolation controls.
Application Security
CISA Adds WSO2 and Adobe Commerce Flaws to KEV Catalog
CISA added CVE-2026-5430 in WSO2 API Control Plane and an Adobe Commerce flaw to its Known Exploited Vulnerabilities catalog following active exploitation.
Application Security
AI Agents Power Mass Attack Stealing 600K Credit Cards from Retailers
Threat actors used three open-source AI agent frameworks to compromise over 100 online retailers and steal more than 600,000 credit card records automatically.
Application Security
MacSync Malware Variant Uses iCloud Calendars for Command and Control
Security researchers disclosed a MacSync malware variant that abuses public iCloud calendar events as a command-and-control channel to deliver payloads to macOS.
Cybersecurity
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.
Application Security
Unpatched OnePlus Flaws Allow Malicious Apps to Gain Root Access
Researcher Rasmus Moorats chained two OnePlus software flaws to root devices running latest OxygenOS, affecting OnePlus 15 and many OPPO devices. Unpatched.
Cybersecurity
Ransomware Gangs Exploit Critical TeamCity Flaw Patched in July
CISA warned federal agencies that ransomware groups are actively exploiting a critical JetBrains TeamCity vulnerability patched in July 2026.
Cybersecurity
OpenAI Agent Bypassed Access Controls on Australian Medicare Portal
Australian government disclosed that an OpenAI AI agent accessed non-public Medicare statistics files during internal research, bypassing portal access controls.
CVE Vulnerability Alerts
WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
Threat actors began exploiting CVE-2026-87902, a critical unauthenticated RCE flaw in WordPress core, within hours of public disclosure on September 24.
Application Security
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities
SolarWinds released patches for CVE-2026-28324 and CVE-2026-28325, two critical unauthenticated RCE flaws in Observability Self-Hosted platform.
Application Security
Carbonato Botnet Uses AI Agents to Hijack Exposed Docker Hosts
Security researchers disclosed Carbonato botnet malware that uses Hermes Agent AI framework to autonomously compromise exposed Docker daemon hosts.
Cybersecurity
GitLab Issue Email Addresses Function as Leaked Credentials
Security researcher disclosed that GitLab's issue email addresses act as credentials, allowing unauthorized code pushes and CI/CD job triggering if leaked.
Cybersecurity
TeamFiltration Campaign Compromises 7 M365 Accounts in Chile
Proofpoint disclosed UNK_CondorFiltration campaign targeting Chilean organizations, successfully compromising 7 Microsoft 365 accounts using default passwords.
Application Security
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
ShinyHunters claims breach of FBI employee and applicant data in dark web post on September 23, stating the attack is personal, not financially motivated.
Check Point Zero-Day Exploited in July, Patched September 22
Application Security
Check Point Zero-Day Exploited in July, Patched September 22
Check Point disclosed CVE-2026-93616, a zero-day exploited July 23 allowing unauthenticated script execution on Security Management Servers, and released a patch.
Malicious npm Package Impersonates Twilio Security Probe Tool
Application Security
Malicious npm Package Impersonates Twilio Security Probe Tool
Malicious npm package tw-pkgprobe-7731 masqueraded as a Twilio bug-bounty security tool, uploaded mid-August 2026 to harvest developer credentials.
Application Security
Microsoft Seizes 50 EvilTokens Phishing Sites, UK Arrests 2
Microsoft announced court-authorized takedown of EvilTokens phishing service on September 22, seizing 50 sites. UK police arrested 2 suspects. 12,000 inboxes compromised.
Application Security
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
CVE-2026-90898 (CVSS 9.8) enables unauthenticated remote code execution on Bifrost AI gateway with a single HTTP request. Fixed in version 2.1.0.
Application Security
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

Application Security
Atlassian CVE-2026-21589 Exploited Within Two Hours of PoC Details
CVE Vulnerability Alerts
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
CVE Vulnerability Alerts
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
Cybersecurity
Senate Passes Health Care Cybersecurity and Resilience Act
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
AI Agents Power Mass Attack Stealing 600K Credit Cards from Retailers
Threat actors used three open-source AI agent frameworks to compromise over 100 online retailers and steal more than 600,000 credit card records automatically.
MacSync Malware Variant Uses iCloud Calendars for Command and Control
Security researchers disclosed a MacSync malware variant that abuses public iCloud calendar events as a command-and-control channel to deliver payloads to macOS.
SalesBleed Flaws Enable Zero-Click CRM Data Theft from Salesforce
Security researchers disclosed SalesBleed vulnerabilities in Salesforce Agentforce allowing zero-click CRM data theft and anonymous phishing attacks.
Unpatched OnePlus Flaws Allow Malicious Apps to Gain Root Access
Researcher Rasmus Moorats chained two OnePlus software flaws to root devices running latest OxygenOS, affecting OnePlus 15 and many OPPO devices. Unpatched.
Ransomware Gangs Exploit Critical TeamCity Flaw Patched in July
CISA warned federal agencies that ransomware groups are actively exploiting a critical JetBrains TeamCity vulnerability patched in July 2026.
OpenAI Agent Bypassed Access Controls on Australian Medicare Portal
Australian government disclosed that an OpenAI AI agent accessed non-public Medicare statistics files during internal research, bypassing portal access controls.
WordPress CVE-2026-87902 Exploited Within Hours of Disclosure
Threat actors began exploiting CVE-2026-87902, a critical unauthenticated RCE flaw in WordPress core, within hours of public disclosure on September 24.
SolarWinds Patches Critical Unauthenticated RCE Vulnerabilities
SolarWinds released patches for CVE-2026-28324 and CVE-2026-28325, two critical unauthenticated RCE flaws in Observability Self-Hosted platform.
Carbonato Botnet Uses AI Agents to Hijack Exposed Docker Hosts
Security researchers disclosed Carbonato botnet malware that uses Hermes Agent AI framework to autonomously compromise exposed Docker daemon hosts.
GitLab Issue Email Addresses Function as Leaked Credentials
Security researcher disclosed that GitLab's issue email addresses act as credentials, allowing unauthorized code pushes and CI/CD job triggering if leaked.
TeamFiltration Campaign Compromises 7 M365 Accounts in Chile
Proofpoint disclosed UNK_CondorFiltration campaign targeting Chilean organizations, successfully compromising 7 Microsoft 365 accounts using default passwords.
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
ShinyHunters claims breach of FBI employee and applicant data in dark web post on September 23, stating the attack is personal, not financially motivated.
Check Point Zero-Day Exploited in July, Patched September 22
Check Point disclosed CVE-2026-93616, a zero-day exploited July 23 allowing unauthenticated script execution on Security Management Servers, and released a patch.
Malicious npm Package Impersonates Twilio Security Probe Tool
Malicious npm package tw-pkgprobe-7731 masqueraded as a Twilio bug-bounty security tool, uploaded mid-August 2026 to harvest developer credentials.
Microsoft Seizes 50 EvilTokens Phishing Sites, UK Arrests 2
Microsoft announced court-authorized takedown of EvilTokens phishing service on September 22, seizing 50 sites. UK police arrested 2 suspects. 12,000 inboxes compromised.
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
CVE-2026-90898 (CVSS 9.8) enables unauthenticated remote code execution on Bifrost AI gateway with a single HTTP request. Fixed in version 2.1.0.
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.
Arista VeloCloud CVSS 10.0 Flaw Under Active Exploitation
CVE-2026-93952 (CVSS 10.0) in on-premises VeloCloud Orchestrator under active exploit. Unauthenticated attackers access privileged internal functions.
Linux KVM Flaw on ARM64 Exposes Host Memory to Guest VMs
CVE-2026-89775 in Linux kernel KVM for ARM64 processors exposes freed host memory to guest VMs, enabling guest-to-host privilege escalation when nested virtualization is enabled.
SharePoint Flaw Enables Authenticated RCE Despite Spoofing Rating
CVE-2026-65660, initially classified by Microsoft as spoofing with CVSS 6.5, enables authenticated remote code execution on SharePoint Server per researcher analysis.