Cyber Security
Cybersecurity
North Korean Jade Sleet Breaches Indian IT Provider
Andrew Doyle
September 21, 2026
North Korean Jade Sleet group compromised an Indian IT services firm using FLATROOF and ROOFDECK backdoors, targeting developers for supply chain attacks.
Cybersecurity
Malicious npm Packages Bypass Install-Script Detection
Mitchell Langley
September 21, 2026
npm attackers hide malware in runtime code execution instead of install scripts, evading traditional supply chain defenses targeting the indexed-btree package.
Cybersecurity
Researchers Escape OpenAI Codex Sandbox, Compromise Staff Accounts
Gabby Lee
September 21, 2026
Security researchers broke out of OpenAI's Codex sandbox using two methods and chained vulnerabilities to compromise ChatGPT and Codex staff accounts.
Application Security
Single Browser Extension Hijacks AI Assistants Across Five Browsers
Andrew Doyle
September 21, 2026
BragJack proof-of-concept uses a single malicious extension and Prompt Forcing to hijack AI assistants in Chrome, Edge, Opera Neon, Perplexity, and Claude.
Cybersecurity
North Korean WaterPlum Stole $10.7M After Infecting 30,000 Devices
Mitchell Langley
September 21, 2026
North Korean WaterPlum hackers compromised 30,000 devices globally in eight-month campaign, stealing over $10.7 million in cryptocurrency traced to Pyongyang.
Cybersecurity
ShinyHunters Breaches Clop Ransomware Leak Site, Threatens Gang
Gabby Lee
September 21, 2026
ShinyHunters extortion gang compromised Clop's Tor leak site, claiming to have stolen server data and private keys, threatening to extort the ransomware gang.
Cybersecurity
Viral AI Actress Service Face-Scans Callers, Tracks Emotions
Gabby Lee
September 21, 2026
Tilly Norwood's Talking Tilly video call service scans every caller's face for age verification and monitors emotions before shutdown on September 27.
Cybersecurity
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
Andrew Doyle
September 11, 2026
Russian threat actor deployed hundreds of AI agents to exploit PaperCut vulnerabilities, compromising 395-440+ organizations between August 15 and September 8.
Application Security
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
Andrew Doyle
September 11, 2026
Two concurrent Android banking malware campaigns — GoldFactory's Gigabud trojan and Mantax Otax ransomware-spyware hybrid — target Indonesian users with credential theft and harassment.
Application Security
Thousands of Scam Apps Exploit Google Play Early Access Program
Mitchell Langley
September 11, 2026
Malicious developers abuse Google Play's Early Access program to push thousands of deceptive Android apps promising money, rewards, and premium content that do not deliver.
Cybersecurity
Four Nation-State Groups Deploy BlueMoon Kit Within 12 Days
Andrew Doyle
September 11, 2026
APT31 and three additional nation-state actors deployed the BlueMoon exploit kit chaining Chrome and Windows zero-days within a two-week window, with researchers suspecting AI assistance.
Cybersecurity
NSA, CISA, FBI Accuse Six Chinese AI Firms of Model Distillation
Andrew Doyle
September 11, 2026
US intelligence agencies accuse DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of extracting billions of tokens from OpenAI, Anthropic, Google, and SpaceX at industrial ...
Application Security
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
Mitchell Langley
September 11, 2026
China-linked UNC3569 exploited a vulnerability in Tencent's Sogou Input Method, one of the most widely used Chinese typing tools for Windows, to install GRAYRABBIT backdoor ...
Application Security
Attackers Use BYOD Weaknesses to Access M365 via Graph API
Mitchell Langley
September 11, 2026
Threat actors exploit BYOD gaps through vishing to gain M365 access, then use Microsoft Graph API to enumerate corporate structure and identify targets for extortion ...
Cybersecurity
Surfshark VPN Breach Exposes Internal Testing and Proxy Servers
Mitchell Langley
September 11, 2026
Surfshark disclosed that hackers accessed internal test servers and proxy infrastructure after a configuration error exposed testing systems to the public internet on September 10.
Application Security
Citrix NetScaler CVE-2026-19490 Exploited Since September 3
Mitchell Langley
September 11, 2026
Critical authentication bypass vulnerability CVE-2026-19490 in Citrix NetScaler has been actively exploited since September 3, enabling unauthenticated attackers to bypass authentication controls.
CVE Vulnerability Alerts
CISA Sets September 12 Deadline for Cisco, Citrix, Fortinet Flaws
Andrew Doyle
September 11, 2026
CISA added three actively exploited vulnerabilities in Cisco, Citrix, and Fortinet products to its KEV catalog on September 10, requiring federal agencies to patch by ...
Application Security
Infostealer Logs Expose Replayable AI Tokens That Bypass MFA
Mitchell Langley
September 11, 2026
Cybercriminals harvest AI session tokens from infostealer malware logs to hijack Google, Anthropic, and OpenAI accounts, bypassing MFA through token replay attacks published September 9.
Application Security
Google Patches Seventh Chrome Zero-Day of 2026, CVE-2026-87491
Andrew Doyle
September 11, 2026
Google released Chrome security update on September 9 patching CVE-2026-87491, an out-of-bounds write in V8 engine — the seventh actively exploited Chrome zero-day of 2026.
Application Security
PoisonedRefresh Rootkit Injects PHP Web Shells into F5 BIG-IP Memory
Andrew Doyle
September 11, 2026
SophosLabs published analysis of PoisonedRefresh, a fileless Linux rootkit that injects PHP web shells directly into F5 BIG-IP APM Apache server memory, leaving no disk ...
Application Security
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
Andrew Doyle
October 5, 2026
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Mitchell Langley
October 5, 2026
Cybersecurity
Ransomware Attack Disrupts Keio Corporation Business Systems
Mitchell Langley
September 29, 2026
TOP CYBERSECURITY HEADLINES
Cybersecurity
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
Application Security
Google Pauses Open-Source Bug Bounty Over AI Report Flood
CVE Vulnerability Alerts
Critical FortiMail Zero-Day Exploited With No Patch Yet
This Week’s Security Spotlight
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Mitchell Langley
October 5, 2026
Application Security
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Gabby Lee
October 5, 2026
Trending
Daily Briefing Newsletter
Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.
Featured Videos
Podcasts
Cyber Security News
Russia’s Star Blizzard Targets 100+ Orgs With Fake Invites
Gabby Lee
September 30, 2026
Fake ChatGPT Custom GPTs Push ClickFix Attacks to Drop RAT
Gabby Lee
September 30, 2026
- All
- Application Security
- Blog
- CVE Vulnerability Alerts
- Cybersecurity
- Cybersecurity Newsletter
- Data Security
- Endpoint Security
- Identity and Access Management
- Information Security
- Network Security
- News
- Phishing
- Podcasts
- Product Reviews
- Ransomware
- Ransomware Victims
- Resources
- Security Spotlight
- Sponsored
- Threat Actors
- Threat Actors
- Threat Detection Tools
Single Browser Extension Hijacks AI Assistants Across Five Browsers
September 21, 2026
BragJack proof-of-concept uses a single malicious extension and Prompt Forcing to hijack AI assistants in Chrome, Edge, Opera Neon, Perplexity, and Claude.
North Korean WaterPlum Stole $10.7M After Infecting 30,000 Devices
September 21, 2026
North Korean WaterPlum hackers compromised 30,000 devices globally in eight-month campaign, stealing over $10.7 million in cryptocurrency traced to Pyongyang.
ShinyHunters Breaches Clop Ransomware Leak Site, Threatens Gang
September 21, 2026
ShinyHunters extortion gang compromised Clop's Tor leak site, claiming to have stolen server data and private keys, threatening to extort the ransomware gang.
Viral AI Actress Service Face-Scans Callers, Tracks Emotions
September 21, 2026
Tilly Norwood's Talking Tilly video call service scans every caller's face for age verification and monitors emotions before shutdown on September 27.
Russian Actor Uses AI to Exploit PaperCut, Hits 440+ Organizations
September 11, 2026
Russian threat actor deployed hundreds of AI agents to exploit PaperCut vulnerabilities, compromising 395-440+ organizations between August 15 and September 8.
GoldFactory and Mantax Otax Target Indonesian Android Bank Users
September 11, 2026
Two concurrent Android banking malware campaigns — GoldFactory's Gigabud trojan and Mantax Otax ransomware-spyware hybrid — target Indonesian users with credential theft and harassment.
Thousands of Scam Apps Exploit Google Play Early Access Program
September 11, 2026
Malicious developers abuse Google Play's Early Access program to push thousands of deceptive Android apps promising money, rewards, and premium content that do not deliver.
Four Nation-State Groups Deploy BlueMoon Kit Within 12 Days
September 11, 2026
APT31 and three additional nation-state actors deployed the BlueMoon exploit kit chaining Chrome and Windows zero-days within a two-week window, with researchers suspecting AI assistance.
NSA, CISA, FBI Accuse Six Chinese AI Firms of Model Distillation
September 11, 2026
US intelligence agencies accuse DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI of extracting billions of tokens from OpenAI, Anthropic, Google, and SpaceX at industrial ...
UNC3569 Exploits Sogou Input Method to Deploy GRAYRABBIT Backdoor
September 11, 2026
China-linked UNC3569 exploited a vulnerability in Tencent's Sogou Input Method, one of the most widely used Chinese typing tools for Windows, to install GRAYRABBIT backdoor ...
Attackers Use BYOD Weaknesses to Access M365 via Graph API
September 11, 2026
Threat actors exploit BYOD gaps through vishing to gain M365 access, then use Microsoft Graph API to enumerate corporate structure and identify targets for extortion ...
Surfshark VPN Breach Exposes Internal Testing and Proxy Servers
September 11, 2026
Surfshark disclosed that hackers accessed internal test servers and proxy infrastructure after a configuration error exposed testing systems to the public internet on September 10.
Citrix NetScaler CVE-2026-19490 Exploited Since September 3
September 11, 2026
Critical authentication bypass vulnerability CVE-2026-19490 in Citrix NetScaler has been actively exploited since September 3, enabling unauthenticated attackers to bypass authentication controls.
CISA Sets September 12 Deadline for Cisco, Citrix, Fortinet Flaws
September 11, 2026
CISA added three actively exploited vulnerabilities in Cisco, Citrix, and Fortinet products to its KEV catalog on September 10, requiring federal agencies to patch by ...
Infostealer Logs Expose Replayable AI Tokens That Bypass MFA
September 11, 2026
Cybercriminals harvest AI session tokens from infostealer malware logs to hijack Google, Anthropic, and OpenAI accounts, bypassing MFA through token replay attacks published September 9.
Google Patches Seventh Chrome Zero-Day of 2026, CVE-2026-87491
September 11, 2026
Google released Chrome security update on September 9 patching CVE-2026-87491, an out-of-bounds write in V8 engine — the seventh actively exploited Chrome zero-day of 2026.
PoisonedRefresh Rootkit Injects PHP Web Shells into F5 BIG-IP Memory
September 11, 2026
SophosLabs published analysis of PoisonedRefresh, a fileless Linux rootkit that injects PHP web shells directly into F5 BIG-IP APM Apache server memory, leaving no disk ...
September Windows Server Updates Break Remote Desktop Services
September 11, 2026
Microsoft's September security updates cause Remote Desktop Services failures on Windows Server 2019, 2022, and 2025, with some systems requiring hard reset reported September 10.
Microsoft Excel KB5002914 Update Breaks Copy and Paste Functions
September 11, 2026
Microsoft's KB5002914 Office security update breaks copy-and-paste operations and formula dragging in Excel, with affected users removing the update to restore functionality reported September 10.
cPanel Critical RCE Enables Full Server Takeover via Mail Account
September 9, 2026
Critical cPanel vulnerability lets authenticated hosting account holders execute root-level code and take complete control of entire server infrastructure.




































