Cyber Security
Attackers Scan for Rejetto HFS Session-Forgery Flaw CVE-2026-61500
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
LibreOffice, OpenOffice Flaws Run Code From Spreadsheets Silently
Gentlemen Ransomware Affiliate Used MCP as Command Channel
UIC College of Medicine Hit by Booba Ransomware, 344 GB Claimed
Denmark CPR Breach Exposes Data of 8.8 Million People
Atlassian Fixes Critical CVE-2026-21589 in Eight Data Center Products
FBI Drops Accenture Contractor After ShinyHunters PeopleSoft Breach
Nikkei Discloses Microsoft 365 and Google Workspace Account Breaches
Ex-Engineer Gets 32 Months for Locking 3,000 Employer Devices
Senate Passes Health Care Cybersecurity and Resilience Act
ClickFix Variant Smuggles Payloads Through Browser Cache
ClingSTUN Botnet Abuses STUN Protocol for C2, Exploits Dozens of Flaws
Rejetto HFS Flaw Lets Hackers Forge Admin Sessions for RCE
Citrix Patches New NetScaler Zero-Day Hit by Active Attacks
South Korea’s President Orders Probe Into Bank Data Breaches
Alleged ShinyHunters Leader ‘Rey’ Reportedly Held in Jordan
Nikkei Discloses M365 Breach, 9,000 Spoofed Emails Sent
Google Pauses Open-Source Bug Bounty Over AI Report Flood
Critical FortiMail Zero-Day Exploited With No Patch Yet
Police Dismantle KillSec Ransomware Gang, Nab Teen Leader
Kiteworks Patches Second Max-Severity Flaw in a Week
Self-Healing WordPress Backdoor Defies Standard Removal
Cisco Patches Actively Exploited Catalyst SD-WAN Flaw
MetaMask Discloses Incident, Exits Ethereum Validators
TeamViewer Patches Critical Access-Control Bypass Flaw
WatchGuard Patches Critical Root Code Execution Flaw
CISA Warns of Critical Pre-Auth Flaw in MikroTik Routers
FTC Confirms Probe Into OpenAI, Anthropic AI Agents
Cybersecurity
TeamFiltration Campaign Compromises 7 M365 Accounts in Chile
Proofpoint disclosed UNK_CondorFiltration campaign targeting Chilean organizations, successfully compromising 7 Microsoft 365 accounts using default passwords.
Application Security
ShinyHunters Claims FBI Employee Data Breach in Dark Web Post
ShinyHunters claims breach of FBI employee and applicant data in dark web post on September 23, stating the attack is personal, not financially motivated.
Check Point Zero-Day Exploited in July, Patched September 22
Application Security
Check Point Zero-Day Exploited in July, Patched September 22
Check Point disclosed CVE-2026-93616, a zero-day exploited July 23 allowing unauthenticated script execution on Security Management Servers, and released a patch.
Malicious npm Package Impersonates Twilio Security Probe Tool
Application Security
Malicious npm Package Impersonates Twilio Security Probe Tool
Malicious npm package tw-pkgprobe-7731 masqueraded as a Twilio bug-bounty security tool, uploaded mid-August 2026 to harvest developer credentials.
Application Security
Microsoft Seizes 50 EvilTokens Phishing Sites, UK Arrests 2
Microsoft announced court-authorized takedown of EvilTokens phishing service on September 22, seizing 50 sites. UK police arrested 2 suspects. 12,000 inboxes compromised.
Application Security
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
CVE-2026-90898 (CVSS 9.8) enables unauthenticated remote code execution on Bifrost AI gateway with a single HTTP request. Fixed in version 2.1.0.
Application Security
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.
Application Security
Arista VeloCloud CVSS 10.0 Flaw Under Active Exploitation
CVE-2026-93952 (CVSS 10.0) in on-premises VeloCloud Orchestrator under active exploit. Unauthenticated attackers access privileged internal functions.
CVE Vulnerability Alerts
Linux KVM Flaw on ARM64 Exposes Host Memory to Guest VMs
CVE-2026-89775 in Linux kernel KVM for ARM64 processors exposes freed host memory to guest VMs, enabling guest-to-host privilege escalation when nested virtualization is enabled.
Application Security
SharePoint Flaw Enables Authenticated RCE Despite Spoofing Rating
CVE-2026-65660, initially classified by Microsoft as spoofing with CVSS 6.5, enables authenticated remote code execution on SharePoint Server per researcher analysis.
Application Security
Malicious npm Package indexed-btree Hides Payload in Runtime Code
indexed-btree npm package hides malicious behavior in application runtime code instead of lifecycle scripts, evading npm security controls, per Checkmarx researchers.
Application Security
SideCopy Expands India Targeting to Academic Institutions
SideCopy threat actor expanded targeting from Indian government to academic institutions using spear-phishing with ReverseRAT and mshta.exe abuse, per Trellix research.
Application Security
Meta Muse AI App Flaw Lets Local Malware Redirect Voice Input
Researcher Patrick Wardle published proof-of-concept on September 21 showing malware can hijack Meta Muse AI assistant by changing a hidden setting to redirect voice input.
Application Security
WordPress Patches Comment2Shell Anonymous-to-RCE Attack Chain
WordPress patched CVE-2026-93485 (Comment2Shell) in version 7.1.1 on September 17, a flaw allowing anonymous comments to achieve RCE when viewed by administrators.
Application Security
Fake LastPass Authenticator Uses Signed Driver to Disable EDR
Fake LastPass Authenticator installer distributed via GitHub installs Microsoft-signed kernel driver to disable antivirus and EDR before deploying password stealer.
Issabel Framework Flaw Enables Unauthenticated OS Command Execution
CVE Vulnerability Alerts
Issabel Framework Flaw Enables Unauthenticated OS Command Execution
CVE-2026-89026 in Issabel Framework under active exploitation allows unauthenticated attackers to execute arbitrary OS commands remotely via hard-coded credentials.
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
Cybersecurity
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
Previously undocumented Brazilian banking malware KREMLIN installs malicious extensions on Chrome and Edge, bypassing security checks to steal credentials and session tokens.
Cybersecurity
North Korean Jade Sleet Breaches Indian IT Provider
North Korean Jade Sleet group compromised an Indian IT services firm using FLATROOF and ROOFDECK backdoors, targeting developers for supply chain attacks.
Malicious npm Packages Bypass Install-Script Detection
Cybersecurity
Malicious npm Packages Bypass Install-Script Detection
npm attackers hide malware in runtime code execution instead of install scripts, evading traditional supply chain defenses targeting the indexed-btree package.
Researchers Escape OpenAI Codex Sandbox, Compromise Staff Accounts
Cybersecurity
Researchers Escape OpenAI Codex Sandbox, Compromise Staff Accounts
Security researchers broke out of OpenAI's Codex sandbox using two methods and chained vulnerabilities to compromise ChatGPT and Codex staff accounts.
Cybersecurity
Gentlemen Ransomware Affiliate Used MCP as Command Channel
Cybersecurity
UIC College of Medicine Hit by Booba Ransomware, 344 GB Claimed

TOP CYBERSECURITY HEADLINES

This Week’s Security Spotlight

CVE Vulnerability Alerts
Dell Patches Root-Level Flaw CVE-2026-86360 in System Update Tool
CVE Vulnerability Alerts
Android October 2026 Update Patches 25 Flaws, Seven Rated Critical
Cybersecurity
Senate Passes Health Care Cybersecurity and Resilience Act
Cybersecurity
South Korea’s President Orders Probe Into Bank Data Breaches
Trending

Daily Briefing Newsletter

Subscribe to the Daily Security Review Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Featured Videos​

  • All
  • Application Security
  • Blog
  • CVE Vulnerability Alerts
  • Cybersecurity
  • Cybersecurity Newsletter
  • Data Security
  • Endpoint Security
  • Identity and Access Management
  • Information Security
  • Network Security
  • News
  • Phishing
  • Podcasts
  • Product Reviews
  • Ransomware
  • Ransomware Victims
  • Resources
  • Security Spotlight
  • Sponsored
  • Threat Actors
  • Threat Actors
  • Threat Detection Tools
Malicious npm Package Impersonates Twilio Security Probe Tool
Malicious npm package tw-pkgprobe-7731 masqueraded as a Twilio bug-bounty security tool, uploaded mid-August 2026 to harvest developer credentials.
Microsoft Seizes 50 EvilTokens Phishing Sites, UK Arrests 2
Microsoft announced court-authorized takedown of EvilTokens phishing service on September 22, seizing 50 sites. UK police arrested 2 suspects. 12,000 inboxes compromised.
Critical Bifrost AI Gateway Flaw Enables Unauthenticated RCE
CVE-2026-90898 (CVSS 9.8) enables unauthenticated remote code execution on Bifrost AI gateway with a single HTTP request. Fixed in version 2.1.0.
BigDiskBuster Zero-Day Blocks Defender Updates, No Patch Issued
Researcher Abdelhamid Naceri published BigDiskBuster proof-of-concept on September 19, preventing Microsoft Defender updates by filling disk space. No patch available.
Arista VeloCloud CVSS 10.0 Flaw Under Active Exploitation
CVE-2026-93952 (CVSS 10.0) in on-premises VeloCloud Orchestrator under active exploit. Unauthenticated attackers access privileged internal functions.
Linux KVM Flaw on ARM64 Exposes Host Memory to Guest VMs
CVE-2026-89775 in Linux kernel KVM for ARM64 processors exposes freed host memory to guest VMs, enabling guest-to-host privilege escalation when nested virtualization is enabled.
SharePoint Flaw Enables Authenticated RCE Despite Spoofing Rating
CVE-2026-65660, initially classified by Microsoft as spoofing with CVSS 6.5, enables authenticated remote code execution on SharePoint Server per researcher analysis.
Malicious npm Package indexed-btree Hides Payload in Runtime Code
indexed-btree npm package hides malicious behavior in application runtime code instead of lifecycle scripts, evading npm security controls, per Checkmarx researchers.
SideCopy Expands India Targeting to Academic Institutions
SideCopy threat actor expanded targeting from Indian government to academic institutions using spear-phishing with ReverseRAT and mshta.exe abuse, per Trellix research.
Meta Muse AI App Flaw Lets Local Malware Redirect Voice Input
Researcher Patrick Wardle published proof-of-concept on September 21 showing malware can hijack Meta Muse AI assistant by changing a hidden setting to redirect voice input.
WordPress Patches Comment2Shell Anonymous-to-RCE Attack Chain
WordPress patched CVE-2026-93485 (Comment2Shell) in version 7.1.1 on September 17, a flaw allowing anonymous comments to achieve RCE when viewed by administrators.
Fake LastPass Authenticator Uses Signed Driver to Disable EDR
Fake LastPass Authenticator installer distributed via GitHub installs Microsoft-signed kernel driver to disable antivirus and EDR before deploying password stealer.
Issabel Framework Flaw Enables Unauthenticated OS Command Execution
CVE-2026-89026 in Issabel Framework under active exploitation allows unauthenticated attackers to execute arbitrary OS commands remotely via hard-coded credentials.
KREMLIN Banking Malware Hijacks Chrome and Edge for Credential Theft
Previously undocumented Brazilian banking malware KREMLIN installs malicious extensions on Chrome and Edge, bypassing security checks to steal credentials and session tokens.
North Korean Jade Sleet Breaches Indian IT Provider
North Korean Jade Sleet group compromised an Indian IT services firm using FLATROOF and ROOFDECK backdoors, targeting developers for supply chain attacks.
Malicious npm Packages Bypass Install-Script Detection
npm attackers hide malware in runtime code execution instead of install scripts, evading traditional supply chain defenses targeting the indexed-btree package.
Researchers Escape OpenAI Codex Sandbox, Compromise Staff Accounts
Security researchers broke out of OpenAI's Codex sandbox using two methods and chained vulnerabilities to compromise ChatGPT and Codex staff accounts.
Single Browser Extension Hijacks AI Assistants Across Five Browsers
BragJack proof-of-concept uses a single malicious extension and Prompt Forcing to hijack AI assistants in Chrome, Edge, Opera Neon, Perplexity, and Claude.
North Korean WaterPlum Stole $10.7M After Infecting 30,000 Devices
North Korean WaterPlum hackers compromised 30,000 devices globally in eight-month campaign, stealing over $10.7 million in cryptocurrency traced to Pyongyang.
ShinyHunters Breaches Clop Ransomware Leak Site, Threatens Gang
ShinyHunters extortion gang compromised Clop's Tor leak site, claiming to have stolen server data and private keys, threatening to extort the ransomware gang.