2026-09-26 07:42 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-26 08:55 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds WordPress flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a WordPress Core flaw, tracked as CVE-2026-87902 (CVSS score of 9.2), to its Known Exploited Vulnerabilities (KEV) catalog. CVE-2026-87902 allows an unauthenticated attacker to make the get_page_template() function include a readable local […]
P35
2026-09-25 23:00 UTC
Vendor Research
Palo Alto Networks Unit 42 · Unit 42 · indexed 2026-09-25 23:20 UTC
Unit 42 security experts address critical cybersecurity misconceptions, offering practical insights to help your organization reinforce its enterprise defenses. The post 3 Consulting Myths Debunked by Unit 42 Experts appeared first on Unit 42.
P0
2026-09-25 21:44 UTC
Independent Research
Krebs on Security · BrianKrebs · indexed 2026-09-25 21:55 UTC
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
P0
2026-09-25 21:41 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-25 21:45 UTC
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. [...]
P25
2026-09-25 21:03 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-25 22:00 UTC
U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-65660 is a code-injection vulnerability in Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary […]
P35
2026-09-25 20:57 UTC
Security Journalism
BleepingComputer · Lawrence Abrams · indexed 2026-09-25 21:00 UTC
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...]
P15
2026-09-25 20:30 UTC
Vendor Research
AWS Security Bulletins · aws@amazon.com · indexed 2026-08-15 18:58 UTC
P0
2026-09-25 20:28 UTC
Security Journalism
Dark Reading · George V. Hulme, Contributing Writer · indexed 2026-09-27 20:45 UTC
Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk, and enable business growth are better prepared to face today's threat landscape.
P0
2026-09-25 20:19 UTC
Security Journalism
The Record · indexed 2026-09-25 20:30 UTC
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”
P0
2026-09-25 19:35 UTC
Security Journalism
The Record · indexed 2026-09-25 19:45 UTC
Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices.
P0
2026-09-25 18:39 UTC
Security Journalism
Dark Reading · Jerry Bui · indexed 2026-09-25 19:00 UTC
When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.
P0
2026-09-25 18:13 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-25 18:15 UTC
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]
P0
2026-09-25 18:02 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-25 18:40 UTC
Bitget says suspected North Korea-linked actors stole $351.6M from hot and warm wallets. Withdrawals were suspended while Mandiant investigates. Cryptocurrency exchange Bitget says suspected North Korea-linked threat actors stole $351.6 million from a limited number of hot and warm wallets. The company detected unauthorized transfers on September 24 and temporarily suspended withdrawals. Bitget said customer […]
P0
2026-09-25 17:56 UTC
Security Journalism
Dark Reading · Rob Wright, Alexander Culafi · indexed 2026-09-25 18:15 UTC
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.
P0
2026-09-25 17:24 UTC
Security Journalism
BleepingComputer · Bill Toulas · indexed 2026-09-25 17:35 UTC
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...]
P35
2026-09-25 16:00 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-25 16:10 UTC
Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. [...]
P0
2026-09-25 15:35 UTC
Vendor Research
Microsoft Security Blog · Microsoft Security Research, Yossi Weizman and Tushar Mudi · indexed 2026-09-25 17:40 UTC
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for defenders. The post Storm-3168: Agentic-driven cloud attacks using compromised service principals appeared first on Microsoft Security Blog.
P0
2026-09-25 15:15 UTC
Security Journalism
The Record · indexed 2026-09-25 15:30 UTC
The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the losses.
P0
2026-09-25 15:07 UTC
Security Journalism
Security Week · SecurityWeek News · indexed 2026-09-25 15:10 UTC
Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul. The post In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure appeared first on SecurityWeek.
P0
2026-09-25 15:00 UTC
Security Journalism
The Record · indexed 2026-09-25 15:15 UTC
Dyfed-Powys Police in Wales said a cyberattack affecting the force disrupted some non-emergency systems and may have compromised staff information.
P0
2026-09-25 14:54 UTC
Security Journalism
BleepingComputer · Mayank Parmar · indexed 2026-09-25 14:55 UTC
OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]
P0
2026-09-25 14:51 UTC
Security Journalism
BleepingComputer · Sponsored by Token Security · indexed 2026-09-25 14:55 UTC
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. [...]
P0
2026-09-25 14:46 UTC
Security Journalism
Dark Reading · Robert Lemos · indexed 2026-09-25 15:45 UTC
Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.
P0
2026-09-25 14:44 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 16:10 UTC
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment Visiting either of the repositories now shows the message: "Access to this
P0
2026-09-25 14:38 UTC
Vendor Research
Rapid7 · The Metasploit Team · indexed 2026-09-25 15:20 UTC
P0
2026-09-25 14:16 UTC
Security Journalism
Security Week · Eduard Kovacs · indexed 2026-09-25 14:30 UTC
Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen. The post North Korea Suspected in $351 Million Bitget Crypto Heist appeared first on SecurityWeek.
P0
2026-09-25 14:00 UTC
Vendor Research
Google Threat Intelligence / Mandiant · Mandiant · indexed 2026-09-26 06:55 UTC
Introduction As an update to the June 2026 post, ShinyHunters Targets Education Sector with Oracle PeopleSoft Exploit, Mandiant and Google Threat Intelligence Group (GTIG) have identified renewed mass exploitation of CVE-2026-35273 by UNC6240 (ShinyHunters), along with expanded global targeting across multiple sectors. In June, the threat actor exploited this vulnerability as a zero-day predominantly against academic institutions. This new wave of activity stems from UNC6240 modifying its explo…
P50
2026-09-25 13:49 UTC
Other
Security Affairs · Pierluigi Paganini · indexed 2026-09-25 14:10 UTC
Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psychedelic Stealer is being distributed through compromised Ukrainian business websites. Attackers injected hidden iframes into legitimate pages and used them to display a fake Cloudflare verification screen to visitors. The affected sites included a hair-treatment […]
P0
2026-09-25 13:18 UTC
Security Journalism
The Hacker News · info@thehackernews.com (The Hacker News) · indexed 2026-09-25 16:10 UTC
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material
P0
2026-09-25 13:00 UTC
Security Journalism
Huntress · indexed 2026-09-26 07:35 UTC
As Huntress scales past 800 teammates, Chief People Officer Kristin Dean reflects on protecting culture and not just letting it happen.
P0