Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 20:09 30/09/2026 UTC
Last updated: 22:20 29/09/2026 UTC

Latest updates

Browse →

Star Blizzard fake event-invitation phishing campaign

Campaign

Updated: 29.09.2026 20:20 · First: 29.09.2026 20:20 · 📰 2 src / 2 articles · H score: 29

Star Blizzard is using the RedFlick delivery chain in 2026 to push the CosmicPulse backdoor through phishing emails and a password-protected archive that leads to a hidden infection sequence. Microsoft says the campaign has targeted Ukraine-linked individuals and institutions and also international NGOs, think tanks, governments, and financial institutions supporting Ukraine. Since January, the operation has affected more than 100 organizations, and Microsoft says it has seen at least 13 distinct large-scale phishing campaigns this year. The new delivery method relies on a disguised shortcut, multiple scheduled tasks, and NOROBOT/BAITSWITCH to automate infection and reduce victim interaction.

Dutch Institute for Vulnerability Disclosure (DIVD) hit by network compromise

Incident

Updated: 29.09.2026 18:39 · First: 29.09.2026 18:39 · 📰 1 src / 2 articles · H score: 25

The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed a cyberattack that used an autonomous AI agent, leaving the nonprofit in an ongoing breach investigation with the full impact still unclear. Investigators say the intrusion began with exploitation of a technical vulnerability in an undisclosed system. DIVD has already notified the police, the Autoriteit Persoonsgegevens, and the NCSC.

Public GitHub repositories valid credential exposure

Data Leak

Updated: 30.09.2026 21:08 · First: 30.09.2026 21:08 · 📰 1 src / 1 articles · H score: 55

More than 543,699 credentials exposed in public GitHub repositories were still valid in July, leaving a large pool of reusable secrets accessible to anyone who found them. The exposed material appeared repeatedly across more than 1.1 million files and repositories, including copies in forks. The median exposure window was 784 days, and some working credentials dated back to 2009. Push Protection reduced some accidental leaks, but it does not revoke secrets that were already exposed.

MSP360 RMM phishing campaign deploying ScreenConnect

Campaign

Updated: 30.09.2026 19:32 · First: 30.09.2026 19:32 · 📰 1 src / 1 articles · H score: 33

A phishing campaign is using deceptive MSP360 RMM installers to establish remote management access on endpoints and then stage ConnectWise ScreenConnect, expanding the attackers' ability to persist and operate remotely. The lure set includes meeting invitations, PDF-themed files, and software-update prompts, while the installer can relaunch through UAC to run with elevated privileges. Microsoft also observed a separate July 2026 wave that swapped in Faronics Deploy Agent, showing the same operation can pivot across multiple remote-management tools.

CISA MikroTik RouterOS mitigation guidance for CVE-2026-84411

Advisory/Mitigation

Updated: 30.09.2026 18:49 · First: 30.09.2026 18:49 · 📰 1 src / 1 articles · H score: 28

CISA issued mitigation guidance for MikroTik RouterOS operators affected by CVE-2026-84411, a pre-authentication integer underflow that can enable root code execution or denial of service. The guidance applies to RouterOS versions below 7.24 and directs administrators toward risk-reduction steps while they update affected systems. CISA said it has no knowledge of active exploitation at this time. Operators are urged to keep control systems off the internet, isolate them behind firewalls, and use updated VPNs for remote access.

MikroTik RouterOS pre-auth integer underflow (CVE-2026-84411)

Vulnerability

Updated: 30.09.2026 18:49 · First: 30.09.2026 18:49 · 📰 1 src / 1 articles · H score: 1

CVE-2026-84411 exposes MikroTik RouterOS management interfaces to unauthenticated root code execution or denial of service through a pre-authentication integer underflow. The affected scope includes RouterOS versions below 7.24. The issue is reachable with a single crafted request.

OpenAI custom GPT ClickFix RAT campaign

Campaign

Updated: 29.09.2026 23:59 · First: 29.09.2026 23:59 · 📰 3 src / 3 articles · H score: 26

Huntress said a ChatGPT Custom GPT abuse campaign used sponsored Google results and a fake Google Sites backup page to push victims into a ClickFix chain that executed PowerShell, installed a malicious MSI, and loaded a modified DLL to deploy a RAT. The activity affected dozens of users, and Huntress linked at least 40 incidents to the Google Sites page, while only two incidents involved a Custom GPT variant. OpenAI removed the first malicious GPT, Plus 5.6, after it was used to steer users toward the lure, but Huntress later found a second linked GPT still active on September 27. The payload supported remote desktop access, camera and microphone capture, file searching, and additional payload execution.

Cisco Catalyst SD-WAN Manager actively exploited authentication-bypass zero-day (CVE-2026-76504)

Vulnerability

Updated: 30.09.2026 17:46 · First: 30.09.2026 17:46 · 📰 2 src / 2 articles · H score: 56

Cisco's fix for CVE-2026-76504 in Catalyst SD-WAN Manager closes a critical zero-day that was being actively exploited to reach admin privileges. The flaw affects all deployments and enables unauthenticated remote access through API session-based authentication management. Cisco told customers to move to a fixed software release and shared log indicators to help identify abuse.

Cisco Catalyst SD-WAN Manager security update for CVE-2026-76504

Security Patch Release

Updated: 30.09.2026 17:46 · First: 30.09.2026 17:46 · 📰 2 src / 2 articles · H score: 52

Cisco released security updates for Catalyst SD-WAN Manager to fix CVE-2026-76504, a critical zero-day that attackers are actively exploiting. The update covers deployments of the network management platform used to administer SD-WAN devices, and Cisco said customers should move to a fixed software release. The flaw can let unauthenticated attackers reach admin privileges remotely.

Microsoft Entra ID adds CSP enforcement to block script injection during sign-ins

Security Tool/Service

Updated: 30.09.2026 16:37 · First: 30.09.2026 16:37 · 📰 1 src / 1 articles · H score: 28

Microsoft Entra ID is rolling out Content Security Policy (CSP) enforcement for browser-based sign-ins, blocking external script injection and reducing XSS-driven credential theft risk. The change applies to login.microsoftonline.com and limits authentication pages to trusted Microsoft-hosted scripts. Microsoft says the rollout starts in mid-October 2026 and finishes by late October 2026. Enterprises using browser extensions or tools that inject code into sign-in pages may need to test for blocked-script violations before the deadline.

TeamViewer urgent update advisory for Full Client and Host

Advisory/Mitigation

Updated: 30.09.2026 15:25 · First: 30.09.2026 15:25 · 📰 1 src / 1 articles · H score: 34

TeamViewer urged users to update to version 15.82 immediately after releasing fixes for multiple high-severity vulnerabilities in TeamViewer Full Client and Host. The advisory covers Windows, Linux, and macOS systems and addresses flaws that could enable unauthorized actions, remote code execution, and privilege escalation. TeamViewer said it is not aware of public exploit code or active exploitation in the wild.

TeamViewer security patch release for CVE-2026-92370

Security Patch Release

Updated: 30.09.2026 15:25 · First: 30.09.2026 15:25 · 📰 1 src / 1 articles · H score: 34

TeamViewer released security updates for Full Client and Host after finding five vulnerabilities affecting Windows, Linux, and macOS systems. The most severe issue, CVE-2026-92370, is an access control bypass that could enable unauthorized actions and remote code execution. TeamViewer says the flaws are fixed in version 15.82 and that it has no evidence of public exploit code or active exploitation.

TeamViewer Full Client and Host access control bypass (CVE-2026-92370)

Vulnerability

Updated: 30.09.2026 15:25 · First: 30.09.2026 15:25 · 📰 1 src / 1 articles · H score: 26

TeamViewer disclosed CVE-2026-92370, a remote session access control bypass in TeamViewer Full Client and Host that can enable remote code execution on Windows, Linux, and macOS systems. The flaw stems from an improper access control weakness in the remote-access software. TeamViewer says the issue is fixed in version 15.82 and that it has no evidence of public exploit code or active exploitation.

Developers at over 300 organizations customer data exposed after GitHub Glow breach

Data Leak

Updated: 30.09.2026 14:30 · First: 30.09.2026 14:30 · 📰 1 src / 1 articles · H score: 41

A public GitHub exposure revealed 13,000+ internal images from developers at 300+ organizations, including customer billing records and unreleased feature screens. The files were posted under developers' personal accounts, making them downloadable outside company-controlled repositories. The leak spreads sensitive internal visuals across many organizations and raises the risk of further public circulation.

Review gates for coding agents block public uploads and personal-account posting

Defensive Guidance

Updated: 30.09.2026 14:30 · First: 30.09.2026 14:30 · 📰 1 src / 1 articles · H score: 24

Companies using coding agents were urged to add review gates and access controls before agents can create public repositories, post to personal accounts or gists, or make private repos public, reducing the risk of exposed screenshots, credentials, and internal dashboards. The guidance targets workarounds that move review artifacts outside company-controlled GitHub organizations and into places security teams may miss. It also recommends removing tools such as gitshot from company machines and reviewing the shared skill files agents load.

Bitget hit by cyberattack

Incident

Updated: 28.09.2026 12:25 · First: 28.09.2026 12:25 · 📰 3 src / 4 articles · H score: 39

Bitget confirmed a breach that forced a temporary withdrawal suspension after attackers moved $387.5 million from compromised hot and warm wallets. The exchange says the incident is contained and that user balances remain unaffected. Withdrawal services are being restored in stages while trading and deposits continue to operate.

CSuite phishing exposure concentrates in the United States and key sectors

Trend

Updated: 30.09.2026 13:45 · First: 30.09.2026 13:45 · 📰 1 src / 1 articles · H score: 28

A US-concentrated CSuite phishing pattern is spreading across 351 sandbox analyses, raising the risk of Microsoft 365 compromise and broader business access across exposed organizations. 51% of related submissions came from the United States, while technology, manufacturing, government, and consulting organizations were the most exposed sectors. Activity also appeared in India and several other countries, showing a wider but uneven exposure footprint.

CSuite phishing campaign stealing Microsoft 365 sessions and deploying remote-access tools

Campaign

Updated: 30.09.2026 13:45 · First: 30.09.2026 13:45 · 📰 1 src / 1 articles · H score: 30

The CSuite phishing campaign is stealing Microsoft 365 sessions and deploying ScreenConnect or Action1, creating paths to account takeover, endpoint control, and business fraud. Researchers traced the operation across 351 sandbox analyses, with 51% of submissions coming from the United States. The activity uses business-themed lures such as Adobe, DocuSign, Zoom, Google Meet, Dropbox, and Microsoft 365, and it is most exposed in technology, manufacturing, government, and consulting organizations. The campaign can turn a single phish into persistent access inside victim environments.

Citrix NetScaler ADC / NetScaler Gateway zero-day RCE flaws remote code execution flaw (multiple vulnerabilities)

Vulnerability

Updated: 28.09.2026 09:24 · First: 28.09.2026 09:24 · 📰 3 src / 6 articles · H score: 43

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 are under active exploitation against unmitigated NetScaler deployments, enabling unauthenticated remote code execution on exposed appliances. Citrix urged immediate patching, and CISA added both flaws to the KEV Catalog while ordering Federal Civilian Executive Branch agencies to remediate by September 30. Mandiant and GTIG say attackers used the flaws to deploy WHIPSHOT and SLAPSHOT, keep root-level access, pivot into internal networks, and steal credentials across North America and Europe in government, financial services, technology, education, legal, and professional services environments.

WHIPSHOT and SLAPSHOT post-exploitation toolkit on Citrix NetScaler appliances

Malware Activity

Updated: 30.09.2026 11:24 · First: 30.09.2026 11:24 · 📰 1 src / 1 articles · H score: 34

A post-exploitation toolkit built around WHIPSHOT and SLAPSHOT is being used after Citrix NetScaler compromises, giving attackers covert C2, reconnaissance, and credential theft capability. The activity was observed in September 2026 after exploitation of CVE-2026-88772 on exposed appliances. WHIPSHOT hides Base64-encoded payloads inside HTTP headers, while SLAPSHOT tunnels traffic into internal networks. The tooling increases the chance of persistent access and follow-on movement across victim environments.

OpenSSL DTLS memory leak or crash flaw (CVE-2026-84782)

Vulnerability

Updated: 30.09.2026 11:09 · First: 30.09.2026 11:09 · 📰 1 src / 1 articles · H score: 24

CVE-2026-84782 affects OpenSSL DTLS and can leak heap memory to the peer or crash affected programs. OpenSSL has released fixes in 4.0.3, 3.6.5, 3.5.9 and 3.4.8, with older branches limited to premium-support customers. The flaw is high severity and has no reported exploitation so far.

OpenSSL September 29 security update bundle (CVE-2026-84782)

Security Patch Release

Updated: 30.09.2026 11:09 · First: 30.09.2026 11:09 · 📰 1 src / 1 articles · H score: 28

OpenSSL's September 29 security update bundle fixed CVE-2026-84782, a High-severity DTLS flaw that could leak heap memory or crash affected programs. Public fixes landed in OpenSSL 4.0.3, 3.6.5, 3.5.9 and 3.4.8, while older branches require premium support. OpenSSL said there is no workaround for users who cannot update.

WSL Containers general availability adds Defender for Endpoint visibility and Intune controls

Security Tool/Service

Updated: 30.09.2026 03:40 · First: 30.09.2026 03:40 · 📰 1 src / 1 articles · H score: 14

WSL Containers reached general availability, expanding Windows support for building and running Linux containers while adding enterprise security visibility and administrative control. The release now connects with Microsoft Defender for Endpoint and Microsoft Intune, letting defenders monitor container activity and restrict registry sources. It also adds a new wslc.exe CLI, a container.exe alias, and an API for Windows apps that need to manage containers programmatically.

PowerShell-triggered RAT payload on Windows

Malware Activity

Updated: 29.09.2026 23:59 · First: 29.09.2026 23:59 · 📰 1 src / 1 articles · H score: 22

The PowerShell-triggered ClickFix chain deployed a remote access trojan (RAT) that gave operators remote desktop access, camera/audio capture, reconnaissance, and additional payload execution on Windows. The malware established persistence with a Run key and scheduled task named Canon Configuration Reader. Delivery used a malicious MSI and a modified DLL loaded through a legitimate signed application, helping the infection blend in. Later variants shifted from a Canon-signed host app to a Stardock-signed one while keeping the same payload.

US Air Force members sentenced in BEC and phishing case

Law Enforcement

Updated: 29.09.2026 21:09 · First: 29.09.2026 21:09 · 📰 1 src / 1 articles · H score: 27

Chijioke Timothy Odimegwu and Harafat Mogaji were sentenced to a combined 189 months in federal prison for a BEC and phishing case that diverted victim payments into conspiracy-controlled accounts. The sentence adds criminal consequences and restitution to a long-running cybercrime scheme that used stolen email credentials and spoofed business correspondence.

JIT engines Branch Target Reuse (BTR) (multiple vulnerabilities)

Vulnerability

Updated: 29.09.2026 20:00 · First: 29.09.2026 20:00 · 📰 2 src / 2 articles · H score: 36

Researchers disclosed Branch Target Reuse (BTR), a new Spectre-v2 vulnerability variant that targets JIT engines in web browsers, language runtimes, and the Linux kernel. Evaluations found the flaw in SpiderMonkey, GraalVM, and the kernel's cBPF JIT across multiple CPU vendors. Two kernel proof-of-concept exploits recovered a root password hash within minutes on a fully patched Intel system, and mitigations were merged for CVE-2026-64507 and CVE-2026-64508.

Linux kernel security patch release for CVE-2026-64507

Security Patch Release

Updated: 29.09.2026 20:00 · First: 29.09.2026 20:00 · 📰 2 src / 2 articles · H score: 24

Mitigations for Branch Target Reuse (BTR) have been released and merged into the Linux kernel, delivering fixes for CVE-2026-64507 and CVE-2026-64508. The update addresses a Spectre-v2 variant that targets JIT engines across browsers, language runtimes, and the operating system kernel. The release follows responsible disclosure after proof-of-concept work showed root password hash leakage on a fully patched Intel system.

RemoteThreat emerges from stealth with $7 million pre-seed round

Industry Action

Updated: 29.09.2026 17:38 · First: 29.09.2026 17:38 · 📰 1 src / 1 articles · H score: 14

RemoteThreat emerged from stealth with $7 million in pre-seed funding, giving the new vendor fresh capital to bring an offensive operations platform to market. The company is backed by Osage University Partners and DataTribe, and it is positioning the platform for enterprise and critical infrastructure red teams, US government mission teams, and vetted defense partners. The launch adds a new, well-financed player to the cybersecurity industry focused on governed offensive operations.

RemoteThreat launches O/C/O Platform

Commercial Activity

Updated: 29.09.2026 17:38 · First: 29.09.2026 17:38 · 📰 1 src / 1 articles · H score: 1

RemoteThreat launched O/C/O Platform, a commercial offensive cyber operations product for enterprise and critical infrastructure red teams, US government mission teams, and vetted defense partners. The platform packages mission planning, command and control, implants, initial access, obfuscation, and AI assistants into one governed offering for advanced cyber operations.

RatHat Android credential-theft malware

Malware Activity

Updated: 17.09.2026 16:00 · First: 17.09.2026 16:00 · 📰 2 src / 3 articles · H score: 27

RatHat is an Android malware activity that Zimperium linked to China-based threat actors and that targets banking credentials, 2FA/OTP data, notifications, and screen and input capture. It spreads through smishing, malvertising, deceptive download portals, third-party forums, and malicious APKs, then uses a dropper, Accessibility abuse, and local ADB self-pairing to break out of the sandbox and gain shell-level privileges. Cleafy later reported that RatHat's C2 panels were rebranded from BlackCat to Panda Workshop, could build, sign, publish, and regenerate samples, and used Gemini to rank victims while campaigns ran across Europe, Latin America and Southeast Asia. Cleafy also observed nearly 100 deployments since April 2026, consistent with a MaaS model, while the malware retained persistence, a hardware-level keylogger, and AI-assisted UI automation.