Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 19:50 22/09/2026 UTC
Last updated: 04:51 22/09/2026 UTC

Latest updates

Browse →

Unnamed Western government organization data exposed after WordPress breach

Data Leak

Updated: 22.09.2026 23:35 · First: 22.09.2026 23:35 · 📰 1 src / 1 articles · H score: 66

A Western government organization suffered a data leak after attackers reached an internal SQL server and stole 18,566 records, exposing accounts, plaintext passwords, and PII. The stolen data was tied to government and law-enforcement agencies, making the theft operationally sensitive. The breach sat inside a broader wp2shell exploitation wave against WordPress Core that hit multiple organizations across 29 countries.

Red Heron-linked wp2shell campaign targeting high-value entities

Campaign

Updated: 22.09.2026 23:35 · First: 22.09.2026 23:35 · 📰 1 src / 1 articles · H score: 57

A Chinese-speaking threat actor tied to Red Heron is running a wp2shell campaign that has breached at least 49 organizations in 29 countries, expanding the risk of credential theft and government data exposure. The operation began in early June 2026 and used the same IP address for scans and attacks. It targeted high-value entities and combined exploitation with post-access recon and credential abuse. The campaign matters because it shows a coordinated, cross-border intrusion effort rather than isolated scanning.

FBI employee and applicant data leak claim

Data Leak

Updated: 22.09.2026 22:13 · First: 22.09.2026 22:13 · 📰 1 src / 1 articles · H score: 61

The FBI is facing a claimed data leak after ShinyHunters said it stole 2TB to 3TB of internal records and sensitive personnel files. The alleged exposure covers current and former FBI employees, job applicants, and other records, including PII/PHI. The group also shared sample records and a defaced FBI Jobs page claiming the information had been compromised. The claims remain unverified, but the reported scope points to a potentially large personnel-data exposure.

Check Point VPN certificate mitigation guidance

Advisory/Mitigation

Updated: 10.09.2026 14:45 · First: 10.09.2026 14:45 · 📰 1 src / 2 articles · H score: 53

Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance matters because some deployments could not patch immediately and had to rely on mitigation steps instead.

Check Point VPN certificate security patch release (CVE-2026-85102, CVE-2026-85103)

Security Patch Release

Updated: 10.09.2026 14:45 · First: 10.09.2026 14:45 · 📰 2 src / 3 articles · H score: 53

Check Point began delivering fixes on September 9 for CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate flaws in Security Gateways and Security Management Server. The release addresses unauthenticated remote code execution risk and gives customers remediation through Check Point Live Patch or the latest Jumbo Hotfix. Affected deployments include R82.10 / Jumbo Hotfix Take 43 or below, R82 / Take 125 or below, and R81.20 / Take 165 or below. Check Point says it found both issues itself and has no indication of attack use.

ClosedQuorum AI-driven Windows post-compromise malware activity

Malware Activity

Updated: 22.09.2026 21:04 · First: 22.09.2026 21:04 · 📰 1 src / 1 articles · H score: 28

The ClosedQuorum Windows malware now uses Google Gemini, DeepSeek, Qwen, and Mistral AI to automate post-compromise attack decisions, increasing the speed and scale of credential theft and persistence operations. The malware can choose among predefined actions such as LSASS dumping, browser credential theft, shellcode injection, and persistence without direct human commands. Researchers say the design shifts tactical C2 decisioning toward AI model voting and away from operator-driven control.

Twilio developer-targeting malicious npm publishing campaign

Campaign

Updated: 22.09.2026 20:58 · First: 22.09.2026 20:58 · 📰 1 src / 1 articles · H score: 35

A malicious npm campaign targeted Twilio developers by publishing 11 package versions in about 45 minutes and disguising the package as an authorized security probe. The activity used the npm registry to reach developer environments, harvest environment variables, and later steal Twilio credentials such as `process.env.ACCOUNT_SID` and `process.env.AUTH_TOKEN`. It also probed Twilio-related hosts and used a webhook for exfiltration, raising the risk of account abuse and unauthorized communication actions.

Tw-pkgprobe-7731 malicious npm package targeting Twilio credentials

Malware Activity

Updated: 22.09.2026 20:58 · First: 22.09.2026 20:58 · 📰 1 src / 1 articles · H score: 37

A malicious tw-pkgprobe-7731 npm package is posing as a Twilio security probe while stealing environment secrets, putting ACCOUNT_SID and AUTH_TOKEN at risk. The package was published through the npm registry and used a webhook to exfiltrate collected data from Twilio developer environments. Later versions expanded the theft behavior to include targeted probing of Twilio-related hosts and AWS metadata.

Bifrost custom plugin HTTP URL RCE/SSRF (CVE-2026-86242)

Vulnerability

Updated: 22.09.2026 19:41 · First: 22.09.2026 19:41 · 📰 1 src / 1 articles · H score: 37

Disclosed on September 6, CVE-2026-86242 gives Bifrost an unauthenticated path to remote code execution through custom plugin registration, with SSRF on builds where code execution is blocked. The flaw affects custom Go plugin support and is strongest on dynamically linked builds that load attacker-controlled code. The fix is in transports/v2.0.0, which closes the unauthenticated plugin-registration path.

Microsoft Defender update-blocking disk exhaustion security flaw

Vulnerability

Updated: 22.09.2026 19:14 · First: 22.09.2026 19:14 · 📰 1 src / 1 articles · H score: 28

BigDiskBuster exposes a Microsoft Defender flaw that can block platform and signature updates by exhausting disk space, leaving detection content stale on affected Windows systems. The zero-day proof-of-concept was published on GitHub on September 19, and there is no patch, CVE, or Microsoft advisory yet. The tool also targets MRT.exe, and the reported behavior appears to affect supported Windows versions.

AI incident response readiness lags AI adoption across organizations

Trend

Updated: 22.09.2026 16:00 · First: 22.09.2026 16:00 · 📰 1 src / 1 articles · H score: 25

Organizations are widening AI use in security operations without matching AI incident response preparation, creating a readiness gap for AI-enabled attacks and misuse. In a 2026 survey, 71% of organizations had not run any AI incident response exercises, only 3% had mature formal runbooks, and 30% had not started response planning. The gap sits alongside rising operational strain, with more attacks, heavier stress, understaffing, and underfunding reported by European IT and cybersecurity professionals.

D-Link DIR-822A DHCP stack-based buffer overflow remote code execution flaw (CVE-2026-86296)

Vulnerability

Updated: 22.09.2026 15:48 · First: 22.09.2026 15:48 · 📰 1 src / 1 articles · H score: 31

The D-Link DIR-822A vulnerability CVE-2026-86296 exposes legacy dual-band routers to unauthenticated attacks that can crash the DHCP daemon or enable remote code execution. The flaw is a stack-based buffer overflow in the DHCP server component and can be triggered with crafted DHCP packets from the same local network. Public PoC exploit code is already available, and no patch was available at disclosure.

DIR-822A L2TP control message parser out-of-bounds write memory corruption flaw (CVE-2026-86510)

Vulnerability

Updated: 22.09.2026 15:48 · First: 22.09.2026 15:48 · 📰 1 src / 1 articles · H score: 31

D-Link is investigating CVE-2026-86510, a critical out-of-bounds write in the L2TP control message parser of DIR-822A routers that can let attackers with basic privileges trigger arbitrary memory corruption on devices using L2TP or L2TPv6 WAN connectivity. A public PoC exploit raises the risk of faster weaponization against exposed routers. D-Link says it is still investigating the flaw and working on security patches.

Arista security patch release for CVE-2026-93952

Security Patch Release

Updated: 22.09.2026 15:29 · First: 22.09.2026 15:29 · 📰 1 src / 1 articles · H score: 53

Arista released fixed VeloCloud Orchestrator (VCO) builds for the 5.2 and 6.4 trains, reducing exposure for deployments tied to CVE-2026-93952. The patch set covers on-premises and Hosted/Dedicated VCO versions, while 6.1 and 7.0 were still awaiting fixes as of September 22. The release matters because VCO manages Edge devices in VeloCloud SD-WAN and compromise can extend beyond the orchestrator itself.

VeloCloud Orchestrator certificate-based privilege escalation (CVE-2026-93952)

Vulnerability

Updated: 22.09.2026 15:29 · First: 22.09.2026 15:29 · 📰 1 src / 1 articles · H score: 49

CVE-2026-93952 is an actively exploited flaw in VeloCloud Orchestrator (VCO) that can let a remote attacker with no login access privilege internal functions and compromise the orchestrator. Exposure is limited to orchestrators configured for certificate-based authentication from VeloCloud Edge devices, and a successful attack can also reach the managed Edge devices. Arista had fixed releases for the 5.2 and 6.4 trains as of September 22, while 6.1 and 7.0 were still awaiting fixes.

Arista mitigation guidance for Arista VeloCloud Orchestrator compensating controls for CVE-2026-93952

Advisory/Mitigation

Updated: 22.09.2026 15:29 · First: 22.09.2026 15:29 · 📰 1 src / 1 articles · H score: 53

Arista issued temporary mitigation steps for exposed VeloCloud Orchestrator (VCO) deployments while a fixed release is pending, limiting the risk from actively exploited CVE-2026-93952. The guidance applies to on-premises VCO systems that use certificate-based authentication and can be reached through the VCO web interface. Administrators are told to restrict access, monitor for malicious activity, and look for backdoor daemons or webshells on the host. The response also includes preserving logs and rotating credentials after remediation where practical.

Policy-based segmentation hardening for mixed OT/IoMT/IT/IoT networks

Defensive Guidance

Updated: 22.09.2026 15:00 · First: 22.09.2026 15:00 · 📰 1 src / 1 articles · H score: 14

Security teams managing mixed OT/IoMT/IT/IoT segments are being urged to tighten segmentation controls to reduce lateral movement risk. The guidance emphasizes continuous visibility, policy-based access controls, and segmentation drift monitoring where multiple device classes share the same network. The operational goal is to shrink blast radius and keep a single compromised device from reaching critical systems.

Mixed OT and IoMT network segments commonly co-locate IT and IoT devices, expanding lateral-movement risk

Trend

Updated: 22.09.2026 15:00 · First: 22.09.2026 15:00 · 📰 1 src / 1 articles · H score: 25

Forescout found that nearly half of OT or IoMT network segments also contain IT and IoT, expanding the blast radius for lateral movement across organizations. The analysis covered 47,700 real-world network segments and showed that mixed-device layouts are common, not exceptional. Segments averaging 54 devices create more opportunities for cross-zone exposure when IT, OT, IoT, and IoMT share the same path. The pattern raises the risk that a single compromise can spread from devices like IP cameras into workstations and servers.

Linux kernel ARM64 KVM guest-to-host escape security flaw (CVE-2026-89775)

Vulnerability

Updated: 22.09.2026 14:38 · First: 22.09.2026 14:38 · 📰 1 src / 1 articles · H score: 31

CVE-2026-89775 is a Linux kernel KVM flaw on ARM64 that can let a guest read and write host kernel memory on systems with nested virtualization enabled. The issue creates a path to guest escape and possible host code execution on exposed hosts. It is fixed in Linux 6.18.51, 7.2.5, and 7.3-rc1.

SharePoint Server authenticated RCE (CVE-2026-65660)

Vulnerability

Updated: 22.09.2026 14:17 · First: 22.09.2026 14:17 · 📰 1 src / 1 articles · H score: 32

CVE-2026-65660 in SharePoint Server is an authenticated remote code execution flaw affecting SharePoint Server 2016, 2019, and Subscription Edition. Microsoft had initially framed it as spoofing, but the published technical analysis shows a much higher-impact attack path. Patches were available since August 11, and defenders now need to treat the issue as a code-execution risk rather than a moderate spoofing bug.

Microsoft security patch release for CVE-2026-65660

Security Patch Release

Updated: 22.09.2026 14:17 · First: 22.09.2026 14:17 · 📰 1 src / 1 articles · H score: 38

Microsoft's August 11 security updates shipped a fix for CVE-2026-65660 across SharePoint Server 2016, 2019, and Subscription Edition, reducing exposure to a flaw now understood to allow authenticated remote code execution. The patch matters because the vulnerability was initially framed as spoofing, but the underlying weakness supports code injection and arbitrary class loading. Microsoft also turned off the vulnerable function by default in the update. Defenders need to treat the release as a security fix for a code-execution issue, not a low-impact spoofing bug.

Microsoft Defender update-blocking zero-day security flaw

Vulnerability

Updated: 22.09.2026 12:55 · First: 22.09.2026 12:55 · 📰 1 src / 1 articles · H score: 7

A Microsoft Defender zero-day named BigDiskBuster can block platform/signature updates on supported Windows versions, freezing antivirus updates while it runs in the background. The flaw is being circulated as a public proof of concept rather than a fixed issue, leaving affected systems stuck on their current definitions and platform version. The disclosure also frames it as part of an earlier Defender flaw pattern, increasing the risk that similar update-blocking weaknesses can be reused.

Rising deepfake and AI-driven social engineering incidents among CISOs

Trend

Updated: 22.09.2026 12:30 · First: 22.09.2026 12:30 · 📰 1 src / 1 articles · H score: 26

A survey of 297 senior cybersecurity leaders found that AI-driven social engineering is becoming more common and more convincing, with almost half of CISOs reporting at least one deepfake incident in the past 12 months. The measured rise in audio-call and video-call impersonation shows that identity abuse is moving beyond email-only phishing and increasing exposure across executive and employee communication channels. The pattern raises the risk of credential theft, BEC, and response failures when familiar detection cues no longer hold up.

SideCopy spear-phishing campaign targeting academic institutions in India

Campaign

Updated: 22.09.2026 10:52 · First: 22.09.2026 10:52 · 📰 1 src / 1 articles · H score: 29

The SideCopy campaign has expanded into academic institutions in India, extending a long-running spear-phishing operation beyond its traditional government targets and raising the risk of credential theft and remote compromise. The latest delivery chain uses a weaponized ZIP archive, a spoofed LNK file, and mshta.exe to fetch malicious content and stage payloads. The campaign deploys ReverseRAT, which supports data exfiltration, remote execution, and persistence.

Meta Muse Mac hidden dictation endpoint security flaw

Vulnerability

Updated: 22.09.2026 09:33 · First: 22.09.2026 09:33 · 📰 1 src / 1 articles · H score: 37

A hidden dictation setting in Meta's Muse assistant for Mac lets malware already running as the logged-in user redirect prompts away from Meta and toward an attacker-controlled destination. The flaw can expose dictated input, inject trusted instructions, and steal the Muse session token, turning the assistant into a backdoor on a compromised Mac. No patch was available at publication, leaving Muse on macOS exposed until Meta fixes the undocumented setting.

WordPress core comment-to-RCE flaw (CVE-2026-93485)

Vulnerability

Updated: 22.09.2026 09:03 · First: 22.09.2026 09:03 · 📰 1 src / 1 articles · H score: 48

WordPress core had a comment-processing flaw in CVE-2026-93485 that could let an anonymous comment plant a hidden script and, if a logged-in administrator opened the page, reach server-side code execution. WordPress 7.1.1 fixed the bug on September 17, and the affected range spans 4.7 through 7.1. The issue is rated 7.1/10 CVSS by Patchstack and is not known to be actively exploited.

WordPress core Click2Shell security flaw

Vulnerability

Updated: 18.09.2026 19:56 · First: 18.09.2026 19:56 · 📰 2 src / 3 articles · H score: 37

WordPress core’s Click2Shell vulnerability is a CSRF chain that can let a logged-in administrator open a crafted URL, force-install a theme from the WordPress.org catalog, and reach arbitrary PHP execution on the server when chained with a theme weakness. The flaw affects WordPress Core 7.1.0 and earlier and was fixed in WordPress 7.1.1 after WordPress shipped the patch on September 17, 2026. pwn.ai later published technical details and a proof-of-concept exploit, showing the chain can be used to force-install other vulnerable themes as well. The public write-up says attacks can be delivered through crafted links and may be triggered by phishing or an XSS condition that causes the administrator’s browser to send the request.

Zyxel GS1900 series switches stack-based buffer overflow security flaw (CVE-2026-7273)

Vulnerability

Updated: 22.09.2026 08:31 · First: 22.09.2026 08:31 · 📰 3 src / 3 articles · H score: 44

CVE-2026-7273 in Zyxel GS1900 series switches is now in CISA’s KEV catalog after evidence of active exploitation, putting affected networks at risk of arbitrary OS command execution via a crafted HTTP request.

BigCommerce merchant shopper data exposure via compromised Ribon app credentials

Data Leak

Updated: 22.09.2026 00:18 · First: 22.09.2026 00:18 · 📰 1 src / 1 articles · H score: 32

A BigCommerce data leak exposed shopper records after attackers used compromised Ribon app credentials to reach merchant environments, affecting Master of Malt and other stores. The exposed data included full names, email addresses, phone numbers, and shipping postal addresses. BigCommerce said the exposure ran from September 13 to September 17, 2026, and that payment cards and account passwords were not exposed. The platform removed the apps and notified merchants after confirming the credential compromise on September 17.

CISA orders federal agencies to patch Linux kernel flaws

Public Sector Action

Updated: 21.09.2026 23:12 · First: 21.09.2026 23:12 · 📰 1 src / 1 articles · H score: 30

CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal timeline. The directive also requires forensic triage on affected assets to check whether exploitation has already occurred. CISA says the vulnerabilities have been exploited in attacks, increasing the operational urgency for agencies.