Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 19:50 28/09/2026 UTC
Last updated: 23:53 27/09/2026 UTC
  • Case Case score 89 Roundcube CVE-2026-48842 Active Exploitation and Patch Pressure Roundcube’s CVE-2026-48842 pre-auth SQL injection is confirmed actively exploited in the wild, advancing patch pressure because attackers can bypass authentication and run database-compromising commands against internet-facing mail servers.
  • Exploitation Wave H score 89 Roundcube Webmail CVE-2026-48842 active exploitation wave An active exploitation wave for Roundcube CVE-2026-48842 is exposing hundreds of thousands of reachable instances, expanding the immediate scale of risk beyond patch availability.
  • Data Leak H score 84 FBI employee and applicant data leak claim ShinyHunters’ renewed Oracle PeopleSoft claims of stealing 2TB–3TB of FBI-related data and compromising multiple services change the incident outlook by moving from unverified chatter to public sample record disclosure while access claims are still under FBI investigation.
  • Vulnerability H score 34 Citrix NetScaler unpatched RCE zero-days actively exploited remote code execution flaw Two Citrix NetScaler unpatched RCE zero-days are being exploited in the wild, prompting emergency actions because patches and official guidance lag while appliances are at immediate compromise risk.
  • Vulnerability H score 47 WordPress unauthenticated path traversal flaw actively exploited (CVE-2026-87902) WordPress CVE-2026-87902 is actively exploited within hours of the WordPress 7.1.2 release, advancing threat severity by shifting from reconnaissance to payload delivery and potential RCE via /tmp and /var/tmp writes.
  • Advisory/Mitigation H score 83 Elementor CSRF bypass mitigation (4.3.2) Elementor released 4.3.2 to block a CSRF query-string bypass that can enable attacker-triggered REST API actions by a logged-in administrator, changing remediation urgency for large numbers of exposed sites.

Latest updates

Browse →

Times Car member and corporate account data leak

Data Leak

Updated: 28.09.2026 23:31 · First: 28.09.2026 23:31 · 📰 1 src / 1 articles · H score: 62

Times Car confirmed a data theft affecting approximately 6.6 million current and former member accounts, creating identity-theft and phishing risk for a large customer base. The exposed data includes names, addresses, birth dates, phone numbers, email addresses, driver’s license information, identity document images, passwords, and linked service IDs. The company said credit card information remained unaffected and there is no evidence the stolen data has been distributed online.

Times Car hit by network compromise

Incident

Updated: 28.09.2026 23:31 · First: 28.09.2026 23:31 · 📰 1 src / 1 articles · H score: 59

Times Car confirmed a cyberattack that compromised about 6.6 million current and former member accounts, exposing personal and identity data across its car-sharing service. The intrusion involved unauthorized access to systems at the beginning of the month and was blocked on September 26. Exposed data included names, addresses, birth dates, phone numbers, email addresses, driver’s license information, account passwords, and linked service IDs. There is no evidence the stolen data has been published online, credit card information was unaffected, and services continue to operate normally.

Apple security patch release for CVE-2026-86950

Security Patch Release

Updated: 28.09.2026 22:18 · First: 28.09.2026 22:18 · 📰 1 src / 1 articles · H score: 36

Apple released security updates for older iOS, iPadOS, and macOS branches to fix CVE-2026-86950, a flaw that could expose devices to arbitrary code execution. The issue is an out-of-bounds write in CoreGraphics that can be triggered by a maliciously crafted file. Apple shipped the fixes in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. The company said the problem may have been used in an extremely sophisticated attack against specific targeted individuals.

Apple CoreGraphics out-of-bounds write security flaw (CVE-2026-86950)

Vulnerability

Updated: 28.09.2026 22:18 · First: 28.09.2026 22:18 · 📰 1 src / 1 articles · H score: 25

Apple released updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics that could enable arbitrary code execution on older iOS, iPadOS, and macOS versions. The flaw was tied to processing a maliciously crafted file and was said to have been possibly exploited in targeted attacks. Apple shipped fixes across iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.

Misconfigured Supabase databases exposing readable tables with sensitive data

Data Leak

Updated: 28.09.2026 21:50 · First: 28.09.2026 21:50 · 📰 1 src / 1 articles · H score: 67

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with PII, passwords, and authentication tokens. A smaller subset also appears to include credit card data, widening the potential fallout beyond account takeover. The exposure is tied to missing or ineffective row-level security and misuse of public keys, and application owners were notified when significant exposure was identified.

NeedyMantis long-term access activity

Malware Activity

Updated: 28.09.2026 21:35 · First: 28.09.2026 21:35 · 📰 1 src / 1 articles · H score: 22

The NeedyMantis malware family is being used to maintain long-term access in already breached networks, affecting a small number of targeted intrusions across telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. Microsoft says the activity dates back to October 2025. In examined cases, the malware arrived through DLL sideloading and established command-and-control over HTTPS and WebSocket. Microsoft published SHA-256 hashes, the corp.tripswithengine[.]com domain, file paths, and hunting queries to help defenders find it.

Bitget hit by cyberattack

Incident

Updated: 28.09.2026 12:25 · First: 28.09.2026 12:25 · 📰 3 src / 3 articles · H score: 39

Bitget confirmed a breach that forced a temporary withdrawal suspension after attackers moved $387.5 million from compromised hot and warm wallets. The exchange says the incident is contained and that user balances remain unaffected. Withdrawal services are being restored in stages while trading and deposits continue to operate.

US cybersecurity leaders face suspected deepfake incidents and million-dollar losses

Trend

Updated: 28.09.2026 16:00 · First: 28.09.2026 16:00 · 📰 1 src / 1 articles · H score: 24

US cybersecurity leaders are facing a sustained wave of suspected deepfake incidents, with 74% saying their organizations encountered one in the last 12 months and severe financial exposure across victims. The measured pattern shows one in four affected organizations reporting over $1m in losses from a single incident. Readiness remains weak, with 93% of leaders saying their organizations are not prepared for the threat.

Nvidia Open Agent Safety Platform launch adds OpenShell sandboxing and Sentry watchdog enforcement

Security Tool/Service

Updated: 28.09.2026 13:27 · First: 28.09.2026 13:27 · 📰 2 src / 2 articles · H score: 20

Nvidia launched Open Agent Safety Platform, adding sandboxing, policy enforcement, and hardware-backed monitoring for AI agents that can drift outside intended boundaries. The release matters because it gives operators a concrete control stack for containing agent behavior from testing through deployment.

Storm-3168 repeated Azure App Services probing campaign

Campaign

Updated: 28.09.2026 12:08 · First: 28.09.2026 12:08 · 📰 1 src / 1 articles · H score: 32

A repeated probing campaign from Storm-3168 linked infrastructure hit several Azure App Services across different customers, signaling coordinated cloud reconnaissance with potential follow-on access risk. The activity was judged likely automated or scripted because the work was split across multiple service principals and separated by timing gaps between operations.

Langflow actively exploited initial access flaw (CVE-2025-3248)

Vulnerability

Updated: 28.09.2026 12:08 · First: 28.09.2026 12:08 · 📰 1 src / 1 articles · H score: 40

The Langflow flaw CVE-2025-3248 was exploited for initial access by JADEPUFFER, creating credential-harvesting and ransomware risk for exposed deployments. The exploit path enabled deeper network access and destructive follow-on activity against the victim environment. The compromise occurred in the June 2026 intrusion context and shows the flaw being used as a real-world entry point.

Citrix NetScaler ADC / NetScaler Gateway zero-day RCE flaws remote code execution flaw (multiple vulnerabilities)

Vulnerability

Updated: 28.09.2026 09:24 · First: 28.09.2026 09:24 · 📰 3 src / 3 articles · H score: 43

Citrix confirmed active exploitation of NetScaler ADC and NetScaler Gateway zero-day flaws, exposing vulnerable appliances to unauthenticated remote code execution. The affected bugs are CVE-2026-88771 and CVE-2026-88772, and Citrix urged customers to install the updated versions immediately. CISA also added both CVEs to the KEV Catalog and ordered federal civilian agencies to remediate by September 30. The exploitation risk is highest for unmitigated NetScaler deployments and Internet-facing systems.

Citrix NetScaler unpatched RCE zero-days actively exploited remote code execution flaw

Vulnerability

Updated: 27.09.2026 19:02 · First: 27.09.2026 19:02 · 📰 1 src / 1 articles · H score: 34

Two Citrix NetScaler remote code execution zero-days are being exploited in the wild, putting exposed appliances at immediate risk before fixes arrive. Private warnings from suppliers, CERTs, law enforcement, and cybersecurity agencies prompted organizations to shut down or restrict exposure on affected systems. The flaws were found during incident response forensics, and patches were expected early next week. No public CVEs or official mitigation guidance were available when the warnings circulated.

Citrix NetScaler ADC and NetScaler Gateway unpatched zero-day RCE flaws remote code execution flaw

Vulnerability

Updated: 27.09.2026 10:47 · First: 27.09.2026 10:47 · 📰 1 src / 1 articles · H score: 34

Citrix NetScaler ADC and NetScaler Gateway are affected by two unpatched zero-day RCE flaws that are actively exploited in the wild, putting edge appliances used for VPN and remote access at immediate compromise risk.

FBI employee and applicant data leak claim

Data Leak

Updated: 22.09.2026 22:13 · First: 22.09.2026 22:13 · 📰 4 src / 5 articles · H score: 99

ShinyHunters publicly claimed it breached FBI jobs systems through an Oracle PeopleSoft flaw, stole 2TB to 3TB of data, and exposed information tied to FBI employees and job applicants from services including Criminal Justice (CJ), HR, and Medlink. The FBI said it is investigating the unauthorized-activity claims affecting FBIjobs.gov, and the access and leak claims remain unverified in the supplied context. Later reporting said Mandiant and the Google Threat Intelligence Group (GTIG) confirmed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft across dozens of systems in higher education, technology, healthcare, agriculture, transportation, and government. The same exploit thread was linked to a URL-encoding bypass against WAF rules and to renewed abuse of unpatched PeopleSoft servers.

Psychedelic Stealer / LunexStealer MaaS infostealer deployment

Malware Activity

Updated: 26.09.2026 21:22 · First: 26.09.2026 21:22 · 📰 1 src / 1 articles · H score: 29

Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while keeping persistent remote access on victim systems. The malware chain uses ClickFix-style lures, bogus MSI installers, and a PowerShell-based Native Messaging Host to survive cleanup and continue operating. It also abuses PDFWKRNL.sys tied to CVE-2023-20598 to weaken defenses and bypass UAC on Windows endpoints.

OpenAI AI agents accidental user-image uploads to third-party image-hosting sites

Data Leak

Updated: 26.09.2026 15:28 · First: 26.09.2026 15:28 · 📰 1 src / 1 articles · H score: 26

OpenAI's AI agents exposed user-provided images by posting them to third-party image-hosting sites, creating a confirmed leak across 53 incidents. The shared links were not publicly listed, so the exposure was limited but still real. OpenAI said it has removed most of the affected content and is still working to clean up the remaining images.

Elementor plugin WordPress CSRF admin account creation security flaw

Vulnerability

Updated: 25.09.2026 21:13 · First: 25.09.2026 21:13 · 📰 2 src / 2 articles · H score: 72

A CSRF vulnerability in the Elementor plugin for WordPress lets an unauthenticated attacker force a logged-in administrator to perform REST API actions that can create attacker-controlled administrator accounts. The flaw affects versions 4.3.0 and 4.3.1, and Elementor has already shipped a fix in 4.3.2.

Elementor CSRF bypass mitigation (4.3.2)

Advisory/Mitigation

Updated: 25.09.2026 21:13 · First: 25.09.2026 21:13 · 📰 2 src / 2 articles · H score: 83

Elementor users are being told to upgrade to version 4.3.2 immediately to block a CSRF bypass that can let a logged-in administrator perform attacker-triggered REST API actions. The fix closes the query-string abuse path in the plugin’s Editor Events module. The affected releases are 4.3.0 and 4.3.1, which are used on up to 2 million sites. On default installations, abuse can lead to an attacker-controlled administrator account.

WSO2, Adobe Commerce, SharePoint, and RouterOS active exploitation wave

Exploitation Wave

Updated: 25.09.2026 20:24 · First: 25.09.2026 20:24 · 📰 2 src / 2 articles · H score: 34

CISA says attackers are actively exploiting four vulnerabilities across WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS, creating a broad exposure window for internet-facing enterprise systems. The wave includes CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, and CVE-2026-67279, spanning authentication bypass, incorrect authorization, code injection, and pre-auth SSH workflow bypass flaws. CISA placed the two critical issues in the KEV catalog and set mitigation deadlines of September 27 for the critical bugs and September 28 for the SharePoint and RouterOS flaws.

Kiteworks six-hour shutdown advisory

Advisory/Mitigation

Updated: 26.09.2026 00:41 · First: 26.09.2026 00:41 · 📰 2 src / 2 articles · H score: 38

Kiteworks issued a worldwide precautionary shutdown advisory after receiving credible threat intelligence that a potential attack on Kiteworks systems may be imminent. Customers were told to take servers offline for six hours on Saturday, September 26, including systems that are not directly exposed to the internet. The company said the warning is preventative, not a response to a confirmed breach, and urged customers to keep running version 9.5.1 with all known vulnerabilities addressed.

AT&T customers customer data exposed after AT&T breach

Data Leak

Updated: 26.09.2026 00:44 · First: 26.09.2026 00:44 · 📰 1 src / 1 articles · H score: 78

A self-claimed leak of AT&T customer call and text metadata exposed records for tens of millions of people, including source and destination numbers, timestamps, and durations. The claim was tied to Kiberphant0m and to public extortion of telecom companies. The exposure created broad privacy risk and increased pressure on victims not to have the data published.

Cameron John Wagenius cybercrime sentencing in Seattle

Law Enforcement

Updated: 26.09.2026 00:44 · First: 26.09.2026 00:44 · 📰 2 src / 2 articles · H score: 82

A federal court in Seattle sentenced Cameron John Wagenius in a cybercrime case, imposing 70 months in prison and $294,978 in restitution for telecom hacking and extortion. The judgment follows the theft of mobile call and text metadata tied to more than 100 million AT&T customers. It also marks the latest legal outcome in the Kiberphant0m telecom extortion case.

Grav security patch release for CVE-2026-42608

Security Patch Release

Updated: 25.09.2026 23:57 · First: 25.09.2026 23:57 · 📰 1 src / 1 articles · H score: 31

Grav backported the CVE-2026-42608 fix to the older 1.7 branch, releasing Grav 1.7.53.4 to close the path-traversal exposure for legacy sites. The update matters because installations that stayed on Grav 1.7 were still exposed even though the flaw had already been fixed in Grav 2.0.

Clop leak site hit by network compromise linked to ShinyHunters

Incident

Updated: 25.09.2026 23:57 · First: 25.09.2026 23:57 · 📰 1 src / 1 articles · H score: 31

The Clop leak site was breached and defaced by ShinyHunters, forcing the operation to shift to a new Tor address. The compromise was tied to Grav CMS 1.7.43 and an unpatched path traversal flaw now identified as CVE-2026-42608. The attacker later claimed to have taken source code, plugins, server logs, and private keys and threatened to leak them for payment. Clop said the old onion address would stay online only temporarily before retirement.

Grav CMS path traversal (CVE-2026-42608)

Vulnerability

Updated: 25.09.2026 23:57 · First: 25.09.2026 23:57 · 📰 1 src / 1 articles · H score: 8

Grav CMS 1.7.x installations were exposed to CVE-2026-42608, an unauthenticated path traversal flaw in form upload handling that could create unsafe upload paths and write files outside the intended directory. Grav said the bug was fixed in Grav 2.0 (2.0.0-beta.2) earlier this year and later backported as Grav 1.7.53.4. The weakness was used against a server running Grav CMS 1.7.43.

Elementor plugin for WordPress security fix in 4.3.2

Security Patch Release

Updated: 25.09.2026 21:13 · First: 25.09.2026 21:13 · 📰 1 src / 1 articles · H score: 30

The Elementor team shipped version 4.3.2 of the Elementor plugin for WordPress to fix a CSRF flaw that could let attackers create administrator accounts on vulnerable sites. The release closes the bypass affecting versions 4.3.0 and 4.3.1, which were installed on as many as 2 million sites. Site operators should upgrade to 4.3.2 to block the REST API abuse path.

CISA KEV remediation deadlines for exploited CVEs

Public Sector Action

Updated: 25.09.2026 20:24 · First: 25.09.2026 20:24 · 📰 1 src / 1 articles · H score: 34

CISA added CVE-2026-5430 and CVE-2026-71362 to the KEV catalog and set September 27 remediation deadlines for federal agencies using the affected products. Agencies must apply updates or mitigations or discontinue use, turning the notice into an immediate operational requirement. CISA also set a September 28 deadline for CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in Mikrotik RouterOS.

PamStealer macOS stealer adds live C2 decryption and multi-layer persistence

Malware Activity

Updated: 25.09.2026 16:18 · First: 25.09.2026 16:18 · 📰 1 src / 1 articles · H score: 29

The PamStealer macOS stealer now uses a server-side decryption chain for its payload, making static recovery impossible without live C2 cooperation. The latest build also swaps in a fake wavel[.]app wallet lure and a Wavel.dmg download to start the infection. It then uses a JXA dropper and /bin/zsh stage to install multi-layer persistence and keep the repair logic alive across logins and Git activity. The final stealer targets passwords, keychain items, browser credentials, system metadata, and user files on macOS.

CISA election software patch-management certification guidance

Advisory/Mitigation

Updated: 25.09.2026 15:39 · First: 25.09.2026 15:39 · 📰 1 src / 1 articles · H score: 39

CISA issued guidance for election software that aligns patch management with certification requirements so security updates can be deployed in real time without breaking certification. The recommendation reduces delay in fixing vulnerabilities across the election infrastructure ecosystem. It directly addresses a remediation bottleneck that can leave vulnerable systems exposed longer than necessary.