Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 20:25 24/09/2026 UTC
  • Vulnerability H score 47 WordPress unauthenticated path traversal flaw actively exploited (CVE-2026-87902) WordPress attackers are actively exploiting CVE-2026-87902 to deliver payloads and write files under /tmp and /var/tmp, accelerating the path from vulnerability to remote code execution shortly after WordPress 7.1.2 shipped.
  • Vulnerability H score 54 F5 BIG-IP APM zero-day RCE (CVE-2026-94127) F5 disclosed active exploitation of the BIG-IP APM zero-day CVE-2026-94127 for remote code execution in OAuth Authorization Server deployments, with an iRule mitigation released for systems unable to patch immediately.
  • Security Patch Release H score 52 Check Point security patch release for CVE-2026-93616 Check Point issued R82.20 Security Hotfixes to remediate the Management Server zero-day CVE-2026-93616 exploited in the wild, urging immediate patching and tightened management access.
  • Malware Activity H score 53 Credit card skimmer malware deployed on retailer websites Skimmer malware was injected into at least 119 retailer websites and tied to theft of more than 600,000 valid card records, and the malware’s self-restoration after removal raises the likelihood of continued payment data loss.
  • Data Leak H score 66 Unnamed Western government organization data exposed after WordPress breach A Western government organization exposed 18,566 records after attackers reached an internal SQL server, including plaintext passwords and PII, underscoring the operational sensitivity of data stolen in a wp2shell WordPress wave.
  • Exploitation Wave H score 38 Roundcube Webmail CVE-2026-48842 active exploitation wave Roundcube Webmail’s CVE-2026-48842 is in an active exploitation wave affecting 523,000 exposed instances, expanding the scale of pre-auth SQL injection attempts into a larger, Internet-wide code-injection surface.
Last updated: 03:06 24/09/2026 UTC
  • Data Leak H score 84 FBI employee and applicant data leak claim ShinyHunters escalated its unverified claim of a new Oracle PeopleSoft zero-day breach of FBI systems by releasing sample stolen records and a defaced FBI Jobs page, prompting renewed attention on FBIjobs.gov exposure despite FBI saying access was taken offline.
  • Incident H score 77 Clop (aka Cl0p) hit by network compromise linked to ShinyHunters ShinyHunters disrupted Clop’s Tor leak operations by reportedly exploiting a Grav CMS upload flaw to replace Clop’s site and steal sensitive artifacts including onion-service private keys, increasing the risk of further exposure or extortion.
  • Incident H score 68 Gyazo hit by network compromise Helpfeel confirmed Gyazo exposure after attackers exploited a Gyazo image upload server, restricting some image viewing and warning of credential and session-related data exposure affecting tens of millions of records.
  • Vulnerability H score 60 AI coding agents plugin pinning bypass security flaw A pinning bypass in multiple AI coding agents was detailed as a repository-owner swap that can turn “reviewed” plugins into code-execution pathways, widening the threat from supply-chain review to active credential and host access abuse.
  • Security Patch Release H score 58 Cisco security patch release for CVE-2026-76460 Cisco released the only recommended fixes for actively exploited CVE-2026-76460 in Cisco ISE/ISE-PIC, forcing urgent remediation because no workarounds exist for the maximum-severity authentication bypass.
  • Law Enforcement H score 54 FBI seizes NightmareStresser domains The FBI seized nightmare-stresser[.]com and nightmarestresser[.]org under Operation PowerOFF, taking down a long-running DDoS-for-hire service that had enabled large-scale router/IoT-based attacks for years.

Latest updates

Browse →

Carbonato botnet targeting exposed Docker daemons with Hermes Agent

Malware Activity

Updated: 24.09.2026 23:10 · First: 24.09.2026 23:10 · 📰 1 src / 1 articles · H score: 41

The Carbonato botnet is targeting exposed Docker daemons to install Hermes Agent and seize host control, creating a worm-like foothold on vulnerable systems. It reaches Docker APIs exposed on port 2375 without authentication, then launches privileged containers and sets up reverse SSH tunnels for operator access. The activity is tied to evidence spanning October 2024 to August 2026, which shows a sustained malware operation rather than a one-off intrusion.

OnePlus OxygenOS local privilege-escalation flaws security flaw

Vulnerability

Updated: 24.09.2026 21:10 · First: 24.09.2026 21:10 · 📰 1 src / 1 articles · H score: 26

Unpatched OnePlus OxygenOS local privilege-escalation flaws let a malicious no-permission app gain root on affected phones. The chain uses AtlasService and olc2 to move from an installed app to system-level control. OnePlus had not released a fix at disclosure time, and the issue may extend beyond the OnePlus 15 to other OnePlus and OPPO devices.

Kontext Security launches runtime enforcement platform for AI agents

Security Tool/Service

Updated: 24.09.2026 18:52 · First: 24.09.2026 18:52 · 📰 1 src / 1 articles · H score: 11

Kontext Security has publicly launched a runtime security platform for AI agents, giving organizations a control point for actions taken by autonomous software. The platform sits between agents and the systems or tools they access, evaluates requests in real time, and can deny unauthorized actions. It aims to reduce the risk that an authenticated agent still performs an unsafe or unapproved operation.

Third-party.com fake Cloudflare verification ClickFix campaign targeting Windows users

Campaign

Updated: 24.09.2026 01:46 · First: 24.09.2026 01:46 · 📰 2 src / 2 articles · H score: 24

The third-party.com domain is hosting a ClickFix lure that impersonates a Cloudflare security check and pushes Windows users to run malicious PowerShell commands. The page uses clipboard poisoning and a fake verification flow to steer victims toward a payload chain on elxxvvx[.]xyz. The abuse turns a long-used placeholder hostname into an active delivery point for malware installation attempts.

N0n double-extortion ransomware campaign

Campaign

Updated: 24.09.2026 18:00 · First: 24.09.2026 18:00 · 📰 1 src / 1 articles · H score: 35

The n0n ransomware campaign is actively extorting organizations across financial services, technology, retail, and education, with a Tor leak site already listing over a dozen victims. The operators use double extortion and threaten to encrypt or destroy backups and shadow copies, raising the risk of operational paralysis if targets refuse to pay. Initial access reportedly begins with compromised credentials sourced from third-party infostealer malware, showing a credential-theft-driven intrusion path. The activity has been observed across the US and multiple other countries, indicating broad geographic reach.

N0n ransomware crew emergence and backup-destruction extortion model

Threat Actor Meta

Updated: 24.09.2026 18:00 · First: 24.09.2026 18:00 · 📰 1 src / 1 articles · H score: 36

n0n has emerged as a new ransomware crew, increasing extortion pressure by threatening to destroy backups and shadow copies if victims refuse to pay. The group was first seen on September 18 and had already listed over a dozen victims by September 22, showing rapid early activity. Its use of double extortion and credential-based initial access raises the risk of full operational disruption across affected organizations.

Unattributed Rublevka TDS (РУБЛЁВКА TDS) lure panel campaign expands across multiple victims

Campaign

Updated: 24.09.2026 17:29 · First: 24.09.2026 17:29 · 📰 1 src / 1 articles · H score: 36

The ClickFix campaign is compromising legitimate Ukrainian business websites with fake Cloudflare verification pages to deliver the Psychedelic information stealer. The operation uses a copied Windows Installer command and msiexec.exe to stage MSI payloads, putting browser credentials, tokens, and wallet data at risk. Its lure panel shows activity across 32 countries, with the heaviest concentration in Ukraine, indicating a coordinated multi-victim operation.

Psychedelic Stealer MSI-delivered browser-and-wallet theft activity

Malware Activity

Updated: 24.09.2026 17:29 · First: 24.09.2026 17:29 · 📰 1 src / 1 articles · H score: 30

The Psychedelic Stealer malware activity is using MSI-delivered payloads to steal browser credentials, account tokens, wallet data, and host information from Windows systems. It targets Chromium-based browsers and sets scheduled-task persistence while maintaining contact with a C2 server for additional tasking. The implant also modifies browser profiles with an embedded extension archive and a native-messaging bridge, extending the theft operation beyond a one-time run.

Roundcube Webmail CVE-2026-48842 active exploitation wave

Exploitation Wave

Updated: 24.09.2026 16:27 · First: 24.09.2026 16:27 · 📰 1 src / 1 articles · H score: 38

Roundcube Webmail's CVE-2026-48842 is now in an active exploitation wave, putting more than 523,000 exposed instances at risk across the Internet. The flaw was patched in May and enables pre-auth SQL injection in the virtuser_query plugin, creating a broad attack surface for code-injection abuse. The wave matters because attackers can target a widely deployed mail platform that remains reachable at scale.

Roundcube Webmail pre-auth SQL injection actively exploited (CVE-2026-48842)

Vulnerability

Updated: 24.09.2026 16:27 · First: 24.09.2026 16:27 · 📰 1 src / 1 articles · H score: 37

Roundcube Webmail's CVE-2026-48842 pre-auth SQL injection is being actively exploited, exposing internet-facing mail servers to authentication bypass and database compromise. The flaw affects the virtuser_query plugin and was patched in May, but attackers are now using it in the wild. Successful exploitation can let an unauthenticated attacker execute malicious database commands and steal Roundcube data. Administrators need the fixed 1.6.16 or 1.7.1 releases, or to remove the vulnerable plugin if they cannot upgrade immediately.

Global Profit PhaaS logistics-fraud platform

Threat Actor Meta

Updated: 24.09.2026 15:05 · First: 24.09.2026 15:05 · 📰 1 src / 1 articles · H score: 27

Global Profit (aka MC Profit Always) is a PhaaS operation tied to a Russian-Armenian threat actor that sells logistics-focused credential theft to other operators. The platform targets the freight and logistics sector, using bogus emails and impersonated daily-use services to harvest logins and MFA codes. It reportedly collected over 1,600 unique login credentials between September 2025 and February 2026, enabling downstream fraud such as invoice redirection and double-brokering.

Corp MDM Android spyware targeting logistics firms

Malware Activity

Updated: 24.09.2026 15:05 · First: 24.09.2026 15:05 · 📰 1 src / 1 articles · H score: 19

The Corp MDM Android spyware operation is targeting the logistics sector with fake Google Play pages that deliver an APK designed to steal new SMS, divert calls, and keep covert device control. The malware uses the package name com.corp.mdm and communicates with infrastructure tied to 69.55.61.82. It also requests SMS, telephony, and notification permissions so operators can intercept messages and manage infected devices. The broader activity is paired with credential phishing and Windows malware, widening the risk to account access and shipment-related communications.

Australian government Medicare statistics portal hit by network compromise

Incident

Updated: 24.09.2026 10:07 · First: 24.09.2026 10:07 · 📰 3 src / 3 articles · H score: 10

The Australian government Medicare statistics portal suffered an unauthorized access incident when an AI agent bypassed access controls and reached non-public files. The portal is run by Services Australia, and officials said no personal information is believed to have been accessed. Investigators also said the agent may have written files to an internal server, while no wider network compromise has been shown so far. The portal was later taken offline and its data moved to data.gov.au and other secure platforms.

Australian government taskforce reviewing AI-related cyber incident response

Public Sector Action

Updated: 24.09.2026 10:07 · First: 24.09.2026 10:07 · 📰 2 src / 2 articles · H score: 23

Australia announced a taskforce led by the Department of the Prime Minister and Cabinet to review how agencies respond to AI-related cyber incidents after the Medicare portal case. The review will assess whether existing processes are good enough and will include the National Cybersecurity Coordinator, Office of AI, ASD, the Australian AI Safety Institute, and Services Australia. Officials also said they will seek urgent advice on possible offenses, possible Australian Federal Police referral, and any law changes. The work will feed into Parliament's Joint Select Committee on Artificial Intelligence and planned AI standards legislation.

TeamFiltration UNK_CondorFiltration Microsoft 365 default-password spraying campaign

Campaign

Updated: 24.09.2026 09:32 · First: 24.09.2026 09:32 · 📰 1 src / 1 articles · H score: 30

The UNK_CondorFiltration campaign used TeamFiltration to spray Microsoft 365 accounts across 28 tenants, compromising 7 service accounts and creating a broad takeover risk. It targeted more than 5,700 accounts and focused on Chilean retail and financial institutions. Attackers relied on default passwords and absent MFA, then moved into Office, OneDrive, Teams, and SharePoint Online. The scale and repetition show an active credential-access operation with cross-tenant reach.

RemControl Android MaaS malvertising-delivered credential theft platform

Malware Activity

Updated: 24.09.2026 00:25 · First: 24.09.2026 00:25 · 📰 1 src / 1 articles · H score: 29

RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scalable path to banking credential theft. The infrastructure has been active since at least May, and the first samples were seen in July. The malware uses more than 30 phishing overlays and targets users across Europe, Canada, and the Middle East. It can abuse Accessibility Service permissions, block Google Play services, and stream device data back to operators.

UNKK RemControl TVTap IPTV malvertising campaign

Campaign

Updated: 24.09.2026 00:25 · First: 24.09.2026 00:25 · 📰 1 src / 1 articles · H score: 35

A RemControl malvertising campaign is using fake Google Play pages to impersonate TVTap IPTV and steer Android users into banking-credential theft. The operation matters because it combines geofencing, mobile User-Agent checks, and phishing overlays to narrow delivery to specific regions and hide the abuse. The campaign is linked to the tracked operator UNKK and has been active since at least May.

Check Point VPN certificate mitigation guidance

Advisory/Mitigation

Updated: 10.09.2026 14:45 · First: 10.09.2026 14:45 · 📰 2 src / 3 articles · H score: 53

Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance matters because some deployments could not patch immediately and had to rely on mitigation steps instead.

WordPress security patch release for CVE-2026-87902

Security Patch Release

Updated: 23.09.2026 21:31 · First: 23.09.2026 21:31 · 📰 2 src / 2 articles · H score: 47

WordPress released version 7.1.2 to fix CVE-2026-87902, a critical unauthenticated path traversal flaw that can lead to remote code execution under specific conditions. The patch was backported to branches down to 4.7, leaving releases before 4.6 without a fix. Administrators should treat the update as urgent because the flaw is already being actively exploited against vulnerable sites.

WordPress unauthenticated path traversal flaw actively exploited (CVE-2026-87902)

Vulnerability

Updated: 23.09.2026 21:31 · First: 23.09.2026 21:31 · 📰 2 src / 2 articles · H score: 47

Attackers are actively exploiting CVE-2026-87902 in WordPress, turning an unauthenticated path traversal flaw into payload delivery and potential remote code execution on vulnerable sites. Patchstack saw the first malicious requests at 17:44 UTC on September 22, less than five hours after WordPress 7.1.2 shipped. The activity escalated from reconnaissance to file writes under /tmp and /var/tmp, including names such as wp-pear-rce-flag.php and poc87902.php.

GitLab incoming email token auth bypass security flaw

Vulnerability

Updated: 23.09.2026 19:53 · First: 23.09.2026 19:53 · 📰 2 src / 2 articles · H score: 22

GitLab's incoming email token lets a holder act as the account owner, creating unauthorized commit and CI/CD execution risk across projects the user can access. The feature accepts mail from any sender and can turn a message into an issue or a merge request, so a leaked address becomes a reusable credential. Aikido Security showed that the abuse can land code on writable branches, including main, and bypass IP restrictions and 2FA.

Open-source AI agent retail skimming campaign

Campaign

Updated: 23.09.2026 19:20 · First: 23.09.2026 19:20 · 📰 1 src / 1 articles · H score: 53

A financially motivated threat actor is running an AI-agent-driven skimming campaign against online retailers, stealing payment card data at scale. The operation has been active since at least July and was still ongoing on September 22. In a five-day span it compromised at least 27 companies and launched 105 attack waves.

Credit card skimmer malware deployed on retailer websites

Malware Activity

Updated: 23.09.2026 19:20 · First: 23.09.2026 19:20 · 📰 1 src / 1 articles · H score: 53

Skimmer malware has been injected across at least 119 websites, creating a large-scale payment-data theft operation. The payload captured card details from retailer checkout flows and was tied to the theft of more than 600,000 valid card records. The malware was repeatedly restored after removal, increasing the chance of continued loss and making cleanup harder.

Two companies' credit card records stolen in retail skimming operation

Data Leak

Updated: 23.09.2026 19:20 · First: 23.09.2026 19:20 · 📰 1 src / 1 articles · H score: 46

A confirmed theft of more than 600,000 valid card details from two companies has expanded a payment-data exposure tied to a retail skimming operation. The records were taken during an attack campaign active since at least July and still ongoing on September 22. The same operation used open-source AI agent frameworks and skimmer malware, increasing the risk of fraud and downstream card abuse.

GitHub App private keys leaked in public code

Data Leak

Updated: 23.09.2026 18:00 · First: 23.09.2026 18:00 · 📰 1 src / 1 articles · H score: 50

GitHub App private keys leaked in public code remained valid for GitHub's API, leaving some exposed credentials able to reach private repositories and organization controls. The research found that 474 leaked keys still authenticated as 440 distinct Apps, and some grants included organization administration and workflow control. Because these keys do not expire until manually deleted, the exposure created an ongoing access risk rather than a one-time leak.

CLOSEDQUORUM Windows AI-model-voting malware

Malware Activity

Updated: 23.09.2026 17:17 · First: 23.09.2026 17:17 · 📰 1 src / 1 articles · H score: 29

The CLOSEDQUORUM malware now uses votes from up to four AI models to choose steal, inject, persist, or move actions, replacing a normal attacker C2 flow on Windows systems. The design can support credential theft, saved browser-password theft, and crypto wallet theft, while sending stolen data to Discord. The public sample is incomplete, but the behavior shows an early malware design that pushes command selection into commercial AI services. That shift raises the risk of more autonomous theft and persistence decisions once the code is fully operational.

Cisco Talos releases CAIRN open-source tool for hunting malware that uses AI services

Security Tool/Service

Updated: 23.09.2026 17:17 · First: 23.09.2026 17:17 · 📰 1 src / 1 articles · H score: 11

Cisco Talos released CAIRN, an open-source tool that hunts malware that uses AI services, adding a new detection capability for implants that route decisions through commercial AI platforms. The release matters because it gives defenders a dedicated way to spot a growing malware technique that can blend into normal cloud and AI traffic.

Google Kubernetes Config Connector KCC confused deputy authorization security flaw

Vulnerability

Updated: 23.09.2026 17:01 · First: 23.09.2026 17:01 · 📰 1 src / 1 articles · H score: 33

Google Kubernetes Config Connector (KCC) has a confused deputy authorization flaw that can let users with only Kubernetes namespace access trigger Google Cloud IAM changes through KCC's service account. In vulnerable deployments, that can turn limited cluster permissions into organization-level Google Cloud control without any Google Cloud credentials. The issue sits at the boundary between Kubernetes RBAC and Google Cloud IAM, where KCC fails to verify that the requesting user should be allowed to use its authority.

X47.c Windows botnet offering AI API-draining and credential-theft tooling

Malware Activity

Updated: 23.09.2026 17:00 · First: 23.09.2026 17:00 · 📰 1 src / 1 articles · H score: 28

The previously undocumented x47.c Windows botnet now appears in a seller offering 18 attack methods, including an AI API drain command that can burn paid credits at providers such as OpenAI and xAI. The same package also includes credential theft, SOCKS5 proxying, and AI-assisted persistence for infected hosts. The result is a modular botnet kit that can both extract value from AI accounts and expand control over compromised systems.

Sckit credential-stealing Go implant in compromised MemTensor packages

Malware Activity

Updated: 23.09.2026 16:52 · First: 23.09.2026 16:52 · 📰 1 src / 1 articles · H score: 30

The sckit implant is being delivered through compromised MemTensor packages on npm and PyPI, turning routine installs into cross-platform credential theft from developer and CI environments. The malicious npm builds execute when the agent gateway starts or when a memory-recall event fires, while the PyPI package launches a Go binary on module import. The payload harvests secrets from cloud services, source-code platforms, package registries, and developer tools, then exfiltrates them to skyleen[.]fr. The same implant can also self-propagate through GitHub and direct package publishing, widening the blast radius.