Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 20:13 23/09/2026 UTC
  • Data Leak H score 84 FBI employee and applicant data leak claim ShinyHunters escalated its unverified claim of stealing 2–3TB from FBI systems using a new Oracle PeopleSoft zero-day, prompting FBI to take affected services offline and raising urgent insider-PII risk.
  • Vulnerability H score 54 F5 BIG-IP APM zero-day RCE (CVE-2026-94127) F5 disclosed active exploitation of the BIG-IP APM zero-day CVE-2026-94127 and issued patches plus an iRule mitigation, advancing immediate RCE-focused remediation for OAuth-configured deployments.
  • Security Patch Release H score 52 Check Point security patch release for CVE-2026-93616 Check Point released hotfixes for the R82.20 TAR and related accumulators to address CVE-2026-93616, a management-server zero-day already exploited in the wild.
  • Security Patch Release H score 47 WordPress security patch release for CVE-2026-87902 WordPress patched CVE-2026-87902 (unauthenticated path traversal with potential RCE) in 7.1.2 with backports to 4.7, changing urgency for sites on older unsupported branches.
  • Malware Activity H score 53 Credit card skimmer malware deployed on retailer websites Skimmer malware was observed repeatedly reinstalled across at least 119 retailer sites to steal over 600,000 valid card records, making persistence-focused cleanup a critical shift.
  • Data Leak H score 50 GitHub App private keys leaked in public code Research found hundreds of GitHub App private keys leaked in public code remained valid and could access private repos and org controls until manually deleted, turning the issue into a continuing credential-compromise risk.
Last updated: 04:05 23/09/2026 UTC

Latest updates

Browse →

Check Point VPN certificate mitigation guidance

Advisory/Mitigation

Updated: 10.09.2026 14:45 · First: 10.09.2026 14:45 · 📰 2 src / 3 articles · H score: 53

Check Point directed affected customers to Live Patch or the latest Jumbo Hotfix for its VPN certificate flaws, with rollout beginning on September 9. The guidance matters because some deployments could not patch immediately and had to rely on mitigation steps instead.

WordPress security patch release for CVE-2026-87902

Security Patch Release

Updated: 23.09.2026 21:31 · First: 23.09.2026 21:31 · 📰 1 src / 1 articles · H score: 47

WordPress released version 7.1.2 to fix CVE-2026-87902, a critical unauthenticated path traversal flaw that can lead to remote code execution under specific conditions. The patch was backported to branches down to 4.7, leaving releases before 4.6 without a fix. Administrators should treat the update as urgent because the flaw is already being actively exploited against vulnerable sites.

WordPress unauthenticated path traversal flaw actively exploited (CVE-2026-87902)

Vulnerability

Updated: 23.09.2026 21:31 · First: 23.09.2026 21:31 · 📰 1 src / 1 articles · H score: 44

Attackers are actively exploiting CVE-2026-87902 in WordPress, turning an unauthenticated path traversal flaw into payload delivery and potential remote code execution on vulnerable sites. Patchstack saw the first malicious requests at 17:44 UTC on September 22, less than five hours after WordPress 7.1.2 shipped. The activity escalated from reconnaissance to file writes under /tmp and /var/tmp, including names such as wp-pear-rce-flag.php and poc87902.php.

GitLab incoming email token auth bypass security flaw

Vulnerability

Updated: 23.09.2026 19:53 · First: 23.09.2026 19:53 · 📰 1 src / 1 articles · H score: 18

GitLab's incoming email token lets a holder act as the account owner, creating unauthorized commit and CI/CD execution risk across projects the user can access. The feature accepts mail from any sender and can turn a message into an issue or a merge request, so a leaked address becomes a reusable credential. Aikido Security showed that the abuse can land code on writable branches, including main, and bypass IP restrictions and 2FA.

Open-source AI agent retail skimming campaign

Campaign

Updated: 23.09.2026 19:20 · First: 23.09.2026 19:20 · 📰 1 src / 1 articles · H score: 53

A financially motivated threat actor is running an AI-agent-driven skimming campaign against online retailers, stealing payment card data at scale. The operation has been active since at least July and was still ongoing on September 22. In a five-day span it compromised at least 27 companies and launched 105 attack waves.

Credit card skimmer malware deployed on retailer websites

Malware Activity

Updated: 23.09.2026 19:20 · First: 23.09.2026 19:20 · 📰 1 src / 1 articles · H score: 53

Skimmer malware has been injected across at least 119 websites, creating a large-scale payment-data theft operation. The payload captured card details from retailer checkout flows and was tied to the theft of more than 600,000 valid card records. The malware was repeatedly restored after removal, increasing the chance of continued loss and making cleanup harder.

Two companies' credit card records stolen in retail skimming operation

Data Leak

Updated: 23.09.2026 19:20 · First: 23.09.2026 19:20 · 📰 1 src / 1 articles · H score: 46

A confirmed theft of more than 600,000 valid card details from two companies has expanded a payment-data exposure tied to a retail skimming operation. The records were taken during an attack campaign active since at least July and still ongoing on September 22. The same operation used open-source AI agent frameworks and skimmer malware, increasing the risk of fraud and downstream card abuse.

GitHub App private keys leaked in public code

Data Leak

Updated: 23.09.2026 18:00 · First: 23.09.2026 18:00 · 📰 1 src / 1 articles · H score: 50

GitHub App private keys leaked in public code remained valid for GitHub's API, leaving some exposed credentials able to reach private repositories and organization controls. The research found that 474 leaked keys still authenticated as 440 distinct Apps, and some grants included organization administration and workflow control. Because these keys do not expire until manually deleted, the exposure created an ongoing access risk rather than a one-time leak.

CLOSEDQUORUM Windows AI-model-voting malware

Malware Activity

Updated: 23.09.2026 17:17 · First: 23.09.2026 17:17 · 📰 1 src / 1 articles · H score: 29

The CLOSEDQUORUM malware now uses votes from up to four AI models to choose steal, inject, persist, or move actions, replacing a normal attacker C2 flow on Windows systems. The design can support credential theft, saved browser-password theft, and crypto wallet theft, while sending stolen data to Discord. The public sample is incomplete, but the behavior shows an early malware design that pushes command selection into commercial AI services. That shift raises the risk of more autonomous theft and persistence decisions once the code is fully operational.

Cisco Talos releases CAIRN open-source tool for hunting malware that uses AI services

Security Tool/Service

Updated: 23.09.2026 17:17 · First: 23.09.2026 17:17 · 📰 1 src / 1 articles · H score: 11

Cisco Talos released CAIRN, an open-source tool that hunts malware that uses AI services, adding a new detection capability for implants that route decisions through commercial AI platforms. The release matters because it gives defenders a dedicated way to spot a growing malware technique that can blend into normal cloud and AI traffic.

Google Kubernetes Config Connector KCC confused deputy authorization security flaw

Vulnerability

Updated: 23.09.2026 17:01 · First: 23.09.2026 17:01 · 📰 1 src / 1 articles · H score: 33

Google Kubernetes Config Connector (KCC) has a confused deputy authorization flaw that can let users with only Kubernetes namespace access trigger Google Cloud IAM changes through KCC's service account. In vulnerable deployments, that can turn limited cluster permissions into organization-level Google Cloud control without any Google Cloud credentials. The issue sits at the boundary between Kubernetes RBAC and Google Cloud IAM, where KCC fails to verify that the requesting user should be allowed to use its authority.

X47.c Windows botnet offering AI API-draining and credential-theft tooling

Malware Activity

Updated: 23.09.2026 17:00 · First: 23.09.2026 17:00 · 📰 1 src / 1 articles · H score: 28

The previously undocumented x47.c Windows botnet now appears in a seller offering 18 attack methods, including an AI API drain command that can burn paid credits at providers such as OpenAI and xAI. The same package also includes credential theft, SOCKS5 proxying, and AI-assisted persistence for infected hosts. The result is a modular botnet kit that can both extract value from AI accounts and expand control over compromised systems.

Sckit credential-stealing Go implant in compromised MemTensor packages

Malware Activity

Updated: 23.09.2026 16:52 · First: 23.09.2026 16:52 · 📰 1 src / 1 articles · H score: 30

The sckit implant is being delivered through compromised MemTensor packages on npm and PyPI, turning routine installs into cross-platform credential theft from developer and CI environments. The malicious npm builds execute when the agent gateway starts or when a memory-recall event fires, while the PyPI package launches a Go binary on module import. The payload harvests secrets from cloud services, source-code platforms, package registries, and developer tools, then exfiltrates them to skyleen[.]fr. The same implant can also self-propagate through GitHub and direct package publishing, widening the blast radius.

Arista security patch release for CVE-2026-93952

Security Patch Release

Updated: 22.09.2026 15:29 · First: 22.09.2026 15:29 · 📰 2 src / 2 articles · H score: 53

Arista released fixed VeloCloud Orchestrator (VCO) builds for the 5.2 and 6.4 trains, reducing exposure for deployments tied to CVE-2026-93952. The patch set covers on-premises and Hosted/Dedicated VCO versions, while 6.1 and 7.0 were still awaiting fixes as of September 22. The release matters because VCO manages Edge devices in VeloCloud SD-WAN and compromise can extend beyond the orchestrator itself.

CPanel CalDAV and CardDAV root code execution security flaw (CVE-2026-87899)

Vulnerability

Updated: 23.09.2026 15:16 · First: 23.09.2026 15:16 · 📰 1 src / 1 articles · H score: 33

cPanel's fix for CVE-2026-87899 closes a CalDAV and CardDAV flaw that let a logged-in hosting account run code as root, putting affected servers at risk of full control. The issue affected cPanel & WHM and WP Squared, and cPanel released patched builds for the supported release lines. No temporary workaround was offered, so exposed systems need an update to remove the risk.

WP Toolkit cross-account database modification security flaw (CVE-2026-87900)

Vulnerability

Updated: 23.09.2026 15:16 · First: 23.09.2026 15:16 · 📰 1 src / 1 articles · H score: 1

The WP Toolkit flaw CVE-2026-87900 lets a logged-in cPanel user change databases in other accounts, creating cross-account data-integrity risk on shared hosting systems. cPanel fixed the issue in WP Toolkit 6.11.3 or later while 6.11.2-10794 and older remain affected.

CPanel CalDAV and CardDAV calendar/contact read flaw (CVE-2026-68490)

Vulnerability

Updated: 23.09.2026 15:16 · First: 23.09.2026 15:16 · 📰 1 src / 1 articles · H score: 27

cPanel fixed CVE-2026-68490, a CalDAV and CardDAV flaw that lets a local user read other accounts' calendar events and contacts on affected hosting systems. The bug is confined to confidentiality, but it still exposes private scheduling and relationship data across accounts. cPanel & WHM and WP Squared received fixed builds, and the vendor said the update also repairs related permissions.

XRanges for AI launches a telemetry-driven autonomous security agent evaluation platform

Security Tool/Service

Updated: 23.09.2026 14:47 · First: 23.09.2026 14:47 · 📰 1 src / 1 articles · H score: 13

XRanges for AI has launched as a managed cloud and self-hosted platform for evaluating autonomous security agents against realistic targets. Built by CTF.ae, it instruments each service, records what an agent actually does, and scores every run live on four independent signals. That gives teams a more reproducible way to benchmark agent behavior across pentesting and bug-bounty workflows.

Microsoft Windows 11 September 2026 updates break Always On VPN connections

Service Disruption

Updated: 23.09.2026 14:18 · First: 23.09.2026 14:18 · 📰 1 src / 1 articles · H score: 0

Microsoft's September 2026 Windows 11 security updates are disrupting Always On VPN connections, leaving some enterprise users stuck in "Connecting" or seeing "The specified port is already in use" errors. The issue affects devices that use automatic protocol selection for VPN tunneling and can block access back to the corporate network. Microsoft has posted a temporary workaround that forces SSTP only or IKEv2 only until a permanent fix is available.

Linux kernel AF_UNIX socket use-after-free security flaw (CVE-2026-80521)

Vulnerability

Updated: 23.09.2026 14:12 · First: 23.09.2026 14:12 · 📰 1 src / 1 articles · H score: 19

Exploit code for CVE-2026-80521 exposed Ubuntu 26.04, 24.04, and 22.04 LTS systems to container-escape risk through a Linux kernel AF_UNIX socket use-after-free. The flaw can let an attacker break out of a container and reach root on the host, and DepthFirst said it targeted Ubuntu 26.04. The bug was fixed upstream on August 6, but Ubuntu had not shipped the patch for the affected releases.

Google Chrome 154 security update (108 vulnerabilities)

Security Patch Release

Updated: 23.09.2026 13:36 · First: 23.09.2026 13:36 · 📰 1 src / 1 articles · H score: 27

Google released Chrome 154 to the stable channel, patching 108 vulnerabilities including 11 critical-severity bugs across desktop builds. The update matters because the fixes cover high-risk memory corruption issues in components such as ANGLE, WebGL, GPU, and browser features that can affect everyday browsing security.

FBI employee and applicant data leak claim

Data Leak

Updated: 22.09.2026 22:13 · First: 22.09.2026 22:13 · 📰 3 src / 3 articles · H score: 84

ShinyHunters claims it breached the FBI using a new Oracle PeopleSoft zero-day and stole data tied to current and former FBI employees and job applicants. The group says the exposure included Criminal Justice (CJ), HR, Medlink, and other FBI systems, and it shared sample records plus a defaced FBI Jobs page. A separate account says ShinyHunters first used remote code execution in Oracle PeopleSoft and then moved into FBI-managed AWS GovCloud infrastructure. The FBI says it is investigating the unauthorized-activity claims affecting FBIjobs.gov; the access and leak claims remain unverified.

BlueMoon exploit kit deployment across espionage clusters

Malware Activity

Updated: 09.09.2026 19:34 · First: 09.09.2026 19:34 · 📰 2 src / 4 articles · H score: 34

BlueMoon is a shared exploit kit used in espionage campaigns that chain Google Chrome and Microsoft Windows flaws into code execution, browser sandbox escape, and Windows local privilege escalation. Proofpoint said it observed the kit in use since August 28, 2026, and Volexity later tied related activity to UTA0560, JungleBamboo / APT31, and UTA0565. The reported chains use CVE-2026-85046, CVE-2026-87491, and CVE-2026-85880, with follow-on delivery that included loaders, DLL sideloading, a Chrome extension or backdoor payload, and CLEANGULP. The activity targeted NGOs, U.S. aerospace companies, a Vietnamese manufacturing entity, and organizations in Indonesia and Singapore, and CISA added CVE-2026-85046 to its Known Exploited Vulnerabilities catalog on September 4.

F5 BIG-IP APM zero-day RCE (CVE-2026-94127)

Vulnerability

Updated: 23.09.2026 10:17 · First: 23.09.2026 10:17 · 📰 2 src / 2 articles · H score: 54

A critical zero-day in F5 BIG-IP APM tracked as CVE-2026-94127 is being actively exploited for remote code execution on deployments configured as an OAuth Authorization Server. F5 released security updates and said systems using APM strictly as an OAuth Client / Resource Server are not affected. Administrators who cannot patch immediately can apply an iRule mitigation and should watch for multiple OAuth authentication failures, suspicious commands, and a TMM SIGABRT.

Next.js ImageResponse SVG code execution security flaw (CVE-2026-94545)

Vulnerability

Updated: 23.09.2026 10:04 · First: 23.09.2026 10:04 · 📰 1 src / 1 articles · H score: 31

CVE-2026-94545 affects Next.js ImageResponse on the Node.js runtime, where attacker-controlled SVG input can lead to server-side code execution. The flaw impacts Next.js 16.2.0 through 16.3.5 and was fixed in 16.3.6. Next.js 15 and the Edge version of ImageResponse are not affected. No public attack reports or public exploit code were known as of September 23.

CISA KEV listing of Check Point flaws and three-day federal patch mandate

Public Sector Action

Updated: 23.09.2026 09:14 · First: 23.09.2026 09:14 · 📰 1 src / 1 articles · H score: 36

CISA added Check Point's exploited zero-day and CVE-2026-85102 to the KEV catalog, triggering a three-day federal patch clock under BOD 26-04. The action forces federal agencies to rapidly remediate the listed Check Point vulnerabilities. It raises immediate urgency for government networks running the affected products.

Check Point Management Server directory traversal/file upload zero-day (CVE-2026-93616)

Vulnerability

Updated: 23.09.2026 09:14 · First: 23.09.2026 09:14 · 📰 1 src / 1 articles · H score: 45

Check Point issued urgent fixes for CVE-2026-93616, a critical zero-day in Management Server products that is being exploited in the wild. The flaw is a directory traversal and file upload issue that can let unauthenticated attackers upload and execute arbitrary scripts on affected servers. Impacted products include Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server, and SmartEvent. Check Point said it is aware of a handful of customers who have been attacked.

Check Point security patch release for CVE-2026-93616

Security Patch Release

Updated: 23.09.2026 09:14 · First: 23.09.2026 09:14 · 📰 1 src / 1 articles · H score: 52

Check Point released R82.20 Security Hotfix (TAR) and updated Jumbo Hotfix Accumulator packages to fix CVE-2026-93616, a Management Server zero-day exploited in the wild. The fixes cover R82.10, R82, R81.20, and R81.10, extending remediation across multiple product branches. Check Point said customers should install the patches immediately and restrict management access behind a firewall or security gateway. The company also warned that LivePatch does not resolve the flaw.

TrustSink rogue external MFA provider attack against Microsoft Entra

Technical Analysis

Updated: 23.09.2026 00:45 · First: 23.09.2026 00:45 · 📰 1 src / 1 articles · H score: 30

Researchers demonstrated TrustSink, a post-compromise technique that abuses Microsoft Entra external MFA providers to capture passwords during legitimate sign-ins, creating credential-theft risk for organizations that rely on external authentication. The attack can keep working across password resets until the rogue provider and related tenant objects are removed.

Unnamed Western government organization data exposed after WordPress breach

Data Leak

Updated: 22.09.2026 23:35 · First: 22.09.2026 23:35 · 📰 1 src / 1 articles · H score: 66

A Western government organization suffered a data leak after attackers reached an internal SQL server and stole 18,566 records, exposing accounts, plaintext passwords, and PII. The stolen data was tied to government and law-enforcement agencies, making the theft operationally sensitive. The breach sat inside a broader wp2shell exploitation wave against WordPress Core that hit multiple organizations across 29 countries.