Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 06:38 17/09/2026 UTC
Last updated: 09:50 16/09/2026 UTC

Latest updates

Browse →

Cisco security patch release for CVE-2026-76460

Security Patch Release

Updated: 17.09.2026 10:20 · First: 17.09.2026 10:20 · 📰 1 src / 1 articles · H score: 40

Cisco released security updates for Cisco ISE and ISE-PIC to fix CVE-2026-76460, a maximum-severity authentication bypass that is actively exploited in the wild. The fixed releases are the only recommended remediation because no workarounds exist. The patch bundle covers the affected ISE software lines and closes a flaw that can expose management access to remote attackers.

Cisco ISE and ISE-PIC actively exploited authentication bypass (CVE-2026-76460)

Vulnerability

Updated: 17.09.2026 10:20 · First: 17.09.2026 10:20 · 📰 1 src / 1 articles · H score: 34

Cisco ISE and ISE-PIC are facing CVE-2026-76460, a maximum-severity API authentication bypass that is actively exploited in the wild. The flaw can let remote attackers send a crafted request and gain unauthorized access by bypassing the web-based management interface. Fixed software releases are available, and CISA has added the CVE to the KEV Catalog with a three-day patch deadline for federal agencies.

Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog ordered federal agencies to patch systems against CVE-2026-76460 for within

Public Sector Action

Updated: 17.09.2026 10:20 · First: 17.09.2026 10:20 · 📰 1 src / 1 articles · H score: 36

CISA ordered federal agencies to patch CVE-2026-76460 within three days, imposing an urgent remediation deadline for an actively exploited Cisco flaw. The order followed the agency's addition of the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on Wednesday. The directive forces rapid mitigation across the federal civilian environment because the flaw allows remote attackers to bypass authentication in Cisco ISE and ISE-PIC.

Cisco Secure Email Gateway insufficient validation flaw (CVE-2026-76461)

Vulnerability

Updated: 15.09.2026 09:11 · First: 15.09.2026 09:11 · 📰 2 src / 2 articles · H score: 45

Cisco Secure Email Gateway devices are exposed to CVE-2026-76461, an actively exploited email-parsing flaw that can let an unauthenticated remote attacker execute commands with root privileges. Cisco says the weakness affects both physical and virtual appliances and released fixes for 15.5 and earlier, 16.0, and 16.5. There are no workarounds beyond upgrading, and Cisco warned that exploitation can hide evidence on the device. CISA added the CVE to KEV and set a September 17, 2026 deadline for FCEB patching.

Windows 11 KB5124008 Active Directory domain trust breakage

Service Disruption

Updated: 16.09.2026 23:39 · First: 16.09.2026 23:39 · 📰 1 src / 1 articles · H score: 0

The Windows 11 KB5124008 security update is breaking Active Directory domain trust on some enterprise systems, preventing valid users from signing in after reboot. Microsoft is investigating the disruption, and affected machines may lose their secure channel with domain controllers. Some administrators have temporarily restored access by changing Machine Identity Isolation settings and repairing the secure channel.

KREMLIN browser-extension credential theft activity

Malware Activity

Updated: 15.09.2026 21:54 · First: 15.09.2026 21:54 · 📰 2 src / 2 articles · H score: 44

The KREMLIN malware activity is a Brazilian banking operation that has been active since at least May 2025 and uses malicious Chrome and Edge extensions to steal credentials, session tokens, and other sensitive browser data. Elastic Security Labs said the loader bypasses Chromium integrity checks, installs the extension without user approval, and uses Ethereum smart contracts and Internet Archive-hosted payloads to rotate infrastructure and deliver the chain. The activity spans seven campaigns, impersonates 12 banks, and includes recent use of REMCOS or Pulsar RAT alongside the browser-extension theft. Elastic also confirmed 1,515 infected systems, almost all in Brazil, and disrupted the current campaign by registering an anti-sandbox canary domain.

New Jersey court Ordered radaris.com and more than a dozen other data broker domains transferred to the plaintiffs on Domain transfer as default-judgment relief in a Daniel’s Law

Regulatory/Legal Action

Updated: 16.09.2026 21:14 · First: 16.09.2026 21:14 · 📰 1 src / 1 articles · H score: 69

A New Jersey court ordered radaris.com and more than a dozen other data broker domains transferred to the plaintiffs, escalating enforcement of Daniel’s Law against a people-search operation accused of exposing protected personal information. The order followed a default judgment after the defendants repeatedly failed to appear and defend the claims. The transfer removes the operation’s main web presence and shows that courts can use domain-level remedies to enforce privacy obligations.

AEPD urges stronger identity and credential controls against AI-assisted machine-speed attacks

Defensive Guidance

Updated: 16.09.2026 20:26 · First: 16.09.2026 20:26 · 📰 1 src / 2 articles · H score: 11

Spanish Data Protection Agency (AEPD) said it was notified of an alleged AI agent attack powered by a known LLM, and urged stronger digital identity and credential security. The reported activity involved searching for vulnerabilities, logging in, probing applications, then modifying personal data and accessing invoices. AEPD has not verified the incident yet, but says AI-assisted attacks can increase speed, scale, and adaptability and compress defenders’ response windows. The guidance calls for faster detection, containment, and response against autonomous activity that can reuse compromised accounts, API keys, or tokens across multiple services at machine speed.

Organization reporting incident hit by network compromise

Incident

Updated: 16.09.2026 20:26 · First: 16.09.2026 20:26 · 📰 1 src / 2 articles · H score: 10

The organization reporting the incident said an AI agent powered by a known LLM carried out an alleged intrusion that searched for flaws, logged into systems, and probed applications for more weaknesses before modifying personal data and accessing invoices. The notification was sent to the Spanish Data Protection Agency (AEPD), which has not verified the claims. AEPD said the report shows AI-related data breaches are moving into operational risk and can speed attacks, expand scope, and shorten defenders' response windows.

Issabel Framework hard-coded JWT signing key RCE (CVE-2026-89026)

Vulnerability

Updated: 16.09.2026 18:50 · First: 16.09.2026 18:50 · 📰 1 src / 1 articles · H score: 46

CVE-2026-89026 in Issabel Framework is under active exploitation, exposing Asterisk deployments to unauthenticated remote OS command execution through forged bearer tokens. A hard-coded JWT signing key lets attackers mint valid tokens and reach the /pbxapi/manager/originate endpoint. A patch was released on August 1, 2026, and defenders should ensure the latest fix is applied promptly.

Issabel Framework security patch for CVE-2026-89026

Security Patch Release

Updated: 16.09.2026 18:50 · First: 16.09.2026 18:50 · 📰 1 src / 1 articles · H score: 50

A security patch for Issabel Framework was pushed on August 1, 2026 to fix CVE-2026-89026, closing an unauthenticated OS command execution path tied to a hard-coded JWT signing key. The update moves the JWT key out of the application code and into /etc/issabel.conf, reducing the risk across affected installations. That remediation is directly relevant because the flaw was already under active exploitation.

NightEagle Russian enterprise VPN GhostContainer campaign

Campaign

Updated: 16.09.2026 18:27 · First: 16.09.2026 18:27 · 📰 1 src / 1 articles · H score: 37

The NightEagle (APT-Q-95) campaign is actively using compromised VPN credentials and GhostContainer to reach Russian enterprise networks, increasing the risk of persistent access and lateral movement. The operators are combining stolen access with a backdoor that can control Microsoft Exchange Server systems, run code, and load modules. The activity has been active since at least 2023 and was highlighted in July 2025. The operation shows sustained targeting rather than a one-off intrusion.

Microsoft Edge AI agent hijack flaw (CVE-2026-55945)

Vulnerability

Updated: 16.09.2026 17:36 · First: 16.09.2026 17:36 · 📰 1 src / 1 articles · H score: 25

Microsoft Edge has a CVE-2026-55945 flaw that let a browser extension influence the Edge AI agent by combining trusted-page control with a race condition during the think/act transition. Microsoft fixed the issue in Edge 150.0.4078.48 on July 2, 2026. The finding was rated 4.2 and was demonstrated as a proof of concept, with no public evidence of in-the-wild abuse.

CISA and NIST issue cloud identity token guidance

Public Sector Action

Updated: 16.09.2026 17:00 · First: 16.09.2026 17:00 · 📰 1 src / 1 articles · H score: 35

CISA and NIST issued final guidance for protecting cloud identity tokens and assertions, setting a federal cybersecurity baseline for federal agencies, cloud service providers, and their customers. The guidance aims to reduce the risk that stolen or forged tokens can be used for lateral movement and access to sensitive data. It is voluntary, but it gives organizations concrete controls for token lifetime, key management, and validation.

Shai-Hulud worm spread across internal repositories after AI assistant hijack

Malware Activity

Updated: 16.09.2026 16:37 · First: 16.09.2026 16:37 · 📰 1 src / 1 articles · H score: 12

The Shai-Hulud worm spread across about 100 internal code repositories, exposing repository secrets and source code after an AI coding-assistant session was hijacked. The intrusion used a poisoned PyPI package and stolen GitHub OAuth tokens to extend access. A second infection followed when a compromised package in the company's official namespace was pulled by another employee. The event shows how a malware chain can turn trusted developer tooling into a rapid repository-wide compromise.

Parallels Desktop 27 security update for CVE-2026-90894

Security Patch Release

Updated: 16.09.2026 16:14 · First: 16.09.2026 16:14 · 📰 1 src / 1 articles · H score: 34

Parallels Desktop 27.0.0 is the fixed release for CVE-2026-90894, closing a local root flaw in Parallels Desktop for Mac. Builds on 26.x remain on the affected line, and Intel Macs cannot install version 27. The patch matters because the flaw lets an ordinary local account reach root on the host Mac.

Parallels Desktop Mac local root escalation security flaw (CVE-2026-90894)

Vulnerability

Updated: 16.09.2026 16:14 · First: 16.09.2026 16:14 · 📰 1 src / 1 articles · H score: 25

CVE-2026-90894 in Parallels Desktop for Mac lets a non-admin local account execute code as root on the Mac host through prl_disp_service and tar argument injection. JFrog demonstrated the flaw on Parallels Desktop 26.4.0 and says Parallels Desktop 27.0.0 fixes it. The weakness affects the Mac host, not guest VMs, and JFrog reports no attacks. Administrators should move to the fixed build or restrict local access until patched.

Classic Outlook for Windows Copilot button disappearance and Kaspersky-linked crash issue

Service Disruption

Updated: 16.09.2026 15:16 · First: 16.09.2026 15:16 · 📰 1 src / 1 articles · H score: 0

Microsoft is still investigating a Classic Outlook for Windows disruption that makes Copilot and Copilot Chat entry points disappear for some Windows users, with the issue confirmed after upgrading to build 20026.20182 and higher. The bug can block access to Copilot from the ribbon, app bar, and add-ins path, and Microsoft has issued a temporary workaround while it works on a permanent fix. Microsoft also confirmed a separate Outlook crash issue on systems running Kaspersky Antivirus, which can trigger Event 1000 entries.

CISA cyber decoy guidance for critical infrastructure detection and response

Defensive Guidance

Updated: 16.09.2026 15:00 · First: 16.09.2026 15:00 · 📰 1 src / 1 articles · H score: 11

CISA released Using Cyber Decoys to Strengthen Detection and Response, a new guide that helps critical infrastructure teams deploy realistic cyber decoys to spot and interrupt malicious activity inside their networks. The guidance focuses on intrusions that use legitimate credentials, native tools, and living off the land techniques, which are often difficult to detect. It positions decoys as a way to improve early detection, generate high-fidelity alerts, and reduce MTTD.

N0va phishing campaign targeting North America and Europe

Campaign

Updated: 16.09.2026 14:58 · First: 16.09.2026 14:58 · 📰 1 src / 1 articles · H score: 36

N0va is running phishing campaigns across North America and Europe that impersonate trusted services and abuse legitimate authentication flows, creating valid-account access that can expose sensitive data, business systems, and cloud resources. The operation uses familiar business-platform lures to increase trust and reduce suspicion. The resulting access can spread from a single account into broader corporate compromise.

Pentera and Recorded Future integrate threat signals into automated TLPT validation

Security Tool/Service

Updated: 16.09.2026 14:15 · First: 16.09.2026 14:15 · 📰 1 src / 1 articles · H score: 14

Pentera and Recorded Future have linked leaked-credential intelligence to automated validation runs, giving security teams a faster way to test whether exposed credentials are exploitable on a real attack surface. The integration turns threat signals into live testing inputs instead of leaving them in a triage queue. It also extends threat-led penetration testing (TLPT) from periodic review into on-demand validation of current exposure.

ConnectWise ScreenConnect Remote Access file-transfer mitigation

Advisory/Mitigation

Updated: 07.09.2026 13:06 · First: 07.09.2026 13:06 · 📰 1 src / 2 articles · H score: 55

ConnectWise issued temporary mitigation steps for a ScreenConnect Remote Access file-transfer flaw affecting cloud and on-premises deployments. Administrators are told to remove the TransferFiles permission, or TransferFilesInSession on legacy setups, to reduce attack exposure. The issue has no CVE yet, so the advisory is the main protection until the permanent fix later this week.

ScreenConnect Remote Access file-transfer security flaw

Vulnerability

Updated: 07.09.2026 13:06 · First: 07.09.2026 13:06 · 📰 1 src / 2 articles · H score: 44

The ScreenConnect Remote Access file-transfer vulnerability affects cloud and on-premises deployments and puts Support and Access sessions at risk. ConnectWise has not yet assigned a CVE and is relying on temporary mitigations while it prepares a permanent fix later this week. Administrators are being told to disable TransferFiles permissions to reduce exposure.

Global organizations face sustained cyber-attack incidence, cost, and downtime over the past 12 months

Trend

Updated: 16.09.2026 14:00 · First: 16.09.2026 14:00 · 📰 1 src / 1 articles · H score: 22

A global cyber-attack trend affecting organizations worldwide persisted over the past 12 months, with 29% hit and average losses of about $52,000 per incident. Affected organizations also averaged four incidents and 32.8 hours of downtime, showing persistent operational disruption. The pattern varies by market, with UK firms at 38% versus US organizations at 20%, and victims reporting broader business harm beyond recovery costs.

Premier Medical Group (PMG) hit by cyberattack

Incident

Updated: 16.09.2026 13:47 · First: 16.09.2026 13:47 · 📰 1 src / 1 articles · H score: 55

Premier Medical Group (PMG) disclosed a June data breach that disrupted some systems and exposed patient information. Investigators said attackers accessed certain files on June 14, and the compromised data included personal and health records. The breach affected 282,075 individuals and created risk of identity, medical, and insurance-related misuse.

Premier Medical Group patient records breach with June 14 file access

Data Leak

Updated: 16.09.2026 13:47 · First: 16.09.2026 13:47 · 📰 1 src / 1 articles · H score: 55

Premier Medical Group (PMG) is notifying 282,075 patients that their personal and medical information was stolen in a June 2026 data breach. The exposed records include names, contact information, dates of birth, treatment details, medication information, health insurance information, dates of service, provider names, and internal patient identification numbers. Attackers accessed certain files on June 14, and the provider has not identified the intrusion method or any responsible group.

TP-Link Tapo C200 zero-day auth bypass and DoS (multiple vulnerabilities)

Vulnerability

Updated: 16.09.2026 13:00 · First: 16.09.2026 13:00 · 📰 1 src / 1 articles · H score: 41

Two zero-day vulnerabilities in the TP-Link Tapo C200 camera could let a network-access attacker gain administrator access, view live video and recordings, or trigger a device crash, and TP-Link has already fixed them in firmware V5_1.4.6.

SE Labs launches PIVOT cybersecurity vendor testing program

Security Tool/Service

Updated: 16.09.2026 12:00 · First: 16.09.2026 12:00 · 📰 1 src / 1 articles · H score: 16

SE Labs has launched PIVOT, a six-month testing program that compares how cybersecurity vendors defend against nation-state groups and other attack techniques, giving buyers a new benchmark for product selection. The program was unveiled on September 15 and is scheduled to publish results in January 2027. It brings in major vendors including Broadcom, CrowdStrike, Fortinet, Palo Alto Networks and Sophos. The testing is designed to show not just detection, but how far an attacker can progress and what defenders can see during an intrusion.

Google security patch release for CVE-2026-58704

Security Patch Release

Updated: 16.09.2026 10:00 · First: 16.09.2026 10:00 · 📰 2 src / 2 articles · H score: 38

Google released September 2026 security patches for Pixel devices, closing 110 vulnerabilities and including a zero-day under limited, targeted exploitation. The update raises urgency for supported devices because the exploited flaw can enable adjacent-network privilege escalation through the modem. Customers are being directed to install the 2026-09-05 patch level and restart devices to complete remediation.

WSO2 security patch release for CVE-2026-5430

Security Patch Release

Updated: 16.09.2026 08:18 · First: 16.09.2026 08:18 · 📰 1 src / 1 articles · H score: 56

WSO2 released fixes and update levels for CVE-2026-5430, a critical JWT signature-verification flaw in WSO2 API Manager and related product lines that can lead to account takeover. The patches cover both community users and support subscription holders across multiple affected branches. Administrators should deploy the updates quickly because exploitation attempts have already been observed in the wild.