Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 06:20 16/09/2026 UTC
  • Vulnerability H score 43 GitLab CE/EE repository commits API path traversal (CVE-2026-85706) CISA added GitLab CE/EE repository commits API path traversal flaw (CVE-2026-85706) to its actively exploited catalog, advancing immediate patching urgency because GitLab servers were already being probed for credential/secret disclosure.
  • Campaign H score 51 REF9334 Brazilian bank lure campaign using malicious browser extensions Elastic Security Labs reported REF9334’s ongoing Brazilian bank lure campaign using a malicious Chrome/Edge extension, advancing active credential-theft risk with telemetry showing thousands of infected systems.
  • Incident H score 45 Adminmenueditor.com hit by network compromise A compromise of adminmenueditor.com enabled malicious Admin Menu Editor Pro updates that installed web shells and hidden accounts on at least 1,500 WordPress sites, raising the likelihood of widespread web-server takeover.
  • Campaign H score 38 Fortinet VPN sustained credential attack campaign A Fortinet VPN credential attack campaign in sustained waves generated tens of millions of authentication failures and included at least one successful login followed by malicious activity, increasing odds of unauthorized access.
  • Data Leak H score 36 Twitch Enhanced Viewer | JeetBot OAuth token leak A Twitch “JeetBot” malicious browser extension leaked OAuth bearer tokens for nearly 31,000 users, advancing account-takeover risk even though a later version stops token forwarding.
  • Security Patch Release H score 36 WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540) Wordfence warned of active exploitation of the WooCommerce Wholesale Lead Capture plugin flaw (CVE-2026-27540), advancing remediation urgency because attackers are uploading PHP web shells via a known unauthenticated file-upload path.
Last updated: 10:35 15/09/2026 UTC

Latest updates

Browse →

Google security patch release for CVE-2026-58704

Security Patch Release

Updated: 16.09.2026 10:00 · First: 16.09.2026 10:00 · 📰 1 src / 1 articles · H score: 38

Google released September 2026 security patches for Pixel devices, closing 110 vulnerabilities and including a zero-day under limited, targeted exploitation. The update raises urgency for supported devices because the exploited flaw can enable adjacent-network privilege escalation through the modem. Customers are being directed to install the 2026-09-05 patch level and restart devices to complete remediation.

WooCommerce Wholesale Lead Capture plugin 2.0.3.2 security update (CVE-2026-27540)

Security Patch Release

Updated: 15.09.2026 17:45 · First: 15.09.2026 17:45 · 📰 2 src / 2 articles · H score: 23

The WooCommerce Wholesale Lead Capture plugin's version 2.0.3.2 release closed CVE-2026-27540, an unauthenticated arbitrary file-upload flaw that let attackers upload PHP webshells to WordPress sites. The update covered version 2.0.3.1 and older and landed on February 20. Site operators were told to upgrade to 2.0.3.2 or later and look for suspicious /wp-admin/admin-ajax.php activity and unexpected PHP files.

WSO2 security patch release for CVE-2026-5430

Security Patch Release

Updated: 16.09.2026 08:18 · First: 16.09.2026 08:18 · 📰 1 src / 1 articles · H score: 56

WSO2 released fixes and update levels for CVE-2026-5430, a critical JWT signature-verification flaw in WSO2 API Manager and related product lines that can lead to account takeover. The patches cover both community users and support subscription holders across multiple affected branches. Administrators should deploy the updates quickly because exploitation attempts have already been observed in the wild.

WSO2 API Manager JWT signature bypass (CVE-2026-5430)

Vulnerability

Updated: 16.09.2026 08:18 · First: 16.09.2026 08:18 · 📰 1 src / 1 articles · H score: 49

Active exploitation of CVE-2026-5430 in WSO2 API Manager puts API Control Plane, Traffic Manager, and Universal Gateway deployments at risk of account takeover and unauthorized access.

Acronis Backup plugin for cPanel & WHM and Plesk local privilege escalation (CVE-2026-87886)

Vulnerability

Updated: 16.09.2026 00:37 · First: 16.09.2026 00:37 · 📰 1 src / 1 articles · H score: 31

Acronis Backup plugin deployments for cPanel & WHM and Plesk are affected by CVE-2026-87886, a high-severity Linux local privilege escalation flaw. The vulnerability can let a low-privileged attacker raise permissions on a vulnerable server and put data, websites, and hosting accounts at risk. Acronis says exploitation has been seen in limited, targeted attacks and urges administrators to apply the available updates immediately.

Adminmenueditor.com hit by network compromise

Incident

Updated: 15.09.2026 23:34 · First: 15.09.2026 23:34 · 📰 1 src / 1 articles · H score: 45

The adminmenueditor.com website compromise led to malicious Admin Menu Editor Pro updates that installed a web shell and hidden accounts on customer sites, affecting at least 1,500 WordPress sites. The tainted version 2.35 was available for roughly 06:00-13:00 UTC on Monday, and a clean 2.36 was pushed later the same day. The incident put customers at risk of unauthorized access and required site owners to verify whether they had installed the malicious releases.

KREMLIN browser-extension credential theft activity

Malware Activity

Updated: 15.09.2026 21:54 · First: 15.09.2026 21:54 · 📰 1 src / 1 articles · H score: 44

The KREMLIN malware operation is using malicious browser extensions and multi-stage loaders to steal credentials and session tokens from Chrome and Edge users, increasing the risk of account takeover and browser-data theft. The activity has been active since at least May 2025 and is tied to a broader toolkit-delivery chain that includes loaders and installers. It also uses infrastructure-hiding and evasion techniques to sustain access and reduce disruption. The scope reaches at least 1,515 infected systems, most of them in Brazil.

REF9334 Brazilian bank lure campaign using malicious browser extensions

Campaign

Updated: 15.09.2026 21:54 · First: 15.09.2026 21:54 · 📰 1 src / 1 articles · H score: 51

The REF9334 campaign is actively using Brazilian bank lures to deploy a malicious browser extension, putting Chrome and Edge users at risk of credential theft. The operation has been active since at least May 2025 and uses repeated lure-and-install chains instead of a one-off payload. Its scale is reinforced by telemetry tied to 1,515 infected systems, with more than 98% geolocated to Brazil.

CenterPoint Energy customer data leak

Data Leak

Updated: 15.09.2026 19:40 · First: 15.09.2026 19:40 · 📰 1 src / 1 articles · H score: 33

CenterPoint Energy confirmed a breach after an attacker leaked allegedly stolen customer records, exposing personal and billing data for a large portion of its customer base. The leak claim covers 7.49 million records and includes names, phone numbers, addresses, account numbers, billing amounts, and partial SSNs. The intruder said the data was taken through the utility’s public API without rate limiting or WAF protection. Electric and gas services were not impacted, but the exposure creates ongoing privacy and fraud risk.

CenterPoint Energy hit by network compromise

Incident

Updated: 15.09.2026 19:40 · First: 15.09.2026 19:40 · 📰 1 src / 1 articles · H score: 33

CenterPoint Energy disclosed a customer data breach after an unauthorized third party obtained personal information through an external-facing system, putting a portion of customers at risk of misuse. The company said the compromise was still under investigation and that it had not identified an impact to its electric and gas services. CenterPoint also said it was working to determine the full scope of affected customers and data while notifying the appropriate parties.

Fraudulent hires are reaching corporate access before detection across US organizations

Trend

Updated: 15.09.2026 18:15 · First: 15.09.2026 18:15 · 📰 1 src / 1 articles · H score: 25

Fraudulent hires are reaching corporate credentials and internal network access before detection across US organizations, creating a measurable insider-risk window. In a sample of 500 US HR executives, 42% of fraudulent candidates successfully reached the hire stage and only 3% were caught on the same day. Detection usually occurred one to six days after hire, and 20% remained undetected for up to three weeks. The access gap leaves organizations exposed to data security risks and shows that hiring fraud can become an identity-assurance failure before IT is aware of it.

BambooToken malware uses MQTT C2 on Windows and Linux systems

Malware Activity

Updated: 15.09.2026 18:00 · First: 15.09.2026 18:00 · 📰 2 src / 2 articles · H score: 31

BambooToken is a multi-platform malware campaign using MQTT for command-and-control on Windows and Linux systems. Lumen Black Lotus Labs says the activity has been active since at least February 2023, was observed again in July 2026, and uses Tendyron OnKey software for DLL sideloading via OnKeyToken_KEB.dll. The campaign targets organizations across Asia and South America and includes infrastructure such as chat5188[.]tk and api80.c2iznja[.]com. Lumen assesses the activity is geared toward extensive data collection.

WooCommerce Wholesale Lead Capture CVE-2026-27540 exploitation wave

Exploitation Wave

Updated: 15.09.2026 17:45 · First: 15.09.2026 17:45 · 📰 2 src / 2 articles · H score: 22

CVE-2026-27540 exploitation against WooCommerce Wholesale Lead Capture is driving repeated spikes and more than 100,000 blocked attacks, putting WordPress sites at risk of PHP webshell uploads and full compromise.

WooCommerce Wholesale Lead Capture actively exploited arbitrary file-upload vulnerability (CVE-2026-27540)

Vulnerability

Updated: 15.09.2026 17:45 · First: 15.09.2026 17:45 · 📰 1 src / 1 articles · H score: 8

CVE-2026-27540 in the WooCommerce Wholesale Lead Capture WordPress plugin is being actively exploited, putting version 2.0.3.1 and older at risk of PHP webshell upload and complete site compromise. The flaw was fixed in version 2.0.3.2. Site operators should treat exposed installs as high risk until patched.

Fenix24 advises dependency mapping and end-to-end restore testing for ransomware recovery

Defensive Guidance

Updated: 15.09.2026 17:30 · First: 15.09.2026 17:30 · 📰 1 src / 1 articles · H score: 30

Fenix24 issued ransomware recovery guidance that pushes operators to map dependencies and test restores end to end, because recovery often breaks long before full operations return. The advice focuses on the most revenue-critical business service and requires a complete dependency map that includes third parties. It also warns that simulations and untested plans leave teams exposed to identity, backup, storage, and network bottlenecks during restoration.

CISA and NIST release IR 8587 cloud identity guidance

Public Sector Action

Updated: 15.09.2026 15:00 · First: 15.09.2026 15:00 · 📰 1 src / 1 articles · H score: 27

CISA and NIST released IR 8587 to guide federal agencies and cloud service providers on protecting tokens and assertions from forgery, theft, and misuse. The guidance targets SSO, federation, and API-based access, where compromised identity material can enable lateral movement into sensitive systems. The report is intended to harden cloud identity controls across government-operated and commercial cloud services.

OpenAEV Attack Chaining launch adds end-to-end multi-stage attack simulation

Security Tool/Service

Updated: 15.09.2026 14:26 · First: 15.09.2026 14:26 · 📰 1 src / 1 articles · H score: 14

OpenAEV added Attack Chaining, a new scenario for end-to-end multi-stage attack simulation that shows how chained actions can bypass isolated security tests. The capability links real outputs from each step, such as harvested credentials and open ports, into the next stage so teams can see the full attack path. It also extends to Autonomous Attack Chaining with XTM One, where an AI agent can plan and execute scoped chains and return exposure results faster than periodic red-team work.

Black Axe Cape Town internet fraud campaign targeting U.S. victims

Campaign

Updated: 15.09.2026 12:50 · First: 15.09.2026 12:50 · 📰 2 src / 2 articles · H score: 29

The Black Axe internet fraud campaign targeted victims in the United States over a 2011 to 2021 span, using advance fee schemes and romance scams to steal money. The operation relied on social media, online dating websites, and VoIP numbers to reach targets and build trust. Its long duration and repeated fraud methods point to a sustained, coordinated financial-crime effort.

Black Axe leaders extradited to U.S. on fraud charges

Law Enforcement

Updated: 15.09.2026 12:50 · First: 15.09.2026 12:50 · 📰 1 src / 1 articles · H score: 22

Five alleged Black Axe leaders were extradited to the United States and charged in a wire fraud and money laundering case, tightening U.S. action against a transnational fraud network. Prosecutors say the case covers an internet fraud campaign that ran from 2011 to 2021 and targeted victims in the U.S. The action raises exposure for the named defendants and underscores the reach of cross-border cyber-enabled fraud enforcement.

LiteSpeed Web Server Enterprise privilege-escalation flaw

Vulnerability

Updated: 15.09.2026 09:52 · First: 15.09.2026 09:52 · 📰 1 src / 1 articles · H score: 26

A critical privilege-escalation flaw in LiteSpeed Web Server Enterprise can let a low-privilege website user gain root access on shared-hosting servers. The issue affects versions before 6.3.7 and can break isolation between hosted accounts, exposing other sites and the server itself. cPanel and LiteSpeed have directed administrators to update to 6.3.7 as the fix, while public details on exploit method, CVE assignment, and active abuse remain unavailable.

LiteSpeed Web Server Enterprise 6.3.7 security release

Security Patch Release

Updated: 15.09.2026 09:52 · First: 15.09.2026 09:52 · 📰 1 src / 1 articles · H score: 32

LiteSpeed published 6.3.7 for LiteSpeed Web Server Enterprise, and cPanel urged administrators to install it to address a flaw affecting versions before 6.3.7. The release is the immediate update path for shared-hosting environments where one low-privilege account could reach root access if the flaw is present. LiteSpeed said the release may take time to reach auto-update, making the manual install command the recommended response.

Fortinet VPN sustained credential attack campaign

Campaign

Updated: 15.09.2026 09:11 · First: 15.09.2026 09:11 · 📰 1 src / 1 articles · H score: 38

A Fortinet VPN credential attack campaign hit multiple U.S. customer environments in two sustained waves, generating tens of millions of authentication failures. The targeting used organization-specific usernames and other identity data rather than generic spraying, pointing to previously collected or enumerated credentials. One observed successful authentication was followed by malicious activity, increasing the risk of unauthorized access in affected environments.

GRIMWEDGE JavaScript backdoor with persistent C2 polling

Malware Activity

Updated: 15.09.2026 08:31 · First: 15.09.2026 08:31 · 📰 1 src / 1 articles · H score: 29

The GRIMWEDGE JavaScript backdoor is being deployed with a persistent C2 loop, giving operators host reconnaissance, file and process management, command execution, and payload delivery on compromised systems. It polls ocr.opusaccel[.]top for instructions and executes them in memory via eval(). The activity increases the risk of follow-on tooling and deeper hands-on-keyboard abuse after the initial foothold.

Japan’s Digital Agency hit by network compromise

Incident

Updated: 14.09.2026 23:36 · First: 14.09.2026 23:36 · 📰 1 src / 1 articles · H score: 52

Japan’s Digital Agency disclosed an unauthorized-access breach that may have exposed about 246,000 record rows of government-employee personal information. The intrusion entered through a VPN device vulnerability in the Government Solution Service (GSS) environment. The agency suspended the compromised account, severed outside communication, and reported no confirmed misuse or government-service outage.

GSS VPN device access security flaw

Vulnerability

Updated: 14.09.2026 23:36 · First: 14.09.2026 23:36 · 📰 1 src / 1 articles · H score: 54

Japan’s Digital Agency disclosed a VPN-device vulnerability in Government Solution Service (GSS) infrastructure that enabled initial access and unauthorized system access. The flaw was described as medium severity and not a zero-day, making it a concrete access-path weakness rather than a speculative issue. The breach may have exposed around 246,000 record rows tied to government-employee personal information.

Homebrew 7.0.0 adds built-in vulnerability scanning and stronger sandboxing for macOS package installs

Security Tool/Service

Updated: 14.09.2026 22:51 · First: 14.09.2026 22:51 · 📰 1 src / 1 articles · H score: 11

Homebrew 7.0.0 now ships a built-in vulnerability scanner, increasing security visibility for macOS package installs and dependency sets. The release also adds stronger security controls and the full BrewUI graphical interface, broadening how users browse and manage packages. The new brew vulns command and Homebrew advisory data help teams identify affected formula versions more quickly.

PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer

Malware Activity

Updated: 14.09.2026 21:34 · First: 14.09.2026 21:34 · 📰 1 src / 1 articles · H score: 29

The PasteSwitch activity is using ClickFix ads to deliver MacSync, AMOS helper, and Amatera Stealer to Windows and macOS users, creating a high-risk path to credential theft and account compromise. A hijacked HBO Max Reddit account amplified the reach with 108 malicious ads over about 48 hours. The delivery chain relies on attacker-supplied commands pasted into trusted operating-system tools, helping the malware bypass some browser and security defenses.

3BB hit by data theft breach

Incident

Updated: 14.09.2026 21:01 · First: 14.09.2026 21:01 · 📰 1 src / 1 articles · H score: 32

The 3BB network intrusion gave an attacker root access to internal machines and a hidden MeshCentral backdoor inside the Thai broadband provider's environment, increasing exposure of subscriber credentials and internal management systems. The operation was still live on June 3, 2026, when an exposed command server and control list were captured. Recovered scripts show password spraying, SSH-based probing of more than 55 internal computers, and searches for stored passwords, database logins, and SSH keys. The toolkit also targeted subscriber RADIUS databases and a FortiGate SSL-VPN gateway tied to CVE-2024-21762, but successful exploitation and data theft were not confirmed.

Telegram Desktop HTML export script injection security flaw

Vulnerability

Updated: 14.09.2026 20:58 · First: 14.09.2026 20:58 · 📰 1 src / 1 articles · H score: 25

Telegram Desktop's HTML export path let unescaped button text inject hidden JavaScript into saved chats, exposing pre-fix exports to message exfiltration or page rewriting when opened in a browser.

Telegram Desktop HTML export escaping fix

Security Patch Release

Updated: 14.09.2026 20:58 · First: 14.09.2026 20:58 · 📰 1 src / 1 articles · H score: 30

Telegram Desktop shipped a fix for an HTML export escaping flaw that could let a bot message inject JavaScript into exported chats. The update closed the issue for 6.9.4 beta and 7.0.1 stable, while older HTML exports created before the fix can still carry the script. Opening one of those files in a browser could expose chat content or let the page be rewritten.