Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 20:36 25/09/2026 UTC
Last updated: 02:21 25/09/2026 UTC
  • Data Leak H score 84 FBI employee and applicant data leak claim ShinyHunters claimed it breached FBI systems via a new Oracle PeopleSoft zero-day and posted sample records plus a defaced FBI Jobs page, advancing a potentially sensitive but still unverified federal data-theft narrative.
  • Vulnerability H score 54 F5 BIG-IP APM zero-day RCE (CVE-2026-94127) Transparent Tribe’s Operation RapidRust is sustaining attacks on India and Afghanistan government/defense targets using new tools and malicious infrastructure, increasing the likelihood of follow-on intrusions beyond initial compromise.
  • Vulnerability H score 47 WordPress unauthenticated path traversal flaw actively exploited (CVE-2026-87902) WordPress attackers are actively exploiting CVE-2026-87902 within hours of patched WordPress 7.1.2, with activity escalating to /tmp and /var/tmp file writes that could enable RCE.
  • Malware Activity H score 41 Carbonato botnet targeting exposed Docker daemons with Hermes Agent The Carbonato botnet continues targeting exposed Docker daemons (e.g., unauthenticated port 2375) to install Hermes Agent and open worm-like footholds, raising risk of widespread container-host takeover.

Latest updates

Browse →

Grav security patch release for CVE-2026-42608

Security Patch Release

Updated: 25.09.2026 23:57 · First: 25.09.2026 23:57 · 📰 1 src / 1 articles · H score: 31

Grav backported the CVE-2026-42608 fix to the older 1.7 branch, releasing Grav 1.7.53.4 to close the path-traversal exposure for legacy sites. The update matters because installations that stayed on Grav 1.7 were still exposed even though the flaw had already been fixed in Grav 2.0.

Clop leak site hit by network compromise linked to ShinyHunters

Incident

Updated: 25.09.2026 23:57 · First: 25.09.2026 23:57 · 📰 1 src / 1 articles · H score: 31

The Clop leak site was breached and defaced by ShinyHunters, forcing the operation to shift to a new Tor address. The compromise was tied to Grav CMS 1.7.43 and an unpatched path traversal flaw now identified as CVE-2026-42608. The attacker later claimed to have taken source code, plugins, server logs, and private keys and threatened to leak them for payment. Clop said the old onion address would stay online only temporarily before retirement.

Grav CMS path traversal (CVE-2026-42608)

Vulnerability

Updated: 25.09.2026 23:57 · First: 25.09.2026 23:57 · 📰 1 src / 1 articles · H score: 8

Grav CMS 1.7.x installations were exposed to CVE-2026-42608, an unauthenticated path traversal flaw in form upload handling that could create unsafe upload paths and write files outside the intended directory. Grav said the bug was fixed in Grav 2.0 (2.0.0-beta.2) earlier this year and later backported as Grav 1.7.53.4. The weakness was used against a server running Grav CMS 1.7.43.

Elementor plugin for WordPress security fix in 4.3.2

Security Patch Release

Updated: 25.09.2026 21:13 · First: 25.09.2026 21:13 · 📰 1 src / 1 articles · H score: 30

The Elementor team shipped version 4.3.2 of the Elementor plugin for WordPress to fix a CSRF flaw that could let attackers create administrator accounts on vulnerable sites. The release closes the bypass affecting versions 4.3.0 and 4.3.1, which were installed on as many as 2 million sites. Site operators should upgrade to 4.3.2 to block the REST API abuse path.

Elementor plugin WordPress CSRF admin account creation security flaw

Vulnerability

Updated: 25.09.2026 21:13 · First: 25.09.2026 21:13 · 📰 1 src / 1 articles · H score: 1

A CSRF vulnerability in the Elementor plugin for WordPress lets an unauthenticated attacker force a logged-in administrator to perform REST API actions that can create attacker-controlled administrator accounts. The flaw affects versions 4.3.0 and 4.3.1, and Elementor has already shipped a fix in 4.3.2.

Elementor CSRF bypass mitigation (4.3.2)

Advisory/Mitigation

Updated: 25.09.2026 21:13 · First: 25.09.2026 21:13 · 📰 1 src / 1 articles · H score: 37

Elementor users are being told to upgrade to version 4.3.2 immediately to block a CSRF bypass that can let a logged-in administrator perform attacker-triggered REST API actions. The fix closes the query-string abuse path in the plugin’s Editor Events module. The affected releases are 4.3.0 and 4.3.1, which are used on up to 2 million sites. On default installations, abuse can lead to an attacker-controlled administrator account.

CISA KEV remediation deadlines for exploited CVEs

Public Sector Action

Updated: 25.09.2026 20:24 · First: 25.09.2026 20:24 · 📰 1 src / 1 articles · H score: 34

CISA added CVE-2026-5430 and CVE-2026-71362 to the KEV catalog and set September 27 remediation deadlines for federal agencies using the affected products. Agencies must apply updates or mitigations or discontinue use, turning the notice into an immediate operational requirement. CISA also set a September 28 deadline for CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in Mikrotik RouterOS.

WSO2, Adobe Commerce, SharePoint, and RouterOS active exploitation wave

Exploitation Wave

Updated: 25.09.2026 20:24 · First: 25.09.2026 20:24 · 📰 1 src / 1 articles · H score: 29

CISA says attackers are actively exploiting four vulnerabilities across WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS, creating a broad exposure window for internet-facing enterprise systems. The wave includes CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, and CVE-2026-67279, spanning authentication bypass, incorrect authorization, code injection, and pre-auth SSH workflow bypass flaws. CISA placed the two critical issues in the KEV catalog and set mitigation deadlines of September 27 for the critical bugs and September 28 for the SharePoint and RouterOS flaws.

PamStealer macOS stealer adds live C2 decryption and multi-layer persistence

Malware Activity

Updated: 25.09.2026 16:18 · First: 25.09.2026 16:18 · 📰 1 src / 1 articles · H score: 29

The PamStealer macOS stealer now uses a server-side decryption chain for its payload, making static recovery impossible without live C2 cooperation. The latest build also swaps in a fake wavel[.]app wallet lure and a Wavel.dmg download to start the infection. It then uses a JXA dropper and /bin/zsh stage to install multi-layer persistence and keep the repair logic alive across logins and Git activity. The final stealer targets passwords, keychain items, browser credentials, system metadata, and user files on macOS.

CISA election software patch-management certification guidance

Advisory/Mitigation

Updated: 25.09.2026 15:39 · First: 25.09.2026 15:39 · 📰 1 src / 1 articles · H score: 39

CISA issued guidance for election software that aligns patch management with certification requirements so security updates can be deployed in real time without breaking certification. The recommendation reduces delay in fixing vulnerabilities across the election infrastructure ecosystem. It directly addresses a remediation bottleneck that can leave vulnerable systems exposed longer than necessary.

CISA election registration database hardening guidance for election offices

Defensive Guidance

Updated: 25.09.2026 15:39 · First: 25.09.2026 15:39 · 📰 1 src / 1 articles · H score: 39

Election infrastructure guidance now prioritizes multi-factor authentication, network monitoring, and least-privilege access for voter registration databases, reducing compromise and lateral-movement risk across election networks. The plan also requires critical logs to be kept for at least a year and keeps public registration and lookup tools walled off from the master database. Those controls give election offices a practical way to shrink the blast radius of workstation or email compromise.

CISA publishes 2026 Election Infrastructure Security Plan

Public Sector Action

Updated: 25.09.2026 15:39 · First: 25.09.2026 15:39 · 📰 1 src / 1 articles · H score: 50

CISA published its 2026 Election Infrastructure Security Plan, adding cyber and physical threat guidance and free services for election officials and partners. The plan lands as state and local election offices handle security for more than 10,000 local jurisdictions and federal support is meant to fill gaps in information, tools, and resources. It also flags patching barriers, voter registration database targeting, and a no-cost information-sharing platform for the 2026 election cycle.

CISA Election Infrastructure Security Plan for the 2026 midterms

Public Sector Action

Updated: 25.09.2026 15:30 · First: 25.09.2026 15:30 · 📰 1 src / 1 articles · H score: 18

CISA published an Election Infrastructure Security Plan for state, local, tribal, and federal election bodies ahead of the November 2026 midterms. The plan adds a formal government security framework for election infrastructure that is exposed to cyber and physical threats. It highlights risks to voter registration databases, voting systems, and vote tabulation locations. It also directs stakeholders toward mitigations such as MFA, monitoring, audit trails, paper ballots, and voluntary services.

Microsoft Windows update black-screen desktop loading failures on Azure Virtual Desktop hosts using FSLogix

Service Disruption

Updated: 25.09.2026 13:30 · First: 25.09.2026 13:30 · 📰 1 src / 1 articles · H score: 0

Microsoft's August 2026 preview updates and later Windows releases are causing desktop loading failures on Azure Virtual Desktop hosts using FSLogix, leaving some users stuck at a black screen after sign-in. Affected users may have to manually launch explorer.exe before they can reach the desktop, and the issue can also surface as Windows Explorer crashes in event logs. Microsoft says enterprise customers can temporarily reduce the impact with Known Issue Rollback (KIR) group policies while it prepares a permanent fix.

Roundcube CVE-2026-48842 Active Exploitation and Patch Pressure

Case

Updated: 25.09.2026 13:14 · First: 24.09.2026 16:27 · 📰 0 src / 2 articles

Roundcube Webmail CVE-2026-48842 is under active exploitation after being patched in May. The flaw is a pre-authenticated SQL injection in virtuser_query that can let unauthenticated attackers bypass authentication, run malicious database commands, and steal data from Roundcube's database. The activity has moved from patch availability to confirmed in-the-wild targeting, with administrators urged to update to 1.6.16 or 1.7.1 or disable the plugin if they cannot patch immediately. Available reporting also points to a large exposed internet-facing surface, while confirmed victim counts, operator attribution, and data-loss totals remain unconfirmed.

RemControl Android MaaS malvertising-delivered credential theft platform

Malware Activity

Updated: 24.09.2026 00:25 · First: 24.09.2026 00:25 · 📰 2 src / 2 articles · H score: 29

RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scalable path to banking credential theft. The infrastructure has been active since at least May, and the first samples were seen in July. The malware uses more than 30 phishing overlays and targets users across Europe, Canada, and the Middle East. It can abuse Accessibility Service permissions, block Google Play services, and stream device data back to operators.

UNKK RemControl TVTap IPTV malvertising campaign

Campaign

Updated: 24.09.2026 00:25 · First: 24.09.2026 00:25 · 📰 2 src / 2 articles · H score: 35

RemControl is an Android banking trojan campaign tied to UNKK that uses fake Google Play Store pages to impersonate TVTap IPTV and push victims through a malicious install flow. The operation has targeted Android users across Western Europe, the Middle East and Canada since July 2026, with Group-IB saying it has confirmed targeting of more than 30 banking institutions across six countries. The trojan abuses Accessibility Services to gain remote control of devices and steal PIN codes, mobile banking codes, and card expiry dates. Group-IB also says UNKK appears to have used an AI assistant to build parts of the C2 backend and phishing overlays, and that exposed C2 panel API documentation gave researchers insight into the infrastructure.

Blocking disposable phishing domains and log-hunting for prior exposure

Defensive Guidance

Updated: 25.09.2026 11:30 · First: 25.09.2026 11:30 · 📰 1 src / 1 articles · H score: 26

EfficientIP recommended blocking disposable phishing domains and IPs after tracking AliExpress-themed entry points that could expose users to credential, payment, and browsing-data theft. The guidance also calls for DNS and proxy log review to find prior connections before the domains are reconfigured or replaced. That helps defenders catch exposure quickly when low-history domains have not yet been classified by reputation systems.

AliExpress-themed phishing operation using disposable redirect domains

Campaign

Updated: 25.09.2026 11:30 · First: 25.09.2026 11:30 · 📰 1 src / 1 articles · H score: 30

An AliExpress-themed phishing campaign surfaced through 10 disposable .cyou domains that were flagged before registration and later redirected visitors to a fake shopping-assistant lure. The infrastructure used a tracking layer with campaign, click, and affiliate parameters, letting the operator swap exposed domains without rebuilding the operation. Users faced risk of credential and payment theft and browsing-activity exposure if they reached the lure. The pattern shows a reusable redirect-and-replacement setup designed to keep the phishing flow alive.

Cloudflare Containers and Sandboxes shared-disk reuse security flaw

Vulnerability

Updated: 25.09.2026 07:49 · First: 25.09.2026 07:49 · 📰 1 src / 1 articles · H score: 3

Cloudflare fixed a shared-disk reuse flaw in Cloudflare Containers and Cloudflare Sandboxes that let one customer read leftover data from other tenants on shared servers. The weakness came from thin-provisioned blocks that were reused without being wiped, creating cross-customer confidentiality risk on container disks. Researchers reported the issue on September 4, Cloudflare said the proof of concept stopped working on September 14, and cleanup finished on September 19.

WSO2 API Manager JWT signature bypass (CVE-2026-5430)

Vulnerability

Updated: 16.09.2026 08:18 · First: 16.09.2026 08:18 · 📰 1 src / 2 articles · H score: 49

Active exploitation of CVE-2026-5430 in WSO2 API Manager puts API Control Plane, Traffic Manager, and Universal Gateway deployments at risk of account takeover and unauthorized access.

PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer

Malware Activity

Updated: 14.09.2026 21:34 · First: 14.09.2026 21:34 · 📰 1 src / 2 articles · H score: 30

PasteSwitch continues to use ClickFix-style social engineering to push MacSync and related payloads onto Windows and macOS systems, with a prior HBO Max Reddit account hijack used to run 108 malicious advertisements over about 48 hours. The campaign steers victims into pasting commands into trusted tools such as Windows Run, PowerShell, and macOS Terminal, and also promotes fake Ledger, Trezor Suite, and Exodus wallet apps. The newer MacSync activity adds public iCloud calendar events as a delivery channel on macOS, hiding commands in a calendar DESCRIPTION: field and fetching the next stage from iCloud. That MacSync variant also includes an Objective-C backdoor that masquerades as Finder, uses LaunchAgent, .zshrc modifications, and global Git hooks for persistence, and can run attacker-supplied AppleScript or replace an installed Ledger wallet app.

MacSync macOS infostealer with iCloud calendar payload delivery

Malware Activity

Updated: 24.09.2026 23:53 · First: 24.09.2026 23:53 · 📰 1 src / 1 articles · H score: 29

MacSync now uses public iCloud calendar events to deliver fresh payloads on macOS, expanding its infection chain and increasing the risk of credential theft and remote control. The malware also adds a new Objective-C backdoor that can run attacker-supplied AppleScript, establish persistence, and upload files to command-and-control infrastructure. Its distribution has included ClickFix-style attacks and fake software lures, including a fake crypto wallet called Toria.

Carbonato botnet targeting exposed Docker daemons with Hermes Agent

Malware Activity

Updated: 24.09.2026 23:10 · First: 24.09.2026 23:10 · 📰 1 src / 1 articles · H score: 41

The Carbonato botnet is targeting exposed Docker daemons to install Hermes Agent and seize host control, creating a worm-like foothold on vulnerable systems. It reaches Docker APIs exposed on port 2375 without authentication, then launches privileged containers and sets up reverse SSH tunnels for operator access. The activity is tied to evidence spanning October 2024 to August 2026, which shows a sustained malware operation rather than a one-off intrusion.

OnePlus OxygenOS local privilege-escalation flaws security flaw

Vulnerability

Updated: 24.09.2026 21:10 · First: 24.09.2026 21:10 · 📰 1 src / 1 articles · H score: 26

Unpatched OnePlus OxygenOS local privilege-escalation flaws let a malicious no-permission app gain root on affected phones. The chain uses AtlasService and olc2 to move from an installed app to system-level control. OnePlus had not released a fix at disclosure time, and the issue may extend beyond the OnePlus 15 to other OnePlus and OPPO devices.

Kontext Security launches runtime enforcement platform for AI agents

Security Tool/Service

Updated: 24.09.2026 18:52 · First: 24.09.2026 18:52 · 📰 1 src / 1 articles · H score: 11

Kontext Security has publicly launched a runtime security platform for AI agents, giving organizations a control point for actions taken by autonomous software. The platform sits between agents and the systems or tools they access, evaluates requests in real time, and can deny unauthorized actions. It aims to reduce the risk that an authenticated agent still performs an unsafe or unapproved operation.

Third-party.com fake Cloudflare verification ClickFix campaign targeting Windows users

Campaign

Updated: 24.09.2026 01:46 · First: 24.09.2026 01:46 · 📰 2 src / 2 articles · H score: 24

The third-party.com domain is hosting a ClickFix lure that impersonates a Cloudflare security check and pushes Windows users to run malicious PowerShell commands. The page uses clipboard poisoning and a fake verification flow to steer victims toward a payload chain on elxxvvx[.]xyz. The abuse turns a long-used placeholder hostname into an active delivery point for malware installation attempts.

N0n double-extortion ransomware campaign

Campaign

Updated: 24.09.2026 18:00 · First: 24.09.2026 18:00 · 📰 1 src / 1 articles · H score: 35

The n0n ransomware campaign is actively extorting organizations across financial services, technology, retail, and education, with a Tor leak site already listing over a dozen victims. The operators use double extortion and threaten to encrypt or destroy backups and shadow copies, raising the risk of operational paralysis if targets refuse to pay. Initial access reportedly begins with compromised credentials sourced from third-party infostealer malware, showing a credential-theft-driven intrusion path. The activity has been observed across the US and multiple other countries, indicating broad geographic reach.

N0n ransomware crew emergence and backup-destruction extortion model

Threat Actor Meta

Updated: 24.09.2026 18:00 · First: 24.09.2026 18:00 · 📰 1 src / 1 articles · H score: 36

n0n has emerged as a new ransomware crew, increasing extortion pressure by threatening to destroy backups and shadow copies if victims refuse to pay. The group was first seen on September 18 and had already listed over a dozen victims by September 22, showing rapid early activity. Its use of double extortion and credential-based initial access raises the risk of full operational disruption across affected organizations.

Unattributed Rublevka TDS (РУБЛЁВКА TDS) lure panel campaign expands across multiple victims

Campaign

Updated: 24.09.2026 17:29 · First: 24.09.2026 17:29 · 📰 1 src / 1 articles · H score: 36

The ClickFix campaign is compromising legitimate Ukrainian business websites with fake Cloudflare verification pages to deliver the Psychedelic information stealer. The operation uses a copied Windows Installer command and msiexec.exe to stage MSI payloads, putting browser credentials, tokens, and wallet data at risk. Its lure panel shows activity across 32 countries, with the heaviest concentration in Ukraine, indicating a coordinated multi-victim operation.