Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 06:39 18/09/2026 UTC
Last updated: 09:05 17/09/2026 UTC

Latest updates

Browse →

MIND raises $72 million Series B for AI-native DLP

Industry Action

Updated: 18.09.2026 10:25 · First: 18.09.2026 10:25 · 📰 1 src / 1 articles · H score: 11

MIND raised $72 million in a Series B round to scale its AI-native DLP platform for enterprise data protection. The financing brings total funding to $112 million and was led by Crosspoint Capital Partners with participation from YL Ventures and Paladin Capital Group. The Seattle startup says the capital will support product development, enterprise expansion, partnerships, and hiring.

RatHat Android credential-theft malware

Malware Activity

Updated: 17.09.2026 16:00 · First: 17.09.2026 16:00 · 📰 2 src / 2 articles · H score: 27

RatHat is a new Android malware activity linked by Zimperium to China-based threat actors and focused on stealing banking credentials, 2FA/OTP data, notifications, and screen and input data from infected devices. It is distributed through smishing, malvertising, deceptive download portals, third-party forums, and malicious APKs, then uses a dropper, Accessibility abuse, and local ADB self-pairing to break out of the sandbox and gain shell-level privileges. The malware also uses an AI-powered automation loop, persistence, and a hardware-level keylogger to retain access and improve operator control.

Check Point Security Management and Log Servers stack overflow security flaw (CVE-2026-91843)

Vulnerability

Updated: 17.09.2026 21:08 · First: 17.09.2026 21:08 · 📰 1 src / 1 articles · H score: 46

Check Point Security Management and Log Servers are affected by CVE-2026-91843, a critical stack overflow that can let unauthenticated attackers run code as root over the network. Check Point says a LivePatch fix is available and has no indication of exploitation in the wild. The flaw affects R82.10, R82, R81.20, R81.10 and older branches, and Check Point also said R82.20, standalone deployments, Log Servers, and Multi-Domain servers are vulnerable. Administrators should install sk1000155 and restrict Trusted Clients to trusted hosts.

Settra ransomware activity using MeshAgent

Malware Activity

Updated: 17.09.2026 20:32 · First: 17.09.2026 20:32 · 📰 1 src / 1 articles · H score: 30

The Settra ransomware group used MeshAgent remote access software in two analyzed intrusions, adding persistence and file encryption to its attack chain. Attackers dropped RESTORE_FILES.txt ransom notes, cleared Windows event logs, and disabled Windows recovery options to hinder response and recovery. One intrusion also showed signs of Bring Your Own Vulnerable Driver (BYOVD) abuse, and the group has since been tied to 70 claimed victims across multiple countries.

Brevo hit by network compromise

Incident

Updated: 17.09.2026 20:11 · First: 17.09.2026 20:11 · 📰 1 src / 1 articles · H score: 57

Brevo confirmed a Cloudflare API key compromise that let attackers inject ClickFix scripts into its web properties, exposing customer-facing pages to malicious content injection. The compromise affected Brevo-hosted pages and customer-embedded JavaScript for roughly five and a half hours on September 14. Brevo said app.brevo.com, its email delivery infrastructure, and customer account data were not affected.

VL Prosperity hit by network compromise

Incident

Updated: 17.09.2026 20:09 · First: 17.09.2026 20:09 · 📰 1 src / 1 articles · H score: 28

The VL Prosperity and a second oil tanker suffered a cyberattack during transit to Texas, disrupting onboard operations and prompting a Coast Guard and FBI boarding. The intrusion reportedly reached the engine room, navigation, and cargo systems, and cut communications for roughly 30 hours. Investigators found evidence of a malicious cyber actor while publicly stopping short of linking the case to Iran.

Docker Sandboxes Unix socket relay flaw (CVE-2026-79994)

Vulnerability

Updated: 17.09.2026 18:37 · First: 17.09.2026 18:37 · 📰 1 src / 1 articles · H score: 31

Docker fixed CVE-2026-79994 in Docker Sandboxes, closing a High relay flaw that could make a guest connect the host to AF_UNIX sockets outside the workspace. The issue carried a CVSS score of 8.7 and was fixed in 0.42.0. Docker and CISA both list no known exploitation.

Docker Sandboxes security update for CVE-2026-77179 and CVE-2026-79994

Security Patch Release

Updated: 17.09.2026 18:37 · First: 17.09.2026 18:37 · 📰 1 src / 1 articles · H score: 34

Docker released a security update for Docker Sandboxes that fixes CVE-2026-77179 and CVE-2026-79994, closing a Critical macOS host-file escape and a High Unix-socket relay flaw. The update ships in 0.42.0 for systems affected before that release. Users should upgrade to 0.42.0 or later or use clone mode if they cannot update yet.

RatHat smishing-malvertising Android APK distribution campaign

Campaign

Updated: 17.09.2026 16:00 · First: 17.09.2026 16:00 · 📰 2 src / 2 articles · H score: 36

RatHat is a newly disclosed Android malware campaign linked to China-based threat actors that spreads through malvertising, SMS phishing, and deceptive phishing sites promoting APK installs from outside Google Play. The malware abuses Accessibility permissions, enables Developer Options and Wireless Debugging to reach ADB shell access, and installs agents that support persistence, tunneling, and device control. Zimperium says the operation uses an AI-powered UI-automation subsystem to navigate infected devices, while also targeting banking and cryptocurrency apps for credential theft, SMS/OTP interception, and screen/input capture. It also tries to block removal and frustrate analysis with fake overlays, APK tampering, a 61MB manifest, and invalid DEX pseudo instructions.

RatHat Android malware analysis with AI-assisted UI automation and anti-analysis layers

Technical Analysis

Updated: 17.09.2026 16:00 · First: 17.09.2026 16:00 · 📰 3 src / 3 articles · H score: 28

RatHat is a new Android malware campaign analyzed by Zimperium zLabs and linked to China-based threat actors. It uses an AI-powered UI-automation subsystem to steer compromised devices in real time, serializing the live Accessibility tree and sending it to an AI assistant for navigation and on-screen text extraction. The malware abuses Accessibility permissions, enables Developer Options and Wireless Debugging for ADB shell access, and deploys agents for persistence and tunneling while targeting banking and cryptocurrency apps for credential theft, OTP interception, and lock-screen data capture. It also includes anti-analysis and anti-debug layers, plus removal-blocking behavior that can cancel uninstall attempts and fake a Google Play error.

Unbound DNSSEC validator heap overflow remote code execution flaw (CVE-2026-81642)

Vulnerability

Updated: 17.09.2026 15:30 · First: 17.09.2026 15:30 · 📰 1 src / 1 articles · H score: 33

A critical heap overflow in the Unbound DNSSEC validator affects Unbound DNS resolver versions up to 1.26.0, creating denial-of-service and possible remote code execution risk. An attacker who controls a malicious DNS zone can trigger the flaw by querying a vulnerable resolver. Unbound 1.26.1 fixes the bug, and no exploitation had been reported at the time of the advisory.

NLnet Labs security patch release for CVE-2026-81642

Security Patch Release

Updated: 17.09.2026 15:30 · First: 17.09.2026 15:30 · 📰 1 src / 1 articles · H score: 39

NLnet Labs released Unbound 1.26.1 to close nine security flaws, including CVE-2026-81642 in the DNSSEC validator. The update addresses a critical heap overflow that could let an attacker using a malicious zone trigger remote code execution on vulnerable resolvers. The affected range covers every Unbound release before 1.26.1, including 1.26.0 and 1.25.2. NLnet Labs said it has not reported exploitation, and the advisory provides upgrade and patch paths.

Unbound CNAME synthesis heap corruption remote code execution flaw (CVE-2026-82717)

Vulnerability

Updated: 17.09.2026 15:30 · First: 17.09.2026 15:30 · 📰 1 src / 1 articles · H score: 33

Unbound versions up to 1.26.0 contain CVE-2026-82717, a heap corruption flaw in CNAME synthesis that can create remote code execution risk on affected builds. The vulnerability is fixed in Unbound 1.26.1, and NLnet Labs said the bug could affect some systems and compilation options. NLnet Labs did not report exploitation of this flaw.

FBI seizes NightmareStresser domains

Law Enforcement

Updated: 17.09.2026 14:33 · First: 17.09.2026 14:33 · 📰 2 src / 2 articles · H score: 24

FBI seized nightmare-stresser[.]com and nightmarestresser[.]org, disrupting NightmareStresser, a long-running DDoS-for-hire service. The seizure was announced by the U.S. Department of Justice and supported by Operation PowerOFF as part of a coordinated law-enforcement action. The service was assessed to have been used since 2022 to launch hundreds of thousands of actual or attempted DDoS attacks against victims worldwide. Prior reporting also tied the platform to 566,000+ registered users and 52 servers, showing the scale of the booter infrastructure.

FamousSparrow SparroWocky Latin America government espionage campaign

Campaign

Updated: 17.09.2026 12:00 · First: 17.09.2026 12:00 · 📰 2 src / 2 articles · H score: 32

FamousSparrow has been using the SparroWocky backdoor against government organizations in Latin America since at least August 2025. ESET Research attributed the activity with high confidence and identified government entities in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group gained access by exploiting publicly reachable Exchange servers, and the malware can run commands, execute files, act as a TCP proxy, collect host and network details, exfiltrate files, and take screenshots. ESET said SparroWocky is a separate family from SparrowDoor, with DLL side-loading, RC4-encrypted exfiltration, and anti-analysis features used to evade detection.

FamousSparrow SparroWocky backdoor activity against Latin American governments

Malware Activity

Updated: 17.09.2026 12:00 · First: 17.09.2026 12:00 · 📰 3 src / 3 articles · H score: 23

FamousSparrow is using the new SparroWocky backdoor against government entities across Latin America, with activity observed since at least August 2025 and a broader regional focus from mid-2025. ESET Research attributed the campaign to the China-aligned group with high confidence and named targets in Argentina, Ecuador, Guatemala, Honduras, Panama, Peru, Puerto Rico, and Venezuela. The group gained access by exploiting publicly reachable Exchange servers. SparroWocky is a separate family from SparrowDoor and can run commands, execute files, act as a TCP proxy, exfiltrate files, and take screenshots while using RC4 and TLS for transfer.

Windows 11 KB5124008 Active Directory domain trust breakage

Service Disruption

Updated: 16.09.2026 23:39 · First: 16.09.2026 23:39 · 📰 1 src / 2 articles · H score: 0

The Windows 11 KB5124008 security update is breaking Active Directory domain trust on some enterprise systems, preventing valid users from signing in after reboot. Microsoft is investigating the disruption, and affected machines may lose their secure channel with domain controllers. Some administrators have temporarily restored access by changing Machine Identity Isolation settings and repairing the secure channel.

ISC BIND 9.20.29 and 9.21.26 security update for 14 flaws

Security Patch Release

Updated: 17.09.2026 11:00 · First: 17.09.2026 11:00 · 📰 1 src / 1 articles · H score: 17

ISC released BIND 9.20.29 and 9.21.26 to fix 14 security flaws in its open-source DNS server, reducing crash, cache-poisoning, and denial-of-service risk for affected deployments. The package also includes 9.20.29-S1 for supported preview customers, while ISC says it is not aware of exploitation and lists no workarounds.

Gyazo hit by network compromise

Incident

Updated: 17.09.2026 10:30 · First: 17.09.2026 10:30 · 📰 1 src / 1 articles · H score: 69

Gyazo suffered a security breach that exposed 23.62 million user records and 490 million image metadata records, creating risk of unauthorized image access and credential abuse. The compromise came through a vulnerability in Gyazo's image upload server, and the attacker used that foothold to run arbitrary commands on Helpfeel's systems. Exposed records included email addresses, password hashes, session-related data, and image-link IDs that could let outsiders view captures without permission. Helpfeel disabled viewing for some images, told users to change passwords, and said the flaw was fixed after suspicious activity was noticed on September 11.

Cisco security patch release for CVE-2026-76460

Security Patch Release

Updated: 17.09.2026 10:20 · First: 17.09.2026 10:20 · 📰 3 src / 3 articles · H score: 58

Cisco released security updates for Cisco ISE and ISE-PIC to fix CVE-2026-76460, a maximum-severity authentication bypass that is actively exploited in the wild. The fixed releases are the only recommended remediation because no workarounds exist. The patch bundle covers the affected ISE software lines and closes a flaw that can expose management access to remote attackers.

Cisco ISE and ISE-PIC actively exploited authentication bypass (CVE-2026-76460)

Vulnerability

Updated: 17.09.2026 10:20 · First: 17.09.2026 10:20 · 📰 3 src / 3 articles · H score: 51

Cisco ISE and ISE-PIC are facing CVE-2026-76460, a maximum-severity API authentication bypass that is actively exploited in the wild. The flaw can let remote attackers send a crafted request and gain unauthorized access by bypassing the web-based management interface. Fixed software releases are available, and CISA has added the CVE to the KEV Catalog with a three-day patch deadline for federal agencies.

Cybersecurity and Infrastructure Security Agency (CISA) Known Exploited Vulnerabilities (KEV) Catalog ordered federal agencies to patch systems against CVE-2026-76460 for within

Public Sector Action

Updated: 17.09.2026 10:20 · First: 17.09.2026 10:20 · 📰 3 src / 3 articles · H score: 37

CISA ordered federal agencies to patch CVE-2026-76460 within three days, imposing an urgent remediation deadline for an actively exploited Cisco flaw. The order followed the agency's addition of the vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog on Wednesday. The directive forces rapid mitigation across the federal civilian environment because the flaw allows remote attackers to bypass authentication in Cisco ISE and ISE-PIC.

Cisco Secure Email Gateway insufficient validation flaw (CVE-2026-76461)

Vulnerability

Updated: 15.09.2026 09:11 · First: 15.09.2026 09:11 · 📰 2 src / 2 articles · H score: 45

Cisco Secure Email Gateway devices are exposed to CVE-2026-76461, an actively exploited email-parsing flaw that can let an unauthenticated remote attacker execute commands with root privileges. Cisco says the weakness affects both physical and virtual appliances and released fixes for 15.5 and earlier, 16.0, and 16.5. There are no workarounds beyond upgrading, and Cisco warned that exploitation can hide evidence on the device. CISA added the CVE to KEV and set a September 17, 2026 deadline for FCEB patching.

KREMLIN browser-extension credential theft activity

Malware Activity

Updated: 15.09.2026 21:54 · First: 15.09.2026 21:54 · 📰 2 src / 2 articles · H score: 44

The KREMLIN malware activity is a Brazilian banking operation that has been active since at least May 2025 and uses malicious Chrome and Edge extensions to steal credentials, session tokens, and other sensitive browser data. Elastic Security Labs said the loader bypasses Chromium integrity checks, installs the extension without user approval, and uses Ethereum smart contracts and Internet Archive-hosted payloads to rotate infrastructure and deliver the chain. The activity spans seven campaigns, impersonates 12 banks, and includes recent use of REMCOS or Pulsar RAT alongside the browser-extension theft. Elastic also confirmed 1,515 infected systems, almost all in Brazil, and disrupted the current campaign by registering an anti-sandbox canary domain.

New Jersey court Ordered radaris.com and more than a dozen other data broker domains transferred to the plaintiffs on Domain transfer as default-judgment relief in a Daniel’s Law

Regulatory/Legal Action

Updated: 16.09.2026 21:14 · First: 16.09.2026 21:14 · 📰 1 src / 1 articles · H score: 69

A New Jersey court ordered radaris.com and more than a dozen other data broker domains transferred to the plaintiffs, escalating enforcement of Daniel’s Law against a people-search operation accused of exposing protected personal information. The order followed a default judgment after the defendants repeatedly failed to appear and defend the claims. The transfer removes the operation’s main web presence and shows that courts can use domain-level remedies to enforce privacy obligations.

AEPD urges stronger identity and credential controls against AI-assisted machine-speed attacks

Defensive Guidance

Updated: 16.09.2026 20:26 · First: 16.09.2026 20:26 · 📰 2 src / 3 articles · H score: 11

Spanish Data Protection Agency (AEPD) said it was notified of an alleged AI agent attack powered by a known LLM, and urged stronger digital identity and credential security. The reported activity involved searching for vulnerabilities, logging in, probing applications, then modifying personal data and accessing invoices. AEPD has not verified the incident yet, but says AI-assisted attacks can increase speed, scale, and adaptability and compress defenders’ response windows. The guidance calls for faster detection, containment, and response against autonomous activity that can reuse compromised accounts, API keys, or tokens across multiple services at machine speed.

Organization reporting incident hit by network compromise

Incident

Updated: 16.09.2026 20:26 · First: 16.09.2026 20:26 · 📰 1 src / 2 articles · H score: 10

The organization reporting the incident said an AI agent powered by a known LLM carried out an alleged intrusion that searched for flaws, logged into systems, and probed applications for more weaknesses before modifying personal data and accessing invoices. The notification was sent to the Spanish Data Protection Agency (AEPD), which has not verified the claims. AEPD said the report shows AI-related data breaches are moving into operational risk and can speed attacks, expand scope, and shorten defenders' response windows.

Issabel Framework hard-coded JWT signing key RCE (CVE-2026-89026)

Vulnerability

Updated: 16.09.2026 18:50 · First: 16.09.2026 18:50 · 📰 1 src / 1 articles · H score: 46

CVE-2026-89026 in Issabel Framework is under active exploitation, exposing Asterisk deployments to unauthenticated remote OS command execution through forged bearer tokens. A hard-coded JWT signing key lets attackers mint valid tokens and reach the /pbxapi/manager/originate endpoint. A patch was released on August 1, 2026, and defenders should ensure the latest fix is applied promptly.

Issabel Framework security patch for CVE-2026-89026

Security Patch Release

Updated: 16.09.2026 18:50 · First: 16.09.2026 18:50 · 📰 1 src / 1 articles · H score: 50

A security patch for Issabel Framework was pushed on August 1, 2026 to fix CVE-2026-89026, closing an unauthenticated OS command execution path tied to a hard-coded JWT signing key. The update moves the JWT key out of the application code and into /etc/issabel.conf, reducing the risk across affected installations. That remediation is directly relevant because the flaw was already under active exploitation.

NightEagle Russian enterprise VPN GhostContainer campaign

Campaign

Updated: 16.09.2026 18:27 · First: 16.09.2026 18:27 · 📰 1 src / 1 articles · H score: 37

The NightEagle (APT-Q-95) campaign is actively using compromised VPN credentials and GhostContainer to reach Russian enterprise networks, increasing the risk of persistent access and lateral movement. The operators are combining stolen access with a backdoor that can control Microsoft Exchange Server systems, run code, and load modules. The activity has been active since at least 2023 and was highlighted in July 2025. The operation shows sustained targeting rather than a one-off intrusion.