Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 21:06 26/09/2026 UTC
  • Advisory/Mitigation H score 83 Elementor CSRF bypass mitigation (4.3.2) Elementor released version 4.3.2 to close a CSRF bypass in the Editor Events module that could let attackers trigger REST API actions as an attacker-controlled administrator, advancing immediate upgrade remediation.
  • Exploitation Wave H score 34 WSO2, Adobe Commerce, SharePoint, and RouterOS active exploitation wave CISA added multiple actively exploited product vulnerabilities to the KEV catalog across WSO2, Adobe Commerce, SharePoint, and RouterOS, tightening federal patch timelines and highlighting a broad ongoing exposure wave.
  • Law Enforcement H score 82 Cameron John Wagenius cybercrime sentencing in Seattle A Seattle federal court sentenced Cameron John Wagenius to 70 months and $294,978 restitution for telecom metadata hacking and extortion, marking a significant legal progression in the Kiberphant0m telecom case.
  • Incident H score 31 Clop leak site hit by network compromise linked to ShinyHunters The Clop leak site was breached and defaced by ShinyHunters and forced an onion address change tied to an unpatched Grav CMS path traversal flaw, escalating uncertainty about alleged theft of keys and logs.
  • Advisory/Mitigation H score 38 Kiteworks six-hour shutdown advisory Kiteworks issued a precautionary worldwide six-hour shutdown after credible threat intelligence of an imminent attack, advancing customer containment guidance and reinforcing that the risk is not limited to internet-facing systems.
  • Data Leak H score 26 OpenAI AI agents accidental user-image uploads to third-party image-hosting sites OpenAI reported that its AI agents accidentally posted user images to third-party hosting sites across 53 incidents and is still cleaning up remaining content, advancing confirmed exposure and mitigation response.
Last updated: 01:36 26/09/2026 UTC
  • Case Case score 89 Roundcube CVE-2026-48842 Active Exploitation and Patch Pressure Roundcube Webmail’s CVE-2026-48842 pre-auth SQL injection is now actively exploited in-the-wild, advancing the case from patch availability to real authentication bypass and database compromise risk that requires immediate upgrade to 1.6.16/1.7.1.
  • Exploitation Wave H score 89 Roundcube Webmail CVE-2026-48842 active exploitation wave The CVE-2026-48842 exploitation wave is putting 523,000+ exposed Roundcube instances at risk, significantly expanding the likely scale and urgency of mitigation across internet-facing mail servers.
  • Data Leak H score 84 FBI employee and applicant data leak claim ShinyHunters’ FBI breach claim tied to an Oracle PeopleSoft zero-day is now accompanied by shared sample records and defaced FBI jobs content, escalating potential impact despite the FBI’s unverified-activity stance.
  • Data Leak H score 66 Unnamed Western government organization data exposed after WordPress breach A WordPress-driven intrusion has exposed 18,566 records from an unnamed Western government organization, including plaintext passwords and PII, raising the consequence of the wp2shell WordPress exploitation wave.
  • Vulnerability H score 54 F5 BIG-IP APM zero-day RCE (CVE-2026-94127) F5 disclosed CVE-2026-94127 as a BIG-IP APM zero-day being actively exploited for remote code execution on OAuth Authorization Server deployments, moving the issue into urgent patch/mitigation territory.
  • Law Enforcement H score 82 Cameron John Wagenius cybercrime sentencing in Seattle A Seattle court sentenced Cameron John Wagenius to 70 months for telecom hacking and extortion impacting data tied to 100M+ AT&T customers, marking a major enforcement milestone in the related Kiberphant0m case.

Latest updates

Browse →

FBI employee and applicant data leak claim

Data Leak

Updated: 22.09.2026 22:13 · First: 22.09.2026 22:13 · 📰 3 src / 4 articles · H score: 84

ShinyHunters claims it used an Oracle PeopleSoft flaw to reach FBI Jobs systems and then moved into FBI-managed AWS GovCloud infrastructure. The group also claimed a 2TB to 3TB theft tied to current and former FBI employees and job applicants, with exposure affecting Criminal Justice (CJ), HR, Medlink, and other internal services. The FBI said it is investigating unauthorized-activity claims affecting FBIjobs.gov, and the access and leak claims remain unverified. Later reporting says the same PeopleSoft thread is being reused with a URL-encoding bypass against CVE-2026-35273, allowing renewed exploitation of unpatched servers and deployment of web shells.

Psychedelic Stealer / LunexStealer MaaS infostealer deployment

Malware Activity

Updated: 26.09.2026 21:22 · First: 26.09.2026 21:22 · 📰 1 src / 1 articles · H score: 29

Psychedelic Stealer / LunexStealer is being deployed through the Lunex MaaS platform to steal Chromium browser credentials and cryptocurrency wallet data while keeping persistent remote access on victim systems. The malware chain uses ClickFix-style lures, bogus MSI installers, and a PowerShell-based Native Messaging Host to survive cleanup and continue operating. It also abuses PDFWKRNL.sys tied to CVE-2023-20598 to weaken defenses and bypass UAC on Windows endpoints.

OpenAI AI agents accidental user-image uploads to third-party image-hosting sites

Data Leak

Updated: 26.09.2026 15:28 · First: 26.09.2026 15:28 · 📰 1 src / 1 articles · H score: 26

OpenAI's AI agents exposed user-provided images by posting them to third-party image-hosting sites, creating a confirmed leak across 53 incidents. The shared links were not publicly listed, so the exposure was limited but still real. OpenAI said it has removed most of the affected content and is still working to clean up the remaining images.

Elementor plugin WordPress CSRF admin account creation security flaw

Vulnerability

Updated: 25.09.2026 21:13 · First: 25.09.2026 21:13 · 📰 2 src / 2 articles · H score: 72

A CSRF vulnerability in the Elementor plugin for WordPress lets an unauthenticated attacker force a logged-in administrator to perform REST API actions that can create attacker-controlled administrator accounts. The flaw affects versions 4.3.0 and 4.3.1, and Elementor has already shipped a fix in 4.3.2.

Elementor CSRF bypass mitigation (4.3.2)

Advisory/Mitigation

Updated: 25.09.2026 21:13 · First: 25.09.2026 21:13 · 📰 2 src / 2 articles · H score: 83

Elementor users are being told to upgrade to version 4.3.2 immediately to block a CSRF bypass that can let a logged-in administrator perform attacker-triggered REST API actions. The fix closes the query-string abuse path in the plugin’s Editor Events module. The affected releases are 4.3.0 and 4.3.1, which are used on up to 2 million sites. On default installations, abuse can lead to an attacker-controlled administrator account.

WSO2, Adobe Commerce, SharePoint, and RouterOS active exploitation wave

Exploitation Wave

Updated: 25.09.2026 20:24 · First: 25.09.2026 20:24 · 📰 2 src / 2 articles · H score: 34

CISA says attackers are actively exploiting four vulnerabilities across WSO2, Adobe Commerce, Microsoft SharePoint, and Mikrotik RouterOS, creating a broad exposure window for internet-facing enterprise systems. The wave includes CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, and CVE-2026-67279, spanning authentication bypass, incorrect authorization, code injection, and pre-auth SSH workflow bypass flaws. CISA placed the two critical issues in the KEV catalog and set mitigation deadlines of September 27 for the critical bugs and September 28 for the SharePoint and RouterOS flaws.

Kiteworks six-hour shutdown advisory

Advisory/Mitigation

Updated: 26.09.2026 00:41 · First: 26.09.2026 00:41 · 📰 2 src / 2 articles · H score: 38

Kiteworks issued a worldwide precautionary shutdown advisory after receiving credible threat intelligence that a potential attack on Kiteworks systems may be imminent. Customers were told to take servers offline for six hours on Saturday, September 26, including systems that are not directly exposed to the internet. The company said the warning is preventative, not a response to a confirmed breach, and urged customers to keep running version 9.5.1 with all known vulnerabilities addressed.

AT&T customers customer data exposed after AT&T breach

Data Leak

Updated: 26.09.2026 00:44 · First: 26.09.2026 00:44 · 📰 1 src / 1 articles · H score: 78

A self-claimed leak of AT&T customer call and text metadata exposed records for tens of millions of people, including source and destination numbers, timestamps, and durations. The claim was tied to Kiberphant0m and to public extortion of telecom companies. The exposure created broad privacy risk and increased pressure on victims not to have the data published.

Cameron John Wagenius cybercrime sentencing in Seattle

Law Enforcement

Updated: 26.09.2026 00:44 · First: 26.09.2026 00:44 · 📰 1 src / 1 articles · H score: 82

A federal court in Seattle sentenced Cameron John Wagenius in a cybercrime case, imposing 70 months in prison and $294,978 in restitution for telecom hacking and extortion. The judgment follows the theft of mobile call and text metadata tied to more than 100 million AT&T customers. It also marks the latest legal outcome in the Kiberphant0m telecom extortion case.

Grav security patch release for CVE-2026-42608

Security Patch Release

Updated: 25.09.2026 23:57 · First: 25.09.2026 23:57 · 📰 1 src / 1 articles · H score: 31

Grav backported the CVE-2026-42608 fix to the older 1.7 branch, releasing Grav 1.7.53.4 to close the path-traversal exposure for legacy sites. The update matters because installations that stayed on Grav 1.7 were still exposed even though the flaw had already been fixed in Grav 2.0.

Clop leak site hit by network compromise linked to ShinyHunters

Incident

Updated: 25.09.2026 23:57 · First: 25.09.2026 23:57 · 📰 1 src / 1 articles · H score: 31

The Clop leak site was breached and defaced by ShinyHunters, forcing the operation to shift to a new Tor address. The compromise was tied to Grav CMS 1.7.43 and an unpatched path traversal flaw now identified as CVE-2026-42608. The attacker later claimed to have taken source code, plugins, server logs, and private keys and threatened to leak them for payment. Clop said the old onion address would stay online only temporarily before retirement.

Grav CMS path traversal (CVE-2026-42608)

Vulnerability

Updated: 25.09.2026 23:57 · First: 25.09.2026 23:57 · 📰 1 src / 1 articles · H score: 8

Grav CMS 1.7.x installations were exposed to CVE-2026-42608, an unauthenticated path traversal flaw in form upload handling that could create unsafe upload paths and write files outside the intended directory. Grav said the bug was fixed in Grav 2.0 (2.0.0-beta.2) earlier this year and later backported as Grav 1.7.53.4. The weakness was used against a server running Grav CMS 1.7.43.

Elementor plugin for WordPress security fix in 4.3.2

Security Patch Release

Updated: 25.09.2026 21:13 · First: 25.09.2026 21:13 · 📰 1 src / 1 articles · H score: 30

The Elementor team shipped version 4.3.2 of the Elementor plugin for WordPress to fix a CSRF flaw that could let attackers create administrator accounts on vulnerable sites. The release closes the bypass affecting versions 4.3.0 and 4.3.1, which were installed on as many as 2 million sites. Site operators should upgrade to 4.3.2 to block the REST API abuse path.

CISA KEV remediation deadlines for exploited CVEs

Public Sector Action

Updated: 25.09.2026 20:24 · First: 25.09.2026 20:24 · 📰 1 src / 1 articles · H score: 34

CISA added CVE-2026-5430 and CVE-2026-71362 to the KEV catalog and set September 27 remediation deadlines for federal agencies using the affected products. Agencies must apply updates or mitigations or discontinue use, turning the notice into an immediate operational requirement. CISA also set a September 28 deadline for CVE-2026-65660 in Microsoft SharePoint and CVE-2026-67279 in Mikrotik RouterOS.

PamStealer macOS stealer adds live C2 decryption and multi-layer persistence

Malware Activity

Updated: 25.09.2026 16:18 · First: 25.09.2026 16:18 · 📰 1 src / 1 articles · H score: 29

The PamStealer macOS stealer now uses a server-side decryption chain for its payload, making static recovery impossible without live C2 cooperation. The latest build also swaps in a fake wavel[.]app wallet lure and a Wavel.dmg download to start the infection. It then uses a JXA dropper and /bin/zsh stage to install multi-layer persistence and keep the repair logic alive across logins and Git activity. The final stealer targets passwords, keychain items, browser credentials, system metadata, and user files on macOS.

CISA election software patch-management certification guidance

Advisory/Mitigation

Updated: 25.09.2026 15:39 · First: 25.09.2026 15:39 · 📰 1 src / 1 articles · H score: 39

CISA issued guidance for election software that aligns patch management with certification requirements so security updates can be deployed in real time without breaking certification. The recommendation reduces delay in fixing vulnerabilities across the election infrastructure ecosystem. It directly addresses a remediation bottleneck that can leave vulnerable systems exposed longer than necessary.

CISA election registration database hardening guidance for election offices

Defensive Guidance

Updated: 25.09.2026 15:39 · First: 25.09.2026 15:39 · 📰 1 src / 1 articles · H score: 39

Election infrastructure guidance now prioritizes multi-factor authentication, network monitoring, and least-privilege access for voter registration databases, reducing compromise and lateral-movement risk across election networks. The plan also requires critical logs to be kept for at least a year and keeps public registration and lookup tools walled off from the master database. Those controls give election offices a practical way to shrink the blast radius of workstation or email compromise.

CISA publishes 2026 Election Infrastructure Security Plan

Public Sector Action

Updated: 25.09.2026 15:39 · First: 25.09.2026 15:39 · 📰 1 src / 1 articles · H score: 50

CISA published its 2026 Election Infrastructure Security Plan, adding cyber and physical threat guidance and free services for election officials and partners. The plan lands as state and local election offices handle security for more than 10,000 local jurisdictions and federal support is meant to fill gaps in information, tools, and resources. It also flags patching barriers, voter registration database targeting, and a no-cost information-sharing platform for the 2026 election cycle.

CISA Election Infrastructure Security Plan for the 2026 midterms

Public Sector Action

Updated: 25.09.2026 15:30 · First: 25.09.2026 15:30 · 📰 1 src / 1 articles · H score: 18

CISA published an Election Infrastructure Security Plan for state, local, tribal, and federal election bodies ahead of the November 2026 midterms. The plan adds a formal government security framework for election infrastructure that is exposed to cyber and physical threats. It highlights risks to voter registration databases, voting systems, and vote tabulation locations. It also directs stakeholders toward mitigations such as MFA, monitoring, audit trails, paper ballots, and voluntary services.

Microsoft Windows update black-screen desktop loading failures on Azure Virtual Desktop hosts using FSLogix

Service Disruption

Updated: 25.09.2026 13:30 · First: 25.09.2026 13:30 · 📰 1 src / 1 articles · H score: 0

Microsoft's August 2026 preview updates and later Windows releases are causing desktop loading failures on Azure Virtual Desktop hosts using FSLogix, leaving some users stuck at a black screen after sign-in. Affected users may have to manually launch explorer.exe before they can reach the desktop, and the issue can also surface as Windows Explorer crashes in event logs. Microsoft says enterprise customers can temporarily reduce the impact with Known Issue Rollback (KIR) group policies while it prepares a permanent fix.

Roundcube CVE-2026-48842 Active Exploitation and Patch Pressure

Case

Updated: 25.09.2026 13:14 · First: 24.09.2026 16:27 · 📰 0 src / 2 articles

Roundcube Webmail CVE-2026-48842 is under active exploitation after being patched in May. The flaw is a pre-authenticated SQL injection in virtuser_query that can let unauthenticated attackers bypass authentication, run malicious database commands, and steal data from Roundcube's database. The activity has moved from patch availability to confirmed in-the-wild targeting, with administrators urged to update to 1.6.16 or 1.7.1 or disable the plugin if they cannot patch immediately. Available reporting also points to a large exposed internet-facing surface, while confirmed victim counts, operator attribution, and data-loss totals remain unconfirmed.

RemControl Android MaaS malvertising-delivered credential theft platform

Malware Activity

Updated: 24.09.2026 00:25 · First: 24.09.2026 00:25 · 📰 2 src / 2 articles · H score: 29

RemControl, a new Android malware-as-a-service, is being distributed through malvertising and fake Google Play pages impersonating TVTap IPTV, creating a scalable path to banking credential theft. The infrastructure has been active since at least May, and the first samples were seen in July. The malware uses more than 30 phishing overlays and targets users across Europe, Canada, and the Middle East. It can abuse Accessibility Service permissions, block Google Play services, and stream device data back to operators.

UNKK RemControl TVTap IPTV malvertising campaign

Campaign

Updated: 24.09.2026 00:25 · First: 24.09.2026 00:25 · 📰 2 src / 2 articles · H score: 35

RemControl is an Android banking trojan campaign tied to UNKK that uses fake Google Play Store pages to impersonate TVTap IPTV and push victims through a malicious install flow. The operation has targeted Android users across Western Europe, the Middle East and Canada since July 2026, with Group-IB saying it has confirmed targeting of more than 30 banking institutions across six countries. The trojan abuses Accessibility Services to gain remote control of devices and steal PIN codes, mobile banking codes, and card expiry dates. Group-IB also says UNKK appears to have used an AI assistant to build parts of the C2 backend and phishing overlays, and that exposed C2 panel API documentation gave researchers insight into the infrastructure.

Blocking disposable phishing domains and log-hunting for prior exposure

Defensive Guidance

Updated: 25.09.2026 11:30 · First: 25.09.2026 11:30 · 📰 1 src / 1 articles · H score: 26

EfficientIP recommended blocking disposable phishing domains and IPs after tracking AliExpress-themed entry points that could expose users to credential, payment, and browsing-data theft. The guidance also calls for DNS and proxy log review to find prior connections before the domains are reconfigured or replaced. That helps defenders catch exposure quickly when low-history domains have not yet been classified by reputation systems.

AliExpress-themed phishing operation using disposable redirect domains

Campaign

Updated: 25.09.2026 11:30 · First: 25.09.2026 11:30 · 📰 1 src / 1 articles · H score: 30

An AliExpress-themed phishing campaign surfaced through 10 disposable .cyou domains that were flagged before registration and later redirected visitors to a fake shopping-assistant lure. The infrastructure used a tracking layer with campaign, click, and affiliate parameters, letting the operator swap exposed domains without rebuilding the operation. Users faced risk of credential and payment theft and browsing-activity exposure if they reached the lure. The pattern shows a reusable redirect-and-replacement setup designed to keep the phishing flow alive.

Cloudflare Containers and Sandboxes shared-disk reuse security flaw

Vulnerability

Updated: 25.09.2026 07:49 · First: 25.09.2026 07:49 · 📰 1 src / 1 articles · H score: 3

Cloudflare fixed a shared-disk reuse flaw in Cloudflare Containers and Cloudflare Sandboxes that let one customer read leftover data from other tenants on shared servers. The weakness came from thin-provisioned blocks that were reused without being wiped, creating cross-customer confidentiality risk on container disks. Researchers reported the issue on September 4, Cloudflare said the proof of concept stopped working on September 14, and cleanup finished on September 19.

WSO2 API Manager JWT signature bypass (CVE-2026-5430)

Vulnerability

Updated: 16.09.2026 08:18 · First: 16.09.2026 08:18 · 📰 1 src / 2 articles · H score: 49

Active exploitation of CVE-2026-5430 in WSO2 API Manager puts API Control Plane, Traffic Manager, and Universal Gateway deployments at risk of account takeover and unauthorized access.

PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer

Malware Activity

Updated: 14.09.2026 21:34 · First: 14.09.2026 21:34 · 📰 1 src / 2 articles · H score: 30

PasteSwitch continues to use ClickFix-style social engineering to push MacSync and related payloads onto Windows and macOS systems, with a prior HBO Max Reddit account hijack used to run 108 malicious advertisements over about 48 hours. The campaign steers victims into pasting commands into trusted tools such as Windows Run, PowerShell, and macOS Terminal, and also promotes fake Ledger, Trezor Suite, and Exodus wallet apps. The newer MacSync activity adds public iCloud calendar events as a delivery channel on macOS, hiding commands in a calendar DESCRIPTION: field and fetching the next stage from iCloud. That MacSync variant also includes an Objective-C backdoor that masquerades as Finder, uses LaunchAgent, .zshrc modifications, and global Git hooks for persistence, and can run attacker-supplied AppleScript or replace an installed Ledger wallet app.

MacSync macOS infostealer with iCloud calendar payload delivery

Malware Activity

Updated: 24.09.2026 23:53 · First: 24.09.2026 23:53 · 📰 1 src / 1 articles · H score: 29

MacSync now uses public iCloud calendar events to deliver fresh payloads on macOS, expanding its infection chain and increasing the risk of credential theft and remote control. The malware also adds a new Objective-C backdoor that can run attacker-supplied AppleScript, establish persistence, and upload files to command-and-control infrastructure. Its distribution has included ClickFix-style attacks and fake software lures, including a fake crypto wallet called Toria.

Carbonato botnet targeting exposed Docker daemons with Hermes Agent

Malware Activity

Updated: 24.09.2026 23:10 · First: 24.09.2026 23:10 · 📰 1 src / 1 articles · H score: 41

The Carbonato botnet is targeting exposed Docker daemons to install Hermes Agent and seize host control, creating a worm-like foothold on vulnerable systems. It reaches Docker APIs exposed on port 2375 without authentication, then launches privileged containers and sets up reverse SSH tunnels for operator access. The activity is tied to evidence spanning October 2024 to August 2026, which shows a sustained malware operation rather than a one-off intrusion.