Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 06:50 19/09/2026 UTC
  • Incident H score 68 Gyazo hit by network compromise Helpfeel blocked the attacker’s access routes and fixed a Gyazo image-upload server vulnerability after exposing tens of millions of user and image-metadata records, reducing ongoing breach risk.
  • Vulnerability H score 60 AI coding agents plugin pinning bypass security flaw A plugin pinning bypass in four AI coding agents enables repo owners to swap “reviewed” plugins for malicious code, and recent patches for Anthropic Claude Code and OpenAI Codex highlight the urgent mitigation gap.
  • Security Patch Release H score 58 Cisco security patch release for CVE-2026-76460 Cisco shipped fixes for an actively exploited maximum-severity Cisco ISE authentication-bypass flaw (CVE-2026-76460) with no workarounds, advancing immediate network-hardening actions.
  • Law Enforcement H score 54 FBI seizes NightmareStresser domains The FBI seized the domains used by NightmareStresser in Operation PowerOFF, disrupting a long-running DDoS-for-hire service that enabled hundreds of thousands of attacks.
  • Incident H score 57 Brevo hit by network compromise Brevo confirmed a Cloudflare API key compromise that allowed ClickFix script injection into customer-facing pages, increasing scrutiny on web-injection controls even as it reported no impact to core accounts.
  • Vulnerability H score 39 Discourse HEIC/HEIF remote code execution flaw Researchers confirmed Discourse can achieve remote code execution via HEIC/HEIF uploads through an unpatched libheif decoding path, raising risk for forums that render decoded images.
Last updated: 07:27 19/09/2026 UTC

Latest updates

Browse →

Linux kernel actively exploited flaws (multiple vulnerabilities)

Vulnerability

Updated: 19.09.2026 09:24 · First: 19.09.2026 09:24 · 📰 1 src / 1 articles · H score: 46

Three Linux kernel vulnerabilities—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—were added to CISA KEV after evidence of active exploitation. The flaws expose affected systems to memory disclosure, denial-of-service, local privilege escalation, and data integrity problems. Red Hat updated advisories on September 19, 2026, and FCEB agencies were told to apply fixes by September 21, 2026.

Red Hat Linux kernel advisory update for active exploitation

Advisory/Mitigation

Updated: 19.09.2026 09:24 · First: 19.09.2026 09:24 · 📰 1 src / 1 articles · H score: 53

Red Hat updated its Linux kernel advisories on September 19, 2026 to flag active exploitation of CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, pushing operators to treat the flaws as high priority. The guidance says there are known public exploits for at least one of the CVEs, increasing the urgency for remediation. FCEB agencies were told to apply the necessary fixes by September 21, 2026 under BOD 26-04.

CISA adds Linux kernel flaws to KEV catalog under BOD 26-04

Public Sector Action

Updated: 19.09.2026 09:24 · First: 19.09.2026 09:24 · 📰 1 src / 1 articles · H score: 36

CISA added three Linux kernel flaws to its KEV catalog after evidence of active exploitation, forcing federal remediation prioritization. Under BOD 26-04, FCEB agencies are recommended to apply fixes by September 21, 2026. Red Hat updated its advisories on September 19, 2026, and the flaws can enable memory disclosure, denial-of-service, and local privilege escalation.

Linux kernel local root escalation flaws multiple vulnerabilities memory corruption flaw (CVE-2026-80844)

Vulnerability

Updated: 18.09.2026 21:02 · First: 18.09.2026 21:02 · 📰 1 src / 1 articles · H score: 26

Linux kernel local-privilege-escalation flaws across DirtyAH6, TUNderflow, PPPoEject, and DiagSpill now have public exploit code, leaving older systems exposed to local root risk until they are updated. Kernel maintainers have already fixed the issues, and up-to-date kernels are not affected. No real-world abuse has been reported yet, but public code increases the danger on shared systems.

WordPress core security release (7.1.1)

Security Patch Release

Updated: 18.09.2026 19:56 · First: 18.09.2026 19:56 · 📰 1 src / 1 articles · H score: 35

WordPress 7.1.1 shipped a security release that patches new WordPress core vulnerabilities and covers supported branches back to 4.7. The update closes a flaw that could let a logged-in administrator trigger a theme install from WordPress.org by opening a crafted link. WordPress told site owners to update right away, and the release is already available for affected branches. WordPress said there is no sign of real-world abuse.

WordPress core Click2Shell security flaw

Vulnerability

Updated: 18.09.2026 19:56 · First: 18.09.2026 19:56 · 📰 1 src / 1 articles · H score: 32

WordPress core now has a fixed Click2Shell flaw that can make a logged-in administrator install an attacker-chosen theme from WordPress.org, creating a path to server compromise when chained with a second bug. WordPress shipped the fix in 7.1.1 on September 17, 2026, and says there is no sign of real-world abuse. The flaw affects the core link-handling flow and can trigger theme installation without an explicit Install click. Researchers showed that the forced install can be combined with a separate theme weakness to reach code execution.

Gyazo hit by network compromise

Incident

Updated: 17.09.2026 10:30 · First: 17.09.2026 10:30 · 📰 2 src / 2 articles · H score: 68

Gyazo suffered a security breach that exposed 23.62 million user records and 490 million image metadata records, creating risk of unauthorized image access and credential abuse. The compromise came through a vulnerability in Gyazo's image upload server, and the attacker used that foothold to run arbitrary commands on Helpfeel's systems. Exposed records included email addresses, password hashes, session-related data, and image-link IDs that could let outsiders view captures without permission. Helpfeel disabled viewing for some images, told users to change passwords, and said the flaw was fixed after suspicious activity was noticed on September 11.

Transparent Tribe Operation RapidRust campaign targeting India and Afghanistan

Campaign

Updated: 18.09.2026 18:24 · First: 18.09.2026 18:24 · 📰 1 src / 1 articles · H score: 38

The Transparent Tribe operation Operation RapidRust is sustaining active cyber attacks against government and defense organizations in India and Afghanistan, raising the risk of follow-on intrusion and credential theft. The group is using newly identified tools RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH to support command-and-control, exfiltration, and USB propagation. It is also abusing private GitHub repositories and typosquatted domains impersonating The Print and India Today to host malicious content. Much of the observed activity fell between August 20 and September 1, 2026, with command activity limited to weekday mornings UTC.

SEO-optimized GitHub software-lure campaign pushing Rapuncel infostealer

Campaign

Updated: 18.09.2026 18:19 · First: 18.09.2026 18:19 · 📰 1 src / 1 articles · H score: 34

An ongoing SEO-optimized GitHub lure campaign is impersonating software firms to push Rapuncel, expanding malware exposure across people searching for popular downloads. The operation uses fake repos that mimic LastPass and at least 39 other companies, turning routine software searches into a malware delivery path. Victims are redirected through download buttons and ZIP archives before the installer sideloads payloads and disables security tools. The chain matters because it combines brand impersonation, search manipulation, and an EDR-killing driver to improve successful infections and data theft.

Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories

Malware Activity

Updated: 18.09.2026 18:19 · First: 18.09.2026 18:19 · 📰 1 src / 1 articles · H score: 26

Rapuncel is being distributed through an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to lure people searching for well-known software, increasing the risk of credential theft and wallet theft on infected Windows devices. The payload chain combines a sideloading installer, a Microsoft-signed kernel driver, and a persistence mechanism that helps the malware keep running after reboots. Once security tools are disabled, the infostealer can collect browser credentials, session tokens, screenshots, and system information before exfiltrating the data.

Microsoft Teams expands Weaponizable File Protection with custom blocked-file controls

Security Tool/Service

Updated: 18.09.2026 16:58 · First: 18.09.2026 16:58 · 📰 1 src / 1 articles · H score: 11

Microsoft Teams is expanding Weaponizable File Protection admin controls so organizations can customize which file types are blocked, reducing exposure to risky attachments in chat and channel messages. The update is slated to begin rolling out in November 2026 and gives security teams the option to keep the Microsoft-recommended default list or apply their own policy. The change broadens policy flexibility across Android, desktop, iOS, macOS, and web deployments.

Settra ransomware multi-incident campaign

Campaign

Updated: 18.09.2026 16:30 · First: 18.09.2026 16:30 · 📰 1 src / 1 articles · H score: 35

The Settra ransomware operation has been linked to repeated attacks across retail and manufacturing victims, indicating a coordinated campaign rather than isolated incidents. The activity spans June through September and pairs MeshAgent RMM, BYOVD, and recovery-disabling steps to maintain access and complicate recovery. The pattern increases the risk of renewed encryption and double-extortion pressure for similar organizations.

Settra ransomware deployments against retail and manufacturing victims

Malware Activity

Updated: 18.09.2026 16:30 · First: 18.09.2026 16:30 · 📰 1 src / 1 articles · H score: 31

The Settra ransomware variant is being deployed against retail and manufacturing victims, encrypting files and hindering recovery. It first appeared in June and was later used in incidents in July and September, showing repeated operational use. Attackers used MeshAgent RMM for persistent access and added BYOVD and other recovery-disruption steps to make restoration harder. The activity also overlaps with double-extortion tactics, raising pressure on affected organizations beyond encryption alone.

OpenAI hit by account takeover attack

Incident

Updated: 18.09.2026 15:45 · First: 18.09.2026 15:45 · 📰 1 src / 1 articles · H score: 18

OpenAI suffered an employee account takeover that led to internal repository access and limited reads of private-repository metadata and commits. The access path ran through an OpenAI employee’s account linked by Codex integration to OpenAI’s GitHub organization. The incident mattered because the intruder was able to open a pull request inside an internal repository before testing stopped.

Discourse HEIC/HEIF remote code execution flaw

Vulnerability

Updated: 18.09.2026 15:45 · First: 18.09.2026 15:45 · 📰 1 src / 1 articles · H score: 39

Researchers confirmed remote code execution through Discourse HEIC/HEIF uploads by exploiting an unpatched libheif flaw in the image-decoding path. The weakness affected Discourse deployments that forwarded unsupported HEIC/HEIF images to ImageMagick for decoding. The bug had been fixed upstream a year earlier, but it had not been treated as a security issue and lacked a CVE. That left exposed services vulnerable until the later fix and sandboxing changes.

Discourse HEIC/HEIF image-processing patch release

Security Patch Release

Updated: 18.09.2026 15:45 · First: 18.09.2026 15:45 · 📰 1 src / 1 articles · H score: 32

Discourse released a fix for the image-processing flaw affecting HEIC/HEIF uploads and added sandboxing to reduce exposure from malicious files. The remediation came within two days and was paired with a security advisory. The patch narrowed the risky path that routed unsupported uploads into ImageMagick/libheif decoding.

CISA hosts Cyber Storm X national cybersecurity exercise

Public Sector Action

Updated: 18.09.2026 15:00 · First: 18.09.2026 15:00 · 📰 1 src / 1 articles · H score: 21

CISA hosted Cyber Storm X, a four-day national cybersecurity exercise that tested response readiness for critical infrastructure across the public and private sectors. The exercise drew 2,000 participants and marked the tenth Cyber Storm in the program’s 20-year history. It centered on a nation-state adversary scenario involving rail, ports, water, and wastewater systems. CISA plans to publish a public after-action report with lessons learned.

AI coding agents plugin pinning bypass security flaw

Vulnerability

Updated: 18.09.2026 14:01 · First: 18.09.2026 14:01 · 📰 1 src / 1 articles · H score: 60

Plugin pinning bypass in four AI coding agents lets a repository owner swap a supposedly reviewed plugin for malicious code, turning a trusted add-on into a code-execution path. The swapped plugin can reach files, saved credentials, and the systems the user can log in to. Anthropic patched Claude Code 2.1.179 and OpenAI patched Codex 0.146.0, while GitHub Copilot has no fix and Gemini CLI will not be patched.

WeaselBiscuit stealer delivered via 13 npm packages

Malware Activity

Updated: 18.09.2026 13:40 · First: 18.09.2026 13:40 · 📰 1 src / 1 articles · H score: 30

The WeaselBiscuit stealer was found in 13 npm packages, expanding supply-chain risk to developer environments and extension data theft. The malware is triggered by an npm import, pulls its payload from an Npoint dead drop, and executes in memory after resolving command-and-control configuration. It harvests Chrome extension storage across Windows, macOS, and Linux, and on Windows it can also log clipboard contents and keystrokes.

FBI seizes NightmareStresser domains

Law Enforcement

Updated: 17.09.2026 14:33 · First: 17.09.2026 14:33 · 📰 3 src / 3 articles · H score: 54

FBI seized nightmare-stresser[.]com and nightmarestresser[.]org, disrupting NightmareStresser, a long-running DDoS-for-hire service. The U.S. Department of Justice said the domain seizure was part of Operation PowerOFF and involved a coordinated law-enforcement action. Authorities said the service had been active since at least 2022 and was used to launch hundreds of thousands of DDoS attacks against victims worldwide. Prior reporting also tied the platform to 566,000+ registered users and 52 servers.

CISA VINCE-NT vulnerability reporting platform upgrade

Security Tool/Service

Updated: 18.09.2026 13:00 · First: 18.09.2026 13:00 · 📰 1 src / 1 articles · H score: 11

CISA moved its vulnerability reporting and coordination workflow to VINCE-NT, adding more automation and built-in tools that improve disclosure handling for reporters, suppliers, and case managers. The shift matters because the platform now supports faster triage, smoother advisory publication, and tighter coordination across active cases. Stakeholders must update reporting procedures to submit through VINCE-NT.

Check Point Security Management and Log Servers stack overflow security flaw (CVE-2026-91843)

Vulnerability

Updated: 17.09.2026 21:08 · First: 17.09.2026 21:08 · 📰 2 src / 2 articles · H score: 46

Check Point Security Management Server and Log Server deployments are affected by CVE-2026-91843, a critical stack-based buffer overflow in the login process that can let an unauthenticated attacker achieve root remote code execution. Check Point says the flaw is not flagged as actively exploited, has released a LivePatch fix, and advises restricting Trusted Clients to known hosts or trusted IP addresses/subnets. The latest scope update says R82.20, standalone deployments, Log Servers, and Multi-Domain servers are also vulnerable, and out-of-support customers should open a ticket with Check Point support.

Manufacturing ransomware victim share rose to 22% with 40% incident growth

Trend

Updated: 18.09.2026 11:00 · First: 18.09.2026 11:00 · 📰 1 src / 1 articles · H score: 32

Manufacturing organizations remained the most targeted ransomware cohort, accounting for 22% of victims and seeing disclosed incidents rise 40% year-over-year. The pattern stayed elevated across 2025-2026, making manufacturing the top ransomware sector for the fifth consecutive year. The regional shift toward Europe adds pressure for manufacturers with exposed operational environments and downtime-sensitive production.

MIND raises $72 million Series B for AI-native DLP

Industry Action

Updated: 18.09.2026 10:25 · First: 18.09.2026 10:25 · 📰 1 src / 1 articles · H score: 11

MIND raised $72 million in a Series B round to scale its AI-native DLP platform for enterprise data protection. The financing brings total funding to $112 million and was led by Crosspoint Capital Partners with participation from YL Ventures and Paladin Capital Group. The Seattle startup says the capital will support product development, enterprise expansion, partnerships, and hiring.

RatHat Android credential-theft malware

Malware Activity

Updated: 17.09.2026 16:00 · First: 17.09.2026 16:00 · 📰 2 src / 2 articles · H score: 27

RatHat is a new Android malware activity linked by Zimperium to China-based threat actors and focused on stealing banking credentials, 2FA/OTP data, notifications, and screen and input data from infected devices. It is distributed through smishing, malvertising, deceptive download portals, third-party forums, and malicious APKs, then uses a dropper, Accessibility abuse, and local ADB self-pairing to break out of the sandbox and gain shell-level privileges. The malware also uses an AI-powered automation loop, persistence, and a hardware-level keylogger to retain access and improve operator control.

Settra ransomware activity using MeshAgent

Malware Activity

Updated: 17.09.2026 20:32 · First: 17.09.2026 20:32 · 📰 1 src / 1 articles · H score: 30

The Settra ransomware group used MeshAgent remote access software in two analyzed intrusions, adding persistence and file encryption to its attack chain. Attackers dropped RESTORE_FILES.txt ransom notes, cleared Windows event logs, and disabled Windows recovery options to hinder response and recovery. One intrusion also showed signs of Bring Your Own Vulnerable Driver (BYOVD) abuse, and the group has since been tied to 70 claimed victims across multiple countries.

Brevo hit by network compromise

Incident

Updated: 17.09.2026 20:11 · First: 17.09.2026 20:11 · 📰 1 src / 1 articles · H score: 57

Brevo confirmed a Cloudflare API key compromise that let attackers inject ClickFix scripts into its web properties, exposing customer-facing pages to malicious content injection. The compromise affected Brevo-hosted pages and customer-embedded JavaScript for roughly five and a half hours on September 14. Brevo said app.brevo.com, its email delivery infrastructure, and customer account data were not affected.

VL Prosperity hit by network compromise

Incident

Updated: 17.09.2026 20:09 · First: 17.09.2026 20:09 · 📰 1 src / 1 articles · H score: 28

The VL Prosperity and a second oil tanker suffered a cyberattack during transit to Texas, disrupting onboard operations and prompting a Coast Guard and FBI boarding. The intrusion reportedly reached the engine room, navigation, and cargo systems, and cut communications for roughly 30 hours. Investigators found evidence of a malicious cyber actor while publicly stopping short of linking the case to Iran.

Docker Sandboxes Unix socket relay flaw (CVE-2026-79994)

Vulnerability

Updated: 17.09.2026 18:37 · First: 17.09.2026 18:37 · 📰 1 src / 1 articles · H score: 31

Docker fixed CVE-2026-79994 in Docker Sandboxes, closing a High relay flaw that could make a guest connect the host to AF_UNIX sockets outside the workspace. The issue carried a CVSS score of 8.7 and was fixed in 0.42.0. Docker and CISA both list no known exploitation.

Docker Sandboxes security update for CVE-2026-77179 and CVE-2026-79994

Security Patch Release

Updated: 17.09.2026 18:37 · First: 17.09.2026 18:37 · 📰 1 src / 1 articles · H score: 34

Docker released a security update for Docker Sandboxes that fixes CVE-2026-77179 and CVE-2026-79994, closing a Critical macOS host-file escape and a High Unix-socket relay flaw. The update ships in 0.42.0 for systems affected before that release. Users should upgrade to 0.42.0 or later or use clone mode if they cannot update yet.