Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 06:05 15/09/2026 UTC
Last updated: 11:20 14/09/2026 UTC

Latest updates

Browse →

Fortinet VPN sustained credential attack campaign

Campaign

Updated: 15.09.2026 09:11 · First: 15.09.2026 09:11 · 📰 1 src / 1 articles · H score: 38

A Fortinet VPN credential attack campaign hit multiple U.S. customer environments in two sustained waves, generating tens of millions of authentication failures. The targeting used organization-specific usernames and other identity data rather than generic spraying, pointing to previously collected or enumerated credentials. One observed successful authentication was followed by malicious activity, increasing the risk of unauthorized access in affected environments.

GRIMWEDGE JavaScript backdoor with persistent C2 polling

Malware Activity

Updated: 15.09.2026 08:31 · First: 15.09.2026 08:31 · 📰 1 src / 1 articles · H score: 29

The GRIMWEDGE JavaScript backdoor is being deployed with a persistent C2 loop, giving operators host reconnaissance, file and process management, command execution, and payload delivery on compromised systems. It polls ocr.opusaccel[.]top for instructions and executes them in memory via eval(). The activity increases the risk of follow-on tooling and deeper hands-on-keyboard abuse after the initial foothold.

Japan’s Digital Agency hit by network compromise

Incident

Updated: 14.09.2026 23:36 · First: 14.09.2026 23:36 · 📰 1 src / 1 articles · H score: 52

Japan’s Digital Agency disclosed an unauthorized-access breach that may have exposed about 246,000 record rows of government-employee personal information. The intrusion entered through a VPN device vulnerability in the Government Solution Service (GSS) environment. The agency suspended the compromised account, severed outside communication, and reported no confirmed misuse or government-service outage.

GSS VPN device access security flaw

Vulnerability

Updated: 14.09.2026 23:36 · First: 14.09.2026 23:36 · 📰 1 src / 1 articles · H score: 54

Japan’s Digital Agency disclosed a VPN-device vulnerability in Government Solution Service (GSS) infrastructure that enabled initial access and unauthorized system access. The flaw was described as medium severity and not a zero-day, making it a concrete access-path weakness rather than a speculative issue. The breach may have exposed around 246,000 record rows tied to government-employee personal information.

Homebrew 7.0.0 adds built-in vulnerability scanning and stronger sandboxing for macOS package installs

Security Tool/Service

Updated: 14.09.2026 22:51 · First: 14.09.2026 22:51 · 📰 1 src / 1 articles · H score: 11

Homebrew 7.0.0 now ships a built-in vulnerability scanner, increasing security visibility for macOS package installs and dependency sets. The release also adds stronger security controls and the full BrewUI graphical interface, broadening how users browse and manage packages. The new brew vulns command and Homebrew advisory data help teams identify affected formula versions more quickly.

PasteSwitch ClickFix malware delivery of MacSync, AMOS helper, and Amatera Stealer

Malware Activity

Updated: 14.09.2026 21:34 · First: 14.09.2026 21:34 · 📰 1 src / 1 articles · H score: 29

The PasteSwitch activity is using ClickFix ads to deliver MacSync, AMOS helper, and Amatera Stealer to Windows and macOS users, creating a high-risk path to credential theft and account compromise. A hijacked HBO Max Reddit account amplified the reach with 108 malicious ads over about 48 hours. The delivery chain relies on attacker-supplied commands pasted into trusted operating-system tools, helping the malware bypass some browser and security defenses.

3BB hit by data theft breach

Incident

Updated: 14.09.2026 21:01 · First: 14.09.2026 21:01 · 📰 1 src / 1 articles · H score: 32

The 3BB network intrusion gave an attacker root access to internal machines and a hidden MeshCentral backdoor inside the Thai broadband provider's environment, increasing exposure of subscriber credentials and internal management systems. The operation was still live on June 3, 2026, when an exposed command server and control list were captured. Recovered scripts show password spraying, SSH-based probing of more than 55 internal computers, and searches for stored passwords, database logins, and SSH keys. The toolkit also targeted subscriber RADIUS databases and a FortiGate SSL-VPN gateway tied to CVE-2024-21762, but successful exploitation and data theft were not confirmed.

Telegram Desktop HTML export script injection security flaw

Vulnerability

Updated: 14.09.2026 20:58 · First: 14.09.2026 20:58 · 📰 1 src / 1 articles · H score: 25

Telegram Desktop's HTML export path let unescaped button text inject hidden JavaScript into saved chats, exposing pre-fix exports to message exfiltration or page rewriting when opened in a browser.

Telegram Desktop HTML export escaping fix

Security Patch Release

Updated: 14.09.2026 20:58 · First: 14.09.2026 20:58 · 📰 1 src / 1 articles · H score: 30

Telegram Desktop shipped a fix for an HTML export escaping flaw that could let a bot message inject JavaScript into exported chats. The update closed the issue for 6.9.4 beta and 7.0.1 stable, while older HTML exports created before the fix can still carry the script. Opening one of those files in a browser could expose chat content or let the page be rewritten.

Telegram Desktop old HTML export mitigation

Advisory/Mitigation

Updated: 14.09.2026 20:58 · First: 14.09.2026 20:58 · 📰 1 src / 1 articles · H score: 30

Telegram Desktop users with old HTML exports should update to 7.0.1 or 6.9.4 beta so pre-fix files no longer remain a browser-executed JavaScript risk. The researchers also advise reopening legacy exports only with JavaScript disabled or re-exporting the chats after updating. The guidance applies to exports created before the July fix, when older files could still carry the injected script.

Intel TDX and AMD SEV-SNP freshness gap security flaw

Vulnerability

Updated: 14.09.2026 19:58 · First: 14.09.2026 19:58 · 📰 1 src / 1 articles · H score: 11

A freshness flaw in Intel TDX and AMD SEV-SNP lets a DDR5 interposer attack make stale encrypted memory look current, undermining confidential-computing integrity. The weakness affects cloud servers that rely on scalable memory encryption and can be abused after brief physical access to the machine. The same design gap also extends to Intel Scalable SGX, and the disclosed attack can read or alter protected memory without the encryption engine detecting the tampering. No simple patch exists; only mitigations such as limiting vulnerable memory-management features or checking whether critical writes landed can reduce risk.

DDRop active interposer attack analysis on DDR5 confidential-computing memory protection

Technical Analysis

Updated: 14.09.2026 19:58 · First: 14.09.2026 19:58 · 📰 1 src / 1 articles · H score: 10

Researchers disclosed DDRop, a hardware interposer attack that breaks Intel TDX and AMD SEV-SNP memory protection on DDR5 cloud servers, letting stale encrypted data be reused as current. The technique needs only a brief physical visit and a low-cost interposer, but it can undermine protected guest memory and attestation state. The disclosure shows that confidential-computing designs can lose integrity when they lack a freshness check on server memory.

Red Heron Gitea RCE exploitation campaign

Campaign

Updated: 14.09.2026 19:56 · First: 14.09.2026 19:56 · 📰 1 src / 1 articles · H score: 17

The Red Heron campaign rapidly weaponized CVE-2026-60004 in Gitea to compromise internet-facing instances, exposing source code, credentials, and connected infrastructure across multiple countries. The operation expanded from initial scanning into persistent access, credential collection, and lateral movement, including root-level access on a three-node Proxmox cluster. The activity matters because it combined fast exploitation with post-compromise follow-on access against organizations in multiple sectors.

Red Heron Gitea CVE-2026-60004 exploitation wave

Exploitation Wave

Updated: 14.09.2026 19:56 · First: 14.09.2026 19:56 · 📰 1 src / 1 articles · H score: 22

An active CVE-2026-60004 exploitation wave is targeting Gitea instances across seven countries, converting public proof-of-concept code into an automated scanning framework. The activity has already driven compromises in Canada, Argentina, Taiwan, the U.S., Qatar, and Sri Lanka and moved beyond initial access into repository theft and credential collection. The wave raises immediate risk for internet-facing self-hosted development platforms because exposed instances can be scanned at scale and quickly turned into persistent footholds.

Mass-scanning campaign targeting internet-exposed Vite development servers campaign expands hybrid attack activity

Campaign

Updated: 14.09.2026 19:15 · First: 14.09.2026 19:15 · 📰 1 src / 1 articles · H score: 35

A mass-scanning campaign is targeting internet-exposed Vite development servers to steal AWS and Azure credentials and configurations, creating immediate risk of cloud compromise. The activity exploits CVE-2026-39364 in Vite 7.1.0–7.3.2 and 8.x before 8.0.5 by abusing query parameters to bypass file-read protections. F5 observed more than 800 attacks and about 32,000 raw events over a month, with traffic from the United States, Belgium, and the Netherlands. Defenders should patch Vite, restrict exposure on port 5173, block suspicious /@fs/ requests, and rotate secrets if vulnerable servers were public.

WordPress.org update API adds automated plugin review and high-risk release blocking

Security Tool/Service

Updated: 14.09.2026 19:00 · First: 14.09.2026 19:00 · 📰 1 src / 1 articles · H score: 16

WordPress.org update API is adding an automated security review that can block high-risk plugin releases before they reach users, reducing the chance that malicious or vulnerable updates are distributed downstream. The rollout combines AI models and Jetpack Scan to score releases, then stops those above the risk threshold. It also formalizes a six-hour cooldown before auto-updates, tightening control over plugin distribution.

Revolut hit by cyberattack

Incident

Updated: 14.09.2026 11:48 · First: 14.09.2026 11:48 · 📰 3 src / 3 articles · H score: 16

Revolut disclosed a data breach after a threat actor impersonated a government agency and obtained customer information through email. The exposed data included identity details, contact information, identity documents, verification selfies, account statements, IBAN numbers, withdrawal records, and full transaction history. Revolut said the breach affected a very limited number of customers, while systems and customer funds are unaffected. The company said it blocked the address and notified government, enforcement, data protection, and financial regulators.

Revolut customer data breach exposing identity and financial records

Data Leak

Updated: 14.09.2026 11:48 · First: 14.09.2026 11:48 · 📰 2 src / 2 articles · H score: 37

Revolut disclosed a data breach that exposed customer information after an attacker impersonated a government agency and obtained data through email. The exposed set included identity documents, facial verification images, and financial records such as IBANs, withdrawal records, and transaction history. Revolut said the breach affected a very limited number of customers and that its systems and customer funds are unaffected.

Microsoft Windows 11 USB audio disruption after September 2026 updates

Service Disruption

Updated: 14.09.2026 11:08 · First: 14.09.2026 11:08 · 📰 1 src / 1 articles · H score: 0

Microsoft's KB5124008 and KB5124012 September 2026 security updates are breaking USB Audio Class 1.0 devices on Windows 11, version 24H2 or later, leaving some PCs with no audio output and Code 10 errors. The disruption also makes volume controls and sound settings unresponsive for affected users. Microsoft has confirmed the issue in a Friday release health update and said the failure can stop devices from starting or producing audio. Some users can temporarily recover sound by switching to 2-channel mode, but an official workaround has not yet been published.

Twitch Enhanced Viewer | JeetBot OAuth token leak

Data Leak

Updated: 14.09.2026 10:24 · First: 14.09.2026 10:24 · 📰 3 src / 3 articles · H score: 36

A malicious Twitch browser extension exposed OAuth bearer tokens for nearly 31,000 users, creating account-takeover risk across chat, whispers, account settings, and channel points. The add-on, Twitch Enhanced Viewer | JeetBot, forwarded the tokens to operator-controlled proxy servers using an `&auth=` parameter. The exposed credentials came from Chrome and Firefox builds published in 2025. A documented update to version 85.8.7 stops the token forwarding, but previously transmitted tokens are not revoked.

Twitch Enhanced Viewer | JeetBot OAuth token-stealing extension

Malware Activity

Updated: 14.09.2026 10:24 · First: 14.09.2026 10:24 · 📰 1 src / 1 articles · H score: 35

Twitch Enhanced Viewer | JeetBot is leaking Twitch OAuth tokens through operator-controlled proxies, exposing bearer credentials that can be used to access chat, whispers, account settings, and channel points. The current v85.x builds forward tokens with an `&auth=` parameter during Twitch playlist requests, and earlier v4.x builds also posted tokens to a dedicated operator endpoint. The extension is listed across Chrome and Firefox stores and is associated with nearly 31,000 users. A documented update to 85.8.7 stops the token forwarding, but older installs continue to transmit credentials until they are changed.

CISA KEV listing and BOD 26-04 remediation deadline for GitLab CVE-2026-85706

Public Sector Action

Updated: 14.09.2026 10:06 · First: 14.09.2026 10:06 · 📰 2 src / 2 articles · H score: 36

CISA added CVE-2026-85706 to its actively exploited catalog and gave federal agencies three days to secure affected systems under BOD 26-04. The move turns the GitLab flaw into an urgent federal remediation priority and increases pressure on agencies running exposed servers. CISA also urged all organizations to prioritize remediation of KEV Catalog vulnerabilities.

GitLab CE/EE security update for CVE-2026-85706

Security Patch Release

Updated: 14.09.2026 10:06 · First: 14.09.2026 10:06 · 📰 2 src / 2 articles · H score: 44

GitLab released CE/EE fixes for CVE-2026-85706, and users were urged to patch immediately to close a repository commits API flaw that can expose credentials and secrets. The update covers GitLab Community Edition (CE) and Enterprise Edition (EE), including 19.3.2, 19.2.6, and 19.1. The patch release matters because vulnerable servers can leak sensitive information through unauthenticated requests.

GitLab CE/EE repository commits API path traversal (CVE-2026-85706)

Vulnerability

Updated: 14.09.2026 10:06 · First: 14.09.2026 10:06 · 📰 2 src / 2 articles · H score: 43

CISA added CVE-2026-85706 to its actively exploited catalog after GitLab CE/EE servers were probed and attacked, increasing the risk of credential and secret disclosure. The flaw is a path traversal problem in the repository commits API caused by missing authentication enforcement and improper path confinement. GitLab released fixes in 19.3.2, 19.2.6, and 19.1 and urged customers to patch immediately.

Windows Server Remote Desktop Services disruption after September 2026 cumulative updates

Service Disruption

Updated: 10.09.2026 23:34 · First: 10.09.2026 23:34 · 📰 1 src / 2 articles · H score: 0

Windows Server Remote Desktop Services is experiencing a service disruption after the September 2026 cumulative updates, leaving some systems unable to accept new connections and causing sessions to hang. The affected scope includes Windows Server 2019, 2022, and 2025 installations, and some administrators report that only a hard reset restores functionality. Rolling back the update has restored service for some environments, but that also removes the month's security fixes.

Sogou Input Method Windows link-handler code-execution flaw (CVE-2026-51990)

Vulnerability

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 2 src / 2 articles · H score: 89

CVE-2026-51990 is a critical one-click RCE in Tencent’s Sogou Input Method for Windows that UNC3569 exploited through a crafted sgbiz: link to load a malicious page and deploy the GRAYRABBIT backdoor. Gen Digital said the chain used biz_helper.exe, SGMyInput.exe, and an outdated, unsandboxed Chromium 80 browser path with disabled web-security protections to reach code execution. Gen reported the issue to Tencent on April 9, 2026, and Tencent completed a fix in version 16.3.0.3498 on April 21, 2026. The patch validates protocol-handler URL arguments, allows only HTTPS, and restricts navigation to approved Sogou and Tencent domains, while the broader browser-engine weakness remained in place.

UNC3569 Sogou Input Method exploitation campaign

Campaign

Updated: 11.09.2026 10:14 · First: 11.09.2026 10:14 · 📰 2 src / 2 articles · H score: 89

UNC3569 is using a crafted sgbiz: link to exploit Tencent’s Sogou Input Method for Windows and deploy the GRAYRABBIT backdoor. Gen Digital says the activity involves CVE-2026-51990, a one-click RCE flaw chained through a protocol handler, an unrestricted webview navigation path, and an outdated Chromium 80 engine running without a sandbox. The research says Tencent received the report on April 9 and released version 16.3.0.3498 on April 21 to validate URL arguments, allow only HTTPS, and restrict navigation to approved Sogou and Tencent domains. Gen Digital also said the sample it analyzed was a more mature 64-bit GrayRabbit variant with an expanded command set and RC4-encoded C2 configuration.

UNC3569 Exploitation and Remediation of Sogou Input Method on Windows

Case

Updated: 13.09.2026 17:26 · First: 11.09.2026 10:14 · 📰 0 src / 2 articles

Sogou Input Method on Windows was exploited through a crafted sgbiz: link that reached CVE-2026-51990, giving attackers code execution with the logged-in user's privileges and leading to GRAYRABBIT installation. The same intrusion chain also used CVE-2021-38003 in the product's Chromium-based browser path, and available material ties the operation to UNC3569. The flaw was reported to Tencent in April 2026, and the vendor said a fix was completed in version 16.3.0.3498 and pushed through automatic update. Public details still leave open the full affected-version range and whether broader browser-engine weaknesses inside the product create additional exposure beyond the closed link-handler path.

Microsoft dual phishing campaigns using CEO impersonation and passkey lures

Campaign

Updated: 13.09.2026 13:11 · First: 13.09.2026 13:11 · 📰 1 src / 1 articles · H score: 34

Microsoft disclosed two coordinated phishing campaigns that used third-party email delivery infrastructure and passkey-themed social engineering to target U.S. enterprise users, raising the risk of payment fraud and cloud account compromise. One wave sent over a million scam emails in August 2026 by impersonating CEOs and pushing fake ACH transfer requests. A separate operation active since May 2026 used counterfeit sign-in pages, AitM and device-code flows, and attacker-controlled MFA enrollment to seize Microsoft cloud accounts. The activity also enabled Graph API reconnaissance and data collection from SharePoint Online, OneDrive, and mailboxes.

Check Point VPN certificate security patch release (CVE-2026-85102, CVE-2026-85103)

Security Patch Release

Updated: 10.09.2026 14:45 · First: 10.09.2026 14:45 · 📰 2 src / 2 articles · H score: 53

Check Point began delivering fixes on September 9 for CVE-2026-85102 and CVE-2026-85103, two critical VPN certificate flaws in Security Gateways and Security Management Server. The release addresses unauthenticated remote code execution risk and gives customers remediation through Check Point Live Patch or the latest Jumbo Hotfix. Affected deployments include R82.10 / Jumbo Hotfix Take 43 or below, R82 / Take 125 or below, and R81.20 / Take 165 or below. Check Point says it found both issues itself and has no indication of attack use.