Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 20:05 29/09/2026 UTC
Last updated: 23:05 28/09/2026 UTC
  • Data Leak H score 99 FBI employee and applicant data leak claim ShinyHunters’ new Oracle PeopleSoft breach claim—backed by later reporting of mass exploitation via CVE-2026-35273—raises the likelihood of large-scale data theft impacting FBI services and forces PeopleSoft patching and forensic review now.
  • Case Case score 89 Roundcube CVE-2026-48842 Active Exploitation and Patch Pressure Roundcube CVE-2026-48842 is now confirmed as being actively exploited in the wild, meaning organizations must urgently patch to 1.6.16/1.7.1 or remove the vulnerable virtuser_query plugin to stop pre-auth SQL injection leading to authentication bypass and database compromise.
  • Advisory/Mitigation H score 83 Elementor CSRF bypass mitigation (4.3.2) Elementor’s 4.3.2 update closes a CSRF bypass that can let attackers trigger REST API actions as a victim admin, so upgrading immediately is the fastest way to reduce takeover risk on up to millions of impacted sites.
  • Exploitation Wave H score 89 Roundcube Webmail CVE-2026-48842 active exploitation wave A Seattle federal court sentenced Cameron John Wagenius to 70 months for telecom hacking and extortion affecting data tied to more than 100 million AT&T customers, underscoring continued momentum against the Kiberphant0m telecom extortion ecosystem.
  • Data Leak H score 67 Misconfigured Supabase databases exposing readable tables with sensitive data Researchers’ discovery of 16,000+ misconfigured Supabase databases exposing readable PII/passwords/tokens—plus some with credit card data—pushes immediate auditing toward enforcing effective row-level security and tightening public key usage.
  • Data Leak H score 62 Times Car member and corporate account data leak Times Car confirmed exposure of personal data for about 6.6 million member and corporate accounts (including passwords and identity documents), expanding identity-theft and phishing urgency even as it says payment card data was unaffected.

Latest updates

Browse →

PowerShell-triggered RAT payload on Windows

Malware Activity

Updated: 29.09.2026 23:59 · First: 29.09.2026 23:59 · 📰 1 src / 1 articles · H score: 22

The PowerShell-triggered ClickFix chain deployed a remote access trojan (RAT) that gave operators remote desktop access, camera/audio capture, reconnaissance, and additional payload execution on Windows. The malware established persistence with a Run key and scheduled task named Canon Configuration Reader. Delivery used a malicious MSI and a modified DLL loaded through a legitimate signed application, helping the infection blend in. Later variants shifted from a Canon-signed host app to a Stardock-signed one while keeping the same payload.

OpenAI custom GPT ClickFix RAT campaign

Campaign

Updated: 29.09.2026 23:59 · First: 29.09.2026 23:59 · 📰 1 src / 1 articles · H score: 33

A malicious custom GPT campaign abused sponsored Google results and fake backup pages to push users into ClickFix execution chains that deployed RAT malware. The operation affected dozens of users and used the legitimate ChatGPT.com domain to add credibility to the lure. OpenAI removed one malicious GPT by September 25, but a second linked variant was still active after September 27. The infection chain later shifted from a Canon-signed host app to a Stardock-signed one while keeping the payload behavior intact.

Citrix NetScaler ADC / NetScaler Gateway zero-day RCE flaws remote code execution flaw (multiple vulnerabilities)

Vulnerability

Updated: 28.09.2026 09:24 · First: 28.09.2026 09:24 · 📰 3 src / 4 articles · H score: 43

Citrix NetScaler CVE-2026-88771 and CVE-2026-88772 are being exploited as zero-days against unmitigated NetScaler deployments, enabling unauthenticated remote code execution on exposed appliances. Citrix urged immediate patching, and CISA added both flaws to the KEV Catalog while ordering Federal Civilian Executive Branch agencies to remediate by September 30. Mandiant now says attackers used the flaws to deploy WHIPSHOT and SLAPSHOT, keep root-level access, pivot into internal networks, and steal credentials across North America and Europe in government, financial services, education, legal, and professional services environments.

US Air Force members sentenced in BEC and phishing case

Law Enforcement

Updated: 29.09.2026 21:09 · First: 29.09.2026 21:09 · 📰 1 src / 1 articles · H score: 27

Chijioke Timothy Odimegwu and Harafat Mogaji were sentenced to a combined 189 months in federal prison for a BEC and phishing case that diverted victim payments into conspiracy-controlled accounts. The sentence adds criminal consequences and restitution to a long-running cybercrime scheme that used stolen email credentials and spoofed business correspondence.

Star Blizzard fake event-invitation phishing campaign

Campaign

Updated: 29.09.2026 20:20 · First: 29.09.2026 20:20 · 📰 1 src / 1 articles · H score: 29

Star Blizzard has run a fake event-invitation phishing campaign that delivers a Windows backdoor to people and organizations tied to Ukraine, affecting more than 100 organizations since January. The operation uses repeated email waves, spoofed host organizations, and malicious archives or links to push its payloads. Microsoft says at least one computer was infected, and the same operation has used multiple lure variants to keep pressure on the target set. Defenders can look for the named scheduled tasks and indicators tied to the campaign.

JIT engines Branch Target Reuse (BTR) (multiple vulnerabilities)

Vulnerability

Updated: 29.09.2026 20:00 · First: 29.09.2026 20:00 · 📰 2 src / 2 articles · H score: 36

Researchers disclosed Branch Target Reuse (BTR), a new Spectre-v2 vulnerability variant that targets JIT engines in web browsers, language runtimes, and the Linux kernel. Evaluations found the flaw in SpiderMonkey, GraalVM, and the kernel's cBPF JIT across multiple CPU vendors. Two kernel proof-of-concept exploits recovered a root password hash within minutes on a fully patched Intel system, and mitigations were merged for CVE-2026-64507 and CVE-2026-64508.

Linux kernel security patch release for CVE-2026-64507

Security Patch Release

Updated: 29.09.2026 20:00 · First: 29.09.2026 20:00 · 📰 2 src / 2 articles · H score: 24

Mitigations for Branch Target Reuse (BTR) have been released and merged into the Linux kernel, delivering fixes for CVE-2026-64507 and CVE-2026-64508. The update addresses a Spectre-v2 variant that targets JIT engines across browsers, language runtimes, and the operating system kernel. The release follows responsible disclosure after proof-of-concept work showed root password hash leakage on a fully patched Intel system.

Dutch Institute for Vulnerability Disclosure (DIVD) hit by network compromise

Incident

Updated: 29.09.2026 18:39 · First: 29.09.2026 18:39 · 📰 1 src / 1 articles · H score: 25

The Dutch Institute for Vulnerability Disclosure (DIVD) confirmed a cyberattack that used an autonomous AI agent, leaving the nonprofit in an ongoing breach investigation with the full impact still unclear. Investigators say the intrusion began with exploitation of a technical vulnerability in an undisclosed system. DIVD has already notified the police, the Autoriteit Persoonsgegevens, and the NCSC.

RemoteThreat emerges from stealth with $7 million pre-seed round

Industry Action

Updated: 29.09.2026 17:38 · First: 29.09.2026 17:38 · 📰 1 src / 1 articles · H score: 14

RemoteThreat emerged from stealth with $7 million in pre-seed funding, giving the new vendor fresh capital to bring an offensive operations platform to market. The company is backed by Osage University Partners and DataTribe, and it is positioning the platform for enterprise and critical infrastructure red teams, US government mission teams, and vetted defense partners. The launch adds a new, well-financed player to the cybersecurity industry focused on governed offensive operations.

RemoteThreat launches O/C/O Platform

Commercial Activity

Updated: 29.09.2026 17:38 · First: 29.09.2026 17:38 · 📰 1 src / 1 articles · H score: 1

RemoteThreat launched O/C/O Platform, a commercial offensive cyber operations product for enterprise and critical infrastructure red teams, US government mission teams, and vetted defense partners. The platform packages mission planning, command and control, implants, initial access, obfuscation, and AI assistants into one governed offering for advanced cyber operations.

RatHat Android credential-theft malware

Malware Activity

Updated: 17.09.2026 16:00 · First: 17.09.2026 16:00 · 📰 2 src / 3 articles · H score: 27

RatHat is an Android malware activity that Zimperium linked to China-based threat actors and that targets banking credentials, 2FA/OTP data, notifications, and screen and input capture. It spreads through smishing, malvertising, deceptive download portals, third-party forums, and malicious APKs, then uses a dropper, Accessibility abuse, and local ADB self-pairing to break out of the sandbox and gain shell-level privileges. Cleafy later reported that RatHat's C2 panels were rebranded from BlackCat to Panda Workshop, could build, sign, publish, and regenerate samples, and used Gemini to rank victims while campaigns ran across Europe, Latin America and Southeast Asia. Cleafy also observed nearly 100 deployments since April 2026, consistent with a MaaS model, while the malware retained persistence, a hardware-level keylogger, and AI-assisted UI automation.

Tenfold expands identity event auditing with Windows and Active Directory monitoring, plus upcoming Entra ID support

Security Tool/Service

Updated: 29.09.2026 17:01 · First: 29.09.2026 17:01 · 📰 1 src / 1 articles · H score: 11

tenfold has expanded its event auditing capability with real-time identity telemetry for Windows and Active Directory, giving defenders faster visibility into suspicious identity activity. The platform also says Entra ID support and automated alerting are coming in upcoming releases, extending the security monitoring scope.

Amazon Bedrock AgentCore Python SDK Code Interpreter command-injection flaw (CVE-2026-12530)

Vulnerability

Updated: 29.09.2026 17:00 · First: 29.09.2026 17:00 · 📰 1 src / 1 articles · H score: 32

CVE-2026-12530 in the Amazon Bedrock AgentCore Python SDK let crafted package names bypass the Code Interpreter helper's blocklist, creating command-execution risk inside AI sandboxes and exposing attached AWS credentials. The flaw affected versions 1.1.3 through 1.6.0 and let a package name become a shell command in the sandbox. AWS fixed it in 1.6.1 by replacing the blocklist with stricter validation.

PhantomSub Baileys-abusing npm package activity

Malware Activity

Updated: 29.09.2026 16:45 · First: 29.09.2026 16:45 · 📰 1 src / 1 articles · H score: 21

The discovery of 101 malicious npm packages abusing Baileys has exposed developers to unwanted WhatsApp group and channel subscriptions across a package set downloaded 490,000 times. Some variants fetch channel IDs from GitHub, while others hide them in cleartext or obfuscated code. The activity turns authenticated WhatsApp sessions into a distribution channel for bot-seller and market groups, many of them tied to Indonesia.

PhantomSub npm WhatsApp subscriber campaign targeting developers

Campaign

Updated: 29.09.2026 16:45 · First: 29.09.2026 16:45 · 📰 1 src / 1 articles · H score: 32

The PhantomSub campaign uses 101 npm packages to add developers to attacker-controlled WhatsApp groups and channels without consent. The packages have drawn 490,000 downloads, including 116,000 in the last 30 days, widening the reach of the operation. Shared channel IDs, remote channel lists, and GitHub accounts tie the packages together instead of isolated publisher activity. The campaign runs through Baileys-based package variants that fetch channel IDs from GitHub, embed them in cleartext, or hide them with encoding/obfuscation.

NeedyMantis long-term access activity

Malware Activity

Updated: 28.09.2026 21:35 · First: 28.09.2026 21:35 · 📰 2 src / 2 articles · H score: 22

The NeedyMantis malware family is being used to maintain long-term access in already breached networks, affecting a small number of targeted intrusions across telecommunications, universities, medical nonprofits, intergovernmental organizations, and government contractors. Microsoft says the activity dates back to October 2025. In examined cases, the malware arrived through DLL sideloading and established command-and-control over HTTPS and WebSocket. Microsoft published SHA-256 hashes, the corp.tripswithengine[.]com domain, file paths, and hunting queries to help defenders find it.

NeedyMantis persistent-access malware framework

Malware Activity

Updated: 29.09.2026 16:30 · First: 29.09.2026 16:30 · 📰 1 src / 1 articles · H score: 23

The NeedyMantis malware framework is enabling persistent access inside compromised networks, giving attackers a hidden foothold for follow-on operations and data theft. It has been active since at least October 2025 and has been used against telecommunications providers, universities, and government-linked organizations. The malware is deployed only after attackers already have access, then uses DLL side-loading and staged loaders to hide inside legitimate software. Its command-and-control stage can support data exfiltration or the installation of additional components.

Pig butchering crypto investment fraud campaign

Campaign

Updated: 29.09.2026 14:41 · First: 29.09.2026 14:41 · 📰 1 src / 1 articles · H score: 31

The pig butchering crypto fraud campaign kept targeting victims through social media, dating sites, and messaging apps, then steering them into fake investment schemes. One identified victim lost $16 million in cryptocurrency, showing the operation's ability to extract large transfers from a trusted online relationship. The scheme also sits inside a broader 2018-2024 wire-fraud pattern tied to more than $125 million in crypto losses.

DOJ charges and arrests Trung Nguyen Van in pig butchering money laundering case

Law Enforcement

Updated: 29.09.2026 14:41 · First: 29.09.2026 14:41 · 📰 1 src / 1 articles · H score: 29

The U.S. Department of Justice charged and arrested Trung Nguyen Van in a money laundering case tied to a pig butchering crypto scam, expanding criminal exposure in a scheme that allegedly drained $16 million from one victim. Prosecutors say Van's wallet was used to receive and move victim crypto, including funds routed to a private wallet off the centralized blockchain network. The case sits inside a broader wire-fraud operation that allegedly moved more than $125,000,000 in cryptocurrency. The action increases pressure on the laundering layer that helps convert scam proceeds into harder-to-trace assets.

Dutch police arrest tied to ShinyHunters hacking investigation

Law Enforcement

Updated: 28.09.2026 22:49 · First: 28.09.2026 22:49 · 📰 3 src / 4 articles · H score: 59

Dutch police and the FBI are moving against ShinyHunters after the arrest of a 24-year-old Amsterdam man alleged to be one of the group's leaders. The suspect was arrested on September 15 and is now set to remain in pre-trial detention for at least another 90 days after a Rotterdam District Court ruling on Tuesday. Dutch police said the suspect had material on his laptop tied to possible additional crimes, and they have not ruled out more arrests. The FBI says ShinyHunters and co-conspirators have breached more than 140 organizations since last year and collected at least $70 million in extortion payments.

Keio Corporation hit by ransomware attack

Incident

Updated: 29.09.2026 12:45 · First: 29.09.2026 12:45 · 📰 1 src / 1 articles · H score: 68

Keio Corporation confirmed a ransomware attack that disrupted sales systems at some group companies and forced the operator to disconnect systems from the internet. Railway operations were not affected, but police are still examining whether business information or customer data was leaked. The incident leaves a major Tokyo-region railway operator managing intrusion fallout while core transport services stayed online.

Times Car member and corporate account data leak

Data Leak

Updated: 28.09.2026 23:31 · First: 28.09.2026 23:31 · 📰 2 src / 2 articles · H score: 63

Times Car confirmed a data theft affecting approximately 6.6 million current and former member accounts, creating identity-theft and phishing risk for a large customer base. The exposed data includes names, addresses, birth dates, phone numbers, email addresses, driver’s license information, identity document images, passwords, and linked service IDs. The company said credit card information remained unaffected and there is no evidence the stolen data has been distributed online.

FBI employee and applicant data leak claim

Data Leak

Updated: 22.09.2026 22:13 · First: 22.09.2026 22:13 · 📰 5 src / 7 articles · H score: 95

ShinyHunters publicly claimed it breached FBI jobs systems through an Oracle PeopleSoft flaw, stole 2TB to 3TB of data, and exposed information tied to FBI employees and job applicants from services including Criminal Justice (CJ), HR, and Medlink. The FBI said it is investigating the unauthorized-activity claims affecting FBIjobs.gov, and the access and leak claims remain unverified in the supplied context. Later reporting said Mandiant and the Google Threat Intelligence Group (GTIG) confirmed mass exploitation of CVE-2026-35273 in Oracle PeopleSoft across dozens of systems in higher education, technology, healthcare, agriculture, transportation, and government. The same exploit thread was linked to a URL-encoding bypass against WAF rules and to renewed abuse of unpatched PeopleSoft servers.

Official MCP Python SDK credential-theft fix release (1.30.0, 2.2.0)

Security Patch Release

Updated: 29.09.2026 09:08 · First: 29.09.2026 09:08 · 📰 1 src / 1 articles · H score: 29

The official MCP Python SDK shipped fixed releases that close an OAuth credential-stealing flaw affecting 1.x and 2.x clients. The patch is available in 1.30.0 and 2.2.0, which add issuer-check behavior before login details are fetched. The release matters because affected clients could send the client secret, authorization code, and PKCE proof key to an attacker-controlled endpoint.

Official MCP Python SDK OAuth credential theft security flaw

Vulnerability

Updated: 29.09.2026 09:08 · First: 29.09.2026 09:08 · 📰 1 src / 1 articles · H score: 32

Official MCP Python SDK clients were found vulnerable to an OAuth credential theft flaw that let a malicious MCP server redirect login handling and capture secrets. The issue affected 1.9.1 through 1.29.1 on the 1.x line and 2.0.0 through 2.1.1 on the 2.x line, exposing the client secret, authorization code, and PKCE proof key. Fixed versions 1.30.0 and 2.2.0 stop the redirect abuse, and no attacks have been reported.

Times Car hit by network compromise

Incident

Updated: 28.09.2026 23:31 · First: 28.09.2026 23:31 · 📰 1 src / 1 articles · H score: 59

Times Car confirmed a cyberattack that compromised about 6.6 million current and former member accounts, exposing personal and identity data across its car-sharing service. The intrusion involved unauthorized access to systems at the beginning of the month and was blocked on September 26. Exposed data included names, addresses, birth dates, phone numbers, email addresses, driver’s license information, account passwords, and linked service IDs. There is no evidence the stolen data has been published online, credit card information was unaffected, and services continue to operate normally.

Apple security patch release for CVE-2026-86950

Security Patch Release

Updated: 28.09.2026 22:18 · First: 28.09.2026 22:18 · 📰 1 src / 1 articles · H score: 36

Apple released security updates for older iOS, iPadOS, and macOS branches to fix CVE-2026-86950, a flaw that could expose devices to arbitrary code execution. The issue is an out-of-bounds write in CoreGraphics that can be triggered by a maliciously crafted file. Apple shipped the fixes in iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1. The company said the problem may have been used in an extremely sophisticated attack against specific targeted individuals.

Apple CoreGraphics out-of-bounds write security flaw (CVE-2026-86950)

Vulnerability

Updated: 28.09.2026 22:18 · First: 28.09.2026 22:18 · 📰 1 src / 1 articles · H score: 25

Apple released updates for CVE-2026-86950, an out-of-bounds write in CoreGraphics that could enable arbitrary code execution on older iOS, iPadOS, and macOS versions. The flaw was tied to processing a maliciously crafted file and was said to have been possibly exploited in targeted attacks. Apple shipped fixes across iOS 26.7.1, iPadOS 26.7.1, macOS Tahoe 26.7.1, and macOS Sequoia 15.8.1.

Misconfigured Supabase databases exposing readable tables with sensitive data

Data Leak

Updated: 28.09.2026 21:50 · First: 28.09.2026 21:50 · 📰 1 src / 1 articles · H score: 67

Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with PII, passwords, and authentication tokens. A smaller subset also appears to include credit card data, widening the potential fallout beyond account takeover. The exposure is tied to missing or ineffective row-level security and misuse of public keys, and application owners were notified when significant exposure was identified.

Bitget hit by cyberattack

Incident

Updated: 28.09.2026 12:25 · First: 28.09.2026 12:25 · 📰 3 src / 3 articles · H score: 39

Bitget confirmed a breach that forced a temporary withdrawal suspension after attackers moved $387.5 million from compromised hot and warm wallets. The exchange says the incident is contained and that user balances remain unaffected. Withdrawal services are being restored in stages while trading and deposits continue to operate.