Cyber Dispatch™️
AI agents steal 600,000 credit cards in attacks on online retailers.
The campaign, active since at least July 2026, has reportedly stolen more than 600,000 unexpired payment card records, deployed web skimmers, and accessed systems belonging to major retailers, travel companies, and industrial firms.
Attackers are exploiting WordPress CVE-2026-87902 within hours of disclosure.
The attacks use pearcmd.php to write attacker-controlled PHP files to disk, but only when specific theme and server conditions are met.
The attacks use pearcmd.php to write attacker-controlled PHP files to disk, but only when specific theme and server conditions are met.
Compromised MemTensor packages are pushing the sckit credential stealer through npm and PyPI.
The Go-based malware targets developer and cloud secrets, launching on memory recall in the npm plugin or as soon as the PyPI module is imported.
The Go-based malware targets developer and cloud secrets, launching on memory recall in the npm plugin or as soon as the PyPI module is imported.
A new cPanel flaw, CVE-2026-87899, in CalDAV/CardDAV lets any logged-in cPanel account run code as root and take full control of the server.
A second flaw, CVE-2026-87900 in WP Toolkit, lets authenticated users modify databases belonging to other accounts.
A second flaw, CVE-2026-87900 in WP Toolkit, lets authenticated users modify databases belonging to other accounts.
Three Chrome-Windows 0-days were exploited in one chain to escape Chrome’s sandbox and achieve remote code execution.
Chinese threat actor UTA0565 used fake sites in the attacks, with the chain ultimately deploying CLEANGULP malware.
Chinese threat actor UTA0565 used fake sites in the attacks, with the chain ultimately deploying CLEANGULP malware.
F5’s BIG-IP APM 0-day is being exploited for unauthenticated RCE.
CVE-2026-94127 affects systems where APM acts as an OAuth authorization server. F5 has released hotfixes, and CISA added the flaw to KEV.
CVE-2026-94127 affects systems where APM acts as an OAuth authorization server. F5 has released hotfixes, and CISA added the flaw to KEV.
Next.js patched a critical ImageResponse flaw that can lead to server code execution.
"CVE-2026-94545" affects 16.2.0 through 16.3.5 on Node.js when attacker-controlled values reach generated SVG. The fix is 16.3.6.
"CVE-2026-94545" affects 16.2.0 through 16.3.5 on Node.js when attacker-controlled values reach generated SVG. The fix is 16.3.6.
ShinyHunters says it breached the FBI and stole data on agents and job applicants.
The FBI says it is investigating claims of unauthorized activity affecting FBIjobs[.]gov.
ShinyHunters also claims a PeopleSoft zero-day was used, but no public technical details of the flaw are available.
The FBI says it is investigating claims of unauthorized activity affecting FBIjobs[.]gov.
ShinyHunters also claims a PeopleSoft zero-day was used, but no public technical details of the flaw are available.
Check Point is warning customers about a newly disclosed Security Management Server zero-day exploited in targeted attacks in July.
CVE-2026-93616 lets an attacker who can reach the web service upload and run scripts without logging in. A fix landed Sept. 22.
CVE-2026-93616 lets an attacker who can reach the web service upload and run scripts without logging in. A fix landed Sept. 22.
Spanish PM Pedro Sánchez on AI:
The paradox is that we have these techno oligarchs investing in a technology that many of their workers say could kill and end humanity. And at the same time, these technical oligarchs are investing massively in immortality.
I think that what we need is serious regulation, responsible development of AI, and not bunkers and Mars missions for saving the techno oligarchs.
The paradox is that we have these techno oligarchs investing in a technology that many of their workers say could kill and end humanity. And at the same time, these technical oligarchs are investing massively in immortality.
I think that what we need is serious regulation, responsible development of AI, and not bunkers and Mars missions for saving the techno oligarchs.
Cyber Dispatch™️
Spanish PM Pedro Sánchez on AI: The paradox is that we have these techno oligarchs investing in a technology that many of their workers say could kill and end humanity. And at the same time, these technical oligarchs are investing massively in immortality.…
Spanish PM Pedro Sánchez:
The situation of the far right is not coming from a specific content but from a specific tool, which is social media and the algorithm.
Because it is poisoning the public debate. It is contributing to dehumanize many political actors. I’m also a victim of it.
The situation of the far right is not coming from a specific content but from a specific tool, which is social media and the algorithm.
Because it is poisoning the public debate. It is contributing to dehumanize many political actors. I’m also a victim of it.
WordPress issues patch a new critical flaw (CVE-2026-87902) that requires no account and can lead to code execution on some servers.
Versions 4.7.0 through 7.1.1 are affected.
Versions 4.7.0 through 7.1.1 are affected.
Russian drone/missile strike on Kyiv hit multiple data centers, knocking out internet for ~100,000 households.
ISPs UTELS, Pavutina, Crazy Network, and Etherlink all reported major node damage.
Hosting providers Cityhost and MiroHost lost Kyiv-based equipment, with MiroHost's local facility destroyed entirely (95% of clients unaffected on foreign servers).
ISPs UTELS, Pavutina, Crazy Network, and Etherlink all reported major node damage.
Hosting providers Cityhost and MiroHost lost Kyiv-based equipment, with MiroHost's local facility destroyed entirely (95% of clients unaffected on foreign servers).
Cyber Dispatch™️
Russian drone/missile strike on Kyiv hit multiple data centers, knocking out internet for ~100,000 households. ISPs UTELS, Pavutina, Crazy Network, and Etherlink all reported major node damage. Hosting providers Cityhost and MiroHost lost Kyiv-based equipment…
Providers are warning of significant price increases, saying current ~300-350 UAH rates are no longer viable given the cost of maintaining resilient infrastructure under constant attack.
Russia claimed the sites supported military communications.
Russia claimed the sites supported military communications.
A fake Cloudflare check ended with Vidar Stealer running inside a signed Microsoft process.
Researchers mapped 17,000+ infected URLs. About 3,000 still served ClickFix lures, while Polygon smart contracts let operators swap lure hosts without touching the compromised sites.
Researchers mapped 17,000+ infected URLs. About 3,000 still served ClickFix lures, while Polygon smart contracts let operators swap lure hosts without touching the compromised sites.