π¨ Attackers are exploiting a critical WooCommerce Wholesale Lead Capture flaw to plant PHP web shells.
Wordfence has blocked over 100,000 exploit attempts since June against CVE-2026-27540, which affects versions through 2.0.3.1.
Read: https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html
Wordfence has blocked over 100,000 exploit attempts since June against CVE-2026-27540, which affects versions through 2.0.3.1.
Read: https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html
π₯3π1
A unified security dashboard can still hide a broken incident workflow.
Run one incident from detection to clean recovery. Count every console switch, permission change, and ownership handoff.
Six tests reveal whether consolidation actually reduces operational friction: https://thehackernews.com/expert-insights/2026/09/how-to-evaluate-unified-security.html
Run one incident from detection to clean recovery. Count every console switch, permission change, and ownership handoff.
Six tests reveal whether consolidation actually reduces operational friction: https://thehackernews.com/expert-insights/2026/09/how-to-evaluate-unified-security.html
π₯2
β οΈ Acronis Backup flaw exploited in limited targeted attacks.
CVE-2026-87886 lets a low-privileged attacker escalate permissions on affected Linux cPanel/WHM and Plesk deployments. Fixes are available.
Which builds need updating β https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html
CVE-2026-87886 lets a low-privileged attacker escalate permissions on affected Linux cPanel/WHM and Plesk deployments. Fixes are available.
Which builds need updating β https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html
π₯2
βΌοΈ ALERT - Google says a Pixel modem flaw may be under limited, targeted exploitation.
CVE-2026-58704 can enable adjacent privilege escalation without user interaction. Google patched it in the September Pixel update.
Whatβs known about the attacks β https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html
CVE-2026-58704 can enable adjacent privilege escalation without user interaction. Google patched it in the September Pixel update.
Whatβs known about the attacks β https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html
π€6π4
A leaked credential is only useful intelligence if you know it still works.
Penteraβs Recorded Future integration automatically tests exposed credentials against an organizationβs external attack surface to confirm which ones can actually be used.
How the validation works β https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html
Penteraβs Recorded Future integration automatically tests exposed credentials against an organizationβs external attack surface to confirm which ones can actually be used.
How the validation works β https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html
π₯3
π A Parallels Desktop flaw lets non-admin Mac users gain root, but Intel Macs canβt install the version containing the fix.
Tracked as CVE-2026-90894, JFrog demonstrated the flaw on Parallels Desktop 26.4.0 and reports no attacks.
How the root escalation works β https://thehackernews.com/2026/09/parallels-desktop-flaw-lets-non-admin.html
Tracked as CVE-2026-90894, JFrog demonstrated the flaw on Parallels Desktop 26.4.0 and reports no attacks.
How the root escalation works β https://thehackernews.com/2026/09/parallels-desktop-flaw-lets-non-admin.html
π4
β οΈ N0va phishing abuses legitimate sign-in flows to capture access and refresh tokens.
The campaign impersonates Teams, SharePoint, DocuSign, Google Drive, and other trusted services, then can establish SSO access to email, files, and cloud apps.
Inside the attack chain β https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html
The campaign impersonates Teams, SharePoint, DocuSign, Google Drive, and other trusted services, then can establish SSO access to email, files, and cloud apps.
Inside the attack chain β https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html
π2
β οΈ One hijacked AI coding session helped spread Shai-Hulud across about 100 internal repositories.
A poisoned PyPI package installed an infostealer, GitHub OAuth tokens were stolen, and a compromised package in the companyβs own namespace caused a second infection.
Read: https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html
A poisoned PyPI package installed an infostealer, GitHub OAuth tokens were stolen, and a compromised package in the companyβs own namespace caused a second infection.
Read: https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html
π9β‘1
βΌοΈ A browser extension could hijack AI agents in Comet, Edge, Opera Neon and Claude, while abusing Chromeβs Gemini integration to reach local files, the camera and mic.
Researchers used the same underlying trust-boundary weakness across all five products after the extension was already installed.
Here's the technique β https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html
Researchers used the same underlying trust-boundary weakness across all five products after the extension was already installed.
Here's the technique β https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html
π₯4π3π1
π¨ From compromised VPN credentials to MQTT and Matrix C2, three threat groups are targeting Russian enterprises.
NightEagle uses GhostContainer, Toy Ghouls now fields a custom backdoor, and Kaspersky links Hacking Cat to Gorilla RAT and destructive malware.
Read: https://thehackernews.com/2026/09/three-threat-groups-target-russian.html
NightEagle uses GhostContainer, Toy Ghouls now fields a custom backdoor, and Kaspersky links Hacking Cat to Gorilla RAT and destructive malware.
Read: https://thehackernews.com/2026/09/three-threat-groups-target-russian.html
π±5π4β‘1
βΌοΈ Attackers are exploiting a critical Issabel Framework flaw.
CVE-2026-89026 uses a hard-coded JWT signing key, letting unauthenticated remote attackers forge tokens and execute OS commands as the Asterisk user. A fix is available.
How the flaw works: https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
CVE-2026-89026 uses a hard-coded JWT signing key, letting unauthenticated remote attackers forge tokens and execute OS commands as the Asterisk user. A fix is available.
How the flaw works: https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html
π₯11β‘2π€1
β‘ U.S. seizes two NightmareStresser domains tied to hundreds of thousands of DDoS attacks and attempts.
The DDoS-for-hire service was assessed to have been used worldwide since 2022.
Operation PowerOFF details β https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html
The DDoS-for-hire service was assessed to have been used worldwide since 2022.
Operation PowerOFF details β https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html
π±4π3π₯2π1
βΌοΈ WARNING - New Cisco ISE flaw CVE-2026-76460 is under active exploitation.
The CVSS 10.0 auth bypass has no workaround, and successful exploitation may lead to root-level command execution.
Affected versions, fixes, and compromise checks: https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html
The CVSS 10.0 auth bypass has no workaround, and successful exploitation may lead to root-level command execution.
Affected versions, fixes, and compromise checks: https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html
π€3π2
β οΈ Gyazo breach exposed 23.62 million user records and 490 million image metadata records.
The leaked data included IDs used to build Gyazo image links. Helpfeel says those IDs could allow unauthorized viewing of some images.
Read: https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html
The leaked data included IDs used to build Gyazo image links. Helpfeel says those IDs could allow unauthorized viewing of some images.
Read: https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html
π1
π¨ A single unauthenticated DoH request can BINDβs named process under a specific connection-close condition.
ISC patched 14 BIND flaws, including crashes, resource exhaustion, and cache-poisoning issues. No active exploits are known.
Details: https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html
ISC patched 14 BIND flaws, including crashes, resource exhaustion, and cache-poisoning issues. No active exploits are known.
Details: https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html
β‘4
βΌοΈ An OpenAI model found and used an exposed GitHub API key without authorization.
The key worked, but the requested data remained unavailable. The model then fabricated the data and attributed it to the requested source.
https://thehackernews.com/2026/09/openai-reveals-six-model-incidents.html
Itβs one of 6 misalignment incidents OpenAI disclosed.
The key worked, but the requested data remained unavailable. The model then fabricated the data and attributed it to the requested source.
https://thehackernews.com/2026/09/openai-reveals-six-model-incidents.html
Itβs one of 6 misalignment incidents OpenAI disclosed.
π€7
Attackers weaponize new vulnerabilities in ~5 days. The median org takes 43 days to patch known-exploited flaws.
Peer-reviewed AI agents exploited 87% of one-day vulnerabilities unaided.
The real test: provable coverage, independent validation, and safe-stop controls in production.
https://thehackernews.com/2026/09/cisos-expert-guide-to-agentic.html
Peer-reviewed AI agents exploited 87% of one-day vulnerabilities unaided.
The real test: provable coverage, independent validation, and safe-stop controls in production.
https://thehackernews.com/2026/09/cisos-expert-guide-to-agentic.html
π€3π₯1
π China-aligned FamousSparrow has shifted to a previously unreported backdoor in attacks across Latin America.
SparroWocky can run commands, exfiltrate files, take screenshots, and load in-memory plugins, with government entities among the targets.
Read: https://thehackernews.com/2026/09/china-aligned-famoussparrow-deploys.html
SparroWocky can run commands, exfiltrate files, take screenshots, and load in-memory plugins, with government entities among the targets.
Read: https://thehackernews.com/2026/09/china-aligned-famoussparrow-deploys.html
π3
Meet Georgetown's cybersecurity faculty on Sept 22 to learn more about the Cybersecurity Risk Management master's program.
Attend our virtual webinar on Sept 22.
Learn more β https://thn.news/risk-management-event
Attend our virtual webinar on Sept 22.
Learn more β https://thn.news/risk-management-event
π2
βΌοΈ Critical Unbound DNSSEC validator flaw (CVE-2026-82717) could allow remote code execution.
An attacker who controls a malicious zone can trigger the heap overflow by querying a vulnerable resolver. 1.26.0 and earlier are affected.
Read details β https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html
An attacker who controls a malicious zone can trigger the heap overflow by querying a vulnerable resolver. 1.26.0 and earlier are affected.
Read details β https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html
π₯3
β‘ Can you prove a CVE is exploitable without running the exploit?
This webinar shows how to map a vulnerability to the attack techniques it requires, then test whether your existing controls actually stop them.
Canβt join live? Sign up and get the recording: https://thehacker.news/ready-for-mythos-class-attacks
This webinar shows how to map a vulnerability to the attack techniques it requires, then test whether your existing controls actually stop them.
Canβt join live? Sign up and get the recording: https://thehacker.news/ready-for-mythos-class-attacks