β‘ U.S. seizes two NightmareStresser domains tied to hundreds of thousands of DDoS attacks and attempts.
The DDoS-for-hire service was assessed to have been used worldwide since 2022.
Operation PowerOFF details β https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html
The DDoS-for-hire service was assessed to have been used worldwide since 2022.
Operation PowerOFF details β https://thehackernews.com/2026/09/us-seizes-nightmarestresser-domains.html
π±5π3π₯2π1
βΌοΈ WARNING - New Cisco ISE flaw CVE-2026-76460 is under active exploitation.
The CVSS 10.0 auth bypass has no workaround, and successful exploitation may lead to root-level command execution.
Affected versions, fixes, and compromise checks: https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html
The CVSS 10.0 auth bypass has no workaround, and successful exploitation may lead to root-level command execution.
Affected versions, fixes, and compromise checks: https://thehackernews.com/2026/09/cisco-warns-of-new-zero-day-ise-auth.html
π€3π2
β οΈ Gyazo breach exposed 23.62 million user records and 490 million image metadata records.
The leaked data included IDs used to build Gyazo image links. Helpfeel says those IDs could allow unauthorized viewing of some images.
Read: https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html
The leaked data included IDs used to build Gyazo image links. Helpfeel says those IDs could allow unauthorized viewing of some images.
Read: https://thehackernews.com/2026/09/gyazo-breach-exposes-2362-million-user.html
π2
π¨ A single unauthenticated DoH request can BINDβs named process under a specific connection-close condition.
ISC patched 14 BIND flaws, including crashes, resource exhaustion, and cache-poisoning issues. No active exploits are known.
Details: https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html
ISC patched 14 BIND flaws, including crashes, resource exhaustion, and cache-poisoning issues. No active exploits are known.
Details: https://thehackernews.com/2026/09/bind-9-update-fixes-14-flaws-including.html
β‘4
βΌοΈ An OpenAI model found and used an exposed GitHub API key without authorization.
The key worked, but the requested data remained unavailable. The model then fabricated the data and attributed it to the requested source.
https://thehackernews.com/2026/09/openai-reveals-six-model-incidents.html
Itβs one of 6 misalignment incidents OpenAI disclosed.
The key worked, but the requested data remained unavailable. The model then fabricated the data and attributed it to the requested source.
https://thehackernews.com/2026/09/openai-reveals-six-model-incidents.html
Itβs one of 6 misalignment incidents OpenAI disclosed.
π€7
Attackers weaponize new vulnerabilities in ~5 days. The median org takes 43 days to patch known-exploited flaws.
Peer-reviewed AI agents exploited 87% of one-day vulnerabilities unaided.
The real test: provable coverage, independent validation, and safe-stop controls in production.
https://thehackernews.com/2026/09/cisos-expert-guide-to-agentic.html
Peer-reviewed AI agents exploited 87% of one-day vulnerabilities unaided.
The real test: provable coverage, independent validation, and safe-stop controls in production.
https://thehackernews.com/2026/09/cisos-expert-guide-to-agentic.html
π€3π₯1
π China-aligned FamousSparrow has shifted to a previously unreported backdoor in attacks across Latin America.
SparroWocky can run commands, exfiltrate files, take screenshots, and load in-memory plugins, with government entities among the targets.
Read: https://thehackernews.com/2026/09/china-aligned-famoussparrow-deploys.html
SparroWocky can run commands, exfiltrate files, take screenshots, and load in-memory plugins, with government entities among the targets.
Read: https://thehackernews.com/2026/09/china-aligned-famoussparrow-deploys.html
π3
Meet Georgetown's cybersecurity faculty on Sept 22 to learn more about the Cybersecurity Risk Management master's program.
Attend our virtual webinar on Sept 22.
Learn more β https://thn.news/risk-management-event
Attend our virtual webinar on Sept 22.
Learn more β https://thn.news/risk-management-event
π2
βΌοΈ Critical Unbound DNSSEC validator flaw (CVE-2026-82717) could allow remote code execution.
An attacker who controls a malicious zone can trigger the heap overflow by querying a vulnerable resolver. 1.26.0 and earlier are affected.
Read details β https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html
An attacker who controls a malicious zone can trigger the heap overflow by querying a vulnerable resolver. 1.26.0 and earlier are affected.
Read details β https://thehackernews.com/2026/09/critical-unbound-dnssec-validator-flaw.html
π₯4
β‘ Can you prove a CVE is exploitable without running the exploit?
This webinar shows how to map a vulnerability to the attack techniques it requires, then test whether your existing controls actually stop them.
Canβt join live? Sign up and get the recording: https://thehacker.news/ready-for-mythos-class-attacks
This webinar shows how to map a vulnerability to the attack techniques it requires, then test whether your existing controls actually stop them.
Canβt join live? Sign up and get the recording: https://thehacker.news/ready-for-mythos-class-attacks
π1
π¨ Iran-linked Handala Hack is tied to a Telegram-controlled backdoor that can steal passwords and messaging data.
HEAVYGRAM also executes commands, captures screenshots, and downloads additional malware.
See how Telegram becomes the control channel: https://thehackernews.com/2026/09/iran-linked-handala-hack-tied-to.html
HEAVYGRAM also executes commands, captures screenshots, and downloads additional malware.
See how Telegram becomes the control channel: https://thehackernews.com/2026/09/iran-linked-handala-hack-tied-to.html
π₯6π€4β‘1
βΌοΈ ALERT - Critical Docker Sandboxes flaw lets malicious guest code escape the shared workspace and read or modify files across a macOS host.
CVE-2026-77179 crosses the virtio-fs boundary with the host accountβs rights.
Read how the escape works β https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
CVE-2026-77179 crosses the virtio-fs boundary with the host accountβs rights.
Read how the escape works β https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
π₯4π2π1
π₯ 25 New CYBER stories in this weekβs ThreatsDay Bulletin:
β Exposed AI systems breached
β Stealers hunt agent tokens + prompts
β Agents rewrite their own models
β Ransomware jumps on a fresh flaw
β Telnet brute-force still works
β RF attacks leak audio remotely
β and more...
Check out the full list of threats here: https://thehackernews.com/2026/09/threatsday-self-rewriting-agents-800.html
β Exposed AI systems breached
β Stealers hunt agent tokens + prompts
β Agents rewrite their own models
β Ransomware jumps on a fresh flaw
β Telnet brute-force still works
β RF attacks leak audio remotely
β and more...
Check out the full list of threats here: https://thehackernews.com/2026/09/threatsday-self-rewriting-agents-800.html
π₯2
βΌοΈ NEW - Critical Check Point management flaw lets unauthenticated attackers run code as root.
The 9.8-rated bug (CVE-2026-91843) sits in the login path before authentication.
Affected versions and fix details: https://thehackernews.com/2026/09/critical-check-point-management-server.html
The 9.8-rated bug (CVE-2026-91843) sits in the login path before authentication.
Affected versions and fix details: https://thehackernews.com/2026/09/critical-check-point-management-server.html
π7π₯2
RatHat can keep shell access to an Android device even after the malicious app is uninstalled.
It abuses Accessibility and local ADB pairing to establish persistent operator access, with AI used to help navigate the device.
How it survives removal: https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html
It abuses Accessibility and local ADB pairing to establish persistent operator access, with AI used to help navigate the device.
How it survives removal: https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html
π€―4π₯2π1π1
π¨ A claimed bug bounty hunter likely used an LLM to build PhantomRaven, an npm stealer that collects developer credentials and CI/CD secrets.
CrowdStrike linked the operator to malicious npm packages and similar activity targeting PyPI.
Read: https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html
CrowdStrike linked the operator to malicious npm packages and similar activity targeting PyPI.
Read: https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html
π2π₯1
β οΈ Importing one of 13 npm packages can load the WeaselBiscuit stealer directly into memory.
It harvests Chrome extension storage on Windows, macOS, and Linux. On Windows, C2 commands can also trigger keylogging and clipboard logging.
How the npm delivery chain works: https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
It harvests Chrome extension storage on Windows, macOS, and Linux. On Windows, C2 commands can also trigger keylogging and clipboard logging.
How the npm delivery chain works: https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
π₯1
π¨ Plugin4Shell vulnerability can make four widely used AI coding agents install plugin code that differs from the version they report as pinned.
The attack requires control of the plugin repository.
How it works: https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html
The attack requires control of the plugin repository.
How it works: https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html