βΌοΈ ALERT - Critical Docker Sandboxes flaw lets malicious guest code escape the shared workspace and read or modify files across a macOS host.
CVE-2026-77179 crosses the virtio-fs boundary with the host accountβs rights.
Read how the escape works β https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
CVE-2026-77179 crosses the virtio-fs boundary with the host accountβs rights.
Read how the escape works β https://thehackernews.com/2026/09/critical-docker-sandboxes-flaw-lets.html
π₯5π4π2
π₯ 25 New CYBER stories in this weekβs ThreatsDay Bulletin:
β Exposed AI systems breached
β Stealers hunt agent tokens + prompts
β Agents rewrite their own models
β Ransomware jumps on a fresh flaw
β Telnet brute-force still works
β RF attacks leak audio remotely
β and more...
Check out the full list of threats here: https://thehackernews.com/2026/09/threatsday-self-rewriting-agents-800.html
β Exposed AI systems breached
β Stealers hunt agent tokens + prompts
β Agents rewrite their own models
β Ransomware jumps on a fresh flaw
β Telnet brute-force still works
β RF attacks leak audio remotely
β and more...
Check out the full list of threats here: https://thehackernews.com/2026/09/threatsday-self-rewriting-agents-800.html
π₯4
βΌοΈ NEW - Critical Check Point management flaw lets unauthenticated attackers run code as root.
The 9.8-rated bug (CVE-2026-91843) sits in the login path before authentication.
Affected versions and fix details: https://thehackernews.com/2026/09/critical-check-point-management-server.html
The 9.8-rated bug (CVE-2026-91843) sits in the login path before authentication.
Affected versions and fix details: https://thehackernews.com/2026/09/critical-check-point-management-server.html
π8π₯4
RatHat can keep shell access to an Android device even after the malicious app is uninstalled.
It abuses Accessibility and local ADB pairing to establish persistent operator access, with AI used to help navigate the device.
How it survives removal: https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html
It abuses Accessibility and local ADB pairing to establish persistent operator access, with AI used to help navigate the device.
How it survives removal: https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html
π€―13π4π₯3π1
π¨ A claimed bug bounty hunter likely used an LLM to build PhantomRaven, an npm stealer that collects developer credentials and CI/CD secrets.
CrowdStrike linked the operator to malicious npm packages and similar activity targeting PyPI.
Read: https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html
CrowdStrike linked the operator to malicious npm packages and similar activity targeting PyPI.
Read: https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html
π₯5π4
β οΈ Importing one of 13 npm packages can load the WeaselBiscuit stealer directly into memory.
It harvests Chrome extension storage on Windows, macOS, and Linux. On Windows, C2 commands can also trigger keylogging and clipboard logging.
How the npm delivery chain works: https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
It harvests Chrome extension storage on Windows, macOS, and Linux. On Windows, C2 commands can also trigger keylogging and clipboard logging.
How the npm delivery chain works: https://thehackernews.com/2026/09/weaselbiscuit-stealer-spreads-via-13.html
π₯7
π¨ Plugin4Shell vulnerability can make four widely used AI coding agents install plugin code that differs from the version they report as pinned.
The attack requires control of the plugin repository.
How it works: https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html
The attack requires control of the plugin repository.
How it works: https://thehackernews.com/2026/09/plugin4shell-lets-repository-owners.html
π₯8
β‘ ReportURI browser alerts caught a ClickFix campaign before some reputation services did.
CSP reports from compromised e-commerce sites exposed attacker-controlled domains used in a chain that copied PowerShell commands to victimsβ clipboards.
How the attack surfaced: https://thehackernews.com/2026/09/an-abandoned-cdn-domain-was-re.html
CSP reports from compromised e-commerce sites exposed attacker-controlled domains used in a chain that copied PowerShell commands to victimsβ clipboards.
How the attack surfaced: https://thehackernews.com/2026/09/an-abandoned-cdn-domain-was-re.html
π₯3
π¨ Azure AI Foundry flaw lets unauthorized attackers elevate privileges over the network.
The CVSS 10.0 issue stems from missing authentication for a critical function. Microsoft says it is fully mitigated, with no evidence of exploitation.
Here's what the flaw could allow: https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html
The CVSS 10.0 issue stems from missing authentication for a critical function. Microsoft says it is fully mitigated, with no evidence of exploitation.
Here's what the flaw could allow: https://thehackernews.com/2026/09/microsoft-patches-cvss-100-azure-ai.html
π4β‘1
β οΈ Transparent Tribe is targeting government and defense entities in India and Afghanistan with a new Rust backdoor.
RUSTYSHADE uses private GitHub repos for encrypted C2, while post-compromise activity includes Windows and Linux file stealers.
Read more about Operation RapidRust: https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html
RUSTYSHADE uses private GitHub repos for encrypted C2, while post-compromise activity includes Windows and Linux file stealers.
Read more about Operation RapidRust: https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html
π5β‘2
This media is not supported in your browser
VIEW IN TELEGRAM
βΌοΈ WARNING - New WordPress "Click2Shell" vulnerability can force a silent theme install from a crafted link.
Researchers chained the flaw with a separate theme bug to execute code on the server.
Read details here β https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html
Researchers chained the flaw with a separate theme bug to execute code on the server.
Read details here β https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html
π₯6β‘3
π¨ Four Linux kernel flaws now have public working exploits for local root.
DirtyAH6, TUNderflow, and PPPoEject require unprivileged user namespaces for an ordinary user. DiagSpill needs SCTP available but no special privileges.
Read β https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html
DirtyAH6, TUNderflow, and PPPoEject require unprivileged user namespaces for an ordinary user. DiagSpill needs SCTP available but no special privileges.
Read β https://thehackernews.com/2026/09/public-exploits-released-for-four-linux.html
π€―9π₯4π4
β οΈ Three Linux kernel flaws are being exploited.
One can enable local privilege escalation. The others can expose memory, crash systems, or corrupt cryptographic results. All three are now in CISAβs KEV catalog.
Read: https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html
One can enable local privilege escalation. The others can expose memory, crash systems, or corrupt cryptographic results. All three are now in CISAβs KEV catalog.
Read: https://thehackernews.com/2026/09/cisa-flags-three-linux-kernel.html
β‘7π₯3
βΌοΈ Google Gemini broke into real company systems during a security test.
A fictional company name matched a real domain while internet access was unintentionally enabled. Gemini guessed one password and found other credentials in a public repository before halting.
Read: https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html
A fictional company name matched a real domain while internet access was unintentionally enabled. Gemini guessed one password and found other credentials in a public repository before halting.
Read: https://thehackernews.com/2026/09/google-gemini-broke-into-real-company.html
π18β‘4π€4
π¨ Attackers are exploiting a critical Orkes Conductor RCE without authentication.
Nearly 7,000 attack attempts were blocked from Sept. 2β9, with attackers submitting crafted workflow definitions containing malicious JavaScript or Python expressions.
Here's how the exploit works: https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html
Upgrade to 3.30.2 or later.
Nearly 7,000 attack attempts were blocked from Sept. 2β9, with attackers submitting crafted workflow definitions containing malicious JavaScript or Python expressions.
Here's how the exploit works: https://thehackernews.com/2026/09/critical-pre-auth-rce-in-orkes.html
Upgrade to 3.30.2 or later.
π₯4β‘1
π¨ A hard-coded static key in SolarWinds ARM can enable unauthenticated RCE.
CVE-2026-28326 affects ARM 2026.2 and earlier and is fixed in 2026.2.1. SolarWinds did not report in-the-wild exploitation.
Read: https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
CVE-2026-28326 affects ARM 2026.2 and earlier and is fixed in 2026.2.1. SolarWinds did not report in-the-wild exploitation.
Read: https://thehackernews.com/2026/09/solarwinds-patches-arm-hard-coded-key.html
π₯3π2
βΌοΈ Claude Opus 5 helped three researchers build an image exploit that took over OpenAI's public help forum server.
A flaw in OpenAI's own login then let them take over staff ChatGPT/Codex accounts and reach an internal code repo β in under 72 hours.
Here's how the chain worked β https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html
A flaw in OpenAI's own login then let them take over staff ChatGPT/Codex accounts and reach an internal code repo β in under 72 hours.
Here's how the chain worked β https://thehackernews.com/2026/09/claude-opus-5-helped-researchers-take.html
π15π₯6π4β‘3π€―3π2
Your IAM dashboard may not show who actually has access.
Local app accounts, embedded service credentials, legacy authentication, and cross-cloud trust can sit outside centralized reviews. Identity visibility maps those hidden paths to effective access and real usage.
Where IAM loses sight: https://thehackernews.com/2026/09/identity-visibility-in-2026-foundation.html
Local app accounts, embedded service credentials, legacy authentication, and cross-cloud trust can sit outside centralized reviews. Identity visibility maps those hidden paths to effective access and real usage.
Where IAM loses sight: https://thehackernews.com/2026/09/identity-visibility-in-2026-foundation.html
π8π₯4