β‘ This weekβs cybersecurity recap goes beyond the biggest headlines.
Chrome 0-Day Attacks β’ Router Takeovers β’ N-central Critical Flaws β’ Storefront Backdoors β’ Coder Supply Chain Breach β’ AI Agent Escapes β’ Fake AI App Stealers β’ QR Phishing Without Images β’ Login Session Theft β’ Wallet Installers Hiding RATs β’ Pre-Login Device Leaks β’ Hijacked AI Summaries β’ Edge Devices Under Attack β’ Scam-Center Crackdown
Read the full recap: https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html
Chrome 0-Day Attacks β’ Router Takeovers β’ N-central Critical Flaws β’ Storefront Backdoors β’ Coder Supply Chain Breach β’ AI Agent Escapes β’ Fake AI App Stealers β’ QR Phishing Without Images β’ Login Session Theft β’ Wallet Installers Hiding RATs β’ Pre-Login Device Leaks β’ Hijacked AI Summaries β’ Edge Devices Under Attack β’ Scam-Center Crackdown
Read the full recap: https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html
π₯5π€―2
π¨ Help desk calls are being used to steal Microsoft 365 session tokens and exfiltrate cloud data for extortion.
PREY-0058 pairs vishing with AitM login pages, then replays captured tokens through residential proxies to access SharePoint, OneDrive, Exchange, and Box.
How the attack works: https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html
PREY-0058 pairs vishing with AitM login pages, then replays captured tokens through residential proxies to access SharePoint, OneDrive, Exchange, and Box.
How the attack works: https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html
π₯5β‘2
βΌοΈ PEEP turns Chrome and Edge into host-level backdoors after compromise.
With prior admin or code-execution access, the Smart Bookmarks extension steals session cookies and credentials, then uses Chromium native messaging to run host commands.
Read: https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html
With prior admin or code-execution access, the Smart Bookmarks extension steals session cookies and credentials, then uses Chromium native messaging to run host commands.
Read: https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html
π₯5π3π€―3β‘2
Grindr will pay Β£26 million to settle U.K. claims that it shared usersβ personal data, including HIV status, with third parties.
The case covers pre-2020 practices and includes no finding or admission of liability.
How the data-sharing claims began: https://thehackernews.com/2026/09/grindr-to-pay-26-million-to-settle-uk.html
The case covers pre-2020 practices and includes no finding or admission of liability.
How the data-sharing claims began: https://thehackernews.com/2026/09/grindr-to-pay-26-million-to-settle-uk.html
β‘5π1
π¨ Poisoned Bing results are pushing MayaBot malware and tech support scams.
BengalSEO uses fake software pages and filtered redirect chains to decide who gets a payload and who gets sent to a scam call center.
How the chain works: https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html
BengalSEO uses fake software pages and filtered redirect chains to decide who gets a payload and who gets sent to a scam call center.
How the chain works: https://thehackernews.com/2026/09/bengalseo-poisons-bing-search-results.html
π±7π€3
β‘ Adobe patches a Magento zero-day already exploited to deploy malware.
CVE-2026-75650 abuses Magento template processing for unauthenticated code execution. Attacks have delivered a Rust #Linux backdoor and PHP web shell.
How the chain works: https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
CVE-2026-75650 abuses Magento template processing for unauthenticated code execution. Attacks have delivered a Rust #Linux backdoor and PHP web shell.
How the chain works: https://thehackernews.com/2026/09/adobe-patches-magento-zero-day.html
π₯7
Attackers are getting more time inside networks again.
Global median dwell time rose from 11 to 14 days, reversing nearly a decade of improvement. Kaseyaβs Austin O'Saben breaks down where defenders lose that time and how AI-native SIEM could cut it.
Where the hours disappear: https://thehackernews.com/expert-insights/2026/09/the-economics-of-dwell-time-and-why-ai.html
Global median dwell time rose from 11 to 14 days, reversing nearly a decade of improvement. Kaseyaβs Austin O'Saben breaks down where defenders lose that time and how AI-native SIEM could cut it.
Where the hours disappear: https://thehackernews.com/expert-insights/2026/09/the-economics-of-dwell-time-and-why-ai.html
π₯5
βΌοΈ A client that has never logged in can create its own Kerberos identity and land in FreeIPAβs administrators group.
Red Hat reproduced the chain on a default install. It depends on a second flaw in 389 Directory Server; no real-world exploitation is documented.
How the two flaws chain: https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
Red Hat reproduced the chain on a default install. It depends on a second flaw in 389 Directory Server; no real-world exploitation is documented.
How the two flaws chain: https://thehackernews.com/2026/09/freeipa-flaw-chain-lets-anonymous.html
π₯8π1
π A WeChat call from a contact could take over your account without an answer.
Researchers demonstrated the zero-click worm spreading across three iPhone and Android test phones.
How the chain worked: https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html
Researchers demonstrated the zero-click worm spreading across three iPhone and Android test phones.
How the chain worked: https://thehackernews.com/2026/09/wechat-zero-click-worm-took-over.html
π₯10π±6β‘4
π¨ An autonomous multi-agent attack framework compromised thousands of third-party credentials in less than six hours.
It autonomously managed scanning, credential harvesting, troubleshooting, and IP rotation.
How the six-hour operation worked: https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html
It autonomously managed scanning, credential harvesting, troubleshooting, and IP rotation.
How the six-hour operation worked: https://thehackernews.com/2026/09/autonomous-ai-agents-compromise.html
π₯1
A dark web marketplace claimed 57,803 counterfeit currency orders across five currencies. Its own payment system had generated fewer than 2,400.
Our Threat Intelligence Lab spent nine days inside the operation. What looked like a thriving criminal market was mostly theater: fake escrow protections, recycled Bitcoin addresses, and "independent" vendors running on shared infrastructure.
No transactions. No exploits. Exposed endpoints were reported, not touched. Findings are now with law enforcement and several central banks. Join us to see how it was done on Thursday, September 10th, 8am PST / 11am EST.
Save your seat: https://thn.news/dark-web-currency
Our Threat Intelligence Lab spent nine days inside the operation. What looked like a thriving criminal market was mostly theater: fake escrow protections, recycled Bitcoin addresses, and "independent" vendors running on shared infrastructure.
No transactions. No exploits. Exposed endpoints were reported, not touched. Findings are now with law enforcement and several central banks. Join us to see how it was done on Thursday, September 10th, 8am PST / 11am EST.
Save your seat: https://thn.news/dark-web-currency
π₯4
This media is not supported in your browser
VIEW IN TELEGRAM
β οΈ A planted ChatGPT instruction could relay connected Gmail data to another ChatGPT account.
Check Point demonstrated the hidden transfer through shared Artifactory metadata. OpenAI has retired the service behind the channel.
Here's how the transfer worked: https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html
Check Point demonstrated the hidden transfer through shared Artifactory metadata. OpenAI has retired the service behind the channel.
Here's how the transfer worked: https://thehackernews.com/2026/09/chatgpt-flaw-let-planted-prompt-send.html
π4π1π±1
Chainguard doubled container build output to 1B+ manifests in six months.
Factory 2.0 continuously reconciles CVEs and upstream changes, using AI for judgment-heavy tasks such as backporting fixes while structured tools verify the work.
How the reconciliation loop works: https://thehackernews.com/2026/09/what-it-took-to-reach-1-billion-build.html
Factory 2.0 continuously reconciles CVEs and upstream changes, using AI for judgment-heavy tasks such as backporting fixes while structured tools verify the work.
How the reconciliation loop works: https://thehackernews.com/2026/09/what-it-took-to-reach-1-billion-build.html
βΌοΈ Liquid hackers returned 3,400 of nearly 4,000 BTC taken using L-BTC created by an Elements bug.
Another 598.5 BTC, worth about $47M, remains at the source address after on-chain exchanges with Blockstream, including an encrypted message.
Neither side has said whether it was part of a deal.
Read: https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html
Another 598.5 BTC, worth about $47M, remains at the source address after on-chain exchanges with Blockstream, including an encrypted message.
Neither side has said whether it was part of a deal.
Read: https://thehackernews.com/2026/09/liquid-hackers-return-3400-bitcoin.html
π5π€―5π±3π1π€1
Engineering absorbs the extra sprint work that EU CRA compliance will require.
That means SBOM coverage, provenance, and remediation records on demand. See where your team's current processes land in comparison to regulation requirements
Take The 5 Minute Assessment: https://thn.news/cra-engineering-teams
That means SBOM coverage, provenance, and remediation records on demand. See where your team's current processes land in comparison to regulation requirements
Take The 5 Minute Assessment: https://thn.news/cra-engineering-teams
π€2
β οΈ Slim Spider stole the secrets controlling crypto assets at a Brazilian financial institution.
The group also abused Azure DevOps to deploy Kubernetes implants and built tooling for bulk unauthorized Pix transfers.
Read the full story: https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html
The group also abused Azure DevOps to deploy Kubernetes implants and built tooling for bulk unauthorized Pix transfers.
Read the full story: https://thehackernews.com/2026/09/slim-spider-steals-crypto-custody.html
π4π3π₯2
β οΈ N-able says CVE-2026-86218 is being exploited in the wild. The CVSS 10.0 N-central flaw can enable pre-auth RCE.
CISA added it to KEV, while Huntress is probing a separate N-central compromise where the exploit used remains unconfirmed.
Read: https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html
CISA added it to KEV, while Huntress is probing a separate N-central compromise where the exploit used remains unconfirmed.
Read: https://thehackernews.com/2026/09/n-able-n-central-pre-auth-rce-flaw.html
π₯3
βΌοΈ Two Windows zero-days are being exploited in the wild.
Microsoft patched them alongside a record 974 vulnerabilities. Both flaws can let authorized attackers elevate privileges locally to SYSTEM, and CISA has added them to its KEV catalog.
Read: https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html
Microsoft patched them alongside a record 974 vulnerabilities. Both flaws can let authorized attackers elevate privileges locally to SYSTEM, and CISA has added them to its KEV catalog.
Read: https://thehackernews.com/2026/09/microsoft-patches-record-974-flaws.html
π5π₯3
β οΈ Days after Microsoft shipped the ShieldBreak fix, a new PoC shows the flaw can still be triggered under specific conditions.
Dubbed ShieldCrash, the bypass demonstrates arbitrary file read as SYSTEM on the latest Windows version.
Read: https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html
Dubbed ShieldCrash, the bypass demonstrates arbitrary file read as SYSTEM on the latest Windows version.
Read: https://thehackernews.com/2026/09/researcher-drops-new-microsoft-defender.html
π5π₯2π1
π¨ Malware linked to F5 BIG-IP APM break-ins hides a PHP web shell in memory while targeted scripts can remain clean on disk.
Sophos found the implant alters what PHP sees when Apache loads those files, helping explain why file checks can miss it.
Read: https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html
Sophos found the implant alters what PHP sees when Apache loads those files, helping explain why file checks can miss it.
Read: https://thehackernews.com/2026/09/f5-big-ip-apm-malware-injects-php-web.html
π₯2
βΌοΈWarning: New CVE-2026-67401 vulnerability in cPanel lets mail-privileged hosting accounts execute code as root.
cPanel says every supported cPanel & WHM version is affected and has released fixed builds.
Read details here: https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html
cPanel says every supported cPanel & WHM version is affected and has released fixed builds.
Read details here: https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account.html
π₯2