ICYMI: 2026-09-07
Latest Headlines
PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
Your Cloud Security Checklist Doesn’t Work the Way You Think It Does
Rogue ScreenConnect Clients Spread Four-Stage VBScript Chain to Newly Connected Hosts
Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released
N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw
JSCeal Malware Can Bypass Google Authentication Using Stolen Session Cookies
Nightmare Eclipse Drops CrowdStrike, Nvidia, Avast Zero-Day Exploits
Bimbo Bakeries USA Confirms Data Breach in Oracle EBS Zero-Day Attack
Linux Rootkit Injects Fileless PHP Web Shells Into Compromised F5 BIG-IP Servers
Online Maths Learning Platform Mathspace Disclosed Data Breach Impacts 1 Million Users
Switzerland Moves Away From Microsoft 365 to Open-Source Alternatives
Hackers Abuse Trusted Google Services to Hide Credential-Stealing Phishing Attacks
Natural Resources Wales Exposes Sensitive Employee Data in Spreadsheet Breach
Microsoft to Retire Manifest V2 Extensions and Switch to V3 for Improved Security and Performance
ConnectWise Warns of New ScreenConnect Remote Access Flaw – Released Mitigation Steps
New Linux Bot Hides as Kernel Process and Launches DDoS Attacks
OpenAI Commits $1 Billion to Give Critical Infrastructure Defenders Frontier AI Cyber Tools
Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
Mathspace discloses data breach affecting over 1 million people
ChatGPT can now connect to your personal apps to mimic writing style
Hackers exploit new MikroTik RouterOS flaws to hijack routers
N-able patches max severity N-central flaw amid ongoing attacks
– MTZ