ICYMI: 2026-09-15
Latest Headlines
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
BambooToken Malware Uses MQTT to Control Windows and Linux Systems
Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server
Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution
China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
“We Think the Security Control Is Working” Is No Longer Good Enough
Exein Secures $270M at $1.7B Valuation for Physical AI Security
Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data
OpenAI Investigates Report Linking AI Agents to RubyGems Attack
Apple Patches 200 Vulnerabilities With New iOS 27, macOS Golden Gate 27 Releases
Microsoft AI Code of Conduct Sets Cyberattack Boundaries, Chain of Command, Safety Constraints
CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse
CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments
Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices
How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap
Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access
Hackers Advertise Uncensored Luciferus AI Service on Underground Forums
CISA Warns of Cisco Secure Email Gateway 0-Day Vulnerability Actively Exploited in Attacks
Japan’s Digital Agency Breach Exposes 240,000+ Users’ Personal Records to Hackers
Homebrew 7.0.0 Adds Built-In Vulnerability Scanner and Stronger Package Sandboxing
cPanel LiteSpeed Web Server Vulnerability Allows Shared Server Users to Gain Root-Level Access
Acronis warns of actively exploited flaw in its cPanel backup plugin
Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
CenterPoint Energy confirms customer data stolen in cyberattack
BambooToken malware controls Windows and Linux systems via MQTT
Hackers target WordPress sites via third-party WooCommerce plugin
CISA: Critical VMware RCE flaw now exploited by ransomware gangs
Suspected Black Axe gang leaders face cybercrime charges in the US
Microsoft confirms KB5002914 Excel update breaks copy and paste
Cisco patches Secure Email Gateway zero-day exploited in attacks
– MTZ