ICYMI: 2026-09-18
Latest Headlines
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents
WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
Meta’s Copyright System Is Being Weaponized Against Albanian Protesters
In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw
AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code
NightmareStresser DDoS Service Disrupted in International Operation
Brevo Supply Chain Attack Injects Malware Into 100,000 Websites
Check Point, Kaspersky, Tanium Patch Product Vulnerabilities
Critical Microsoft Azure AI Foundry Vulnerability Allows Attackers to Escalate Privileges
Feral Wolf Ransomware Attacks Exploit Atlassian Confluence and Misconfigured 1C Systems
New SETTRA Ransomware Uses MeshAgent RMM and BYOVD to Encrypt Windows Systems
AI Agents Now Run Ransomware Attacks End-to-End Without Human Operators
Linux Kernel Hit by Four Privilege Escalation Flaws Enabling Root Access
Hackers Impersonate ChatGPT Subscription Alerts to Steal OpenAI Account Credentials
Tutor LMS Flaw Exposes 100,000+ WordPress Sites to Remote Code Execution
Chrome 153 Patches 16 Security Vulnerabilities Including Critical Dawn and WebGL Flaws
Android Apps Can Now Check If Your Phone Is Missing Critical Security Patches
MikroTrick Attack Lets Hackers Gain Full Admin Control of MikroTik Routers Without Login
Gyazo server flaw exploited to steal 23.6 million user records
Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
Secure enterprise sharing with access reviews for Microsoft 365
Microsoft Teams will let admins block custom file extensions
Webinar: Which Google Workspace security controls actually matter?
Microsoft fixes bug behind ‘Defender Antivirus is turned off’ alerts
New Check Point flaw lets hackers execute code with root privileges
– MTZ