ICYMI: 2026-09-22
Latest Headlines
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
A New Tool Found Malware That’s Guided by an AI Hive Mind—No Humans in Sight
Nightmare Eclipse Drops New Microsoft Defender Exploit After Revealing Identity
Only 13% of OT Network Segments Are Fully Isolated: Analysis
Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers
Malicious B-tree NPM Package Accumulates Millions of Downloads
Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
US Proposes AI Incident Alert System in Talks With China, Bessent Says
Check Point Management Server 0-Day Vulnerability Actively Exploited in Attacks
Scaling SOC Capabilities: How Threat Intelligence Cuts Triage Time and Burnout
Autonomous AI Agents Hack Retailers for $25 and Steal 600,000 Credit Cards
CAIRN – A New Tool to Track AI Malware That Operates Without Human Control
Microsoft SharePoint Flaw Lets Attackers Execute Code Remotely With Low Privileges
New TASK#STOMP Backdoor Uses PowerShell to Steal Documents and Wi-Fi Passwords
Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access
Veeam Agent Flaw Actively Exploited to Gain SYSTEM Privileges on Windows
Red Hat OpenShift Flaw Lets Attackers Bypass PGP Checks and Push Malicious Releases
Rogue external MFA providers can steal passwords during logins
Sweden fines Miljödata $183,000 over breach affecting 2.2 million
Chinese hackers exploit WordPress, Zyxel flaws to steal govt data
ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
New ClosedQuorum Windows malware uses AI for attack decisions
Check Point warns of Management Server zero-day exploited in attacks
EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
Webinar tomorrow: Inside real-world Google Workspace breaches
D-Link warns of max severity zero-day bug in DIR-822A routers
New Windows Defender zero-day blocks Microsoft antivirus updates
CISA orders feds to patch Zyxel flaw exploited for data theft
– MTZ