ICYMI: 2026-09-26
Latest Headlines
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
Local AI Model Modifies Windows Credential Dumper to Bypass EDR Detection
OpenAI’s AI Agents Tried Hacking 4 Websites Without Being Prompted
16-Year-Old Researcher Finds Microsoft Auth Vulnerability that Exposes 17.3 Trillion Stored Records
ShinyHunters uses WAF bypass trick in Oracle PeopleSoft attacks
Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer
Microsoft pauses KB5002907 update after Office license deactivations
GitHub Actions re-enabled with Mini Shai-Hulud payload still active
OpenAI’s AI agents accidentally uploaded user-provided images to third-party sites
– MTZ