[{"id":775,"source_name":"BleepingComputer","title":"Placeholder domain used in dev docs now serves ClickFix attacks","summary":"The \"third-party.com\" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. [...]","url":"https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-serves-clickfix-attacks/","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T22:46:01","created_at":"2026-09-24T01:00:23.528546"},{"id":776,"source_name":"BleepingComputer","title":"New RemControl Android banking malware targets users in Europe and Canada","summary":"A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]","url":"https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada/","category":"banking","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T21:25:13","created_at":"2026-09-24T01:00:23.528552"},{"id":777,"source_name":"BleepingComputer","title":"Check Point warns of hackers exploiting Security Gateway VPN RCE flaw","summary":"Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]","url":"https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/","category":"other","risk_level":"high","thumbnail_url":null,"published_at":"2026-09-23T19:53:54","created_at":"2026-09-24T01:00:23.528556"},{"id":767,"source_name":"BleepingComputer","title":"Hackers start exploiting critical WordPress flaw for code execution","summary":"Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]","url":"https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/","category":"other","risk_level":"high","thumbnail_url":null,"published_at":"2026-09-23T18:31:22","created_at":"2026-09-23T19:00:23.416818"},{"id":778,"source_name":"The Hacker News","title":"Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry","summary":"Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.\n\nAccording to Aikido, the list of Terraform providers and Go modules is below -\n\n\n  gocommunity-io/dockerd (222 downloads)\n  kreuzwenker/","url":"https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html","category":"malware","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T18:06:30","created_at":"2026-09-24T01:00:24.903255"},{"id":771,"source_name":"The Hacker News","title":"A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You","summary":"The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you.\n\nGitLab shows each user this address behind a button labeled \"Email work item to this project.\" Mail sent to it opens an issue in that project, authored","url":"https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html","category":"email","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T16:53:10","created_at":"2026-09-23T19:00:24.850105"},{"id":768,"source_name":"BleepingComputer","title":"Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers","summary":"A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]","url":"https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T16:20:54","created_at":"2026-09-23T19:00:23.416823"},{"id":772,"source_name":"The Hacker News","title":"MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key","summary":"Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.\n\nThe chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at","url":"https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T16:06:41","created_at":"2026-09-23T19:00:24.850110"},{"id":769,"source_name":"BleepingComputer","title":"InfraTrust report warns network management systems under attack","summary":"Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]","url":"https://www.bleepingcomputer.com/news/security/infratrust-report-warns-network-management-systems-under-attack/","category":"other","risk_level":"high","thumbnail_url":null,"published_at":"2026-09-23T14:35:26","created_at":"2026-09-23T19:00:23.416828"},{"id":773,"source_name":"The Hacker News","title":"This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move","summary":"A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server,&nbsp;Cisco Talos said&nbsp;on September 22.\n\nThe models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.","url":"https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html","category":"malware","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T14:17:58","created_at":"2026-09-23T19:00:24.850114"},{"id":770,"source_name":"BleepingComputer","title":"How One Kubernetes YAML Can Hand Over a GCP Organization","summary":"A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. [...]","url":"https://www.bleepingcomputer.com/news/security/how-one-kubernetes-yaml-can-hand-over-a-gcp-organization/","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T14:01:11","created_at":"2026-09-23T19:00:23.416833"},{"id":774,"source_name":"The Hacker News","title":"Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI","summary":"Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.\n\nAccording to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below -\n\n\n  @memtensor/memos-cloud-openclaw-plugin versions","url":"https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T13:52:46","created_at":"2026-09-23T19:00:24.850119"},{"id":756,"source_name":"BleepingComputer","title":"Arista patches actively exploited VeloCloud Orchestrator zero-day","summary":"Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. [...]","url":"https://www.bleepingcomputer.com/news/security/arista-patches-actively-exploited-velocloud-orchestrator-zero-day/","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T12:29:53","created_at":"2026-09-23T13:00:23.381364"},{"id":760,"source_name":"The Hacker News","title":"New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control","summary":"A flaw in cPanel's&nbsp;CalDAV and CardDAV service&nbsp;lets anyone with a cPanel hosting account run code as root and take \"full control of the server,\" the company said on September 22.\n\nA&nbsp;second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.\n\ncPanel has released fixed versions for both,","url":"https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T12:16:00","created_at":"2026-09-23T13:00:24.153122"},{"id":761,"source_name":"The Hacker News","title":"545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent","summary":"Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security background then sits down and checks every claim against the target. Which findings are real,","url":"https://thehackernews.com/2026/09/545-hackers-tested-it-first-now-xranges.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T11:47:19","created_at":"2026-09-23T13:00:24.153127"},{"id":762,"source_name":"The Hacker News","title":"Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests","summary":"Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior.\n\nOpus 5.5, per Anthropic, is a \"major step up from Opus 5,\" and \"achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands","url":"https://thehackernews.com/2026/09/anthropic-and-openai-models-still.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T11:47:13","created_at":"2026-09-23T13:00:24.153131"},{"id":757,"source_name":"BleepingComputer","title":"Microsoft: September Windows updates break Always On VPN connections","summary":"Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. [...]","url":"https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T11:18:13","created_at":"2026-09-23T13:00:23.381369"},{"id":763,"source_name":"The Hacker News","title":"Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape","summary":"A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst&nbsp;said in research published September 22.\n\nThe flaw, tracked as&nbsp;CVE-2026-80521&nbsp;(CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst&nbsp;","url":"https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html","category":"other","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T11:12:18","created_at":"2026-09-23T13:00:24.153136"},{"id":764,"source_name":"The Hacker News","title":"F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers","summary":"Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.\n\nThe flaw,&nbsp;CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in&nbsp;an advisory&nbsp;on September 22 and has released engineering hotfixes.","url":"https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html","category":"other","risk_level":"high","thumbnail_url":null,"published_at":"2026-09-23T08:29:48","created_at":"2026-09-23T13:00:24.153140"},{"id":765,"source_name":"The Hacker News","title":"Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware","summary":"A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.\n\nThe attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break","url":"https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html","category":"malware","risk_level":"medium","thumbnail_url":null,"published_at":"2026-09-23T08:29:24","created_at":"2026-09-23T13:00:24.153145"}]