Latest Cybersecurity News and Articles


Chrome, Firefox Updates Patch 115 Vulnerabilities

16 September 2026
Google resolved 42 security defects in Chrome, and Mozilla fixed 73 bugs in Firefox. The post Chrome, Firefox Updates Patch 115 Vulnerabilities appeared first on SecurityWeek.

Acronis Patches Exploited Vulnerability in cPanel Backup Plugin

16 September 2026
CVE-2026-87886 is a high-severity insecure file permissions flaw that can lead to local privilege escalation. The post Acronis Patches Exploited Vulnerability in cPanel Backup Plugin appeared first on SecurityWeek.

Enterprises Warned of Attacks Exploiting WSO2 Vulnerability

16 September 2026
The vulnerability, tracked as CVE-2026-5430, can be exploited to gain access to valuable enterprise data. The post Enterprises Warned of Attacks Exploiting WSO2 Vulnerability appeared first on SecurityWeek.

Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

16 September 2026
The security updates resolve over 800 vulnerabilities across 17 product families, including over 100 critical-severity flaws. The post Oracle Patches 800+ Vulnerabilities in September 2026 Security Update appeared first on SecurityWeek.

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

16 September 2026
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over

Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

16 September 2026
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication

Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?

15 September 2026
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers. The post Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow? appeared first on SecurityWeek.

“We Think the Security Control Is Working” Is No Longer Good Enough

15 September 2026
Point-in-time audits and sampled assessments offer only snapshots; continuous control monitoring provides evidence that security controls are working today. The post “We Think the Security Control Is Working” Is No Longer Good Enough appeared first on SecurityWeek.

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

15 September 2026
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

15 September 2026
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record

$1 Million Sandbox Challenge Uncovers Linux Kernel Flaws

15 September 2026
AI-assisted researchers flooded Vercel with reports, forcing the company to automate vulnerability triage. The post $1 Million Sandbox Challenge Uncovers Linux Kernel Flaws appeared first on SecurityWeek.

Exein Secures $270M at $1.7B Valuation for Physical AI Security

15 September 2026
The cybersecurity startup is building a proprietary foundation model and plans to accelerate global expansion. The post Exein Secures $270M at $1.7B Valuation for Physical AI Security appeared first on SecurityWeek.

Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

15 September 2026
A hacker claims to have stolen 7.5 million customer records after breaching the company’s systems. The post Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data appeared first on SecurityWeek.

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

15 September 2026
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.

Thai Broadband Provider Hacked via Fortinet Vulnerability

15 September 2026
The hackers staged numerous scripts for reconnaissance and CVE probing, along with brute-force utilities and privilege escalation tools. The post Thai Broadband Provider Hacked via Fortinet Vulnerability appeared first on SecurityWeek.

OpenAI Investigates Report Linking AI Agents to RubyGems Attack

15 September 2026
The incident occurred in May, when RubyGems maintainers suspended new account registrations due to what appeared like malicious activity. The post OpenAI Investigates Report Linking AI Agents to RubyGems Attack appeared first on SecurityWeek.

UK and allies expose spyware used by Iranian state actors to target dissidents, activists and journalists

15 September 2026
UK and allies provide advice to help organisations and individuals at risk detect and counter the threat from CHOSEN BRICK malware.

Iranian cyber targeting of dissidents, activists and journalists

15 September 2026
Advisory on CHOSEN BRICK malware, including technical analysis and advice to help individuals and organisations protect themselves.

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

15 September 2026
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access. In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH

240,000 Hit by Data Breach at Japan’s Digital Agency

15 September 2026
Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people. The post 240,000 Hit by Data Breach at Japan’s Digital Agency appeared first on SecurityWeek.