September 2026

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution 2026-09-18 at 19:56 By WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without […]

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution Read More »

CFTC submits crypto market regulation plan for White House review

CFTC submits crypto market regulation plan for White House review 2026-09-18 at 19:04 By Cointelegraph by Nate Kostar The US commodities regulator submitted a new crypto market regulatory action for White House review days after the Senate failed to advance the CLARITY Act. This article is an excerpt from Cointelegraph.com News View Original Source

CFTC submits crypto market regulation plan for White House review Read More »

Edge Processing Is Quietly Changing Physical Security — Here’s Why It Matters

Edge Processing Is Quietly Changing Physical Security — Here’s Why It Matters 2026-09-18 at 19:00 By Examining edge and cloud processing in detail, including the benefits and trade-offs of each.  This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original Source

Edge Processing Is Quietly Changing Physical Security — Here’s Why It Matters Read More »

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 2026-09-18 at 18:24 By The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the […]

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2 Read More »

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation 2026-09-18 at 17:47 By Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. “Missing authentication […]

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation Read More »

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. 2026-09-18 at 17:47 By In July 2025, someone registered a domain that used to belong to a content delivery network.  The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not […]

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It. Read More »

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents 2026-09-18 at 17:47 By A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed […]

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents Read More »

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw 2026-09-18 at 17:25 By SecurityWeek News Noteworthy stories that might have slipped under the radar: Mandiant’s 2026 AI risk report, PhantomRaven malware used by bug bounty hunter, WordPress plugin bug exploited. The post In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical […]

In Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP Flaw Read More »

The Best Way to Thank Security Officers Is to Give Them the Support They Deserve

The Best Way to Thank Security Officers Is to Give Them the Support They Deserve 2026-09-18 at 16:05 By National Security Officer Appreciation Week is about more than recognition. It’s about giving officers the tools and support they need to succeed. This article is an excerpt from Subscribe to Security Magazine’s RSS Feed View Original […]

The Best Way to Thank Security Officers Is to Give Them the Support They Deserve Read More »

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code 2026-09-18 at 15:45 By Eduard Kovacs Hacktron researchers earned a bug bounty after demonstrating access to OpenAI employee accounts.  The post AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View […]

AI-Built Exploit and Sign-In Flaw Opened Path to Internal OpenAI Code Read More »

23 Million User Records Compromised in Gyazo Data Breach 

23 Million User Records Compromised in Gyazo Data Breach  2026-09-18 at 14:38 By Eduard Kovacs Gyazo maker Helpfeel said the attacker exploited a vulnerability in its image upload server to gain unauthorized access. The post 23 Million User Records Compromised in Gyazo Data Breach  appeared first on SecurityWeek. This article is an excerpt from SecurityWeek […]

23 Million User Records Compromised in Gyazo Data Breach  Read More »

Larry Ellison’s about-face on an Oracle stock sale sparks chatter in Silicon Valley, Hollywood 

Larry Ellison’s about-face on an Oracle stock sale sparks chatter in Silicon Valley, Hollywood  2026-09-18 at 14:00 By Charles Gasparino Was this Ellison being crazy like a fox? This article is an excerpt from Latest Technology News | New York Post View Original Source

Larry Ellison’s about-face on an Oracle stock sale sparks chatter in Silicon Valley, Hollywood  Read More »

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products 2026-09-18 at 13:57 By Eduard Kovacs Microsoft fixed vulnerabilities across Azure and AI-branded products, with privilege escalation flaws accounting for the majority. The post Microsoft Patches 18 Vulnerabilities in AI, Cloud Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Microsoft Patches 18 Vulnerabilities in AI, Cloud Products Read More »

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage 2026-09-18 at 13:40 By Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the […]

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage Read More »

Bots with good manners are better at fooling people on social media

Bots with good manners are better at fooling people on social media 2026-09-18 at 13:15 By Sinisa Markovic Most people can’t tell a bot from a human online, and the bots most likely to fool them are the polite ones, according to a new Surfshark study. The company analyzed 1,722 participants worldwide, testing their ability […]

Bots with good manners are better at fooling people on social media Read More »

Scroll to Top