2026

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware 2026-09-25 at 18:57 By Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below – actions-cool/issues-helper […]

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware Read More »

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence 2026-09-25 at 18:57 By Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation […]

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence Read More »

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure 2026-09-25 at 18:07 By SecurityWeek News Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul. The post In Other News: Clop Leak Site Takeover, Docker […]

In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure Read More »

North Korea Suspected in $351 Million Bitget Crypto Heist

North Korea Suspected in $351 Million Bitget Crypto Heist 2026-09-25 at 17:16 By Eduard Kovacs Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen. The post North Korea Suspected in $351 Million Bitget Crypto Heist appeared first on SecurityWeek. This article is an […]

North Korea Suspected in $351 Million Bitget Crypto Heist Read More »

SlowMist has yet to confirm crypto theft from iPhone Safari attack

SlowMist has yet to confirm crypto theft from iPhone Safari attack 2026-09-25 at 16:05 By Cointelegraph by Helen Partz The analyzed Safari sample targets iOS 18.4–18.6.2 using previously patched flaws, while its effectiveness on iOS 26.5 remains unverified. This article is an excerpt from Cointelegraph.com News View Original Source

SlowMist has yet to confirm crypto theft from iPhone Safari attack Read More »

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks 2026-09-25 at 15:39 By Eduard Kovacs Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July.  The post CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks Read More »

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court 2026-09-25 at 15:16 By Ionut Arghire Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services. The post Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court appeared first on SecurityWeek. This article is an excerpt from […]

Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court Read More »

Threat detection dashboards are masking security coverage gaps

Threat detection dashboards are masking security coverage gaps 2026-09-25 at 15:04 By Sinisa Markovic A detection rule can show up as deployed on a coverage dashboard and still never fire when an attacker uses the technique it was built to catch. Conifers assessed 14,652 detections in its customer base, including rules written by customers and […]

Threat detection dashboards are masking security coverage gaps Read More »

Windows, Linux, Android File Notification Systems Leak User Activity

Windows, Linux, Android File Notification Systems Leak User Activity 2026-09-25 at 13:53 By Eduard Kovacs Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events. The post Windows, Linux, Android File Notification Systems Leak User Activity appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original […]

Windows, Linux, Android File Notification Systems Leak User Activity Read More »

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise 2026-09-25 at 13:35 By Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.  “At 18:31 UTC on September 24, 2026, Bitget’s security systems identified unauthorized transfers involving a limited number of hot wallets,” BitGet […]

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise Read More »

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild 2026-09-25 at 13:14 By The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail […]

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild Read More »

Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data

Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data 2026-09-25 at 13:00 By A flaw in Cloudflare Containers let a paying customer read data that other customers’ containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space […]

Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data Read More »

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV 2026-09-25 at 13:00 By The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are listed […]

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV Read More »

Magic Eden scare puts 3,832 NFTs in whitehat protective custody

Magic Eden scare puts 3,832 NFTs in whitehat protective custody 2026-09-25 at 12:48 By Cointelegraph by Ezra Reguerra Yuga Labs’ 0xQuit said the NFTs are safe and will be returned once the risk passes, while holders were urged to revoke NFT permissions. This article is an excerpt from Cointelegraph.com News View Original Source

Magic Eden scare puts 3,832 NFTs in whitehat protective custody Read More »

Scroll to Top