2026

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers 2026-09-22 at 14:55 By Ionut Arghire A Chinese threat actor has exploited the bug to exfiltrate sensitive information from nearly 1,000 ZyXEL switches. The post Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Recent ZyXEL Switch Vulnerability Exploited by Chinese Hackers Read More »

DORA Year Two: Can Your SOC Actually See the Attack?

DORA Year Two: Can Your SOC Actually See the Attack? 2026-09-22 at 14:45 By When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and documenting incident escalation […]

DORA Year Two: Can Your SOC Actually See the Attack? Read More »

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory 2026-09-22 at 14:38 By A new flaw in the Linux kernel’s KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows […]

New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory Read More »

Malicious B-tree NPM Package Accumulates Millions of Downloads

Malicious B-tree NPM Package Accumulates Millions of Downloads 2026-09-22 at 14:33 By Ionut Arghire Posing as the legitimate sorted-btree package, indexed-btree hides a malware trigger in its prototype method. The post Malicious B-tree NPM Package Accumulates Millions of Downloads appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

Malicious B-tree NPM Package Accumulates Millions of Downloads Read More »

ECB to put its own money into tokenized securities via new Pontes DLT

ECB to put its own money into tokenized securities via new Pontes DLT 2026-09-22 at 14:29 By Cointelegraph by Yohan Yun The ECB aims to gain firsthand DLT market experience by buying tokenized public-sector securities and settling the trades through Pontes. This article is an excerpt from Cointelegraph.com News View Original Source

ECB to put its own money into tokenized securities via new Pontes DLT Read More »

ECB, EU cenbanks seek changes in MiCA’s minimum bank deposit for stablecoins

ECB, EU cenbanks seek changes in MiCA’s minimum bank deposit for stablecoins 2026-09-22 at 14:22 By Cointelegraph by Helen Partz The ECB and EU central banks want to replace MiCA’s stablecoin bank-deposit requirements with liquidity thresholds, warning that sudden withdrawals could strain lenders. This article is an excerpt from Cointelegraph.com News View Original Source

ECB, EU cenbanks seek changes in MiCA’s minimum bank deposit for stablecoins Read More »

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE 2026-09-22 at 14:17 By A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, […]

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE Read More »

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273)

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) 2026-09-22 at 13:42 By Zeljka Zorz A Chinese-speaking threat actor has exploited a vulnerability (CVE-2026-7273) in unpatched ZyXEL GS1900 Smart Managed Switches and has exfiltrated sensitive data from 996 devices across 48 countries, GreyNoise reported on Monday. The affected switches are predominantly located in Italy, the […]

Attacker compromised nearly 1000 Zyxel switches since August (CVE-2026-7273) Read More »

Somewhere in your traffic logs, a bot is doing more than looking

Somewhere in your traffic logs, a bot is doing more than looking 2026-09-22 at 13:30 By Mirko Zorz Akamai has watched verified AI crawlers, ChatGPT among them, move from reading web pages to sending high-frequency POST requests. In a 30-day analysis of its global customers, ecommerce accounted for 44.8% of those AI bot POST transactions, […]

Somewhere in your traffic logs, a bot is doing more than looking Read More »

WordPress Patches ‘Click2Shell’ Vulnerability

WordPress Patches ‘Click2Shell’ Vulnerability 2026-09-22 at 13:22 By Ionut Arghire The bug lets attackers automatically install and preview themes and could lead to remote code execution. The post WordPress Patches ‘Click2Shell’ Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek View Original Source

WordPress Patches ‘Click2Shell’ Vulnerability Read More »

Crypto metric signals altseason as Bitcoin market-cap share stalls below 60%

Crypto metric signals altseason as Bitcoin market-cap share stalls below 60% 2026-09-22 at 13:00 By Cointelegraph by William Suberg Glassnode’s Altcoin Cycle Signal printed a new altseason signal after a month of Bitcoin and altcoin market-cap gains. This article is an excerpt from Cointelegraph.com News View Original Source

Crypto metric signals altseason as Bitcoin market-cap share stalls below 60% Read More »

Crypto market cap reclaims $3 trillion as Bitcoin, altcoins rally

Crypto market cap reclaims $3 trillion as Bitcoin, altcoins rally 2026-09-22 at 12:58 By Cointelegraph by Ezra Reguerra Bitcoin traded near $86,000 as major altcoins gained, while rising derivatives leverage pointed to growing speculative activity across crypto markets. This article is an excerpt from Cointelegraph.com News View Original Source

Crypto market cap reclaims $3 trillion as Bitcoin, altcoins rally Read More »

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions 2026-09-22 at 11:54 By Sinisa Markovic Scammers are using a $249 website toolkit to sell unverified AI subscriptions worth up to $2,000 a year, and a genuine Google sign-in screen is what makes the sites convincing. Malwarebytes found more than 100 websites built this […]

Scammers use genuine Google sign-ins to sell costly, unverified AI subscriptions Read More »

Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme

Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme 2026-09-22 at 11:37 By Eduard Kovacs The US, Japan, Germany and Australia have published a joint report detailing the scope of North Korea’s WaterPlum campaign. The post Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme […]

Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme Read More »

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing 2026-09-22 at 10:52 By The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. “SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious […]

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing Read More »

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor 2026-09-22 at 09:33 By Malware already running on a Mac can quietly take over Meta’s Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works […]

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor Read More »

A cheap fake base station can still track 5G subscribers

A cheap fake base station can still track 5G subscribers 2026-09-22 at 09:30 By Anamarija Pogorelec Researchers from the i2CAT Foundation, the University of Murcia, and NEC Laboratories Europe built a low-cost tool called 5G-Shark that lures a target phone onto a fake base station and questions it, then used it to audit commercial 5G […]

A cheap fake base station can still track 5G subscribers Read More »

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session 2026-09-22 at 09:03 By A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site’s server. […]

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session Read More »

Scroll to Top