# Today's Top Stories
September 17, 2026
-
1The Hacker News general Sep 16Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
Mandiant documented a case where an attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider, used it to recommend poisoned software packages, then spread the Shai-Hulud worm across approximately 100 internal code repositories, stealing secrets and source code. This represents a novel supply-chain attack vector where AI coding assistants become both the initial access vector and the propagation mechanism, a significant concern for organizations that have integrated AI pair programmers into development workflows.
-
2The Hacker News general Sep 16Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
CVE-2026-5430 (CVSS 9.8), a critical JWT authentication bypass in WSO2 API Manager that allows forged admin tokens via improper cryptographic signature verification, is under active exploitation in the wild, as confirmed by watchTowr. Attackers with forged admin tokens can gain full control of enterprise API management infrastructure, making immediate patching essential for any organization running WSO2 API Manager.
-
3The Hacker News general Sep 16Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google patched CVE-2026-58704 (CVSS 8.0), a privilege escalation flaw in the Pixel Cellular Modem caused by a logic error enabling permission bypass, in its September 15 security bulletin covering 110 vulnerabilities for Pixel devices. The vulnerability has been confirmed exploited in limited, targeted attacks in the wild, making prompt patching critical for Pixel device users in high-risk environments.
-
4The Hacker News general Sep 16One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
Security researchers at Forever Security demonstrated that a single malicious browser extension can hijack the built-in AI assistants across five Chromium-based products simultaneously: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude for Chrome extension. The BragJack attack class allows the extension to execute actions, access sensitive data, and exfiltrate information through the AI assistant's elevated permissions with a single click post-installation.
-
5BleepingComputer general Sep 16Critical ScreenConnect flaw now actively exploited in attacks
CISA confirmed active exploitation of a critical-severity vulnerability in ConnectWise ScreenConnect, the widely deployed remote access platform used by MSPs and enterprise IT teams globally. Security practitioners managing ScreenConnect deployments should treat this as an emergency patching priority given the product's privileged access to endpoint environments.
-
ADSponsoredProtect Your Business
Expert cybersecurity solutions to safeguard your organization from evolving threats.
Get Protected → -
6The Hacker News general Sep 16Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
CVE-2026-87886 (CVSS 7.8), a local privilege escalation flaw in Acronis Backup plugin for cPanel, WHM, and Plesk caused by insecure file permissions on Linux systems, has been confirmed actively exploited in targeted attacks. Web hosting providers and managed service providers running Acronis cPanel backup integrations are at direct risk and should apply available patches immediately.
-
7BleepingComputer general Sep 16Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
US, UK, and Dutch government agencies jointly published a report exposing CHOSEN BRICK, a Windows malware strain used by Iranian state-linked threat actors to surveil dissidents, activists, and journalists worldwide, with the FBI specifically detailing abuse of Telegram as the command-and-control channel. The advisory provides actionable indicators for defenders protecting high-risk individuals and organizations targeted by Iranian intelligence operations.
-
8SecurityWeek general Sep 16Chrome, Firefox Updates Patch 115 Vulnerabilities
Google patched 42 security defects in Chrome while Mozilla fixed 73 bugs in Firefox, totaling 115 vulnerabilities addressed across the two dominant browsers in a single release cycle. Security teams should prioritize browser update enforcement across managed endpoints, particularly for organizations where browser-based attacks are a primary threat vector.
-
9SecurityWeek general Sep 15Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data
Texas electric and gas utility CenterPoint Energy confirmed a data breach after a hacker posted and leaked data on the dark web, claiming theft of 7.5 million customer records including personal information. The breach of critical infrastructure customer data warrants attention from practitioners focused on utility sector security and third-party data exposure risks.
-
10SecurityWeek general Sep 16Oracle Patches 800+ Vulnerabilities in September 2026 Security Update
Oracle's September 2026 Critical Patch Update resolves over 800 vulnerabilities across 17 product families, including more than 100 classified as critical severity. The sheer volume and breadth across Oracle's product portfolio — spanning database, middleware, cloud, and enterprise applications — demands immediate triage by security teams with Oracle deployments in their environments.