# Today's Top Stories

September 17, 2026

  1. 1
    0
    The Hacker News general Sep 16
    Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

    Mandiant documented a case where an attacker hijacked an active AI coding-assistant session at an unnamed SaaS provider, used it to recommend poisoned software packages, then spread the Shai-Hulud worm across approximately 100 internal code repositories, stealing secrets and source code. This represents a novel supply-chain attack vector where AI coding assistants become both the initial access vector and the propagation mechanism, a significant concern for organizations that have integrated AI pair programmers into development workflows.

  2. 2
    0
    The Hacker News general Sep 16
    Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

    CVE-2026-5430 (CVSS 9.8), a critical JWT authentication bypass in WSO2 API Manager that allows forged admin tokens via improper cryptographic signature verification, is under active exploitation in the wild, as confirmed by watchTowr. Attackers with forged admin tokens can gain full control of enterprise API management infrastructure, making immediate patching essential for any organization running WSO2 API Manager.

  3. 3
    0
    The Hacker News general Sep 16
    Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

    Google patched CVE-2026-58704 (CVSS 8.0), a privilege escalation flaw in the Pixel Cellular Modem caused by a logic error enabling permission bypass, in its September 15 security bulletin covering 110 vulnerabilities for Pixel devices. The vulnerability has been confirmed exploited in limited, targeted attacks in the wild, making prompt patching critical for Pixel device users in high-risk environments.

  4. 4
    0
    The Hacker News general Sep 16
    One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude

    Security researchers at Forever Security demonstrated that a single malicious browser extension can hijack the built-in AI assistants across five Chromium-based products simultaneously: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon, and the Claude for Chrome extension. The BragJack attack class allows the extension to execute actions, access sensitive data, and exfiltrate information through the AI assistant's elevated permissions with a single click post-installation.

  5. 5
    0
    BleepingComputer general Sep 16
    Critical ScreenConnect flaw now actively exploited in attacks

    CISA confirmed active exploitation of a critical-severity vulnerability in ConnectWise ScreenConnect, the widely deployed remote access platform used by MSPs and enterprise IT teams globally. Security practitioners managing ScreenConnect deployments should treat this as an emergency patching priority given the product's privileged access to endpoint environments.

  6. 6
    0
    The Hacker News general Sep 16
    Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

    CVE-2026-87886 (CVSS 7.8), a local privilege escalation flaw in Acronis Backup plugin for cPanel, WHM, and Plesk caused by insecure file permissions on Linux systems, has been confirmed actively exploited in targeted attacks. Web hosting providers and managed service providers running Acronis cPanel backup integrations are at direct risk and should apply available patches immediately.

  7. 7
    0
    BleepingComputer general Sep 16
    Iranian hackers use CHOSEN BRICK Windows malware to spy on targets

    US, UK, and Dutch government agencies jointly published a report exposing CHOSEN BRICK, a Windows malware strain used by Iranian state-linked threat actors to surveil dissidents, activists, and journalists worldwide, with the FBI specifically detailing abuse of Telegram as the command-and-control channel. The advisory provides actionable indicators for defenders protecting high-risk individuals and organizations targeted by Iranian intelligence operations.

  8. 8
    0
    SecurityWeek general Sep 16
    Chrome, Firefox Updates Patch 115 Vulnerabilities

    Google patched 42 security defects in Chrome while Mozilla fixed 73 bugs in Firefox, totaling 115 vulnerabilities addressed across the two dominant browsers in a single release cycle. Security teams should prioritize browser update enforcement across managed endpoints, particularly for organizations where browser-based attacks are a primary threat vector.

  9. 9
    0
    SecurityWeek general Sep 15
    Texas Utility CenterPoint Energy Confirms Breach After Hacker Leaks Data

    Texas electric and gas utility CenterPoint Energy confirmed a data breach after a hacker posted and leaked data on the dark web, claiming theft of 7.5 million customer records including personal information. The breach of critical infrastructure customer data warrants attention from practitioners focused on utility sector security and third-party data exposure risks.

  10. 10
    0
    SecurityWeek general Sep 16
    Oracle Patches 800+ Vulnerabilities in September 2026 Security Update

    Oracle's September 2026 Critical Patch Update resolves over 800 vulnerabilities across 17 product families, including more than 100 classified as critical severity. The sheer volume and breadth across Oracle's product portfolio — spanning database, middleware, cloud, and enterprise applications — demands immediate triage by security teams with Oracle deployments in their environments.