# Today's Top Stories
September 12, 2026
-
1The Hacker News general Sep 11GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
CVE-2026-85706, a CVSS 10.0 path traversal flaw in GitLab's repository commits API, allows unauthenticated attackers to read arbitrary files from self-managed GitLab servers. Internet-wide probing began within hours of public disclosure, making this an urgent patch priority for any organization running self-hosted GitLab instances.
-
2The Hacker News general Sep 11Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware
Three distinct threat clusters — including ransomware operators and state-sponsored actors — are actively exploiting CVE-2026-20079 (CVSS 10.0), an authentication bypass in Cisco Secure Firewall Management Center, to deploy Qilin ransomware and steal credentials. Cisco and CISA have both issued warnings, and the flaw was originally disclosed in March 2026, meaning unpatched systems have had extended exposure.
-
3The Hacker News general Sep 11Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
Wiz researchers observed attacks between August 15 and September 8 in which threat actors chained two vulnerabilities in JFrog Artifactory to gain administrative control of self-hosted servers and deploy a Rust-based backdoor. Both flaws were patched by JFrog prior to the observed attacks, meaning only unpatched installations were compromised.
-
4BleepingComputer general Sep 10AI-powered attack exploited PaperCut flaws to hack 395 organizations
A likely Russian-speaking threat actor deployed hundreds of AI agents to discover and exploit vulnerabilities in PaperCut NG/MF servers, ultimately compromising 395 organizations globally. PaperCut has since released patched versions 26.0.5, 25.0.13, and 24.1.10 replacing earlier emergency patches for the two actively exploited flaws.
-
5The Hacker News general Sep 11Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic identified and disrupted GTG-20006, a Russian state-sponsored group aligned with Midnight Blizzard, which used Claude to automate malware evasion by rebuilding detected malware variants in near-real-time. The group targeted more than 20 government, intelligence, diplomatic, and defense organizations, representing a significant escalation in AI-assisted offensive operations.
-
ADSponsoredPenetration Testing
Comprehensive security assessments by certified professionals. Find vulnerabilities before attackers do.
Learn More → -
6The Hacker News general Sep 11China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor
China-linked threat group UNC3569 exploited a vulnerability in Sogou Input Method — one of the most widely used Chinese-character input tools on Windows — to deploy the GRAYRABBIT backdoor via a crafted link. Gen Digital published the research on September 11; Tencent owns Sogou, adding supply-chain implications for Chinese-language Windows users worldwide.
-
7SecurityWeek general Sep 10Critical NetScaler Vulnerability Exploited in Attacks
CVE-2026-19490, a critical authentication bypass in Citrix NetScaler, has been actively exploited in the wild since at least September 3, according to SecurityWeek reporting. Organizations running NetScaler ADC or Gateway should treat this as an emergency patching priority given its confirmed in-the-wild exploitation.
-
8BleepingComputer general Sep 11Trezor: 347,000 users targeted in phishing attacks after Brevo breach
Trezor confirmed that 347,000 user email addresses were exposed and 2,500 users clicked malicious links in phishing emails sent after attackers breached the Brevo marketing platform. The attack also affected users of BitBox and CoinTracking, illustrating the downstream risk of third-party email service provider compromises in the cryptocurrency ecosystem.
-
9BleepingComputer general Sep 11Florida confirms DMV database breached via stolen police account
Florida's DAVID driver database was breached after cybercrime group ShinyHunters used credentials stolen from a law enforcement officer's personal device to gain access. The breach of a law enforcement-linked credential store raises serious concerns about BYOD policy enforcement and credential hygiene across public-sector agencies.
-
10The Record threat-intel Sep 11Ukrainian hacker gets four years in US prison over Conti ransomware attacks
Oleksii Oleksiyovych Lytvynenko, a Ukrainian national who joined the Conti ransomware operation in 2021 and participated in attacks on at least 12 companies, was sentenced to four years in a U.S. federal prison. Lytvynenko was arrested in Ireland in 2023; his sentencing marks continued DOJ action against Conti members following the group's 2022 shutdown after attacking over 1,000 victims worldwide.