# Today's Top Stories

September 20, 2026

  1. 1
    0
    BleepingComputer general Sep 19
    ShinyHunters hacks Clop leak site, threatens to extort ransomware gang

    ShinyHunters breached Clop ransomware's Tor-hosted data leak site, defacing it and allegedly exfiltrating server data along with the private keys for Clop's onion service. This is a rare instance of one major criminal group attacking another, and the theft of onion service private keys could expose Clop's infrastructure and victim communications to further compromise.

  2. 2
    0
    BleepingComputer general Sep 19
    North Korean WaterPlum hackers infected 30,000 devices worldwide

    A joint law enforcement advisory from the FBI, DoD, Japan's NPA, and agencies in Australia and Germany warns that North Korean hacking group WaterPlum compromised at least 30,000 devices across 100 countries between December 2025 and July 2026, funneling over $10.7 million in stolen cryptocurrency to Pyongyang by posing as AI and blockchain companies to target job applicants.

  3. 3
    0
    The Hacker News general Sep 19
    Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild

    CVE-2026-58138 (CVSS 9.8), an unauthenticated RCE flaw in Orkes Conductor versions prior to 3.30.2, is being actively exploited in the wild according to Fortinet, allowing remote attackers to execute arbitrary code via inline workflow definitions without any authentication. Organizations running Orkes Conductor 3.21.21 or earlier should prioritize patching immediately.

  4. 4
    0
    The Hacker News general Sep 19
    Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

    Researchers at Hacktron used Anthropic's Claude Opus 5 to chain two vulnerabilities — a bug in OpenAI's public help forum software and a weakness in OpenAI's login system — to take over ChatGPT and Codex accounts of several OpenAI employees and reach an internal OpenAI code repository. The attack demonstrates AI models' growing capability as offensive security tools when chaining multi-step exploit paths.

  5. 5
    0
    Dark Reading general Sep 18
    Cisco Zero-Day Highlights API Endpoint Authentication Issues

    Cisco disclosed CVE-2026-76460, a CVSS 10.0 authentication bypass zero-day in its Identity Services Engine (ISE), stemming from improper API endpoint authentication. ISE is widely deployed as a network access control solution, making a maximum-severity unauthenticated flaw particularly dangerous for enterprise network perimeters.

  6. 6
    0
    The Hacker News general Sep 19
    CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

    CISA added three actively exploited Linux kernel vulnerabilities to its KEV catalog, including CVE-2025-39682 (CVSS 9.8), an improper exception-handling flaw in the TLS receive path. Federal agencies face mandatory remediation deadlines, and the critical severity scores indicate these flaws pose significant risk to Linux-based infrastructure across both government and enterprise environments.

  7. 7
    0
    The Hacker News general Sep 19
    SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE

    SolarWinds patched CVE-2026-28326 (CVSS 8.8), a hard-coded cryptographic key vulnerability in Access Rights Manager (ARM) affecting all versions through 2026.2 that enables unauthenticated remote code execution. ARM is used for privileged access governance, making unauthenticated RCE in this product a high-value target for attackers seeking lateral movement into sensitive identity infrastructure.

  8. 8
    0
    The Hacker News general Sep 19
    CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

    CrowdSec disclosed on September 18 that an attacker copied approximately 170 private GitHub repositories on May 22 by leveraging the still-active GitHub account of a recently departed employee whose laptop was compromised in the TanStack npm supply chain attack — in which malicious npm package versions stole developer credentials. The incident illustrates compounding risk from supply chain attacks combined with inadequate offboarding procedures.

  9. 9
    0
    BleepingComputer general Sep 18
    Gyazo server flaw exploited to steal 23.6 million user records

    Image-sharing platform Gyazo confirmed a data breach in which attackers exploited a server vulnerability in its image upload infrastructure to steal 23.6 million user records. The breach is notable for the scale of exposure and the exploitation of a server-side flaw rather than credential-based access.

  10. 10
    0
    CyberScoop general Sep 18
    Early Scattered Spider member pleads guilty to cybercrime spree

    Ahmed Elbadawy, an early member of the Scattered Spider threat group, pleaded guilty to his role in a cybercrime spree that netted massive illicit proceeds; prosecutors are seeking forfeiture of approximately $17.6 million in virtual currency along with luxury vehicles, jewelry, and designer goods. Elbadawy's guilty plea is a significant law enforcement milestone against Scattered Spider, which has been linked to high-profile attacks on MGM Resorts and Caesars Entertainment.