# Archive

Browse past daily curated stories

Sep 12 Sep 11 Sep 10 Sep 09 Sep 08 Sep 06 Sep 05 Sep 04 Sep 03 Sep 01 Aug 31 Aug 30 Aug 29 Aug 28 Aug 27 Aug 26 Aug 25 Aug 24 Aug 23 Aug 22 Aug 21 Aug 20 Aug 19 Aug 18 Aug 16 Aug 15 Aug 14 Aug 13 Aug 12 Aug 09

Saturday, September 12, 2026

  1. 1
    0
    The Hacker News general
    GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

    CVE-2026-85706, a CVSS 10.0 path traversal flaw in GitLab's repository commits API, allows unauthenticated attackers to read arbitrary files from self-managed GitLab servers. Internet-wide probing began within hours of public disclosure, making this an urgent patch priority for any organization running self-hosted GitLab instances.

  2. 2
    0
    The Hacker News general
    Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

    Three distinct threat clusters — including ransomware operators and state-sponsored actors — are actively exploiting CVE-2026-20079 (CVSS 10.0), an authentication bypass in Cisco Secure Firewall Management Center, to deploy Qilin ransomware and steal credentials. Cisco and CISA have both issued warnings, and the flaw was originally disclosed in March 2026, meaning unpatched systems have had extended exposure.

  3. 3
    0
    The Hacker News general
    Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

    Wiz researchers observed attacks between August 15 and September 8 in which threat actors chained two vulnerabilities in JFrog Artifactory to gain administrative control of self-hosted servers and deploy a Rust-based backdoor. Both flaws were patched by JFrog prior to the observed attacks, meaning only unpatched installations were compromised.

  4. 4
    0
    BleepingComputer general
    AI-powered attack exploited PaperCut flaws to hack 395 organizations

    A likely Russian-speaking threat actor deployed hundreds of AI agents to discover and exploit vulnerabilities in PaperCut NG/MF servers, ultimately compromising 395 organizations globally. PaperCut has since released patched versions 26.0.5, 25.0.13, and 24.1.10 replacing earlier emergency patches for the two actively exploited flaws.

  5. 5
    0
    The Hacker News general
    Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

    Anthropic identified and disrupted GTG-20006, a Russian state-sponsored group aligned with Midnight Blizzard, which used Claude to automate malware evasion by rebuilding detected malware variants in near-real-time. The group targeted more than 20 government, intelligence, diplomatic, and defense organizations, representing a significant escalation in AI-assisted offensive operations.

  6. 6
    0
    The Hacker News general
    China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

    China-linked threat group UNC3569 exploited a vulnerability in Sogou Input Method — one of the most widely used Chinese-character input tools on Windows — to deploy the GRAYRABBIT backdoor via a crafted link. Gen Digital published the research on September 11; Tencent owns Sogou, adding supply-chain implications for Chinese-language Windows users worldwide.

  7. 7
    0
    SecurityWeek general
    Critical NetScaler Vulnerability Exploited in Attacks

    CVE-2026-19490, a critical authentication bypass in Citrix NetScaler, has been actively exploited in the wild since at least September 3, according to SecurityWeek reporting. Organizations running NetScaler ADC or Gateway should treat this as an emergency patching priority given its confirmed in-the-wild exploitation.

  8. 8
    0
    BleepingComputer general
    Trezor: 347,000 users targeted in phishing attacks after Brevo breach

    Trezor confirmed that 347,000 user email addresses were exposed and 2,500 users clicked malicious links in phishing emails sent after attackers breached the Brevo marketing platform. The attack also affected users of BitBox and CoinTracking, illustrating the downstream risk of third-party email service provider compromises in the cryptocurrency ecosystem.

  9. 9
    0
    BleepingComputer general
    Florida confirms DMV database breached via stolen police account

    Florida's DAVID driver database was breached after cybercrime group ShinyHunters used credentials stolen from a law enforcement officer's personal device to gain access. The breach of a law enforcement-linked credential store raises serious concerns about BYOD policy enforcement and credential hygiene across public-sector agencies.

  10. 10
    0
    The Record threat-intel
    Ukrainian hacker gets four years in US prison over Conti ransomware attacks

    Oleksii Oleksiyovych Lytvynenko, a Ukrainian national who joined the Conti ransomware operation in 2021 and participated in attacks on at least 12 companies, was sentenced to four years in a U.S. federal prison. Lytvynenko was arrested in Ireland in 2023; his sentencing marks continued DOJ action against Conti members following the group's 2022 shutdown after attacking over 1,000 victims worldwide.