# Archive

Browse past daily curated stories

Sep 18 Sep 17 Sep 16 Sep 15 Sep 14 Sep 13 Sep 12 Sep 11 Sep 10 Sep 09 Sep 08 Sep 06 Sep 05 Sep 04 Sep 03 Sep 01 Aug 31 Aug 30 Aug 29 Aug 28 Aug 27 Aug 26 Aug 25 Aug 24 Aug 23 Aug 22 Aug 21 Aug 20 Aug 19 Aug 18

Friday, September 18, 2026

  1. 1
    0
    The Hacker News general
    Cisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active Attacks

    Cisco disclosed CVE-2026-76460, a CVSS 10.0 authentication bypass zero-day in Identity Services Engine (ISE) that allows unauthenticated remote attackers to bypass authentication via crafted API requests. This is the second actively exploited ISE zero-day disclosed in as many days, and ISE has now seen three actively exploited vulnerabilities since June 2025 — making it a critical priority for patching in enterprise environments.

  2. 2
    0
    CyberScoop general
    Cisco alerts customers to second actively exploited zero-day in as many days

    Cisco issued an emergency alert about a second maximum-severity zero-day in Identity Services Engine within a 24-hour window, underscoring a pattern of active exploitation targeting this product. Security teams running ISE should treat both vulnerabilities as urgent given confirmed in-the-wild exploitation and the product's central role in network access control.

  3. 3
    0
    BleepingComputer general
    Brevo supply-chain attack injected ClickFix scripts on customer sites

    A supply-chain attack against email platform Brevo saw attackers steal a Cloudflare API key to inject malicious ClickFix scripts into Brevo's own websites and JavaScript files embedded on customer sites, enabling downstream malware distribution. The incident illustrates how a single stolen cloud service credential can propagate malicious payloads across thousands of third-party sites relying on shared JS assets.

  4. 4
    0
    SecurityWeek general
    Cyberattacks on Two Oil Tankers Prompt Coast Guard, FBI to Board Vessels

    The US Coast Guard and FBI physically boarded two oil tankers — including the supertanker VL Prosperity — after evidence of network compromise by foreign cyber actors, marking a rare kinetic response to maritime cyber incidents. The Coast Guard confirmed malicious cyber activity on the VL Prosperity but has not formally attributed the attack, while the vessels were US-bound through the Gulf of Mexico.

  5. 5
    0
    The Hacker News general
    Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root

    Check Point disclosed a critical unauthenticated remote code execution vulnerability in its Security Management Server and Log Server products, allowing network-accessible attackers to run arbitrary code as root without credentials. Check Point has released a fix via its LivePatch channel and reports no evidence of exploitation in the wild, but the affected system controls firewall policy and administrator access — making it a high-value target.

  6. 6
    0
    The Hacker News general
    China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America

    China-aligned APT FamousSparrow has deployed a new modular C++ backdoor called SparroWocky against government organizations across Latin America since at least August 2025, according to ESET researchers Alexandre Côté Cyr and Romain Dumont. The campaign aligns with growing US-China competition for influence in the region and represents a previously unreported toolset from this established espionage actor.

  7. 7
    0
    The Hacker News general
    Gyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records

    Image-sharing platform Gyazo suffered a breach exposing approximately 23.62 million user records — including email addresses and password hashes — along with roughly 490 million image metadata records, primarily for images from January 2019 or earlier. Kyoto-based parent company Helpfeel disclosed the incident Wednesday; the scale of metadata exposure creates significant privacy risk through enumerable image link IDs.

  8. 8
    0
    SecurityWeek general
    Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M Ransom

    Revolut allegedly had customer data fed to hackers over a five-month period, with attackers impersonating an Italian government agency to extract information on 680 high-profile accounts and subsequently demanding a $3 million ransom. The extended duration of the breach before detection is a significant red flag for social-engineering-based insider threat scenarios targeting financial institutions.

  9. 9
    0
    The Hacker News general
    BIND 9 Update Fixes 14 Flaws, Including an Unauthenticated Crash Over DNS-over-HTTPS

    ISC released BIND 9.20.29 and 9.21.26 on September 16 to fix 14 security flaws, including an unauthenticated crash vulnerability affecting any BIND server configured with DNS-over-HTTPS — a single malformed SIG record is sufficient to kill the named process. Additionally, CVE-2026-81642 is a critical heap overflow in the DNSSEC validator in Unbound before version 1.26.1 that enables RCE via a malicious DNS zone.

  10. 10
    0
    The Hacker News general
    Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords

    Iran-linked hacktivist persona Handala Hack has been attributed to HEAVYGRAM, a Telegram-based surveillance backdoor built with capabilities including remote command execution, credential and session file exfiltration, screenshot capture, DLL sideloading, and Telegram session hijacking, alongside a Delphi-based utility called CRUDEEXCLUDE. The attribution links a politically motivated persona to sophisticated persistent access tooling, raising the operational threat level of what had appeared to be a hacktivist group.