# Archive

Browse past daily curated stories

Sep 19 Sep 18 Sep 17 Sep 16 Sep 15 Sep 14 Sep 13 Sep 12 Sep 11 Sep 10 Sep 09 Sep 08 Sep 06 Sep 05 Sep 04 Sep 03 Sep 01 Aug 31 Aug 30 Aug 29 Aug 28 Aug 27 Aug 26 Aug 25 Aug 24 Aug 23 Aug 22 Aug 21 Aug 20 Aug 19

Saturday, September 19, 2026

  1. 1
    0
    BleepingComputer general
    Cisco warns of max severity ISE zero-day exploited in attacks

    Cisco issued an emergency patch for CVE-2026-76460, a maximum-severity (CVSS 10.0) authentication bypass zero-day in its Identity Services Engine (ISE) that remote, unauthenticated attackers are actively exploiting via crafted API requests. ISE is widely deployed as a network access control solution, making active exploitation of a max-severity auth bypass a critical priority for enterprise security teams to patch immediately.

  2. 2
    0
    SecurityWeek general
    Brevo Supply Chain Attack Injects Malware Into 100,000 Websites

    A supply chain attack against email marketing platform Brevo used a compromised API key to deploy a malicious Cloudflare Worker that injected malicious scripts into approximately 100,000 websites. The attack demonstrates how a single compromised vendor credential can cascade into mass website compromise, affecting downstream visitors of all affected sites.

  3. 3
    0
    The Hacker News general
    Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

    Microsoft patched CVE-2026-85889, a CVSS 10.0 privilege escalation flaw in Azure AI Foundry caused by missing authentication for a critical function, allowing unauthenticated network attackers to escalate privileges. Microsoft stated no customer action is required, indicating the fix was applied server-side, but the maximum severity score in a widely used AI development platform warrants attention from teams relying on Azure AI infrastructure.

  4. 4
    0
    The Hacker News general
    Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone

    NLnet Labs disclosed CVE-2026-81642, a critical heap overflow in the DNSSEC validator of all Unbound DNS resolver releases prior to version 1.26.1, exploitable by an attacker controlling a malicious DNS zone to achieve remote code execution on vulnerable resolvers. Unbound 1.26.1 was released simultaneously with the advisory; administrators running Unbound in production should upgrade immediately given the RCE impact on core DNS infrastructure.

  5. 5
    0
    The Hacker News general
    Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

    Security firm Air Security disclosed 'Plugin4Shell,' a flaw affecting four widely used AI coding agents — patched in Anthropic's Claude Code 2.1.179 and OpenAI's Codex 0.146.0 — that allows a malicious plugin repository owner to substitute pinned, reviewed plugin code with arbitrary malicious code at install time. GitHub Copilot remains unpatched, and the flaw undermines version-pinning as a supply chain security control in AI-assisted development workflows.

  6. 6
    0
    The Hacker News general
    An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

    A researcher identified that thousands of websites, code repositories, and documentation pages still contain hard-coded references to a CDN domain that was re-registered in July 2025 after the original CDN was decommissioned and its domain allowed to expire. Any site still loading assets from this domain is effectively serving attacker-controlled content to all visitors, representing a widespread passive supply chain compromise.

  7. 7
    0
    The Hacker News general
    Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

    A security researcher published working exploit code for four Linux kernel local privilege escalation vulnerabilities, each allowing a local user to gain root access. Kernel maintainers have patched all four flaws in recent weeks, but systems running unpatched kernels are now at elevated risk given the public availability of exploit code.

  8. 8
    0
    CyberScoop general
    International security agencies warn about North Korean hackers exploiting job seekers to steal crypto, data

    A joint advisory from the U.S. (FBI, DoD), Japan's National Police Agency, Australia, and Germany warns that North Korean threat group 'WaterPlum' has infected over 30,000 devices across 100 countries by posing as AI and blockchain companies to deliver malware to job seekers. The campaign targets cryptocurrency theft and sensitive data, reflecting continued DPRK reliance on financially motivated cyber operations disguised as legitimate hiring activity.

  9. 9
    0
    The Hacker News general
    Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

    Zscaler ThreatLabz attributed a new campaign dubbed 'Operation [redacted]' to Pakistan-aligned APT36 (Transparent Tribe/Earth Karkaddan), deploying four previously undocumented tools — RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH — against Indian and Afghan government and defense entities, using private GitHub repositories for command-and-control. The use of GitHub as C2 infrastructure complicates detection and blocking efforts for defenders in targeted organizations.

  10. 10
    0
    BleepingComputer general
    New Check Point flaw lets hackers execute code with root privileges

    Check Point Software released patches for a critical vulnerability in its Security Management and Log Server products that allows remote attackers to execute code with root privileges. Security management platforms are high-value targets as they provide visibility into and control over an organization's entire security posture, making this flaw particularly dangerous if left unpatched.