# Archive
Browse past daily curated stories
Sunday, September 20, 2026
-
1BleepingComputer generalShinyHunters hacks Clop leak site, threatens to extort ransomware gang
ShinyHunters breached Clop ransomware's Tor-hosted data leak site, defacing it and allegedly exfiltrating server data along with the private keys for Clop's onion service. This is a rare instance of one major criminal group attacking another, and the theft of onion service private keys could expose Clop's infrastructure and victim communications to further compromise.
-
2BleepingComputer generalNorth Korean WaterPlum hackers infected 30,000 devices worldwide
A joint law enforcement advisory from the FBI, DoD, Japan's NPA, and agencies in Australia and Germany warns that North Korean hacking group WaterPlum compromised at least 30,000 devices across 100 countries between December 2025 and July 2026, funneling over $10.7 million in stolen cryptocurrency to Pyongyang by posing as AI and blockchain companies to target job applicants.
-
3The Hacker News generalCritical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
CVE-2026-58138 (CVSS 9.8), an unauthenticated RCE flaw in Orkes Conductor versions prior to 3.30.2, is being actively exploited in the wild according to Fortinet, allowing remote attackers to execute arbitrary code via inline workflow definitions without any authentication. Organizations running Orkes Conductor 3.21.21 or earlier should prioritize patching immediately.
-
4The Hacker News generalClaude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws
Researchers at Hacktron used Anthropic's Claude Opus 5 to chain two vulnerabilities — a bug in OpenAI's public help forum software and a weakness in OpenAI's login system — to take over ChatGPT and Codex accounts of several OpenAI employees and reach an internal OpenAI code repository. The attack demonstrates AI models' growing capability as offensive security tools when chaining multi-step exploit paths.
-
5Dark Reading generalCisco Zero-Day Highlights API Endpoint Authentication Issues
Cisco disclosed CVE-2026-76460, a CVSS 10.0 authentication bypass zero-day in its Identity Services Engine (ISE), stemming from improper API endpoint authentication. ISE is widely deployed as a network access control solution, making a maximum-severity unauthenticated flaw particularly dangerous for enterprise network perimeters.
-
6The Hacker News generalCISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
CISA added three actively exploited Linux kernel vulnerabilities to its KEV catalog, including CVE-2025-39682 (CVSS 9.8), an improper exception-handling flaw in the TLS receive path. Federal agencies face mandatory remediation deadlines, and the critical severity scores indicate these flaws pose significant risk to Linux-based infrastructure across both government and enterprise environments.
-
7The Hacker News generalSolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds patched CVE-2026-28326 (CVSS 8.8), a hard-coded cryptographic key vulnerability in Access Rights Manager (ARM) affecting all versions through 2026.2 that enables unauthenticated remote code execution. ARM is used for privileged access governance, making unauthenticated RCE in this product a high-value target for attackers seeking lateral movement into sensitive identity infrastructure.
-
8The Hacker News generalCrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories
CrowdSec disclosed on September 18 that an attacker copied approximately 170 private GitHub repositories on May 22 by leveraging the still-active GitHub account of a recently departed employee whose laptop was compromised in the TanStack npm supply chain attack — in which malicious npm package versions stole developer credentials. The incident illustrates compounding risk from supply chain attacks combined with inadequate offboarding procedures.
-
9BleepingComputer generalGyazo server flaw exploited to steal 23.6 million user records
Image-sharing platform Gyazo confirmed a data breach in which attackers exploited a server vulnerability in its image upload infrastructure to steal 23.6 million user records. The breach is notable for the scale of exposure and the exploitation of a server-side flaw rather than credential-based access.
-
10CyberScoop generalEarly Scattered Spider member pleads guilty to cybercrime spree
Ahmed Elbadawy, an early member of the Scattered Spider threat group, pleaded guilty to his role in a cybercrime spree that netted massive illicit proceeds; prosecutors are seeking forfeiture of approximately $17.6 million in virtual currency along with luxury vehicles, jewelry, and designer goods. Elbadawy's guilty plea is a significant law enforcement milestone against Scattered Spider, which has been linked to high-profile attacks on MGM Resorts and Caesars Entertainment.