# Archive

Browse past daily curated stories

Sep 23 Sep 22 Sep 21 Sep 20 Sep 19 Sep 18 Sep 17 Sep 16 Sep 15 Sep 14 Sep 13 Sep 12 Sep 11 Sep 10 Sep 09 Sep 08 Sep 06 Sep 05 Sep 04 Sep 03 Sep 01 Aug 31 Aug 30 Aug 29 Aug 28 Aug 27 Aug 26 Aug 25 Aug 24 Aug 23

Wednesday, September 23, 2026

  1. 1
    0
    BleepingComputer general
    ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach

    ShinyHunters claims to have breached FBI systems via a zero-day in Oracle PeopleSoft, gaining access to internal services and stealing data on employees and job applicants. The FBI jobs site was defaced and remains unavailable while the agency investigates. This is a high-profile claim involving a named threat actor, a specific vulnerable product (Oracle PeopleSoft), and a target of significant national security sensitivity.

  2. 2
    0
    BleepingComputer general
    EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts

    Microsoft's Digital Crimes Unit disrupted EvilTokens, a phishing-as-a-service platform that compromised over 12,000 Microsoft 365 accounts across 10,000+ organizations. The operation — coordinated with Health-ISAC, Cloudflare, Coinbase, OpenAI, and others under a U.S. District Court order — seized 50 websites and disabled 150+ domains. EvilTokens used AI throughout its attack chain and was available on Telegram for a $1,500 initiation fee plus $500/month, with two UK arrests made.

  3. 3
    0
    BleepingComputer general
    Check Point warns of Management Server zero-day exploited in attacks

    Check Point released emergency hotfixes for CVE-2026-93616, a critical zero-day in its Security Management Server that allows unauthenticated remote script execution via the server's web service. Targeted attacks were observed on July 23, with the patch released September 22. Security teams running Check Point firewall management infrastructure should apply the fix immediately given the unauthenticated exploitation vector.

  4. 4
    0
    The Hacker News general
    WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    WordPress shipped version 7.1.2 on September 22 to fix a critical unauthenticated RCE flaw allowing attackers to load arbitrary PHP files outside theme directories. The patch covers all supported branches back to version 4.7, and on vulnerable server configurations the flaw can lead to full code execution without any account. Site administrators should update immediately given the breadth of affected installations.

  5. 5
    0
    The Hacker News general
    Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

    CISA added CVE-2026-7273, a CVSS 8.8 stack-based buffer overflow in Zyxel GS1900-series switches, to its Known Exploited Vulnerabilities catalog after Chinese threat actors used it to exfiltrate data from 996 devices and over 18,500 backend database records. Federal agencies face a mandatory patching deadline, and the active exploitation by a nation-state actor makes this urgent for network administrators running Zyxel managed switches.

  6. 6
    0
    The Hacker News general
    New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

    CVE-2026-89775 is a Linux kernel KVM vulnerability on ARM64 processors that exposes freed host memory to guest VMs when nested virtualization is enabled, allowing a guest to read and write host kernel memory and potentially escape to the host. The researcher who discovered the bug confirmed it can be leveraged for guest-to-host code execution, making it critical for cloud and virtualization environments running ARM64 KVM workloads.

  7. 7
    0
    The Hacker News general
    New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

    CVE-2026-93952 (CVSS 10.0) is a critical flaw in on-premises Arista VeloCloud Orchestrator actively exploited in the wild, enabling unauthenticated remote attackers to access privileged internal functions and affect the VCO host. Only orchestrators using certificate-based Edge authentication are vulnerable. SD-WAN operators running on-prem VCO deployments should treat this as a priority patch given active exploitation and maximum CVSS score.

  8. 8
    0
    The Hacker News general
    Google Fined €403 Million Over GDPR Violations Tied to Location Data

    Ireland's Data Protection Commission fined Google €403 million (~$462 million) for GDPR violations related to how three product features processed users' location data between May 2018 and February 2020. Google has been ordered to bring its location data processing into compliance within six months. This is one of the largest GDPR fines to date and has broad implications for how tech companies handle location telemetry under EU law.

  9. 9
    0
    SecurityWeek general
    Fake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer

    Attackers distributing fake LastPass installers are deploying a kernel-level EDR killer alongside the 'Rapuncel' infostealer, impersonating at least 40 companies and disabling 145 security products. The campaign uses legitimate-looking software distribution infrastructure to bypass endpoint defenses before dropping credential-harvesting malware. Security teams should review detections for kernel driver abuse and monitor for LastPass-themed social engineering lures.

  10. 10
    0
    SecurityWeek general
    Japan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme

    Japan dismantled its first North Korean laptop farm as part of the WaterPlum campaign, a scheme documented in a joint advisory from the US, Japan, Germany, and Australia detailing how North Korean IT workers embed in Western companies using remote work. The multi-nation advisory provides operational detail on infrastructure, tradecraft, and indicators that defenders and HR teams can use to identify fraudulent contractor activity targeting tech sector employers.