# Archive
Browse past daily curated stories
Wednesday, September 23, 2026
-
1BleepingComputer generalShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
ShinyHunters claims to have breached FBI systems via a zero-day in Oracle PeopleSoft, gaining access to internal services and stealing data on employees and job applicants. The FBI jobs site was defaced and remains unavailable while the agency investigates. This is a high-profile claim involving a named threat actor, a specific vulnerable product (Oracle PeopleSoft), and a target of significant national security sensitivity.
-
2BleepingComputer generalEvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
Microsoft's Digital Crimes Unit disrupted EvilTokens, a phishing-as-a-service platform that compromised over 12,000 Microsoft 365 accounts across 10,000+ organizations. The operation — coordinated with Health-ISAC, Cloudflare, Coinbase, OpenAI, and others under a U.S. District Court order — seized 50 websites and disabled 150+ domains. EvilTokens used AI throughout its attack chain and was available on Telegram for a $1,500 initiation fee plus $500/month, with two UK arrests made.
-
3BleepingComputer generalCheck Point warns of Management Server zero-day exploited in attacks
Check Point released emergency hotfixes for CVE-2026-93616, a critical zero-day in its Security Management Server that allows unauthenticated remote script execution via the server's web service. Targeted attacks were observed on July 23, with the patch released September 22. Security teams running Check Point firewall management infrastructure should apply the fix immediately given the unauthenticated exploitation vector.
-
4The Hacker News generalWordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress shipped version 7.1.2 on September 22 to fix a critical unauthenticated RCE flaw allowing attackers to load arbitrary PHP files outside theme directories. The patch covers all supported branches back to version 4.7, and on vulnerable server configurations the flaw can lead to full code execution without any account. Site administrators should update immediately given the breadth of affected installations.
-
5The Hacker News generalZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
CISA added CVE-2026-7273, a CVSS 8.8 stack-based buffer overflow in Zyxel GS1900-series switches, to its Known Exploited Vulnerabilities catalog after Chinese threat actors used it to exfiltrate data from 996 devices and over 18,500 backend database records. Federal agencies face a mandatory patching deadline, and the active exploitation by a nation-state actor makes this urgent for network administrators running Zyxel managed switches.
-
6The Hacker News generalNew Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
CVE-2026-89775 is a Linux kernel KVM vulnerability on ARM64 processors that exposes freed host memory to guest VMs when nested virtualization is enabled, allowing a guest to read and write host kernel memory and potentially escape to the host. The researcher who discovered the bug confirmed it can be leveraged for guest-to-host code execution, making it critical for cloud and virtualization environments running ARM64 KVM workloads.
-
7The Hacker News generalNew CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
CVE-2026-93952 (CVSS 10.0) is a critical flaw in on-premises Arista VeloCloud Orchestrator actively exploited in the wild, enabling unauthenticated remote attackers to access privileged internal functions and affect the VCO host. Only orchestrators using certificate-based Edge authentication are vulnerable. SD-WAN operators running on-prem VCO deployments should treat this as a priority patch given active exploitation and maximum CVSS score.
-
8The Hacker News generalGoogle Fined €403 Million Over GDPR Violations Tied to Location Data
Ireland's Data Protection Commission fined Google €403 million (~$462 million) for GDPR violations related to how three product features processed users' location data between May 2018 and February 2020. Google has been ordered to bring its location data processing into compliance within six months. This is one of the largest GDPR fines to date and has broad implications for how tech companies handle location telemetry under EU law.
-
9SecurityWeek generalFake LastPass Installers Push Kernel-Level EDR Killer, ‘Rapuncel’ Stealer
Attackers distributing fake LastPass installers are deploying a kernel-level EDR killer alongside the 'Rapuncel' infostealer, impersonating at least 40 companies and disabling 145 security products. The campaign uses legitimate-looking software distribution infrastructure to bypass endpoint defenses before dropping credential-harvesting malware. Security teams should review detections for kernel driver abuse and monitor for LastPass-themed social engineering lures.
-
10SecurityWeek generalJapan Dismantles First North Korean Laptop Farm as US and Allies Detail Wider Scheme
Japan dismantled its first North Korean laptop farm as part of the WaterPlum campaign, a scheme documented in a joint advisory from the US, Japan, Germany, and Australia detailing how North Korean IT workers embed in Western companies using remote work. The multi-nation advisory provides operational detail on infrastructure, tradecraft, and indicators that defenders and HR teams can use to identify fraudulent contractor activity targeting tech sector employers.