π Bitget says an attacker exploited a third-party security product flaw, stole high-level internal credentials, and used them in a $388M theft.
The wallet system accepted fraudulent withdrawal commands as legitimate, bypassing risk controls.
Read: https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
The wallet system accepted fraudulent withdrawal commands as legitimate, bypassing risk controls.
Read: https://thehackernews.com/2026/09/bitget-says-attacker-exploited-third.html
π€―8π±3
π¨ IAM can show what an AI agent is allowed to do. It may miss what the agent actually does.
Agents can chain tools and actions inside applications that authentication logs may not capture. That makes runtime telemetry, scoped delegation, and distinct agent identities part of the control model.
Why traditional IAM falls short: https://thehackernews.com/2026/09/iam-for-ai-agent.html
Agents can chain tools and actions inside applications that authentication logs may not capture. That makes runtime telemetry, scoped delegation, and distinct agent identities part of the control model.
Why traditional IAM falls short: https://thehackernews.com/2026/09/iam-for-ai-agent.html
π4π₯3
β οΈ NeedyMantis keeps attackers inside networks they already breached.
Microsoft saw the malware in a small number of targeted intrusions, where it uses DLL sideloading and a WebSocket C2 channel to load additional modules.
Read: https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
Microsoft saw the malware in a small number of targeted intrusions, where it uses DLL sideloading and a WebSocket C2 channel to load additional modules.
Read: https://thehackernews.com/2026/09/hackers-use-needymantis-to-maintain.html
π€7π2π±2
βΌοΈ Apple patched a new CoreGraphics flaw that may have been exploited in targeted iOS attacks.
CVE-2026-86950 can trigger arbitrary code execution when a maliciously crafted file is processed. Fixes are available for affected older iOS, iPadOS, and macOS releases.
Read: https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html
CVE-2026-86950 can trigger arbitrary code execution when a maliciously crafted file is processed. Fixes are available for affected older iOS, iPadOS, and macOS releases.
Read: https://thehackernews.com/2026/09/apple-patches-coregraphics-flaw.html
β‘2π2π€2π1
OpenAI paused tool use on its most capable models after an RL agent got past internet restrictions and reached a public chatbot.
The gap was insufficient DNS filtering. Monitoring caught the behavior within 15 minutes, and OpenAI added blocking at two separate layers.
Read: https://thehackernews.com/2026/09/openai-pauses-tool-use-after-agent.html
The gap was insufficient DNS filtering. Monitoring caught the behavior within 15 minutes, and OpenAI added blocking at two separate layers.
Read: https://thehackernews.com/2026/09/openai-pauses-tool-use-after-agent.html
π3
β οΈ OpenAI shelved GPT-6.1 Astra after safety tests found deceptive behavior and actions taken without permission.
In simulations, GPT-6 Astra created fake identities and delivered malicious payloads to open-source codebases.
What the tests found: https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html
In simulations, GPT-6 Astra created fake identities and delivered malicious payloads to open-source codebases.
What the tests found: https://thehackernews.com/2026/09/openai-shelves-gpt-61-astra-after-tests.html
π₯9π3β‘2
βΌοΈ Malicious MCP servers can steal OAuth credentials from affected MCP Python SDK clients.
The vulnerability can expose the client secret, auth code, and PKCE verifier, letting an attacker request a valid access token from the real service.
Details β https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html
The vulnerability can expose the client secret, auth code, and PKCE verifier, letting an attacker request a valid access token from the real service.
Details β https://thehackernews.com/2026/09/official-mcp-python-sdk-flaw-can-let.html
β‘2
Source code tops the data sent to external GenAI models in Verizonβs DLP dataset.
Shadow AI is also the third most common non-malicious insider action, up fourfold. Teramind Field CISO Pete Hadjigeorgiou details what an IRM platform should be able to see, prove, and stop.
The 8 checks β https://thehackernews.com/expert-insights/2026/09/what-to-look-for-in-insider-risk.html
Shadow AI is also the third most common non-malicious insider action, up fourfold. Teramind Field CISO Pete Hadjigeorgiou details what an IRM platform should be able to see, prove, and stop.
The 8 checks β https://thehackernews.com/expert-insights/2026/09/what-to-look-for-in-insider-risk.html
π€1
Dutch police arrested a 24-year-old in a ShinyHunters investigation.
Police have not publicly named the suspect. Independent reports identify him as Pepijn van der Stap, previously apprehended in 2023 over data thefts and extortions.
Read: https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html
Police have not publicly named the suspect. Independent reports identify him as Pepijn van der Stap, previously apprehended in 2023 over data thefts and extortions.
Read: https://thehackernews.com/2026/09/dutch-police-arrest-24-year-old.html
π8π3π€2π₯1
π¨ 101 malicious npm packages can quietly add WhatsApp accounts to groups without consent.
The PhantomSub cluster abuses Baileys forks and has logged 490,000 downloads, including 116,000 in the last 30 days.
Read: https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html
The PhantomSub cluster abuses Baileys forks and has logged 490,000 downloads, including 116,000 in the last 30 days.
Read: https://thehackernews.com/2026/09/101-malicious-npm-packages-add.html
π3π€3
Media is too big
VIEW IN TELEGRAM
Six days of hands-on training, then NetWars and SANS@Night talks in the evenings. SANS CDI 2026 in D.C., Dec 14-19.
Details and registration: https://go.sans.org/JoHtqR
Details and registration: https://go.sans.org/JoHtqR
π3
Kiteworks fixed a critical flaw discovered during its precautionary shutdown, affecting a capability enabled for under 1% of customers.
The company says there is no evidence of malicious exploitation.
Read: https://thehackernews.com/2026/09/kiteworks-fixes-critical-flaw-found.html
The company says there is no evidence of malicious exploitation.
Read: https://thehackernews.com/2026/09/kiteworks-fixes-critical-flaw-found.html
π₯3
βΌοΈ A new Spectre-v2 attack can leak arbitrary Linux memory by reusing stale CPU branch predictions.
VUSec showed Branch Target Reuse working end to end on modern Intel CPUs, bypassing the Spectre defenses enabled in its test setup.
π Hereβs how BTR attack works β https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html
VUSec showed Branch Target Reuse working end to end on modern Intel CPUs, bypassing the Spectre defenses enabled in its test setup.
π Hereβs how BTR attack works β https://thehackernews.com/2026/09/new-spectre-v2-btr-attack-leaks-linux.html
π₯3π±2
β οΈ Russia-linked Star Blizzard has targeted 100+ Ukraine-linked organizations this year, often with fake event invites.
If a target replies, the group may send a password-protected archive containing an LNK disguised as a PDF. Opening it can start a chain that installs the CosmicPulse backdoor.
How it gets in: https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html
If a target replies, the group may send a password-protected archive containing an LNK disguised as a PDF. Opening it can start a chain that installs the CosmicPulse backdoor.
How it gets in: https://thehackernews.com/2026/09/russias-star-blizzard-targets-100.html
π₯6π€―6
βΌοΈ French tax data theft stayed undetected for seven weeks, until the attacker claimed it online.
Stolen staff passwords opened the door. DGFIP wasnβt monitoring ADER, and one password reset left an active session alive as E-Contact scraping continued for nearly 16 hours.
Read about this: https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html
Stolen staff passwords opened the door. DGFIP wasnβt monitoring ADER, and one password reset left an active session alive as E-Contact scraping continued for nearly 16 hours.
Read about this: https://thehackernews.com/2026/09/french-tax-data-theft-using-stolen.html
π10β‘4
π Citrix NetScaler CVE-2026-88772 can turn 120 crafted DTLS records into root-level shellcode execution.
watchTowrβs new analysis shows how about 174 KB of reassembled data overruns a 35,840-byte scratch buffer, hijacks control flow, and uses mprotect() to bypass NX.
The flaw is already exploited in the wild.
Inside the exploit chain: https://thehackernews.com/2026/09/citrix-netscaler-cve-2026-88772-exploit.html
watchTowrβs new analysis shows how about 174 KB of reassembled data overruns a 35,840-byte scratch buffer, hijacks control flow, and uses mprotect() to bypass NX.
The flaw is already exploited in the wild.
Inside the exploit chain: https://thehackernews.com/2026/09/citrix-netscaler-cve-2026-88772-exploit.html
π2π±2
π¨ A High-severity OpenSSL bug can leak heap memory to a DTLS peer or crash the process, OpenSSL says.
It can happen when the resend timer fires while a larger handshake message is stuck mid-send.
Latest releases fix 13 other flaws: 1 Moderate, 12 Low.
Read: https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html
It can happen when the resend timer fires while a larger handshake message is stuck mid-send.
Latest releases fix 13 other flaws: 1 Moderate, 12 Low.
Read: https://thehackernews.com/2026/09/openssl-fixes-high-severity-dtls-flaw.html
π₯4π2
β‘ Attackers are exploiting a Citrix NetScaler flaw to gain root access and hide PHP web shells behind .deb and .sig files.
The attacks also deploy SLAPSHOT, a Python tunneler. In at least one case, attackers used it for internal reconnaissance and credential theft.
Inside the attack chain: https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html
The attacks also deploy SLAPSHOT, a Python tunneler. In at least one case, attackers used it for internal reconnaissance and credential theft.
Inside the attack chain: https://thehackernews.com/2026/09/attackers-exploit-netscaler-flaw-for.html
π±6β‘2
π¨ CSuite phishing can turn one phish into both Microsoft 365 session theft and remote endpoint access.
ANYRUN traced 351 related sandbox analyses. Some chains deployed ScreenConnect or Action1, and 51% of submissions came from the U.S.
π How the chain works β https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html
ANYRUN traced 351 related sandbox analyses. Some chains deployed ScreenConnect or Action1, and 51% of submissions came from the U.S.
π How the chain works β https://thehackernews.com/2026/09/us-focused-csuite-phishing-steals.html
π₯2
AI coding agents asked for review screenshots put internal images in public GitHub repos, researchers say.
Researchers counted 13,000+ images at 300+ orgs, including customer billing records. In 93% of cases, they sat in personal accounts.
Read β https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html
Researchers counted 13,000+ images at 300+ orgs, including customer billing records. In 93% of cases, they sat in personal accounts.
Read β https://thehackernews.com/2026/09/ai-coding-agents-exposed-13000-internal.html
π1