MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Sep 26, 2026, 12:05 AM (UTC+3)
Latest stories
U. S. Cybersecurity and Infrastructure Security Agency (CISA) adds Microsoft SharePoint and Mikrotik RouterOS flaws flaws to its Known Exploited Vulnerabilities catalog. The U. S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog : • CVE-2026-65660 (CVSS score of 8.8) Microsoft SharePoint Code Injection Vulnerability • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability CVE-2026-65660 is a code-injection vulnerability in Microsoft SharePoint Server that allows an authenticated, low-privileged attacker to execute arbitrary code remotely. The flaw affects SharePoint Server 2016, 2019, and Subscription Edition. The second flaw added to the catalog, tracked as CVE-2026-67279 (CVSS score of 6.
Kiteworks urges customers pull the plug on vulnerable servers. CISA lays out its election security plan. Known vulnerabilities linger unpatched. Big AI labs consider a new standards body. Questions surround claims of an OpenAI Medicare hack. File notifications become a privacy leak. SectopRAT hides in audio software. A new Android banking trojan takes control. An attacker puts open-source AI agents to work hacking hundreds of organizations. A Rydox cybercrime marketplace operator pleads guilty. Our guest is Todd Thorsen, CISO of CrashPlan, with ways to prepare for and react to critical infrastructure campaigns. Americans give AI the side-eye. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing , and you’ll never miss a beat . And be sure to follow CyberWire Daily on LinkedIn .
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for customers.”
Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with data security practices.
September 25, 2026 Introduction On 22 September the group ShinyHunters announced on their leak site they had accessed data from the FBI and that they would release this in a week if the FBI did not negotiate. They claimed that they had information on around 38,000 FBI staff. The post claims “We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job”. The FBI have announced they are actively investigating the allegations. Who are ShinyHunters? ShinyHunters is thought to be a financially motivated data-theft and extortion group that has been active since 2019. The name comes from “shiny” Pokémon.
When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.
Bitget says suspected North Korea-linked actors stole $351. 6M from hot and warm wallets. Withdrawals were suspended while Mandiant investigates. Cryptocurrency exchange Bitget says suspected North Korea-linked threat actors stole $351. 6 million from a limited number of hot and warm wallets. The company detected unauthorized transfers on September 24 and temporarily suspended withdrawals. At 18:31 UTC on September 24, 2026, Bitget’s security systems identified unauthorized transfers involving a limited number of hot wallets. Our security team immediately activated emergency response procedures and began a full investigation. Based on our current assessment,… https://t.co/7xF5xW0JQ1 — Bitget (@bitget) September 24, 2026 Bitget said customer balances, cold wallets and most platform assets remain secure.
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.
The findings highlight how AI-generated and vibe-coded apps can spill and expose users' data when not configured or secured properly.
Overview Three cross-site scripting (XSS) vulnerabilities identified in Readwise Reader for Android version 8. 7. 2 are disclosed. An attacker with the ability to craft malicious documents or metadata can exploit these vulnerabilities by supplying poisoned content that bypasses sanitization. Successful exploitation could allow the attacker to execute arbitrary JavaScript within the application's WebView context and compromise the confidentiality and integrity of user data, including access to stored documents, credentials, and session tokens. Description Readwise Reader from Readwise is designed to provide a unified read-it-later service that helps individuals collect and organize articles, newsletters, videos, and other content of interest into a single reading interface. It is available on multiple platforms including Android and can synchronize content across devices.
The tech giant, which allows companies to send large datasets over the internet, said it received a "credible threat" from law enforcement about an imminent attack.
The Redox OS open-source, Rust-based operating system has seen a lot of activity in recent weeks with many notable improvements landing...
Northern Ireland journalist subject to unlawful communications surveillance seeks damages from police in Northern Ireland in high court claim for data protection breaches and harassment
An as-yet undisclosed zero-day vulnerability has prompted managed file transfer provider Kiteworks to tell users to preemptively switch off their servers.
The CEO said the company has a User Protection Fund that has over $464 million and those funds will be used to cover the losses.
Go beyond the basics with XRY Kiosk – extract logical, full file system, physical and RAM data through controlled, compliant workflows built for fast frontline forensics.
Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul. The post In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure appeared first on SecurityWeek .
LinkedIn is adding trust and verification features aimed at making fake professional identities, invented work histories, and company impersonation harder to pull off. The company is responding to an environment in which generative AI enables imposters to create an entirely made-up professional persona. It reduces the cost of creating convincing headshots, biographies, résumés, outreach messages, and recommendations. LinkedIn’s new features use verified people and company Pages to help check other users’ claims. Colleague and classmate vouching: People can confirm that they worked or studied with someone during the period listed on that person’s profile. This confirms an affiliation; it does not rate the person’s ability or recommend them.
Dyfed-Powys Police in Wales said a cyberattack affecting the force disrupted some non-emergency systems and may have compromised staff information.
We discovered an undocumented remote-access Trojan (RAT) called Kothamine Agent . It supports more than 30 commands and it gives attackers control of an infected Windows computer: they can run commands, read and change files, and add new capabilities. Some versions can also steal browser data and record through the camera and microphone. We found Kothamine linked to malicious npm packages, which could put users and developers who install those packages at risk. In recent versions, the malware uses tailcat , an open-source tool from Tailscale, to receive commands over an encrypted connection. That makes its communications harder to inspect and gives defenders no conventional command-and-control (C2) domain to block. Based on VirusTotal uploads and GitHub commits, Kothamine appears to have been in development or distribution since at least July.
Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.
IBM’s experience shows how contributing to open source can support business strategy, inform security decisions, and develop the people who lead technology forward. Through OpenSSF, that participation brings enterprise experience into a community working to secure the software upon which everyone depends. For Jamie Thomas, open source comes with a responsibility: understand what you use and help sustain it. In her conversation with CRob for Big Thoughts, Open Sources , published June 16, 2026, Thomas describes how IBM’s journey through Java, Linux, and Red Hat shaped its approach to enterprise participation. As IBM Enterprise Security Executive and an OpenSSF Governing Board member and former chair, she connects that history to a practical challenge: turning dependence on open source into intentional stewardship. “If you are a direct consumer of open source, do it with intent.”
Metasploit Wrap Up: Belgian Waffles, Chocolates, and…Modules-Frites?
Bitget’s security systems caught the unauthorized transfers on September 24, and some wallet addresses linked to the attacker have been frozen. The post North Korea Suspected in $351 Million Bitget Crypto Heist appeared first on SecurityWeek .
Attackers hijacked Ukrainian websites to deliver a fake Cloudflare CAPTCHA that installs Psychedelic Stealer and steals browser and crypto credentials. Psychedelic Stealer is being distributed through compromised Ukrainian business websites. Attackers injected hidden iframes into legitimate pages and used them to display a fake Cloudflare verification screen to visitors. The affected sites included a hair-treatment clinic, a scale-model manufacturer, a specialist bookseller, a psychological facility, a tool retailer, and an automotive retailer. These were legitimate businesses with established social media profiles and third-party listings. Visitors were therefore directed to a trusted website they may have visited before, making the fake Cloudflare CAPTCHA harder to recognize. That’s the core of what makes this campaign uncomfortable to dismiss.
The ‘SalesBleed’ set of weaknesses in Salesforce’s Agentforce agents exposed CRM data to attackers via prompt injection and DNS exfiltration
The $351 million theft from crypto exchange Bitget is the latest in a string of high-profile hacks targeting the crypto sector.
Apple's former head of Apple retail, Ron Johnson, has a book "Shop Different" and joins William on the latest AppleInsider Podcast for a guest interview. Also, your hosts discuss new Macs, perceived Apple failures, and more. Ron Johnson with the interior of Apple's iconic Fifth Avenue store - images credit: Apple. Ron Johnson was brought in to Apple by Steve Jobs to create the Apple Stores in what is now seen as a brilliant move, but back in the late 1990s and early 2000s, was believed to be Apple's folly. Hear from the man himself, though, on why he believes Apple had to do stores — and would not be here today if it hadn't. Outside of Apple retail, things are busy. RAM prices aren't going to get any better anytime soon, and Apple has solidified the price it will be paying at least through early 2027. Continue Reading on AppleInsider • Discuss on our Forums
By Andréanne Bergeron, Security Researcher Every few months, another headline announces a major cybercrime takedown: servers seized, domains sinkholed, arrests made. Recent examples include Operation Magnus (targeting RedLine and META stealers in October 2024), Operation Endgame (targeting dropper infrastructure in May 2024), and the May 2025 FBI/DOJ/Europol/Microsoft action against LummaC2. These operations generate significant press coverage and signal meaningful institutional commitment to combating cybercrime. But what is their actual impact on the cybercrime ecosystem? Key Findings on Law Enforcement Takedowns • Most law enforcement takedowns fail to reduce cybercrime in the long term. While they often disrupt the targeted malware, criminal activity usually shifts to alternative infostealer families instead of disappearing. • Cybercriminal ecosystems are resilient and adaptive.
Introduction
A domain that has long appeared in software documentation, code examples, and developer test material is now being used to push a ClickFix attack against Windows users. A placeholder domain stands in for a website in an example. The best-known is probably example. com . Another, third-party[. ]com , has often been used in documentation to represent an external website, API, or service. However, there is a very important difference between the two: example. com is reserved for documentation, while third-party[. ]com is an ordinary domain. Anyone could register it, and someone did. Every document, test, and skill that hardcoded it now points readers and users to the attacker’s infrastructure. Researchers at Manifold Security found that third-party[. ]com was serving a fake Cloudflare-style verification page to Windows visitors.
Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July. The post CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks appeared first on SecurityWeek .
The CISA plan provides guidance and resources for election officials to secure systems such as voter registration databases and voting machines
Security researchers at Huntress have uncovered an unusual attack in which a threat actor compiled a cryptocurrency miner directly on a victim’s computer, rather than simply dropping a ready-made one, and in doing so generated so much activity that the intrusion stood out. The incident began in early September 2026 with the exploitation of CVE-2025-4632, a vulnerability in Samsung MagicINFO, the content management software used to run digital signage. The flaw, which lets an attacker write arbitrary files with system-level privileges, was fixed in May 2025 after an earlier bug (CVE-2024-7399) whose fix proved incomplete. Despite the organisation being alerted to the initial compromise and advised on remediation, the same endpoint was flagged again eight days later for fresh malicious activity tied to the same access route.
Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services. The post Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court appeared first on SecurityWeek .
ANY. RUN once again joined the RootedCON community this year, taking part in Rooted Valencia 2026 on September 18. The event brought together cybersecurity professionals, researchers, hackers, and technology enthusiasts from across the global cybersecurity community. For our team, the event became yet another opportunity to meet security professionals, speak with clients, and demonstrate how interactive sandboxing and threat intelligence can support SOCs and MSSPs at any scale. We also shared some of the latest capabilities designed to help analysts investigate incidents faster and get more context from their findings. Rooted Valencia Agenda 2026 The Valencia edition of RootedCON covered a wide range of topics, from AI agents and prompt injection to cloud security, command-and-control, and malware research.
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability • CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. • CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies.
Researchers are questioning whether an OpenAI agent needed to hack an Australian government health portal to access it, after a review of the website’s archived code found it explicitly directed visitors to an unauthenticated endpoint.
Far from hurting sales, raising iPhone prices has brought Apple growing market share in India, at least for now, and at least while it also has installment plans. Deirdre O'Brien (left) and Tim Cook open Apple BKC, the first Apple Store in India, back in 2023 (Source: Apple) Analysts have predictably yet plausibly argued that higher iPhone prices and no base iPhone 18 would hit Apple's bottom line . That may well be true in most places, but a new CNBC report says it definitely is not in India. Reportedly, the iPhone 18 Pro is seeing almost 20% more demand in the country than the iPhone 17 Pro at this point in 2025. "Apple's volume market share is likely to hit 10% in 2026," said Counterpoint Research director Tarun Pathak, "reaching double digits in a single calendar year for the first time, up from 4% in 2022." Continue Reading on AppleInsider • Discuss on our Forums