MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Sep 24, 2026, 2:02 AM (UTC+3)
Topic · Threat Actors & Campaigns
CVE ID : CVE-2026-93352 Published : Sept. 23, 2026, 10:16 p. m. • 42 minutes ago Description : Laravel-Mediable 7. 0. 0 before 7. 0. 2 contains an incomplete patch for CVE-2026-49972 in which the . pht extension is absent from the forbidden_extensions blocklist in config/mediable. php. The blocklist introduced to address CVE-2026-49972 includes phpt but omits pht, which Apache executes as PHP via the default FilesMatch directive on Debian and Ubuntu systems. An attacker can upload a . pht file that passes all validation in MediaUploader::verifyExtension() and File::sanitizeFileName() because pht is not present in the blocklist, causing the file to be written to disk and executed as PHP when requested, enabling remote code execution with the privileges of the web server process.
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [... ]
A new dedicated leak site by threat actors calling themselves “The Seven Deadly Sins” lists Canva Pty Ltd among the sites that haven’t paid them. DataBreaches obtained additional details on the incident and this new group. Attack on Canva A spokesperson for The Seven Deadly Sins (TSDS) informed DataBreaches that on August 28, TSDS attacked… Source https://databreaches.net/2026/09/23/canva-hacked-via-vendors-salesforce-instance-other-customers-affected-as-well/1post-1participantReadfulltopic
ShinyHunters claims to have breached FBI systems. CLOSEDQUORUM malware delegates command-and-control decisions to commercial LLMs. An IT error erases 11 years of hospital maternity data. F5 patches a critical BIG-IP APM zero-day. Ransomware activity remains high. Microsoft disrupts the EvilTokens cybercrime platform. Researchers turn Claude Code’s normal workflow against itself. Pundits propose an AI Assurance Compact. A Ryuk ransomware gang member gets two years prison time. Our guest is Jen Sovada, General Manager of Public Sector at Claroty, on Project Watershed 250 and the challenges facing U. S. water utilities. Meta’s Muse mettles with messages. Remember to leave us a 5-star rating and review in your favorite podcast app. Miss an episode? Sign-up for our daily intelligence roundup, Daily Briefing, and you’ll never miss a beat. And be sure to follow CyberWire Daily on LinkedIn.
Serial Number: AV26-960 Date: September 23, 2026 As of September 23, 2026, Forcepoint is affected by a vulnerability in the following product: • Forcepoint Security Engine (NGFW) • Versions 7.1.0 to 7.1.13 • Versions 7.3.0 to 7.3.1 • Version 7.33 • Version 7.4.0 to 7.4.1 • Version 7.5.0 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. • Forcepoint Hub • Forcepoint Help and Resource Center Forcepoint security advisory (AV26-960) - Canadian Centre for Cyber Security
Serial number: AV26-959 Date: September 23, 2026 As of September 21, 2026, Dell is affected by vulnerabilities in the following products: • Dell Command Powershell Provider (DCPP) • Prior to 2.10.2 • Dell Command Monitor (DCM) • Prior to 10.13.2 • Dell Inventory Collector Client • Prior to 15.0.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available.
You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts. The message claims the code will let you open the document or join the meeting. In fact, it approves a sign-in the scammer started. The page is real and the code works, which is why this type of attack—known as device code phishing—is so dangerous. Device code phishing abuses a legitimate sign-in feature intended for devices that cannot easily display a normal login screen (such as smart TVs, printers, conference-room equipment, and some command-line tools). Instead of entering a username and password on the device itself, you open a browser on another device, visit a sign-in page, enter a short code, and approve the sign-in.
With Pwn2Own Ireland 2026 coming up, I wanted to share an unreleased blog post from my time as a Pwn2Own contestant. This post covers the discovery and exploitation of CVE-2024-0244, which is an unauthenticated heap-based buffer overflow leading to an arbitrary free() in the Canon MF753Cdw printer featured in Pwn2Own Toronto 2023. This blog post gives an overview of the vulnerability and the exploitation techniques used. Figure 1 - MF753Cdw printer Figure 1 - MF753Cdw printer Previously, I had exploited the very similarly named MF743Cdw at Pwn2Own Toronto 2022 using a classic stack buffer overflow, so I had a solid baseline understanding of this family of printers and their quirks. Starting Point Over the years at Pwn2Own, the Canon family of printers has been exploited many times, which means that many researchers have combed through the firmware.
Serial number: AV26-958 Date: September 23, 2026 As of September 22, 2026, MikroTik is affected by a vulnerability in the following product: • RouterOS • Prior to 7.25beta5 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. • 7.25beta [development] is released! MikroTik security advisory (AV26-958) - Canadian Centre for Cyber Security
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [... ]
The potentially serious breach highlights the supply chain risks facing even the most sophisticated organizations.
Serial number: AV26-957 Date: September 23, 2026 As of September 22, 2026, NVIDIA is affected by vulnerabilities in the following products: • Infrastructure Controller • Versions 0 to 1.9 • NeMo Speech • Versions 0.0 to 2.9 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. • Security Bulletin: NVIDIA Infrastructure Controller - September 2026 • Security Bulletin: NVIDIA NeMo Speech - September 2026 • NVIDIA Product Security NVIDIA security advisory (AV26-957) - Canadian Centre for Cyber Security
The Pentagon’s top civilian cyber policy official said Tuesday her single priority is expanding the cyber options available to the president and the defense secretary, describing a gap between what commanders are asking for and what the force can deliver. “I’m focused on one single priority, and that is building a more robust set of capabilities for the secretary and the president,” said Katie Sutton, assistant secretary of defense for cyber policy, at DefenseTalks, hosted by DefenseScoop. “The demand far exceeds the supply we have.” Sutton traced the department’s posture to 2018, when the military gained authorities to run cyber operations as a traditional military activity. “In those last eight years, we’ve learned a lot, but I feel like the last year has really been the year that cyber has sort of entered the limelight,” she said.
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terraform providers and Go modules is below - gocommunity-io/dockerd (222 downloads) kreuzwenker/
Serial number: AV26-954 Date: September 23, 2026 As of September 22, 2026, Ubiquiti Inc is affected by vulnerabilities in the following products: • Cloud Gateways • Prior to 5.1.31 • Dream Machines • Prior to 5.1.31 • Dream Routers • Prior to 5.1.31 • Dream Wall • Prior to 5.1.31 • Enterprise Firewalls • Prior to 5.1.31 • Express • Prior to 4.0.21 • Express 7 • Prior to 5.1.31 • UniFi Gateways • Prior to 5.1.26 The Cyber Centre encourages users and administrators to review the provided web link and apply any necessary updates as they become available. • Security Advisory Bulletin 069 Ubiquiti security advisory (AV26-954) - Canadian Centre for Cyber Security
A 35-year-old Armenian national was sentenced to two years in prison for his involvement in a series of Ryuk ransomware attacks while living in Ukraine and Russia in 2019 and 2020, the Justice Department said Tuesday. Karen Vardanyan was extradited from Ukraine to the United States last year and pleaded guilty to computer fraud and conspiracy to commit fraud and extortion in July. Vardanyan’s sentencing, which also calls for about $1. 2 million in restitution to victims, matches terms of a plea agreement he reached with prosecutors. Vardanyan and his co-conspirators’ victims include a Michigan-based company that paid a ransom of nearly $1.2 million in January 2020, a Watsonville, Oregon-based technology company that was attacked in December 2019 and a Texas-based school breached in February 2020, according to court records.
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [... ]
The United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.
The physics of cybersecurity are changing. So must the security operations center (SOC). Cyberattackers are using agents to automate execution at unprecedented scale. What once required entire teams now requires a single operator and an agent framework. That shift has exposed a hard truth: security cannot operate at AI speed when protection and operations are built as separate systems. Every handoff, integration, and boundary slows defenders down. Agents inherit that complexity. For agentic security to work, the industry needs a different model. It needs a modern cyber stack with the breadth to see across the environment and the depth to investigate and act. Security operations and native protection must function as one system. This is the integrated security operations center (ISOC).
OpenAI and the Ukrainian government have agreed to a partnership that will provide AI tools and subsidized computing resources to better protect the nation’s critical infrastructure from cyberattacks. The agreement, announced Wednesday at OpenAI’s New York office, will provide Ukrainian cybersecurity officials with access to advanced AI models designed for cybersecurity work through the company’s Daybreak program. OpenAI said it is also pledging over $1 billion in subsidized tokens to support the initiative. During a panel discussion Dmytro Kushneruk, consul general of Ukraine in San Francisco, outlined how the tools would be used for cybersecurity automation, including functions such as incident response, threat triaging, login analysis, inventorying systems, code analysis and validating vulnerabilities.
Many companies still aren’t preparing thoroughly enough to face a hack, the insurance firm Travelers said in a new report.
Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.
The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS, we strongly support this message. As threat actors continue to target credentials through phishing, credential stuffing, and social engineering, passwords alone are no longer enough. MFA is one of the most effective security controls available. It’s a cornerstone of ASD’s Essential Eight maturity model and a recognized component of major cybersecurity frameworks worldwide.
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
Qrator found a Windows botnet advertised with AI API draining, credential theft and SOCKS5 proxying
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS. According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below - @memtensor/memos-cloud-openclaw-plugin versions
DarkMe, a remote access trojan and info-stealer that has previously been associated with a threat group that targeted financial market traders and cryptocurrency users, has been spotted again. This time around, its distribution has been simplified: instead of leveraging zero-day exploits, attackers are betting on a simple email to convince targets to run it on their machine: The malicious email pointing to the first stage downloader for DarkMe (Source: Huntress) The link supposedly points to … More → The post DarkMe RAT trades zero-days for plain phishing emails appeared first on Help Net Security .
Phishing follows whatever people want at the moment, and right now that includes AI subscriptions they don’t have to pay for. We recently uncovered a new variation on this theme: A fake Claude Max giveaway that uses a convincing Google sign-in window to steal login information. Claude’s paid plans start at $20 a month and cost considerably more for higher usage limits, while free accounts have stricter limits. That makes the promise of a free upgrade an attractive lure. Microsoft reported in June that it had seen a growing number of phishing, malicious advertising, and search-based campaigns impersonating services such as ChatGPT, Claude, DeepSeek and Copilot. Some claim that a payment has failed and send you to a fake checkout. Others offer an app download that installs malware. The campaign we found takes a different approach.
A financially motivated threat actor is using autonomous AI agents to compromise online retailers at a reported average cost of roughly $25 per target. The campaign, active since at least July 2026, has reportedly stolen more than 600,000 unexpired payment card records, deployed web skimmers, and accessed systems belonging to major retailers, travel companies, and … The post AI agents steal 600,000 credit cards in attacks on online retailers appeared first on CyberInsider .
Extortion group ShinyHunters is not afraid to make enemies. Now it claims to have breached the FBI. After reportedly taking over ransomware group Clop’s leak site , ShinyHunters says it attacked the FBI to punish the agency for spreading what it calls false information about the group. In a very long post on its leak site, the group outlines its grievances: “ PSA – READ THIS NOW Dear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI, During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended. We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to “disrupt” our operations, an effort that ultimately proved unsuccessful.
Introduction The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical infrastructure entities to reduce risk and minimize vulnerabilities when working with third-party industrial control system (ICS) integrators. ICS is an umbrella term referring to integrated networks of hardware and software designed to monitor and automate physical processes, encompassing specialized control systems and devices, such as supervisory control and data acquisition (SCADA) systems and programmable logic controllers. Third-party integrators provide varying types of services for ICS, such as control system design, installation, operational data analysis, device support and service, and daily operational control.
Fake verification pages are steering people toward malware, but the web addresses behind the lures keep changing. Over five months, investigators tracked four different attack chains that began with the same hosting network, even as domains, downloads and command servers shifted. The pattern makes blocking individual websites a poor way to stop the first step. Most victims reached a fake CAPTCHA through online ads, although one arrived through an emailed link. The page quietly copied a command to the clipboard, then told the visitor to open the Windows Run box and paste it. As with earlier fake CAPTCHA attacks , following those instructions could start an infection without opening a suspicious attachment. Analysts from ActiveSOC identified the shared infrastructure while reviewing roughly 150 alerts across monitored environments.
Lapsus$ is a hacking and extortion group first known for breaching Okta, Microsoft, Nvidia, Samsung, and Uber in 2021 and 2022 using social engineering rather than malware, and it has since reemerged as part of a larger collective called Scattered Lapsus$ Hunters. Unlike ransomware gangs that rely on encryption, Lapsus$ built its reputation on stealing source code and internal data, then threatening to leak it publicly unless the victim paid or complied with its demands. This tactic made it one of the most disruptive threat actors of the past few years despite reportedly being run largely by teenagers. That threat hasn’t gone away; it’s evolved.
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold to cybercriminals through Telegram. The service costs $1,500 upfront and $500 per month, with additional tools available for extra fees. Its control panel lets customers build and manage phishing campaigns, customize landing pages, configure domains, track victims, and manage stolen authentication tokens. The platform includes 44 themes and uses AI to create targeted phishing emails based on a victim’s role.
EvilTokens turns a Microsoft sign-in into a route to corporate email fraud. The phishing kit, first seen in February 2026, tricks people into approving an attacker’s login through a real device code process without handing over a password. The lure usually arrives as an urgent email about an invoice, shared file, document signature or expiring password. A link or attachment takes the recipient to a page that presents a code and urges them to continue with the sign-in. The request looks routine. Microsoft researchers tied EvilTokens to a group they track as Storm-2992 and said the toolkit helped scale business email compromise. Microsoft said in a report shared with Cyber Security News (CSN) that campaigns using the kit compromised more than 12,000 inboxes at over 10,000 organizations worldwide. Affected sectors include finance, construction, healthcare and education.
A threat group best known for exploiting previously unknown flaws in WinRAR and Windows has switched to a much simpler method: an email link to what appears to be an image. New research from Huntress details a 2026 campaign delivering DarkMe, a remote access trojan (RAT) historically linked to Water Hydra and also tracked as DarkCasino. The group made headlines in 2023 and 2024 for weaponising two zero-days, CVE-2023-38831 in WinRAR and CVE-2024-21412 in Windows Defender SmartScreen, in attacks on foreign exchange traders. This time, no exploit is involved. According to Huntress, victims receive a phishing email containing a link that looks like it serves a picture but instead downloads a file called image. pif, a Windows program in disguise. The file carries forged details suggesting it belongs to a security product named “Aegis Sentinel”.
According to fresh ANY. RUN data, phishing exposure remains above 70% in several critical industries. This doesn’t happen because organizations aren’t protected enough. Companies have been implementing email filtering, MFA, and phishing-awareness training for years. However, threats continue to evolve, and security methods that were highly effective yesterday can develop visibility gaps as attackers adapt. In this article, ANY.RUN explores data-driven insights to get to the bottom of phishing risk across key industries in the United States and examines how SOC teams can mitigate it. See our previous article on phishing risk among US-based financial organizations. Phishing Risk Remains High Across Critical Industries Phishing exposure statistics based on ANY.RUN submissions data, 2026 As the statistics show, very different industries face almost the same level of phishing exposure.
ManageEngine has fixed a high-severity remote code execution vulnerability in ADSelfService Plus that could allow an unauthenticated attacker with physical access to a Windows logon screen to execute arbitrary code as NT AUTHORITY\SYSTEM. Tracked as CVE-2026-74849, the flaw affects the product’s GINA client component, which integrates ADSelfService Plus password reset and account-unlock functions into the Windows logon experience. The issue affects ADSelfService Plus builds 7000 and earlier and was fixed in build 7001, released on August 24, 2026. ManageEngine ADSelfService Plus Flaw The vulnerable GINA client presents the ADSelfService Plus self-service password reset and account unlock portal directly on the Windows sign-in screen. It uses an embedded kiosk browser to enable users to access those recovery capabilities before authenticating to Windows.
WordPress has released version 7. 1. 2 to address a critical core vulnerability that could allow unauthenticated attackers to achieve remote code execution under specific server and theme configurations. Tracked as CVE-2026-87902 and GHSA-7hp8-65ch-5whp, the flaw carries a CVSS v4 score of 9. 2 and affects WordPress installations dating back to version 4. 7. The issue resides in WordPress page-template resolution, specifically within the get_page_template() functionality. An attacker does not need a WordPress account or any privileges to exploit the flaw. Critical WordPress Core Flaw By manipulating page-template handling, they may be able to cause WordPress to include a readable local PHP file located outside the active theme directory.
A new PamStealer variant is targeting macOS users through a fake cryptocurrency wallet installer. In research published on September 22, Jamf Threat Labs said the malware steals passwords and browser data while using a server-controlled decryption process that makes its payload harder to analyze. The attack begins at wavel[. ]app , a site impersonating a multichain crypto wallet. Its macOS download button delivers a disk image containing a compiled . scpt file. Because Finder normally hides file extensions, the file can appear to be an ordinary document. If a user opens it in Script Editor and follows the displayed instructions, embedded JavaScript for Automation runs a hidden zsh dropper. The dropper downloads a tool called pkgunpack and an encrypted payload from wavel. apple03cloudstore[. ]com . Unlike earlier PamStealer variants, it does not carry the payload’s decryption key.