This website uses cookies

Read our Privacy policy and Terms of use for more information.

ShinyHunters is exploiting Oracle PeopleSoft systems across multiple industries, and Google’s threat intelligence teams found web shells on dozens of systems. The group changed its exploit to bypass web application firewall rules, while media reports linked a PeopleSoft breach at the FBI to stolen staff information, including Social Security numbers and medical records.

Other attacks are reaching systems that control access and hold sensitive data: attackers are exploiting F5 BIG-IP systems configured as OAuth authorization servers, SharePoint and MikroTik routers.

Separately, the Pentagon confirmed that intruders exploited a file-sharing flaw to expose unencrypted personal information on 2.76 million living people and about 294,000 deceased people.

AI credentials and tools are also turning up in active attacks, not just lab tests: Carbonato steals AI API keys from hacked Docker hosts, and RatHat uses Gemini to rank victims by estimated bank balances.

Those findings differ from the AI-voting malware reported by Cisco Talos, which researchers have not observed working end to end, and OpenAI’s self-replicating prompt injections, which remained inside simulations.

Chinese threat actor UTA0565 exploited Chrome and Windows zero-days through fake websites to deploy CLEANGULP malware, including in a phishing campaign targeting Asian government entities. Attacks detected September 3–4, 2026, chained Chrome flaws CVE-2026-85046 and CVE-2026-87491 with Windows flaw CVE-2026-85880 to escape the browser sandbox and execute code. CLEANGULP supports command execution, file transfers and process listing.

Apple released iOS 26.7.1 and iPadOS 26.7.1 to fix CVE-2026-86950, a CoreGraphics zero-day it says may have been exploited against specific individuals running iOS versions before iOS 27. The out-of-bounds write flaw allows arbitrary code execution through a maliciously crafted file and affects iPhone 11 and later models and supported iPads. Meta Product Security reported the vulnerability.

A cluster of 31 Russian-language Chrome extensions posing as VPN tools routed browser traffic through remotely controlled proxies and amassed roughly 356,000 installations. The extensions share a codebase and download routing instructions that let operators change targeted sites and proxy servers without updating the extensions. Most target specific services, but the “Total VPN” variant routes all browser traffic.

Google released Chrome 154 for Windows, macOS and Linux to fix 108 vulnerabilities, including 11 critical flaws that could allow code execution through malicious web content. The fixes include CVE-2026-95350, a buffer overflow in the ANGLE graphics layer, and critical memory-corruption bugs in WebGL and GPU components. The update is rolling out gradually.

Researcher Abdelhamid Naceri published BigDiskBuster on GitHub on September 19, a proof-of-concept tool that fills available disk space to block Microsoft Defender platform and signature updates. Defender keeps running, but its detection content grows stale. No patch, CVE or Microsoft advisory exists, and no independent researcher has confirmed Naceri’s claim that the tool works on all supported Windows versions.

Microsoft patched CVE-2026-66804, a Windows flaw that let low-privileged local users gain SYSTEM privileges by planting a malicious DLL, in its August 2026 updates. The vulnerability stemmed from a dangling CrossDevice COM registration left behind by an incomplete fix for “Dark Elevator.” Public proof-of-concept code and a commercial exploitation module are available.

watchTowr reported that attackers exploited two unpatched remote code execution flaws in Citrix NetScaler, citing forensic investigations. Citrix had not issued an advisory, CVE identifiers or affected builds at the time of publication, and the claims lacked vendor confirmation. watchTowr described the flaws as separate from previously disclosed vulnerabilities, including the actively exploited authentication bypass CVE-2026-19490.

Attackers are exploiting CVE-2026-94127 to run code without authentication on F5 BIG-IP Access Policy Manager systems configured as OAuth authorization servers. F5 released engineering hotfixes for the critical heap-based buffer overflow; systems used only as OAuth clients or resource servers are unaffected. CISA added the flaw to its Known Exploited Vulnerabilities catalog and set a September 25 mitigation deadline for federal civilian agencies.

CISA added an actively exploited flaw in Zyxel GS1900 switches, CVE-2026-7273, to its Known Exploited Vulnerabilities catalog; the patched bug allows unauthenticated attackers on the LAN to execute OS commands. Arctic Wolf also reported active exploitation of CVE-2026-32996 in Veeam Agent for Microsoft Windows, which lets attackers with local access execute commands as SYSTEM.

Poper Blocker, a purported ad blocker downloaded by millions, exfiltrates large amounts of sensitive information and remains available in the Chrome Store. Researchers have warned about the extension, which continues to benefit from Google's stamp of approval.

Microsoft identified NeedyMantis, a modular malware framework used to maintain access to breached networks in a small number of targeted intrusions affecting telecom providers, universities, medical nonprofits, intergovernmental bodies and government contractors. Activity dates to at least October 2025. Attackers deploy it after gaining initial access, using DLL sideloading through legitimate applications; Microsoft has not observed delivery through the compromised DAEMON Tools supply chain.

Quick Hits

Reply

Avatar

or to participate