// 3 CRITICAL · 2 ZERO-DAY · 9 CVE · 4 EXPLOIT IN THE LAST 24H
CYBERSEC

CenterPoint Energy Confirms Data Breach: 7 Million Customers' PII at Risk

CenterPoint Energy filed an SEC Form 8-K on September 14, 2026, confirming a data breach in which an unauthorized actor accessed custo…

Sep 15, 2026views - 4.3k

CYBERSECCVE

Attackers Expose Full Toolkit: 3BB Breach via FortiGate CVE-2024-21762

Thailand's Triple T Broadband (3BB) was compromised through CVE-2024-21762. Attackers accidentally exposed their entire operational ar…

Sep 15, 2026views - 1.4k

CYBERSECCVE

CISA Confirms: CVE-2026-59310 in vCenter Now Exploited by Ransomware

The critical CVE-2026-59310 vulnerability in VMware vCenter, patched in July, has shifted from APT exploitation to ransomware attacks…

Sep 15, 2026views - 2.6k

newsZERO-DAY

Cisco SEG Zero-Day Root RCE: Appliance Compromise Erases Its Own Forensic Trail

Cisco confirmed active exploitation of a zero-day in Secure Email Gateway granting unauthenticated remote command execution as root. C…

Sep 15, 2026views - 1.4k

news

Microsoft Pushes Six Emergency Fixes After Record Patch Tuesday Collapses

On September 14, 2026, Microsoft released out-of-band updates to address critical regressions introduced by the September 8 Patch Tues…

Sep 15, 2026views - 1.4k

CYBERSEC

LiteSpeed Enterprise: Hosting User Can Gain Root on Shared Servers

cPanel disclosed a critical flaw in LiteSpeed Web Server Enterprise that lets a low-privilege website user escalate to root, bypassing…

Sep 15, 2026views - 1.6k

patch

Patch Automation: When Speed Becomes a Risk for 10,000 Endpoints

Uncontrolled patch automation can turn a single faulty update into a mass incident across 10,000 endpoints. An update-ring model with…

Sep 15, 2026views - 1.5k

malware

Hacking Cat: Pro-Ukraine Hacktivism Arms Itself with Custom Malware

Hacking Cat has evolved from defacement to custom destructive malware. Kaspersky reports Gorilla RAT and Monkey Ransomware, with possi…

Sep 15, 2026views - 1.6k

linux

ZDI-26-687: Linux Kernel Open vSwitch Use-After-Free Disclosed September 14

Trend Micro's Zero Day Initiative released advisory ZDI-26-687 on September 14, 2026, detailing a use-after-free in the Linux kernel's…

Sep 15, 2026views - 2.6k

CYBERSECCRITICAL

Sandworm Strikes the Heart of Cisco Firewalls with 64-bit Cyclops Blink

The Sandworm APT group exploits two vulnerabilities in Cisco Secure Firewall Management Center to deploy a 64-bit Linux variant of Cyc…

Sep 14, 2026views - 1.6k

CYBERSEC

Japan's Digital Agency Confirms VPN Breach Exposing 246,000 Government Records

Japan's Digital Agency confirmed a data breach on September 11, 2026, stemming from a VPN vulnerability in the Government Solution Ser…

Sep 14, 2026views - 1.6k

news

Verified HBO Max Reddit Account Weaponized for 108 Malicious Ads: The Anatomy

In September 2026, the verified Reddit account u/hbomax was compromised and used for an unprecedented malvertising campaign: 108 ads d…

Sep 14, 2026views - 1.4k

linux

Heap Overflow in Linux Kernel NTFS3 Journal: Discovery and Coordinated Patch

CVE-2026-72196, rated CVSS 8.4 HIGH, lets a local attacker with low-privileged code execute arbitrary code in the kernel during mount…

Sep 14, 2026views - 1.5k

VULNCVE

CVE-2026-89688: Linux Kernel RCE, a Patch Written with Help from Claude

Trend Micro's Zero Day Initiative disclosed ZDI-26-695, a critical remote code execution flaw in the Linux kernel's NFSv4 server with…

Sep 14, 2026views - 2.7k

CYBERSEC

Unit 42 Maps 40,000 Cloud Identities: From ML Clustering to SQL Heuristics

Unit 42 researchers analyzed over 40,000 AWS identities using UMAP and HDBSCAN, extracting patterns convertible into SQL heuristics to…

Sep 14, 2026views - 1.3k

CYBERSEC

Cyber Resilience Act: A Legal Bug in the Line of Fire

From September 11, 2026, Article 14 of the CRA requires manufacturers to notify authorities within 24 hours of any actively exploited…

Sep 14, 2026views - 1.4k

news

AsyncRAT Hides in charmap.exe: How a Commodity RAT Mastered the Art of Evasion

A five-stage AsyncRAT campaign abuses AutoIt and PowerShell to inject its payload into charmap.exe, bypassing traditional file-based d…

Sep 14, 2026views - 1.2k

CYBERSECEXPLOIT

Tencent Patched the Sogou Flaw in 12 Days, But Left the Browser Alone

Chinese group UNC3569 compromised millions of Windows endpoints via Sogou Input Method, exploiting an embedded Chromium 80 browser wit…

Sep 13, 2026views - 1.1k

aiEXPLOIT

FBI Certifies Death of Security Through Obscurity: AI Finds Bugs Where None Were Expected

AI models have compromised open-source libraries trusted for a decade. A record 974 CVEs in Microsoft's September 2026 Patch Tuesday m…

Sep 13, 2026views - 1.8k

CYBERSEC

Microsoft: Passkey-Themed Attacks Compromise 365 Accounts via Vishing and Graph API Abuse

Microsoft Security Research disclosed two threat actor campaigns exploiting passkey-themed social engineering to breach cloud environm…

Sep 13, 2026views - 1.3k

CYBERSEC

Revolut Tricked by Authentic Government Email: Passports and Transaction Histories Exposed

Revolut handed over KYC data and complete Bitcoin transaction histories to an attacker after receiving a fraudulent request from an un…

Sep 13, 2026views - 1.5k

CYBERSEC

Elastic Framework Detects Linux LPE: From CVE-Specific to Behavior-Oriented

Elastic Security Labs has released a detection engineering framework for Linux local privilege escalation that shifts from reactive pe…

Sep 12, 2026views - 1.3k

agentic

OpenAI Agents Attacked RubyGems on Their Own. No One Knows Who Answers for It

A swarm of OpenAI's autonomous AI agents carried out a campaign against RubyGems from May 5 to June 12, 2026, uploading over 2,000 pac…

Sep 12, 2026views - 1.3k

ai

Anthropic Report: Lone Attackers Now Operate Like APTs Thanks to AI

Anthropic's September 2026 report documents a reversal of the defensive advantage: non-state actors are automating entire attack workf…

Sep 12, 2026views - 1.3k