WaterPlum North Korean Hackers Infect 30,000 Devices and Steal $10.7 Million in Cryptocurrency
September 19, 2026 A joint law enforcement advisory from the United States, Japan, Australia, and Germany warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide. The group also transferred more than $10.7…
BragJack Attack Hijacks AI Browser Agents
September 19, 2026 Security researcher Gal Weizman of Forever Security has disclosed BragJack, a new attack technique that hijacks AI browser agents through malicious extensions. The proof-of-concept works against five major Chromium-based browsers and…
Gyazo Data Breach Exposes 23.6 Million Users
September 19, 2026 The Gyazo image-sharing platform has confirmed a massive data breach after attackers exploited a server vulnerability. Consequently, approximately 23.6 million user records and 490 million image metadata entries were exposed. The…
Check Point Root RCE via Management Server Login Flaw
September 18, 2026 Check Point Software has disclosed a critical vulnerability that lets unauthenticated attackers execute code with root privileges on Security Management Server and Log Server systems. The flaw, tracked as CVE-2026-91843, stems from a…
Critical Unbound DNSSEC Validator RCE via Malicious DNS Zone
September 18, 2026 A critical heap overflow vulnerability in the Unbound DNS resolver enables remote code execution through malicious DNS zones. The flaw, tracked as CVE-2026-81642, affects every Unbound release before version 1.26.1 and carries a CVSS…
Iranian Hackers Deploy CHOSEN BRICK Malware
September 16, 2026 Government agencies in the United States, United Kingdom, and the Netherlands have issued a joint warning about an Iranian state-linked espionage campaign that deploys a Windows malware strain named CHOSEN BRICK. The malware targets…
Ransomware Gangs Exploit Critical VMware vCenter RCE CVE
September 16, 2026 Ransomware gangs have joined attacks exploiting a critical VMware vCenter remote code execution flaw. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities catalog to flag…
Google Patches Actively Exploited Android Zero-Day on Pixel Devices
September 16, 2026 Google has released the September 2026 security patches for Pixel devices. This update fixes 110 vulnerabilities, including one zero-day flaw that is actively exploited in targeted attacks. The zero-day, tracked as CVE-2026-58704, is a…
Cisco Secure Email Gateway CVE Critical Zero-Day
September 15, 2026 Cisco has disclosed a critical zero-day vulnerability in its Secure Email Gateway that threat actors are actively exploiting to gain root-level command execution. The flaw, tracked as CVE-2026-76461, carries a CVSS score of 9.8 and was…
CISA Confirms Active Exploitation of Critical GitLab Path Traversal
September 14, 2026 CISA has added CVE-2026-85706 to its Known Exploited Vulnerabilities catalog after confirming active exploitation in the wild. This maximum-severity path traversal flaw affects GitLab Community Edition and Enterprise Edition.…