Find notable cyber news and cases, enriched with sources, timelines, and signals.

Recent notable Happenings and Cases

Hide ▲
Last updated: 19:20 21/09/2026 UTC
  • Campaign H score 36 Rust crate-owner social engineering campaign via video calls A Rust ecosystem social-engineering campaign is targeting Rust team members and crate owners via video calls to drive malicious code installs or clipboard payloads, raising the risk of trusted crates.io account abuse.
  • Campaign H score 32 PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account PasteSwitch abused HBO Max’s verified Reddit account to push ClickFix ads that delivered information-stealing malware to Windows and macOS users, showing how brand channels are being weaponized for rapid infection.
  • Campaign H score 31 TASK#STOMP PowerShell backdoor delivery campaign The newly disclosed TASK#STOMP campaign uses VBScript and PowerShell stages to drop a persistent backdoor that steals documents, credentials, clipboard contents, and screenshots, expanding the active toolkit for data theft and remote control.
  • Campaign H score 30 Revolut customer smishing and phishing campaign Malwarebytes linked a Revolut smishing/phishing wave to a Revolut data breach, escalating account-takeover risk by extending lures into fraudulent KYC checks impersonating law enforcement.
  • Regulatory/Legal Action H score 29 Ireland DPC fines Google over GDPR location-data processing Ireland’s DPC fined Google €403 million over GDPR violations in location-data processing and ordered changes within six months, tightening regulatory pressure on how major platforms handle location history and retention.
  • Malware Activity H score 27 GHAPPIER loader in @dforge-core/dforge-mcp malicious npm release CloudSEK traced the GHAPPIER loader from a malicious npm release across at least 65 repositories and 22 accounts, underscoring supply-chain reach even when provenance checks appear valid.
Last updated: 05:50 21/09/2026 UTC

Latest updates

Browse →

CISA orders federal agencies to patch Linux kernel flaws

Public Sector Action

Updated: 21.09.2026 23:12 · First: 21.09.2026 23:12 · 📰 1 src / 1 articles · H score: 30

CISA ordered federal agencies to apply security updates and mitigations for three Linux kernel flaws by end of today, putting the response on an urgent federal timeline. The directive also requires forensic triage on affected assets to check whether exploitation has already occurred. CISA says the vulnerabilities have been exploited in attacks, increasing the operational urgency for agencies.

Linux kernel active exploitation wave (CVE-2025-39964, CVE-2026-53266, CVE-2025-39682)

Exploitation Wave

Updated: 21.09.2026 23:12 · First: 21.09.2026 23:12 · 📰 1 src / 1 articles · H score: 35

CISA has warned that three Linux kernel vulnerabilities are being exploited in attacks, including one critical flaw, creating immediate risk for exposed systems. The wave covers CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, with public exploits available for at least one issue and a known exploit for another. Federal agencies were ordered to apply available security updates and mitigations by end of today and to perform forensic triage on affected assets.

Linux kernel race condition, out-of-bounds write, and TLS flaw (multiple vulnerabilities)

Vulnerability

Updated: 21.09.2026 23:12 · First: 21.09.2026 23:12 · 📰 1 src / 1 articles · H score: 36

Attackers are actively exploiting three Linux kernel vulnerabilities in AF_ALG, ebtables SNAT, and kTLS, and CISA has ordered urgent mitigation for federal systems. The flaws are CVE-2025-39964, CVE-2026-53266, and CVE-2025-39682, spanning medium to critical severity and including a critical race condition, an out-of-bounds write, and a TLS receive-path logic flaw. Public exploits are available for two of the flaws, and one was demonstrated with privilege escalation and container escape.

WordPress core security release (7.1.1)

Security Patch Release

Updated: 18.09.2026 19:56 · First: 18.09.2026 19:56 · 📰 2 src / 2 articles · H score: 45

WordPress 7.1.1 is a security release that fixed the Click2Shell WordPress Core flaw, a CSRF issue that could let a logged-in administrator open a crafted link and trigger a theme install from WordPress.org without clicking Install. pwn.ai said the flaw can be chained with a separate weakness in the Mobile Repair Zone theme to reach server-side code execution and run attacker PHP. The published report says the issue can be abused through a crafted URL and was fixed in WordPress 7.1.1, with support covering branches back to 4.7.

WordPress core Click2Shell security flaw

Vulnerability

Updated: 18.09.2026 19:56 · First: 18.09.2026 19:56 · 📰 2 src / 2 articles · H score: 37

WordPress core’s Click2Shell vulnerability is a CSRF chain that can let a logged-in administrator open a crafted URL, force-install a theme from the WordPress.org catalog, and reach arbitrary PHP execution on the server when chained with a theme weakness. The flaw affects WordPress Core 7.1.0 and earlier and was fixed in WordPress 7.1.1 after WordPress shipped the patch on September 17, 2026. pwn.ai later published technical details and a proof-of-concept exploit, showing the chain can be used to force-install other vulnerable themes as well. The public write-up says attacks can be delivered through crafted links and may be triggered by phishing or an XSS condition that causes the administrator’s browser to send the request.

Rapuncel infostealer delivered through SEO-optimized fake GitHub repositories

Malware Activity

Updated: 18.09.2026 18:19 · First: 18.09.2026 18:19 · 📰 2 src / 2 articles · H score: 26

Rapuncel is an ongoing malware campaign that uses SEO-optimized fake GitHub repositories to impersonate software brands, including LastPass, and lure people searching for LastPass Authenticator or similar software. The delivery chain drops a ZIP with vsdbg.exe and vsdbg.dll, then loads the Microsoft Windows Hardware Compatibility Publisher-signed Alinubx.sys driver to kill antivirus and EDR before the stealer runs. Researchers at LastPass and Delphos Labs said the fake page at github.com/LastPass-Authenticator also led to collection of browser passwords, Windows Credential Manager data, cryptocurrency wallet files, and Discord, Steam, and Telegram sessions. LastPass said its own systems, services, and customer vaults were untouched.

Ireland DPC fines Google over GDPR location-data processing

Regulatory/Legal Action

Updated: 21.09.2026 18:41 · First: 21.09.2026 18:41 · 📰 2 src / 2 articles · H score: 29

Ireland’s Data Protection Commission imposed a €403 million penalty on Google for GDPR violations tied to location-data processing, forcing the company to change its data practices. The order covers Web and App Activity, Location History, and Location Accuracy, with findings on unlawful processing, transparency failures, and excessive retention. Google must bring its user data processing into compliance within six months.

Irish Data Protection Commission (DPC) Fined Google €403m and required compliance changes within six months. on The order addresses unlawful location-data processing transparency

Regulatory/Legal Action

Updated: 21.09.2026 18:00 · First: 21.09.2026 18:00 · 📰 2 src / 2 articles · H score: 28

The Irish Data Protection Commission fined Google €403m ($460m) for GDPR violations involving location data. The enforcement action covers Web & App Activity, Location History and Location Accuracy over May 25, 2018 to February 4, 2020. Google must bring its processing into compliance within six months, after regulators said the practices weakened users’ control over their personal data.

Exvicy and ErrTraffic code reuse analysis

Technical Analysis

Updated: 21.09.2026 17:30 · First: 21.09.2026 17:30 · 📰 1 src / 1 articles · H score: 22

Exvicy now has a high-confidence code link to ErrTraffic, giving defenders a clearer basis for attribution and detection across the shared delivery chain. The comparison shows the two frameworks reuse the same logic in the injected script and lure page, not just similar messaging. Shared functions include clipboard handling, fingerprinting, anti-analysis, and polling routines, while Exvicy differs by hardcoding two C2 servers. The code overlap exposes a reusable technical fingerprint for tracking related ClickFix infrastructure.

TASK#STOMP PowerShell backdoor delivery campaign

Campaign

Updated: 21.09.2026 17:15 · First: 21.09.2026 17:15 · 📰 1 src / 1 articles · H score: 31

TASK#STOMP is a newly disclosed campaign that uses VBScript and PowerShell stages to deploy a backdoor on compromised hosts, creating ongoing risk of data theft and remote command execution. The payload steals business documents, Wi‑Fi passwords, clipboard contents, and screenshots, then sends them through redundant C2 servers. The chain relies on wscript.exe, scheduled tasks, and Startup-folder persistence to stay resident and hard to remove.

TASK#STOMP PowerShell backdoor with redundant C2

Malware Activity

Updated: 21.09.2026 17:15 · First: 21.09.2026 17:15 · 📰 1 src / 1 articles · H score: 27

The TASK#STOMP PowerShell backdoor is stealing business documents, Wi‑Fi passwords, clipboard contents, and screenshots from compromised hosts while retaining remote command execution. It uses two redundant, token-authenticated C2 servers and multiple persistence layers to keep operating after one path is removed. The activity raises the risk of ongoing credential theft and long-lived access on infected Windows systems.

FBI CJIS Security Policy v6.1 update

Public Sector Action

Updated: 21.09.2026 17:02 · First: 21.09.2026 17:02 · 📰 1 src / 1 articles · H score: 24

FBI published CJIS Security Policy v6.1 on June 25, 2026, tightening requirements for organizations that handle CJI. The update raises SC-13 encryption strength for CJI in transit from 128-bit to 256-bit and sets SC-28 at 256-bit for CJI at rest. It also changes vulnerability scanning from quarterly to at least monthly, increasing the cadence of control verification. The policy now sets the current compliance baseline for agencies preparing audits and assessments.

GHAPPIER loader in @dforge-core/dforge-mcp malicious npm release

Malware Activity

Updated: 21.09.2026 16:30 · First: 21.09.2026 16:30 · 📰 1 src / 1 articles · H score: 27

A malicious npm release of @dforge-core/dforge-mcp shipped the GHAPPIER loader with valid provenance, affecting 65 public repositories, 73 infected files, and 22 accounts. The release used GitHub Actions and OIDC trusted publishing, allowing the package to pass provenance checks while still carrying malicious code. The loader activated when the MCP server launched and opened a staged chain that ended in a self-deleting remote shell.

Rust crate-owner social engineering campaign via video calls

Campaign

Updated: 21.09.2026 14:57 · First: 21.09.2026 14:57 · 📰 1 src / 1 articles · H score: 36

The ongoing social engineering campaign against Rust-lang team members and popular crate owners threatens developer credentials and the integrity of crates.io packages. Attackers lure targets into video calls using fake job offers and contract opportunities, then push them to install software or execute clipboard-pasted code. The operation can lead to malicious packages being published from trusted accounts.

Gyazo hit by network compromise

Incident

Updated: 17.09.2026 10:30 · First: 17.09.2026 10:30 · 📰 3 src / 3 articles · H score: 68

Gyazo suffered a security breach that exposed 23.62 million user records and 490 million image metadata records, creating risk of unauthorized image access and credential abuse. The compromise came through a vulnerability in Gyazo's image upload server, and the attacker used that foothold to run arbitrary commands on Helpfeel's systems. Exposed records included email addresses, password hashes, session-related data, and image-link IDs that could let outsiders view captures without permission. Helpfeel disabled viewing for some images, told users to change passwords, and said the flaw was fixed after suspicious activity was noticed on September 11.

Revolut customer smishing and phishing campaign

Campaign

Updated: 21.09.2026 12:00 · First: 21.09.2026 12:00 · 📰 1 src / 1 articles · H score: 30

A smishing campaign is using the Revolut breach to push Revolut customers toward fake identity checks and password theft, raising the risk of account takeover. Messages seen on September 14 mimicked legitimate bank communication, including text that appeared in an existing conversation thread. The phishing flow led victims to a camera-permission prompt, a fake live-video identity check, and a password screen.

Revolut's Lithuanian-regulated entity hit by account takeover attack

Incident

Updated: 21.09.2026 12:00 · First: 21.09.2026 12:00 · 📰 1 src / 1 articles · H score: 10

Revolut's Lithuanian-regulated entity suffered a data breach tied to fraudulent KYC requests, putting several hundred accounts at risk of account takeover and identity fraud. The compromise was leveraged through compromised Italian Ministry of the Interior email accounts used to impersonate Italian law enforcement. Follow-on smishing texts and fake liveness checks extended the exposure and helped attackers harvest account credentials.

ChainScript RAT delivered via ClickFix-like lures

Malware Activity

Updated: 21.09.2026 11:39 · First: 21.09.2026 11:39 · 📰 1 src / 1 articles · H score: 23

The ChainScript RAT is being delivered through ClickFix-like lures, giving operators remote access and payload deployment control on compromised Windows systems. The malware also supports screenshot capture, file operations, wallet enumeration, and remote JavaScript execution, expanding attacker control after infection. Its operators use an EtherHiding-style C2 discovery method tied to a Polygon smart contract to locate active WebSocket infrastructure. The combination of lure-based delivery, persistence, and rotating backend discovery makes the malware harder to detect and disrupt.

PasteSwitch malicious ClickFix ads campaign via HBO Max Reddit account

Campaign

Updated: 21.09.2026 11:39 · First: 21.09.2026 11:39 · 📰 1 src / 1 articles · H score: 32

The PasteSwitch campaign abused HBO Max's official Reddit account (u/hbomax) to push 108 malicious ads over 48 hours, turning a trusted brand channel into a delivery route for ClickFix attacks. The operation infected Windows and macOS users with information-stealing malware in mid-September 2026. The lure relied on a verified account to lower suspicion and widen exposure. The campaign spread theft-oriented payloads across both desktop ecosystems.

Indexed-btree linked npm malware campaign

Campaign

Updated: 20.09.2026 17:11 · First: 20.09.2026 17:11 · 📰 1 src / 1 articles · H score: 26

The indexed-btree npm malware campaign expanded to nine additional packages linked to the same operation, widening exposure across the npm ecosystem. The packages impersonated sorted-btree and used runtime execution to bypass npm v12 install-script defenses, putting developers at risk of hidden code execution. The malware could collect host details, exfiltrate them through Slack and Telegram, and use a Sepolia smart contract for command and control.

Indexed-btree npm runtime malware activity

Malware Activity

Updated: 20.09.2026 17:11 · First: 20.09.2026 17:11 · 📰 1 src / 1 articles · H score: 24

The indexed-btree npm package is an ongoing malware activity that hides a loader in normal runtime code to evade supply-chain defenses and reach developer environments at execution time. The package impersonates sorted-btree, has about 2 million weekly downloads, and can collect host details before exfiltrating them through Slack and Telegram. It also polls a Sepolia smart contract for C2 data and can stage a second payload.

OpenAI Codex sandbox escape fixes in Desktop and CLI

Security Tool/Service

Updated: 20.09.2026 15:00 · First: 20.09.2026 15:00 · 📰 1 src / 1 articles · H score: 11

OpenAI fixed Heapjack in Codex Desktop and Overpatch in Codex CLI, closing sandbox escapes that could let untrusted agent activity reach a developer's host. The flaws broke command-execution boundaries in OpenAI Codex, including a path to unsandboxed command execution from read-only mode. Researchers reported both issues on August 12, and OpenAI patched them within eight days. Users should upgrade to Codex Desktop build 26.818.21641 or Codex CLI 0.149.0 or later.

TigerByte Cyber seed funding and stealth emergence

Industry Action

Updated: 19.09.2026 17:30 · First: 19.09.2026 17:30 · 📰 1 src / 1 articles · H score: 14

TigerByte Cyber emerged from stealth with $3 million in seed funding led by Hale Capital Partners and backed by Tenon VC, expanding a cybersecurity business focused on AI and edge devices. The company says its Cyber Protection Suite (CPS) hardens legacy systems with hardware-enforced controls such as data validation, deep packet inspection, network segmentation, and post-quantum encryption. The new capital will support scaling into military and commercial aircraft, drones, satellites, and vehicles and expanding US manufacturing.

Clop (aka Cl0p) hit by network compromise linked to ShinyHunters

Incident

Updated: 19.09.2026 16:48 · First: 19.09.2026 16:48 · 📰 2 src / 2 articles · H score: 77

ShinyHunters breached and defaced Clop’s Tor-based data leak site on 18 September, replacing it with its own message and link after an alleged Grav CMS upload flaw. The group claimed full access to the server, said it stole server data, source code, /var/log files, and onion-service private keys, and threatened to extort Clop. The compromise is part of a 2025 feud between the groups tied to competing claims over Oracle E-Business Suite vulnerabilities, including CVE-2025-61882. The event disrupts Clop’s leak infrastructure and could expose operator activity and authentication records if the theft claims are accurate.

SolarWinds Access Rights Manager security update for CVE-2026-28326

Security Patch Release

Updated: 19.09.2026 12:31 · First: 19.09.2026 12:31 · 📰 1 src / 1 articles · H score: 39

SolarWinds released security updates for Access Rights Manager (ARM) to fix CVE-2026-28326, a high-severity flaw that could enable unauthenticated remote code execution. The issue affects all versions of ARM 2026.2 and prior and is rated CVSS 8.8. SolarWinds patched the bug in ARM 2026.2.1 after the flaw was reported by Armadin researcher Kai Huang. SolarWinds said it has no evidence of in-the-wild exploitation.

Orkes Conductor unauthenticated RCE (CVE-2026-58138)

Vulnerability

Updated: 19.09.2026 11:18 · First: 19.09.2026 11:18 · 📰 1 src / 1 articles · H score: 46

CVE-2026-58138 is an unauthenticated remote code execution flaw in Orkes Conductor 3.21.21 before 3.30.2 that is being actively exploited. Attackers can submit crafted workflow definitions with JavaScript or Python expressions to the workflow API before authentication and trigger arbitrary OS command execution. Organizations running affected versions face immediate takeover risk on exposed Conductor instances until they upgrade or isolate the API.

Linux kernel actively exploited flaws (multiple vulnerabilities)

Vulnerability

Updated: 19.09.2026 09:24 · First: 19.09.2026 09:24 · 📰 1 src / 1 articles · H score: 46

Three Linux kernel vulnerabilities—CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964—were added to CISA KEV after evidence of active exploitation. The flaws expose affected systems to memory disclosure, denial-of-service, local privilege escalation, and data integrity problems. Red Hat updated advisories on September 19, 2026, and FCEB agencies were told to apply fixes by September 21, 2026.

Red Hat Linux kernel advisory update for active exploitation

Advisory/Mitigation

Updated: 19.09.2026 09:24 · First: 19.09.2026 09:24 · 📰 1 src / 1 articles · H score: 53

Red Hat updated its Linux kernel advisories on September 19, 2026 to flag active exploitation of CVE-2025-39682, CVE-2026-53266, and CVE-2025-39964, pushing operators to treat the flaws as high priority. The guidance says there are known public exploits for at least one of the CVEs, increasing the urgency for remediation. FCEB agencies were told to apply the necessary fixes by September 21, 2026 under BOD 26-04.

CISA adds Linux kernel flaws to KEV catalog under BOD 26-04

Public Sector Action

Updated: 19.09.2026 09:24 · First: 19.09.2026 09:24 · 📰 1 src / 1 articles · H score: 36

CISA added three Linux kernel flaws to its KEV catalog after evidence of active exploitation, forcing federal remediation prioritization. Under BOD 26-04, FCEB agencies are recommended to apply fixes by September 21, 2026. Red Hat updated its advisories on September 19, 2026, and the flaws can enable memory disclosure, denial-of-service, and local privilege escalation.

Linux kernel local root escalation flaws multiple vulnerabilities memory corruption flaw (CVE-2026-80844)

Vulnerability

Updated: 18.09.2026 21:02 · First: 18.09.2026 21:02 · 📰 1 src / 1 articles · H score: 26

Linux kernel local-privilege-escalation flaws across DirtyAH6, TUNderflow, PPPoEject, and DiagSpill now have public exploit code, leaving older systems exposed to local root risk until they are updated. Kernel maintainers have already fixed the issues, and up-to-date kernels are not affected. No real-world abuse has been reported yet, but public code increases the danger on shared systems.