Press "Enter" to skip to content

OSINT / CyberSec report 09.09.2026 00:05

1. Adobe released patches for a critical zero day vulnerability in Magento and Adobe Commerce tracked as CVE 2026 75650 which is being actively exploited to deploy backdoors (thehackernews.com).

2. A Vietnam linked database leak exposed 220 million traveler and crew records including passport numbers and flight details via a cloud path using default credentials (bleepingcomputer.com).

3. The BigBear 2.0 phishing as a service framework successfully bypassed multi factor authentication at 258 organizations to steal over 5000 Microsoft 365 credentials (bleepingcomputer.com).

4. Hackers are actively exploiting a chain of two vulnerabilities in MikroTik RouterOS to hijack devices with exposed SSH ports (bleepingcomputer.com).

5. Mathspace disclosed a data breach involving the theft of personal information belonging to over 1 million students, staff, and parents (bleepingcomputer.com).

6. N able issued a fourth emergency hotfix for the N central RMM platform to address an unauthenticated remote code execution flaw reported as exploited in the wild (thehackernews.com).

7. Researchers identified a post exploitation toolkit named PEEP that masquerades as a browser extension to turn Chrome and Edge into backdoors for command execution (thehackernews.com).

8. A data breach at the shipping provider ShipMonk resulted in the exposure of data belonging to an additional 67000 Trezor customers (bleepingcomputer.com).

9. Threat actors are using IT help desk vishing and adversary in the middle token theft to target executives and steal Microsoft 365 data (thehackernews.com).

10. The BengalSEO campaign has been poisoning Bing search results since 2015 to distribute the MayaBot malware and facilitate tech support scams (thehackernews.com).

11. Rogue ScreenConnect clients are being used to distribute malicious VBScript payloads to newly connected hosts via multiple initial access vectors (thehackernews.com).

12. Berlin authorities are investigating a second data breach involving the publication of stolen government login credentials online (therecord.media).

13. Grindr agreed to pay 26 million pounds to settle a lawsuit regarding the unauthorized sharing of sensitive user data including HIV status (thehackernews.com).

14. Geekom admitted to shipping malware laced network drivers for its AMD mini PCs and has since removed the malicious packages (reddit.com).

15. Thomson Reuters reported a breach of its C Track court case management platform affecting multiple US states and Canada (research.checkpoint.com).

Be First to Comment

    Leave a Reply

    Your email address will not be published. Required fields are marked *