Press "Enter" to skip to content

OSINT / CyberSec report 17.09.2026 00:10

1. Google released security patches for Pixel devices to address an actively exploited zero day vulnerability. (https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/)

2. A critical security flaw in WSO2 API Manager tracked as CVE 2026 5430 is under active exploitation by attackers using forged admin tokens. (https://thehackernews.com/2026/09/active-exploitation-attempts-target.html)

3. Threat actors are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture plugin to upload PHP web shells. (https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html)

4. CISA warned that ransomware gangs are actively exploiting a critical VMware vCenter remote code execution vulnerability patched in July. (https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/)

5. Acronis issued a warning regarding a high severity local privilege escalation vulnerability in its cPanel backup plugin that is being exploited in the wild. (https://www.bleepingcomputer.com/news/security/acronis-warns-of-actively-exploited-flaw-in-its-cpanel-backup-plugin/)

6. A North Korean APT group is targeting South Korean media and automotive sectors using a previously undocumented Linux espionage toolkit. (https://www.darkreading.com/cyberattacks-data-breaches/cyber-south-korean-media-automotive)

7. CenterPoint Energy confirmed a data breach after an attacker leaked customer information stolen from the utility company. (https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/)

8. Malicious versions of the Admin Menu Editor Pro WordPress plugin were distributed to over 200 customers after the maintainer website was compromised. (https://www.bleepingcomputer.com/news/security/malcious-admin-menu-editor-pro-plugin-backdoors-1-500-wordpress-sites/)

9. Iranian state sponsored actors are using Telegram controlled malware to spy on dissidents and journalists. (https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html)

10. Researchers identified a multi platform malware family called BambooToken that uses the MQTT protocol to control Windows and Linux systems. (https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html)

11. A Brazilian banking malware operation is using a toolkit called KREMLIN to hijack Chrome and Edge browsers for credential theft. (https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html)

12. A mass scanning campaign is targeting exposed Vite development servers to extract cloud credentials and infrastructure state files. (https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html)

Be First to Comment

    Leave a Reply

    Your email address will not be published. Required fields are marked *