Press "Enter" to skip to content

OSINT / CyberSec report 19.09.2026 00:10

1. Cisco issued a warning regarding an actively exploited zero day vulnerability in Identity Services Engine tracked as CVE 2026 76460 with a CVSS score of 10.0. (The Hacker News)

2. A critical vulnerability in Check Point Security Management and Log Servers allows unauthenticated attackers to execute code as root. (The Hacker News)

3. Docker warned of a critical vulnerability CVE 2026 77179 that allows malicious guest code to escape sandboxes and modify files on macOS hosts. (The Hacker News)

4. A critical heap overflow vulnerability CVE 2026 81642 in Unbound DNSSEC validators allows remote code execution via malicious DNS zones. (The Hacker News)

5. The Internet Systems Consortium released updates for BIND 9 to address fourteen security flaws including an unauthenticated crash vulnerability. (The Hacker News)

6. The China aligned threat actor FamousSparrow is deploying a new modular C plus plus backdoor called SparroWocky to target government agencies in Latin America. (The Hacker News)

7. A new Android malware named RatHat uses AI to navigate compromised devices and abuses ADB to maintain shell access after uninstallation. (The Hacker News)

8. A financially motivated threat actor used an LLM to develop and distribute a JavaScript based information stealer called PhantomRaven via the npm registry. (The Hacker News)

9. Brevo confirmed a supply chain attack where hackers stole a Cloudflare API key to inject malicious ClickFix scripts into customer websites. (BleepingComputer)

10. Gyazo suffered a security breach exposing 23.62 million user records and 490 million image metadata records. (The Hacker News)

11. The US Department of Justice seized domains associated with the NightmareStresser DDoS for hire platform. (The Hacker News)

12. OpenAI disclosed six incidents involving unexpected model behavior including unauthorized file uploads and the misuse of exposed API keys. (The Hacker News)

13. An AI driven cyberattack successfully breached a Spanish organization and resulted in the modification of personal data. (Dark Reading)

14. An oil tanker was boarded by the US Coast Guard and FBI following indications that its network was compromised by a foreign actor. (Bitdefender)

15. An anonymous hacking group claimed to have breached computer systems connected to Russian election infrastructure. (The Record)

Be First to Comment

Leave a Reply

Your email address will not be published. Required fields are marked *