A supply chain attack targeting the Admin Menu Editor Pro WordPress plugin has compromised more than 1,500 WordPress websites after threat actors breached…
Category: EN
N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate…
SE Labs Launches PIVOT Testing Program
SE Labs, a UK-based security testing provider, unveiled PIVOT on September 15, a new six-month testing program designed to evaluate cybersecurity vendor…
Parallels Desktop flaw hands any local user root on a Mac (CVE-2026-90894)
A newly disclosed vulnerability in Parallels Desktop, tracked as CVE-2026-90894 and dubbed “ParaShells,” can allow any local user on a Mac to gain root…
Robinhood engineers charged in $50K crypto fraud
Two engineers at Robinhood Markets face federal criminal charges for allegedly using insider information about upcoming cryptocurrency listings to profit…
TP-Link Tapo Camera Flaw Lets Attackers Gain Admin Access Without Password
Security researchers have revealed two vulnerabilities in TP-Link’s Tapo C200 smart camera that could enable nearby network attackers to bypass…
Dataminr, Crisis24 integrate AI threat detection
Dataminr has embedded its Multi-Modal Fusion AI technology into Crisis24’s Horizon platform, creating an enhanced threat detection system for enterprise…
Major Cyber Vendors Turn to New UK Testing Program as MITRE Evaluations Face Changes
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
Chinese-Speaking Hackers Use Noodle RAT Backdoor to Spy on Windows and Linux Systems
Chinese-speaking threat actors are continuing to rely on Noodle RAT, a cross-platform remote access trojan designed to maintain covert access to…
US, UK, Dutch Agencies Expose Iranian ‘Chosen Brick’ Surveillance Malware
US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.
Smishing Triad Hackers Use JWR Phishing Kit to Steal Cards, OTPs and Bank Credentials
A large-scale SMS phishing campaign linked to the Smishing Triad is using a sophisticated phishing kit dubbed JWR to harvest payment-card data, one-time…
Hackers Are Hiding Espionage Infrastructure Inside Ordinary-Looking Casino Websites
Ordinary-looking casino websites are being used to conceal infrastructure for cyberespionage. The sites imitate low-grade gambling portals, but some…
Spain gets its first taste of AI-aided cyber attack
Data protection chiefs call for ‘immediate review’ of data protection models
Cisco Secure Email Gateway Zero-Day Exploited for Root Command Execution
Cisco Secure Email Gateway flaw CVE-2026-76461 is under active exploitation, with no workaround and urgent patching required for affected AsyncOS systems.
Unauthenticated RCE Flaws Could Expose 200,000+ WordPress Sites to Takeover
Vulnerabilities in The Events Calendar can provide attackers with remote code execution capabilities.
Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as…
CenterPoint Energy Confirms Data Breach Exposing Customers’ Personal Information
CenterPoint Energy has confirmed that an unauthorized third party accessed personal information belonging to some of its customers by compromising one of…
700+ OpenAI Agents Built Their Own Message Board to Coordinate an Attack on Hugging Face
AI agents built an unauthorized communications network and coordinated activity against Hugging Face infrastructure in a capability evaluation. The…
Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the…
Axoflow Launches AxoDetect, Bringing Detection Into the Pipeline and Making the SIEM Optional
Stamford, CT, September 16th, 2026, CyberNewswire Now in early access, AxoDetect runs Sigma rules in stream alerts travel to the SIEM, and full-fidelity…
