Breaking News – Cyber Threats – 2026-09-07 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-07 13:00 PDT
- PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution
The Hacker News • 2026-09-07 11:12 • thehackernews.com
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser.“Requiring prior administrative or code execution access, its installer injects the extension directly into Chrome/Edge profiles, bypassing Web Store checks and user prompts by forging Chromium’s own Secure Preferences
https://thehackernews.com/2026/09/peep-turns-chrome-and-edge-into-post.html - Magento StyleSmuggler zero-day exploited to deploy Linux backdoor
BleepingComputer • 2026-09-07 09:50 • www.bleepingcomputer.com
A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. […]
https://www.bleepingcomputer.com/news/security/magento-stylesmuggler-zero-day-exploited-to-deploy-linux-backdoor/ - Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks
The Hacker News • 2026-09-07 08:51 • thehackernews.com
Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-in-the-middle (AitM) token theft, and residential-proxy sign-ins.The activity, which mainly singles out directors, vice presidents, and other executive staff
https://thehackernews.com/2026/09/microsoft-365-attackers-use-help-desk.html - BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations
BleepingComputer • 2026-09-07 08:39 • www.bleepingcomputer.com
A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. […]
https://www.bleepingcomputer.com/news/security/bigbear-microsoft-365-phishing-service-bypassed-mfa-at-258-organizations/ - ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More
The Hacker News • 2026-09-07 07:36 • thehackernews.com
Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precaution you were counting on.Elsewhere, a trusted software source delivered code that stole credentials, and a protocol designed for secure network management
https://thehackernews.com/2026/09/weekly-recap-chrome-0-day-router.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.