Breaking News – Cyber Threats – 2026-09-15 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-15 08:00 PDT
- Hackers target WordPress sites via third-party WooCommerce plugin
BleepingComputer • 2026-09-15 07:45 • www.bleepingcomputer.com
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. […]
https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/ - What Zero-Day Response Should Be in the Post-Mythos Era
BleepingComputer • 2026-09-15 06:45 • www.bleepingcomputer.com
AI is shrinking the time between vulnerability disclosure and exploitation, leaving defenders less time to wait for patches or public exploits. Picus Security explains how exploitability validation, security control testing, and autonomous pentesting can help teams close exposure gaps before attackers arrive. […]
https://www.bleepingcomputer.com/news/security/what-zero-day-response-should-be-in-the-post-mythos-era/ - CISA: Critical VMware RCE flaw now exploited by ransomware gangs
BleepingComputer • 2026-09-15 05:16 • www.bleepingcomputer.com
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned security teams that ransomware gangs have now joined ongoing attacks exploiting a critical VMware vCenter vulnerability patched in July. […]
https://www.bleepingcomputer.com/news/security/cisa-critical-vmware-vcenter-rce-flaw-now-exploited-by-ransomware-gangs/ - Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds
The Hacker News • 2026-09-15 04:52 • thehackernews.com
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly after gaining initial access.In one instance highlighted by the cloud security company, the threat actor pivoted from a vulnerable Marimo notebook to an SSH
https://thehackernews.com/2026/09/human-attacker-exploits-marimo-rce.html - Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point
The Hacker News • 2026-09-15 04:26 • thehackernews.com
IntroductionSecurity teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this SIEM rule fire on this particular technique? And, in more mature organizations, this testing happens continuously rather than as a one-off exercise.
But no matter how much you validate against these
https://thehackernews.com/2026/09/attack-chains-not-just-attack-surfaces.html - Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers
The Hacker News • 2026-09-15 04:12 • thehackernews.com
Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data.The first is an automated effort aimed at internet-exposed Vite development servers that’s designed to steal cloud credentials, configurations from Amazon Web Services (AWS) and Microsoft Azure instances, and infrastructure state files, per F5 Labs.
The
https://thehackernews.com/2026/09/mass-scanning-campaign-exploits-vite.html - 25 Years of Mass Surveillance Is Enough
Schneier on Security • 2026-09-15 04:01 • www.schneier.comThis essay was written with Cindy Cohn, and originally appeared in Lawfare.
One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/trap and trace orders—to mass surveillance techniques—such as tapping into the internet backbone or mass collection of telephone or internet metadata. The legal and technical architecture of modern mass surveillance, initially fram…
https://www.schneier.com/blog/archives/2026/09/25-years-of-mass-surveillance-is-enough.html - On the NSA’s Supercomputer from the 1960s
Schneier on Security • 2026-09-15 03:16 • www.schneier.comReally interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.
https://www.schneier.com/blog/archives/2026/09/on-the-nsas-supercomputer-from-the-1960s.html
- Suspected Black Axe gang leaders face cybercrime charges in the US
BleepingComputer • 2026-09-15 02:50 • www.bleepingcomputer.com
Five alleged leaders of the Black Axe cybercrime syndicate, known for its involvement in global-scale cyber-enabled financial fraud, have been extradited to the United States to face wire fraud and money laundering charges. […]
https://www.bleepingcomputer.com/news/security/black-axe-gang-members-extradited-to-us-face-cybercrime-charges/ - Former AT&T store worker jailed after moonlighting as a SIM-swap gang’s inside man
Graham Cluley • 2026-09-15 02:43 • www.bitdefender.com
44-year-old Kenneth Carter from Portland, Oregon, used to work in an AT&T retail store. But now he has been sentenced to 16 months in a federal prison.That should be plenty of time for him to rue the day he agreed to increase his monthly income by helping a SIM swap gang in their attempt to steal over half a million dollars.
Read more in my article on the Hot for Security blog.
https://www.bitdefender.com/en-us/blog/hotforsecurity/former-at-t-worker-jailed-sim-swap
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.