Breaking News – Cyber Threats – 2026-09-15 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-15 13:00 PDT
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
The Hacker News • 2026-09-15 11:54 • thehackernews.com
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN.Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at least May 2025, the threat actor has used lures that impersonate a dozen Brazilian banks and install a malicious browser extension on Google Chrome and
https://thehackernews.com/2026/09/kremlin-banking-malware-hijacks-chrome.html - CenterPoint Energy confirms customer data stolen in cyberattack
BleepingComputer • 2026-09-15 09:40 • www.bleepingcomputer.com
CenterPoint Energy disclosed a breach compromising some customers’ personal information after an attacker leaked data allegedly stolen from the utility company. […]
https://www.bleepingcomputer.com/news/security/centerpoint-energy-confirms-customer-data-stolen-in-cyberattack/ - Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
The Hacker News • 2026-09-15 09:29 • thehackernews.com
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and activists around the world.The malware is controlled via the Telegram messaging app and can copy a target’s emails and chat messages, take screenshots, and activate the microphone to record
https://thehackernews.com/2026/09/iranian-hackers-use-telegram-controlled.html - MacOS 27 – First Boot, (Tue, Sep 15th)
SANS ISC Diary (full) • 2026-09-15 08:23 • isc.sans.eduI have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 “Golden Gate” to see what traffic you should expect. Here are some of the highlights:
- BambooToken Malware Uses MQTT to Control Windows and Linux Systems
The Hacker News • 2026-09-15 08:23 • thehackernews.com
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems.The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.
https://thehackernews.com/2026/09/bambootoken-malware-uses-mqtt-to.html - BambooToken malware controls Windows and Linux systems via MQTT
BleepingComputer • 2026-09-15 08:00 • www.bleepingcomputer.com
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. […]
https://www.bleepingcomputer.com/news/security/bambootoken-malware-controls-windows-and-linux-systems-via-mqtt/ - Hackers target WordPress sites via third-party WooCommerce plugin
BleepingComputer • 2026-09-15 07:45 • www.bleepingcomputer.com
Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor. […]
https://www.bleepingcomputer.com/news/security/hackers-target-wordpress-sites-via-third-party-woocommerce-plugin/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.