Breaking News – Cyber Threats – 2026-09-16 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-16 13:00 PDT
- Malware bypasses browser checks to force install Chrome, Edge extensions
BleepingComputer • 2026-09-16 11:50 • www.bleepingcomputer.com
A banking malware operation active since mid-2025 has been using a toolkit named KREMLIN to install malicious Chrome and Edge extensions that steal credentials, session tokens, and sensitive data. […]
https://www.bleepingcomputer.com/news/security/malware-bypasses-browser-checks-to-force-install-chrome-edge-extensions/ - Scans Targeting Hospitality Applications, (Wed, Sep 16th)
SANS ISC Diary (full) • 2026-09-16 11:44 • isc.sans.eduEarlier today, I noted an odd request showing up in our “First Seen” report:
- Data Broker Radaris Loses Domains in Privacy Fight
KrebsOnSecurity • 2026-09-16 11:14 • krebsonsecurity.com
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of people-search services online. That reputation caught up with the company recently in a lawsuit alleging Radaris violated a New Jersey privacy law that provides for hefty fines against data brokers that publish personal information on state law enforcement officials. In the face of repeated stonewalling and prevarication by attorneys for Radaris, the judge in the case ordered that radaris.com and more than a dozen other data broker domains be transferre…
https://krebsonsecurity.com/2026/09/data-broker-radaris-loses-domains-in-privacy-fight/ - Spain's data agency gets first report of AI-powered data breach
BleepingComputer • 2026-09-16 10:26 • www.bleepingcomputer.com
The Spanish Data Protection Agency (AEPD) was notified of an attack allegedly carried out with an AI agent powered by a known large language model (LLM). […]
https://www.bleepingcomputer.com/news/security/spains-data-agency-gets-first-report-of-ai-powered-data-breach/ - Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
The Hacker News • 2026-09-16 08:50 • thehackernews.com
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation.The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded
https://thehackernews.com/2026/09/attackers-exploit-issabel-framework.html - Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
The Hacker News • 2026-09-16 08:27 • thehackernews.com
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky.The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.
https://thehackernews.com/2026/09/three-threat-groups-target-russian.html - One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
The Hacker News • 2026-09-16 07:36 • thehackernews.com
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into five Chromium-based products: Gemini Live in Chrome, Perplexity Comet, Microsoft Edge, Opera Neon and the Claude in Chrome extension.Once the extension was installed, it could access each product’s built-in AI with a single click. On Comet, Edge,
https://thehackernews.com/2026/09/one-extension-could-hijack-ai.html - The true cost of a ransomware attack, with and without BCDR
BleepingComputer • 2026-09-16 07:00 • www.bleepingcomputer.com
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. […]
https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.