Breaking News – Cyber Threats – 2026-09-18 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-18 13:00 PDT
- New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
The Hacker News • 2026-09-18 09:56 • thehackernews.com
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only
https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html - Gyazo server flaw exploited to steal 23.6 million user records
BleepingComputer • 2026-09-18 09:00 • www.bleepingcomputer.com
The Gyazo image-sharing platform has confirmed it suffered a data breach after hackers exploited a server vulnerability that allowed them to steal 23.6 million user records. […]
https://www.bleepingcomputer.com/news/security/gyazo-server-flaw-exploited-to-steal-236-million-user-records/ - Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2
The Hacker News • 2026-09-18 08:24 • thehackernews.com
The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan.The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation
https://thehackernews.com/2026/09/transparent-tribe-deploys-new-rust.html - Fake LastPass Authenticator GitHub repos push new Rapuncel infostealer
BleepingComputer • 2026-09-18 08:19 • www.bleepingcomputer.com
An ongoing malware campaign uses SEO-optimized GitHub repositories to impersonate well-known software firms to push a previously undocumented information stealer called Rapuncel. […]
https://www.bleepingcomputer.com/news/security/fake-lastpass-authenticator-github-repos-push-new-rapuncel-infostealer/ - Secure enterprise sharing with access reviews for Microsoft 365
BleepingComputer • 2026-09-18 07:00 • www.bleepingcomputer.com
Microsoft 365 makes sharing files easy, but access can remain long after its original purpose has ended, leaving organizations with little visibility into who can still reach sensitive data. tenfold Software explains how centralized access governance and owner-driven reviews can help identify and remove unnecessary access. […]
https://www.bleepingcomputer.com/news/security/secure-enterprise-sharing-with-access-reviews-for-microsoft-365/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.