Breaking News – Cyber Threats – 2026-09-21 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-21 08:00 PDT
- Microsoft fixes broken Excel copy and paste for all Office users
BleepingComputer • 2026-09-21 07:42 • www.bleepingcomputer.com
Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-broken-excel-copy-and-paste-for-all-office-users/ - Reverse-Engineering Flock Cameras
Schneier on Security • 2026-09-21 07:37 • www.schneier.comHackers captured a Flock camera and got a look (alternate link) at the software:
While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a…
https://www.schneier.com/blog/archives/2026/09/reverse-engineering-flock-cameras.html - ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
The Hacker News • 2026-09-21 07:24 • thehackernews.com
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not
https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html - TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
The Hacker News • 2026-09-21 07:15 • thehackernews.com
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.The backdoor “automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary
https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html - FBI's CJIS v6.1: What Security Teams Need to Know.
BleepingComputer • 2026-09-21 07:02 • www.bleepingcomputer.com
The FBI’s CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. […]
https://www.bleepingcomputer.com/news/security/fbis-cjis-v61-what-security-teams-need-to-know/ - Microsoft reminds admins to migrate Entra ID users to passkeys
BleepingComputer • 2026-09-21 06:16 • www.bleepingcomputer.com
Microsoft has reminded admins to migrate Entra ID users to phishing-resistant authentication methods to avoid sign-in disruptions after it retires SMS first-factor sign-in starting in February 2027. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-reminds-admins-to-migrate-entra-id-users-to-passkeys/ - Microsoft: September updates break File History backup feature
BleepingComputer • 2026-09-21 04:45 • www.bleepingcomputer.com
Microsoft warned that the built-in File History backup feature in Windows may stop working on some systems after installing the September 2026 security updates. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-updates-break-file-history-backup-feature/ - TerminalFix: PNG Steganography, (Mon, Sep 21st)
SANS ISC Diary (full) • 2026-09-21 03:33 • isc.sans.eduMicrosoft Security Research published an interesting blog post “TerminalFix campaign deploys a reverse tunnel through multistage intrusion” about a malware campaign. The aspect that I want to take a closer look at, is the fact that the threat actors used PNG files with steganography. I reached out to the researchers and they kindly shared the IOCs for the PNG files with me.
- Group Policy hijacked: PAYLOAD ransomware weaponizes Active Directory GPO
Securelist • 2026-09-21 03:00 • securelist.com
Kaspersky GERT experts dive into the technical incident analysis of PAYLOAD ransomware: an encryptionless, binary-less operation that abused Active Directory mechanisms for managing Group Policy Objects.
https://securelist.com/tr/payload-ransomware-via-group-policy/121335/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.