Breaking News – Cyber Threats – 2026-09-22 03:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-22 03:00 PDT
- CISA orders feds to patch Zyxel flaw exploited for data theft
BleepingComputer • 2026-09-22 01:53 • www.bleepingcomputer.com
Attackers are now actively exploiting a high-severity vulnerability in Zyxel GS1900 series switches, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). […]
https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-actively-exploited-zyxel-flaw-by-thursday/ - SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
The Hacker News • 2026-09-22 00:52 • thehackernews.com
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities.“SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of mshta.exe to execute malicious scripts and circumvent standard security protocols,” Trellix researchers
https://thehackernews.com/2026/09/sidecopy-broadens-india-targeting-to.html - One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
The Hacker News • 2026-09-21 23:33 • thehackernews.com
Malware already running on a Mac can quietly take over Meta’s Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21.It works by changing a hidden setting so that when the user taps the microphone and dictates a prompt, the words go to the attacker instead of Meta.
The flaw is in
https://thehackernews.com/2026/09/one-hidden-meta-muse-setting-could-let.html - WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
The Hacker News • 2026-09-21 23:03 • thehackernews.com
A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site’s server.WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed “Comment2Shell,” on September 17 in version 7.1.1 and told site owners to update right away. The
https://thehackernews.com/2026/09/wordpress-comment2shell-flaw-can-turn.html - Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
The Hacker News • 2026-09-21 22:31 • thehackernews.com
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.The vulnerability, tracked as CVE-2026-7273 (CVSS score: 8.8), is a stack-based buffer overflow vulnerability that could result in arbitrary operating
https://thehackernews.com/2026/09/zyxel-and-veeam-flaws-under-active.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.