Breaking News – Cyber Threats – 2026-09-23 03:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-23 03:00 PDT
- F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
The Hacker News • 2026-09-23 01:29 • thehackernews.com
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
https://thehackernews.com/2026/09/f5-patches-critical-big-ip-apm-zero-day.html - Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
The Hacker News • 2026-09-23 01:29 • thehackernews.com
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome (CVE-2026-85046, CVE-2026-87491) and one impacting Windows Advanced Local Procedure Call (CVE-2026-85880) to break
https://thehackernews.com/2026/09/chinese-hackers-exploit-chrome-windows.html - Ryuk ransomware member sentenced to 24 months in prison
BleepingComputer • 2026-09-23 01:20 • www.bleepingcomputer.com
An Armenian man was sentenced to 24 months in prison and 3 years of supervised release for hacking U.S. companies and encrypting their systems in Ryuk ransomware attacks. […]
https://www.bleepingcomputer.com/news/security/ryuk-ransomware-member-sentenced-to-24-months-in-prison/ - F5 patches BIG-IP APM zero-day flaw exploited in RCE attacks
BleepingComputer • 2026-09-23 00:17 • www.bleepingcomputer.com
F5 has released security updates to address a critical BIG-IP APM zero-day vulnerability being exploited in remote code execution attacks. […]
https://www.bleepingcomputer.com/news/security/f5-warns-of-big-ip-apm-remote-code-execution-zero-day-exploited-in-attacks/ - Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
The Hacker News • 2026-09-23 00:04 • thehackernews.com
A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said.The risk applies when an app puts values an attacker controls, such as text read from the request URL, into the image. Vercel, which develops Next.js, fixed the flaw on September 22 in version
https://thehackernews.com/2026/09/critical-nextjs-imageresponse-flaw-can.html - ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
The Hacker News • 2026-09-22 22:30 • thehackernews.com
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.“We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job,” the group said in a statement posted on their dark
https://thehackernews.com/2026/09/shinyhunters-claims-fbi-breach-says-it.html - Weekly Update 522: Live From Oslo with Scott Helme
Troy Hunt • 2026-09-22 22:18 • www.troyhunt.comHeads up: the first 7 mins is a bit quiet until we worked out the external mic was misbehaving – sorry! But get through that and have a listen to Scott's experiences with how Report URI is identifying malware-infected machines within orgs, all due to CSP reporting. It&
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.