Breaking News – Cyber Threats – 2026-09-24 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-24 08:00 PDT
- FedRAMP VDR & VER: Daily Scans Are Only the Beginning
BleepingComputer • 2026-09-24 07:02 • www.bleepingcomputer.com
FedRAMP’s new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. […]
https://www.bleepingcomputer.com/news/security/fedramp-vdr-and-ver-daily-scans-are-only-the-beginning/ - Hackers now exploit critical Roundcube flaw in code injection attacks
BleepingComputer • 2026-09-24 06:27 • www.bleepingcomputer.com
A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. […]
https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/ - Ukrainian ransomware developer jailed for nearly 13 years
Graham Cluley • 2026-09-24 05:42 • www.bitdefender.com
A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world.Read more in my article on the Hot for Security blog.
https://www.bitdefender.com/en-us/blog/hotforsecurity/ukrainian-ransomware-developer-jailed-for-nearly-13-years - Windows 11 KB5124010 update released with 46 changes and fixes
BleepingComputer • 2026-09-24 05:16 • www.bleepingcomputer.com
Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. […]
https://www.bleepingcomputer.com/news/microsoft/windows-11-kb5124010-update-released-with-46-changes-and-fixes/ - Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
The Hacker News • 2026-09-24 05:05 • thehackernews.com
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM.According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW Logistics to distribute an Android Package Kit (APK) file that’s dressed up as a system service. The delivered app has the package name “com.corp.mdm”
Corp MDM
https://thehackernews.com/2026/09/corp-mdm-spyware-targets-logistics.html - Malicious npm Packages That Evade Defenses
Schneier on Security • 2026-09-24 04:07 • www.schneier.comThis is an impressive piece of malware. Its sophistication says nation-state to me, but there is no direct evidence and certainly no attribution.
https://www.schneier.com/blog/archives/2026/09/malicious-npm-packages-that-evade-defenses.html
- Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore
The Hacker News • 2026-09-24 04:00 • thehackernews.com
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are leaking secrets at approximately twice the rate of human-written ones. Most of the fastest-growing categories of leaked credentials are now connected to AI
https://thehackernews.com/2026/09/secrets-sprawl-is-identity-problem-that.html - CISA: Ransomware gangs now exploiting critical TeamCity flaw
BleepingComputer • 2026-09-24 03:42 • www.bleepingcomputer.com
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. […]
https://www.bleepingcomputer.com/news/security/cisa-ransomware-gangs-now-exploiting-critical-teamcity-flaw/ - MacSync under the microscope: new delivery methods and a new payload
Securelist • 2026-09-24 03:00 • securelist.com
We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.
https://securelist.com/macsync-new-version/121383/ - OpenAI hacked Australian Medicare govt site, probed data providers
BleepingComputer • 2026-09-24 02:38 • www.bleepingcomputer.com
OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as part of a research project. […]
https://www.bleepingcomputer.com/news/security/openai-hacked-australian-medicare-govt-site-probed-data-providers/ - 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
The Hacker News • 2026-09-24 02:14 • thehackernews.com
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructure and a state-sponsored user base, and explains why blocking malicious domains is no longer a useful defense.Read
https://thehackernews.com/2026/09/17000-urls-reveal-how-clickfix-turns.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.