Breaking News – Cyber Threats – 2026-09-24 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-24 13:00 PDT
- Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
The Hacker News • 2026-09-24 11:10 • thehackernews.com
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus’s own software to gain root access, the highest level of control over an Android phone.OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not
https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html - ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
The Hacker News • 2026-09-24 10:52 • thehackernews.com
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before.That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just
https://thehackernews.com/2026/09/threatsday-ai-search-poisoning-ai.html - Exposed GitLab project email addresses let attackers push code
BleepingComputer • 2026-09-24 10:47 • www.bleepingcomputer.com
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. […]
https://www.bleepingcomputer.com/news/security/exposed-gitlab-project-email-addresses-let-attackers-push-code/ - Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The Hacker News • 2026-09-24 08:27 • thehackernews.com
The “third-party[.]com” domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users.“third-party[.]com has been a generic documentation placeholder for years, the same role example.com plays,” Manifold Security’s Head of Research, Ax Sharma, said. “Unlike ‘example[.]com,’ third-party[.]com
https://thehackernews.com/2026/09/placeholder-third-partycom-referenced.html - Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
The Hacker News • 2026-09-24 07:29 • thehackernews.com
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic.“When a visitor interacts with the page, the lure copies a Windows Installer command to the clipboard and instructs the visitor to paste it into the
https://thehackernews.com/2026/09/hacked-ukrainian-sites-serve-fake.html - FedRAMP VDR & VER: Daily Scans Are Only the Beginning
BleepingComputer • 2026-09-24 07:02 • www.bleepingcomputer.com
FedRAMP’s new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadline is just the beginning of a broader shift toward continuous, automated compliance validation. […]
https://www.bleepingcomputer.com/news/security/fedramp-vdr-and-ver-daily-scans-are-only-the-beginning/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.