Breaking News – Cyber Threats – 2026-09-25 17:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-25 17:00 PDT
- U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
KrebsOnSecurity • 2026-09-25 14:44 • krebsonsecurity.com
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims.
https://krebsonsecurity.com/2026/09/u-s-soldier-gets-70-months-in-prison-for-att-verizon-extortions/ - Kiteworks urges 6-hour server shutdown over potential zero-day attacks
BleepingComputer • 2026-09-25 14:41 • www.bleepingcomputer.com
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. […]
https://www.bleepingcomputer.com/news/security/kiteworks-urges-6-hour-server-shutdown-over-potential-zero-day-attacks/ - Friday Squid Blogging: Participatory Squid Dissection in October in Tennessee
Schneier on Security • 2026-09-25 14:08 • www.schneier.comI feel like someone who reads this blog will want to go to this:
Families are invited to dive into the fascinating world of marine biology during an exciting, hands-on Family Squid Dissection at the Hands-On Science Center. Designed for curious learners of all ages, this unique experience combines an interactive lesson with the opportunity to explore the anatomy and adaptations of real ocean life.
[…]
During the guide…
https://www.schneier.com/blog/archives/2026/09/friday-squid-blogging-participatory-squid-dissection-in-october-in-tennessee.html - ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
BleepingComputer • 2026-09-25 13:57 • www.bleepingcomputer.com
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. […]
https://www.bleepingcomputer.com/news/security/shinyhunters-hacked-clop-leak-site-using-grav-cms-path-traversal-flaw/ - Elementor WordPress flaw lets attackers create admin accounts
BleepingComputer • 2026-09-25 11:13 • www.bleepingcomputer.com
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. […]
https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.