Breaking News – Cyber Threats – 2026-09-03 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-03 08:00 PDT
- Critical Elementor Pro flaw exploited to take over WordPress sites
BleepingComputer • 2026-09-03 07:52 • www.bleepingcomputer.com
A recently patched critical vulnerability (CVE-2026-32475) in the Elementor Pro plugin for WordPress is being exploited in attacks that deliver a webshell payload and execute arbitrary commands on the server. […]
https://www.bleepingcomputer.com/news/security/critical-elementor-pro-flaw-exploited-to-take-over-wordpress-sites/ - Your Employee’s Password Appeared in an Infostealer Log. Now What?
BleepingComputer • 2026-09-03 06:50 • www.bleepingcomputer.com
Infostealers can expose far more than passwords, including authenticated sessions that may let attackers bypass MFA. Flare explains how defenders can prioritize compromised identities, determine whether stolen access is still usable, and respond before it leads to account takeover. […]
https://www.bleepingcomputer.com/news/security/your-employees-password-appeared-in-an-infostealer-log-now-what/ - Microsoft says KB5120998 Windows update resets desktop settings
BleepingComputer • 2026-09-03 05:16 • www.bleepingcomputer.com
Microsoft has confirmed that desktop settings are lost or reset on some Windows devices after installing the KB5120998 August 2026 preview update. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-says-kb5120998-windows-update-resets-desktop-settings/ - US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries
The Hacker News • 2026-09-03 04:58 • thehackernews.com
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries.Around 45% of observed activity was associated with the United States, making it the campaign’s top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses
https://thehackernews.com/2026/09/us-becomes-top-target-in-rmm-phishing.html - Researching Employment Scams
Schneier on Security • 2026-09-03 04:18 • www.schneier.comResearchers built a fake company to study fake employee scams.
https://www.schneier.com/blog/archives/2026/09/researching-employment-scams.html
- Plex warns users to patch security vulnerabilities immediately
BleepingComputer • 2026-09-03 04:02 • www.bleepingcomputer.com
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. […]
https://www.bleepingcomputer.com/news/security/plex-warns-users-to-patch-security-vulnerabilities-immediately/ - Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks
The Hacker News • 2026-09-03 03:43 • thehackernews.com
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.
“The technique’s appeal is that node.exe (the
https://thehackernews.com/2026/09/attackers-turn-trusted-nodejs-runtime.html - Shai-Hulud's Reach Just Grew to 469 Credential Locations. Here's What That Means
The Hacker News • 2026-09-03 03:36 • thehackernews.com
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across 469 locations across developer environments, Continuous Integration/Continuous Deployment (CI/CD) tooling, cloud configurations, and even AI tool configs.Earlier variants of the infostealer worm only checked 189 paths. The jump says a lot. Attackers have
https://thehackernews.com/2026/09/shai-huluds-reach-just-grew-to-469.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.