Breaking News – Cyber Threats – 2026-09-16 03:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-16 03:00 PDT
- Windows Server 2022 reaches end of mainstream support next month
BleepingComputer • 2026-09-16 02:10 • www.bleepingcomputer.com
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. […]
https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-next-month/ - Google fixes actively exploited Android zero-day on Pixel devices
BleepingComputer • 2026-09-16 00:00 • www.bleepingcomputer.com
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks. […]
https://www.bleepingcomputer.com/news/security/google-fixes-actively-exploited-android-zero-day-on-pixel-devices/ - Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
The Hacker News • 2026-09-15 22:48 • thehackernews.com
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs.“This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution,” Wordfence said.
The WordPress security company said it has blocked over
https://thehackernews.com/2026/09/attackers-exploit-woocommerce-wholesale.html - Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
The Hacker News • 2026-09-15 22:18 • thehackernews.com
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr.The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw.
“JWT authentication
https://thehackernews.com/2026/09/active-exploitation-attempts-target.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.