Breaking News – Cyber Threats – 2026-09-16 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-16 08:00 PDT
- The true cost of a ransomware attack, with and without BCDR
BleepingComputer • 2026-09-16 07:00 • www.bleepingcomputer.com
The ransom itself can be only a fraction of the total cost of a ransomware attack, with downtime, recovery, remediation, and legal obligations adding millions to the bill. Datto explains how a mature BCDR strategy can reduce downtime and provide a faster, more predictable path to recovery. […]
https://www.bleepingcomputer.com/news/security/the-true-cost-of-a-ransomware-attack-with-and-without-bcdr/ - Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories
The Hacker News • 2026-09-16 06:37 • thehackernews.com
Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories.Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the
https://thehackernews.com/2026/09/attacker-hijacks-ai-coding-assistant.html - Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix
The Hacker News • 2026-09-16 06:14 • thehackernews.com
Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week.The attack needs code already running on the machine as a normal user, so it does not work over the network. JFrog says the fix is in Parallels Desktop 27, a version that Intel Macs cannot install.
Yuval Moravchick, who leads
https://thehackernews.com/2026/09/parallels-desktop-flaw-lets-non-admin.html - Microsoft says Copilot buttons still missing in classic Outlook
BleepingComputer • 2026-09-16 05:16 • www.bleepingcomputer.com
Microsoft says it’s still investigating a known issue that causes the Copilot and Copilot Chat buttons in Classic Outlook to disappear for some Windows users. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-shares-workaround-for-missing-outlook-copilot-buttons/ - Webinar: What happens in the first hours of a Google Workspace breach
BleepingComputer • 2026-09-16 05:11 • www.bleepingcomputer.com
The first hours after discovering a Google Workspace breach can determine how an incident unfolds. This webinar examines real-world breaches to show which early response decisions can limit the impact and which can make matters worse. […]
https://www.bleepingcomputer.com/news/security/webinar-what-happens-in-the-first-hours-of-a-google-workspace-breach/ - N0va Phishkit Targets US and EU Businesses: A New Challenge for Identity Security
The Hacker News • 2026-09-16 04:58 • thehackernews.com
N0va is targeting organizations across North America and Europe with phishing campaigns that impersonate trusted services and abuse legitimate authentication flows. Successful attacks can give threat actors access to valid accounts without relying on obvious malware activity.From there, a single compromised identity can open the door to sensitive data, business systems, and additional cloud
https://thehackernews.com/2026/09/n0va-phishkit-targets-us-and-eu.html - Fake CAPTCHA Scams
Schneier on Security • 2026-09-16 04:25 • www.schneier.comNew variant of an old scam: Use the framing of a CAPTCHA to get an unsuspecting user to download and run a malicious program.
https://www.schneier.com/blog/archives/2026/09/fake-captcha-scams.html
- Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation
The Hacker News • 2026-09-16 04:15 • thehackernews.com
Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild.The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw.
“In Cellular Modem, there is a possible permission bypass due to a logic error in the code,” according to a description of the bug in the NIST National Vulnerability Database
https://thehackernews.com/2026/09/google-patches-pixel-modem-flaw-amid.html - Threat Intelligence Alone Won't Close the Exploitation Gap
The Hacker News • 2026-09-16 04:15 • thehackernews.com
A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.
https://thehackernews.com/2026/09/threat-intelligence-alone-wont-close.html - Critical ScreenConnect flaw now actively exploited in attacks
BleepingComputer • 2026-09-16 04:14 • www.bleepingcomputer.com
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). […]
https://www.bleepingcomputer.com/news/security/cisa-warns-of-hackers-exploiting-critical-screenconnect-flaw/ - Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks
The Hacker News • 2026-09-16 04:08 • thehackernews.com
Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild.The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions –
Acronis Backup plugin for cPanel & WHM (Linux
https://thehackernews.com/2026/09/acronis-cpanel-backup-plugin.html - NightEagle targets Russian companies
Securelist • 2026-09-16 03:00 • securelist.com
Kaspersky GERT experts have uncovered a new campaign by the NightEagle APT, featuring the GhostContainer backdoor and tools hosted on GitHub. The group is also exploiting vulnerabilities in Active Directory and RDP.
https://securelist.com/tr/nighteagle-apt-ghostcontainer-and-tunneling/121323/ - Windows Server 2022 reaches end of mainstream support next month
BleepingComputer • 2026-09-16 02:10 • www.bleepingcomputer.com
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031. […]
https://www.bleepingcomputer.com/news/microsoft/windows-server-2022-reaches-end-of-mainstream-support-next-month/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.