Breaking News – Cyber Threats – 2026-09-18 03:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-18 03:00 PDT
- New Check Point flaw lets hackers execute code with root privileges
BleepingComputer • 2026-09-18 02:34 • www.bleepingcomputer.com
Check Point Software has released security updates to address a critical vulnerability that can let attackers execute code with root privileges on management systems. […]
https://www.bleepingcomputer.com/news/security/check-point-warns-critical-flaw-lets-hackers-execute-code-as-root/ - Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
The Hacker News • 2026-09-18 02:18 • thehackernews.com
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry.“The developer likely wrote the malware using a large language model (LLM), an assessment made with high confidence based on verbose comments, placeholder code, and statistical token-analysis patterns,”
https://thehackernews.com/2026/09/claimed-bug-bounty-hunter-likely-used.html - Microsoft fixes broken copy and paste for Excel 2016 users
BleepingComputer • 2026-09-18 00:35 • www.bleepingcomputer.com
Microsoft has fixed a known issue that causes copy-and-paste failures for some Excel users after installing the September 2026 KB5002914 security update. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-broken-copy-and-paste-for-excel-2016-users/ - RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
The Hacker News • 2026-09-17 23:17 • thehackernews.com
Cybersecurity researchers have flagged a new Android malware called RatHat that’s assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices.“Distributed primarily via targeted smishing (SMS/text phishing) and malvertising campaigns leading to deceptive third-party download portals, RatHat uses
https://thehackernews.com/2026/09/rathat-android-malware-abuses-adb-to.html - HTTP QUERY Method: The Grey Zone Between GET And POST., (Fri, Sep 18th)
SANS ISC Diary (full) • 2026-09-17 23:05 • isc.sans.eduIn June 2026 the IETF published RFC 10008[1], defining a new HTTP method: “QUERY”. The HTTP protocol faced already by changes (HTTP/2, HTTP/2) but it's the first new standard HTTP verb since “PATCH” in 2010!
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.