Breaking News – Cyber Threats – 2026-09-21 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-21 13:00 PDT
- WordPress Click2Shell flaw lets hackers execute PHP on the server
BleepingComputer • 2026-09-21 11:23 • www.bleepingcomputer.com
Technical details and a proof-of-concept exploit have been published for a new WordPress cross-site request forgery (CSRF) vulnerability dubbed ‘Click2Shell’ that affects the platform’s Core component. […]
https://www.bleepingcomputer.com/news/security/wordpress-click2shell-flaw-lets-hackers-execute-php-on-the-server/ - Microsoft to retire Microsoft 365 Companion apps in December
BleepingComputer • 2026-09-21 10:54 • www.bleepingcomputer.com
Microsoft will retire the Calendar, People, and Files Microsoft 365 companion apps on December 16 and has asked admins to remove them from managed devices. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-to-retire-microsoft-365-companion-apps-in-december/ - Fake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDR
The Hacker News • 2026-09-21 10:31 • thehackernews.com
A fake LastPass Authenticator installer offered on GitHub installs a Windows kernel driver that shuts off antivirus and other security software before a password stealer runs if a victim downloads and runs it, researchers at LastPass and Delphos Labs said on September 17.Microsoft’s own hardware-compatibility program signs the driver, scored zero detections on VirusTotal when researchers
https://thehackernews.com/2026/09/fake-lastpass-authenticator-installer.html - Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The Hacker News • 2026-09-21 10:19 • thehackernews.com
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory.The primary targets of the campaign are individual web designers, engineers, and specialists in cryptocurrency,
https://thehackernews.com/2026/09/contagious-interview-campaign.html - Google Fined €403 Million Over GDPR Violations Tied to Location Data
The Hacker News • 2026-09-21 09:57 • thehackernews.com
Google has been fined €403 million for breaking the EU’s data protection law, the GDPR, in the way three of its features handled people’s location data from May 2018 to February 2020.Ireland’s Data Protection Commission (DPC), Google’s lead regulator in the EU, also ordered the company to make its processing comply with the law within 6 months. The DPC has not said publicly which
https://thehackernews.com/2026/09/google-fined-403-million-over-gdpr.html - Google fined €403 million over location data privacy violations
BleepingComputer • 2026-09-21 08:41 • www.bleepingcomputer.com
Ireland’s Data Protection Commission (DPC) has fined Google €403 million ($463M) for multiple GDPR violations related to processing users’ location data. […]
https://www.bleepingcomputer.com/news/security/google-fined-403-million-over-location-data-privacy-violations/ - Microsoft fixes broken Excel copy and paste for all Office users
BleepingComputer • 2026-09-21 07:42 • www.bleepingcomputer.com
Microsoft has fixed a known issue that causes copy-and-paste failures for Excel users after installing the September 2026 security updates. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-fixes-broken-excel-copy-and-paste-for-all-office-users/ - Reverse-Engineering Flock Cameras
Schneier on Security • 2026-09-21 07:37 • www.schneier.comHackers captured a Flock camera and got a look (alternate link) at the software:
While much of the automatic license plate reader’s (ALPR) most sensitive storage remained encrypted and inaccessible, the joint analysis of the recovered data shows that software running on the device explicitly detects people as well as vehicles, license plates, and bicycles. The camera can produce dozens of images of a…
https://www.schneier.com/blog/archives/2026/09/reverse-engineering-flock-cameras.html - ⚡ Weekly Recap: Cisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser Hijacks
The Hacker News • 2026-09-21 07:24 • thehackernews.com
A browser. A plugin. A package. A login screen. Normal stuff. That is basically the problem this week.The trouble keeps showing up inside things people already trust: code that takes a bad turn, old payloads coming back, exposed systems, weak checks, fake fixes, and attack paths that look almost too easy. Even the research side is getting messy, with more findings, more automation, and not
https://thehackernews.com/2026/09/weekly-recap-cisco-0-day-ai-agent-rce.html - TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
The Hacker News • 2026-09-21 07:15 • thehackernews.com
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts.The backdoor “automatically harvests and exfiltrates business documents, watches the filesystem for new files in real time, steals Wi-Fi passwords and clipboard contents, takes screenshots, and accepts arbitrary
https://thehackernews.com/2026/09/taskstomp-powershell-backdoor-steals.html - FBI's CJIS v6.1: What Security Teams Need to Know.
BleepingComputer • 2026-09-21 07:02 • www.bleepingcomputer.com
The FBI’s CJIS Security Policy v6.1 strengthens requirements around encryption and vulnerability scanning while continuing the shift toward more continuous security assessment. Specops explains what changed and how agencies can address password, MFA, and identity requirements as they prepare for upcoming audits. […]
https://www.bleepingcomputer.com/news/security/fbis-cjis-v61-what-security-teams-need-to-know/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.