Skip to content
-
Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

Xloggs AI Security and News Xloggs AI Security and News

AI Security Tools and Security Headlines

  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
  • Documents for Information Security
  • OWASP TOP 10 AI
  • Security Related Links
  • EPSS Lookup
  • SSH Attacks
Close

Search

Breaking News

Breaking News – Cyber Threats – 2026-09-22 13:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-22 13:00 PDT ShinyHunters claims FBI hack, data theft…

Report Bot
By Report Bot
On
September 22, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-22 08:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-22 08:00 PDT The Truth about GET and HTTP Standards,…

Report Bot
By Report Bot
On
September 22, 2026
Uncategorized

Morning Security Report – 2026-09-22

# Morning Security Report – 2026-09-22 **Report Type**: Real-time News Summary **Date**: 2026-09-22 **Source**:…

Xloggs MCP
By Xloggs MCP
On
September 22, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-22 03:00 PDT

Breaking News – Cyber Threats (last 6h) Generated: 2026-09-22 03:00 PDT CISA orders feds to patch Zyxel flaw…

Report Bot
By Report Bot
On
September 22, 2026
Uncategorized

Top Security Breaches 2026-09-22

Top Security Breaches 2026-09-22 Auto-generated 2026-09-22T09:00:32.968703+00:00 (UTC) ShinyHunters hacks Clop leak…

Report Bot
By Report Bot
On
September 22, 2026
Uncategorized

Weekly Exploit Roundup 2026-09-22

Weekly Exploit Roundup Generated 2026-09-22T08:00:11.485865+00:00 (UTC) Critical Pre-Auth RCE in Orkes Conductor…

Report Bot
By Report Bot
On
September 22, 2026
Breaking News

Breaking News – Cyber Threats – 2026-09-22 13:00 PDT

By Report Bot
September 22, 2026 3 Min Read
Comments Off on Breaking News – Cyber Threats – 2026-09-22 13:00 PDT

Breaking News – Cyber Threats (last 6h)

Generated: 2026-09-22 13:00 PDT

  • ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
    BleepingComputer • 2026-09-22 12:13 • www.bleepingcomputer.com
    The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. […]
    https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/
  • The Truth about GET and HTTP Standards, (Tue, Sep 22nd)
    SANS ISC Diary (full) • 2026-09-22 12:06 • isc.sans.edu

    On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow “GET” requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if they do?


    https://isc.sans.edu/diary/rss/33358

  • Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
    The Hacker News • 2026-09-22 11:29 • thehackernews.com
    Attackers exploited a previously unknown flaw in Check Point’s Security Management Server in a handful of targeted attacks on July 23, the company said.

    The flaw, CVE-2026-93616, allows an attacker who can access the server’s web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point
    https://thehackernews.com/2026/09/check-point-warns-of-management-server.html

  • New ClosedQuorum Windows malware uses AI for attack decisions
    BleepingComputer • 2026-09-22 11:04 • www.bleepingcomputer.com
    A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. […]
    https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/
  • WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
    The Hacker News • 2026-09-22 11:03 • thehackernews.com
    WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.

    On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners
    https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html

  • Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
    The Hacker News • 2026-09-22 10:58 • thehackernews.com
    Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.

    The package, named “tw-pkgprobe-7731,” was first uploaded to the npm registry in mid-August 2026 by an npm account named “twdepprobe7731.”
    https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html

  • Reducing shadow IT visibility gaps with Wazuh
    BleepingComputer • 2026-09-22 10:17 • www.bleepingcomputer.com
    Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. […]
    https://www.bleepingcomputer.com/news/security/reducing-shadow-it-visibility-gaps-with-wazuh/
  • Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
    The Hacker News • 2026-09-22 10:03 • thehackernews.com
    Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”

    The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver
    https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html

  • Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
    The Hacker News • 2026-09-22 09:41 • thehackernews.com
    A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.

    The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is
    https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html

  • Check Point warns of Management Server zero-day exploited in attacks
    BleepingComputer • 2026-09-22 09:32 • www.bleepingcomputer.com
    Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. […]
    https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/
  • Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
    The Hacker News • 2026-09-22 09:14 • thehackernews.com
    A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19.

    The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in
    https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html

  • EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
    BleepingComputer • 2026-09-22 08:00 • www.bleepingcomputer.com
    The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft’s Digital Crimes Unit (DCU). […]
    https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/

Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.

Author

Report Bot

Follow Me
Other Articles
Previous

Breaking News – Cyber Threats – 2026-09-22 08:00 PDT

  • Clippie retired for Mico the Avatar.
  • reco.jpg
  • password-security.jpg

Newsletter signup

Join today to get site updates in your inbox. Opt-out anytime. No advertisement or email list up for sale.

Please wait...

Thank you for sign up!

Copyright 2026 — Xloggs AI Security and News. All rights reserved. Blogsy WordPress Theme