Breaking News – Cyber Threats – 2026-09-22 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-22 13:00 PDT
- ShinyHunters claims FBI hack, data theft in PeopleSoft zero-day breach
BleepingComputer • 2026-09-22 12:13 • www.bleepingcomputer.com
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. […]
https://www.bleepingcomputer.com/news/security/shinyhunters-claims-fbi-hack-data-theft-in-peoplesoft-zero-day-breach/ - The Truth about GET and HTTP Standards, (Tue, Sep 22nd)
SANS ISC Diary (full) • 2026-09-22 12:06 • isc.sans.eduOn Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow “GET” requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if they do?
- Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
The Hacker News • 2026-09-22 11:29 • thehackernews.com
Attackers exploited a previously unknown flaw in Check Point’s Security Management Server in a handful of targeted attacks on July 23, the company said.The flaw, CVE-2026-93616, allows an attacker who can access the server’s web service to run scripts on it without logging in. Check Point released a fix on September 22 for the server that controls firewall policies for the Check Point
https://thehackernews.com/2026/09/check-point-warns-of-management-server.html - New ClosedQuorum Windows malware uses AI for attack decisions
BleepingComputer • 2026-09-22 11:04 • www.bleepingcomputer.com
A new Windows malware named ClosedQuorum uses Google Gemini, DeepSeek, Qwen, and Mistral AI models to autonomously determine the actions to take during post-compromise stages of an attack. […]
https://www.bleepingcomputer.com/news/security/new-closedquorum-windows-malware-uses-ai-for-attack-decisions/ - WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
The Hacker News • 2026-09-22 11:03 • thehackernews.com
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders.On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPress 7.1.2, with fixes for every branch the project still supports, back to 4.7, and WordPress is telling site owners
https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html - Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
The Hacker News • 2026-09-22 10:58 • thehackernews.com
Cybersecurity researchers have disclosed details of a malicious npm package named “tw-pkgprobe-7731” that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data.The package, named “tw-pkgprobe-7731,” was first uploaded to the npm registry in mid-August 2026 by an npm account named “twdepprobe7731.”
https://thehackernews.com/2026/09/malicious-npm-package-poses-as-twilio.html - Reducing shadow IT visibility gaps with Wazuh
BleepingComputer • 2026-09-22 10:17 • www.bleepingcomputer.com
Shadow IT can leave security teams unaware of unmanaged endpoints, unauthorized software, and other assets that fall outside existing monitoring. Wazuh explains how endpoint inventory, agentless monitoring, and centralized analysis can help organizations identify and reduce these visibility gaps. […]
https://www.bleepingcomputer.com/news/security/reducing-shadow-it-visibility-gaps-with-wazuh/ - Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
The Hacker News • 2026-09-22 10:03 • thehackernews.com
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) “at every step of the attack chain.”The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the efforts of Health-ISAC, alongside Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver
https://thehackernews.com/2026/09/microsoft-takes-down-eviltokens-device.html - Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
The Hacker News • 2026-09-22 09:41 • thehackernews.com
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request.The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all versions of the Bifrost HTTP transport before 2.1.0 when management authentication is
https://thehackernews.com/2026/09/critical-bifrost-ai-gateway-flaw-lets.html - Check Point warns of Management Server zero-day exploited in attacks
BleepingComputer • 2026-09-22 09:32 • www.bleepingcomputer.com
Check Point Software released emergency hotfixes to address a critical Security Management Server vulnerability that could let attackers run arbitrary scripts. […]
https://www.bleepingcomputer.com/news/security/check-point-patches-management-server-zero-day-exploited-in-attacks/ - Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
The Hacker News • 2026-09-22 09:14 • thehackernews.com
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19.The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid Naceri, is a former Microsoft security researcher whose earlier Defender exploits were used in
https://thehackernews.com/2026/09/researcher-drops-bigdiskbuster-zero-day.html - EvilTokens PhaaS disrupted after compromising 12,000 Microsoft accounts
BleepingComputer • 2026-09-22 08:00 • www.bleepingcomputer.com
The EvilTokens platform that compromised more than 12,000 Microsoft accounts at over 10,000 organizations has been disrupted in an effort led by Microsoft’s Digital Crimes Unit (DCU). […]
https://www.bleepingcomputer.com/news/security/eviltokens-phaas-disrupted-after-compromising-12-000-microsoft-accounts/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.