Breaking News – Cyber Threats – 2026-09-23 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-23 08:00 PDT
- InfraTrust report warns network management systems under attack
BleepingComputer • 2026-09-23 07:35 • www.bleepingcomputer.com
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. […]
https://www.bleepingcomputer.com/news/security/infratrust-report-warns-network-management-systems-under-attack/ - How One Kubernetes YAML Can Hand Over a GCP Organization
BleepingComputer • 2026-09-23 07:01 • www.bleepingcomputer.com
A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. […]
https://www.bleepingcomputer.com/news/security/how-one-kubernetes-yaml-can-hand-over-a-gcp-organization/ - Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
The Hacker News • 2026-09-23 06:52 • thehackernews.com
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.According to reports from Aikido, SafeDep, Socket, and StepSecurity, the libraries in question below –
@memtensor/memos-cloud-openclaw-plugin versions
https://thehackernews.com/2026/09/compromised-memtensor-packages-deliver.html - Arista patches actively exploited VeloCloud Orchestrator zero-day
BleepingComputer • 2026-09-23 05:29 • www.bleepingcomputer.com
Arista Networks has released security patches for a zero-day flaw that is being actively exploited and affects VeloCloud Orchestrator (VCO) On-Prem deployments. […]
https://www.bleepingcomputer.com/news/security/arista-patches-actively-exploited-velocloud-orchestrator-zero-day/ - New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
The Hacker News • 2026-09-23 05:16 • thehackernews.com
A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take “full control of the server,” the company said on September 22.A second bug in the WP Toolkit plugin, used to install and manage WordPress sites, allows an account holder to change databases that belong to other accounts.
cPanel has released fixed versions for both,
https://thehackernews.com/2026/09/new-cpanel-flaw-lets-hosting-account_0272795595.html - 545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
The Hacker News • 2026-09-23 04:47 • thehackernews.com
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and no way to tell which of them happened. Someone with a security background then sits down and checks every claim against the target. Which findings are real,
https://thehackernews.com/2026/09/545-hackers-tested-it-first-now-xranges.html - Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
The Hacker News • 2026-09-23 04:47 • thehackernews.com
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior.Opus 5.5, per Anthropic, is a “major step up from Opus 5,” and “achieves the best scores of any model to date on our automated behavioral audit, our alignment suite that tests Claude across thousands
https://thehackernews.com/2026/09/anthropic-and-openai-models-still.html - Microsoft: September Windows updates break Always On VPN connections
BleepingComputer • 2026-09-23 04:18 • www.bleepingcomputer.com
Microsoft warned that the September 2026 security updates may also break Always On VPN connections on some Windows 11 systems. […]
https://www.bleepingcomputer.com/news/microsoft/microsoft-september-2026-windows-updates-break-always-on-vpn-connections/ - Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
The Hacker News • 2026-09-23 04:12 • thehackernews.com
A use-after-free in the Linux kernel’s AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.The flaw, tracked as CVE-2026-80521 (CVSS score: 7.8), was fixed upstream on August 6, but Ubuntu has not shipped the patch for its 26.04, 24.04, or 22.04 LTS releases. DepthFirst
https://thehackernews.com/2026/09/exploit-released-for-unpatched-ubuntu.html - Research on Models Engaging in Genie-Like Behavior
Schneier on Security • 2026-09-23 04:03 • www.schneier.comNew paper: “Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training.”
Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to j…
https://www.schneier.com/blog/archives/2026/09/research-on-models-engaging-in-genie-like-behavior.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.