Breaking News – Cyber Threats – 2026-09-23 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-23 13:00 PDT
- Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
BleepingComputer • 2026-09-23 12:53 • www.bleepingcomputer.com
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. […]
https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/ - Hackers start exploiting critical WordPress flaw for code execution
BleepingComputer • 2026-09-23 11:31 • www.bleepingcomputer.com
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. […]
https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/ - Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
The Hacker News • 2026-09-23 11:06 • thehackernews.com
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.According to Aikido, the list of Terraform providers and Go modules is below –
gocommunity-io/dockerd (222 downloads)
kreuzwenker/
https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html - A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The Hacker News • 2026-09-23 09:53 • thehackernews.com
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run as you.GitLab shows each user this address behind a button labeled “Email work item to this project.” Mail sent to it opens an issue in that project, authored
https://thehackernews.com/2026/09/a-leaked-gitlab-issue-email-address.html - Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers
BleepingComputer • 2026-09-23 09:20 • www.bleepingcomputer.com
A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. […]
https://www.bleepingcomputer.com/news/security/malicious-ai-agents-steal-600k-credit-cards-infect-100-plus-sites-with-skimmers/ - Macfinger ClickFix campaign, (Tue, Sep 22nd)
SANS ISC Diary (full) • 2026-09-23 09:14 • isc.sans.eduIntroduction
- MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
The Hacker News • 2026-09-23 09:06 • thehackernews.com
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication.The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2026-67279) with an argument-injection bug in the RouterOS login process (CVE-2026-86060). Attack logs date to at
https://thehackernews.com/2026/09/mikrotrick-chain-let-attackers-take.html - InfraTrust report warns network management systems under attack
BleepingComputer • 2026-09-23 07:35 • www.bleepingcomputer.com
Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. […]
https://www.bleepingcomputer.com/news/security/infratrust-report-warns-network-management-systems-under-attack/ - This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
The Hacker News • 2026-09-23 07:17 • thehackernews.com
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker’s server, Cisco Talos said on September 22.The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this setup work from start to finish, and the public version of the malware does not work as it is.
https://thehackernews.com/2026/09/windows-malware-is-built-to-let-up-to.html - How One Kubernetes YAML Can Hand Over a GCP Organization
BleepingComputer • 2026-09-23 07:01 • www.bleepingcomputer.com
A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused deputy problem can turn a single Kubernetes YAML file into a path to organization-wide privilege escalation. […]
https://www.bleepingcomputer.com/news/security/how-one-kubernetes-yaml-can-hand-over-a-gcp-organization/
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.