Breaking News – Cyber Threats – 2026-09-23 17:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-23 17:00 PDT
- Smashing Security podcast #486: Vibe-coded shops, and hackable Flock cameras
Graham Cluley • 2026-09-23 16:15 • grahamcluley.com
A store in Auckland vibe-coded itself a new website. Within hours, its inventory had somehow expanded to include a pair of crusty socks, an $850 banana, and all of New Zealand’s national parks. What could possibly have gone wrong?Meanwhile, a hacker collective backed a truck into one of the license-plate-reading Flock safety cameras popping up on American street corners, and took a very close look inside.
All this and more in episode 486 of the “Smashing Security” podcast with cybersecurity expert and keynote speaker Graham Cluley, and special guest Dave Bittner.
https://grahamcluley.com/smashing-security-podcast-486/ - Placeholder domain used in dev docs now serves ClickFix attacks
BleepingComputer • 2026-09-23 15:46 • www.bleepingcomputer.com
The “third-party.com” domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. […]
https://www.bleepingcomputer.com/news/security/placeholder-domain-used-in-dev-docs-now-serves-clickfix-attacks/ - New RemControl Android banking malware targets users in Europe and Canada
BleepingComputer • 2026-09-23 14:25 • www.bleepingcomputer.com
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. […]
https://www.bleepingcomputer.com/news/security/new-remcontrol-android-banking-malware-targets-users-in-europe-and-canada/ - Check Point warns of hackers exploiting Security Gateway VPN RCE flaw
BleepingComputer • 2026-09-23 12:53 • www.bleepingcomputer.com
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. […]
https://www.bleepingcomputer.com/news/security/check-point-warns-of-hackers-exploiting-security-gateway-vpn-rce-flaw/ - Hackers start exploiting critical WordPress flaw for code execution
BleepingComputer • 2026-09-23 11:31 • www.bleepingcomputer.com
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. […]
https://www.bleepingcomputer.com/news/security/hackers-start-exploiting-critical-wordpress-flaw-for-code-execution/ - Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
The Hacker News • 2026-09-23 11:06 • thehackernews.com
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads.According to Aikido, the list of Terraform providers and Go modules is below –
gocommunity-io/dockerd (222 downloads)
kreuzwenker/
https://thehackernews.com/2026/09/attackers-use-malicious-terraform.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.