Breaking News – Cyber Threats – 2026-09-24 17:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-24 17:00 PDT
- MacSync malware uses public iCloud calendars to deliver new payloads
BleepingComputer • 2026-09-24 13:53 • www.bleepingcomputer.com
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. […]
https://www.bleepingcomputer.com/news/security/macsync-malware-uses-public-icloud-calendars-to-deliver-new-payloads/ - New Carbonato malware uses AI agents to hijack exposed Docker hosts
BleepingComputer • 2026-09-24 13:10 • www.bleepingcomputer.com
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. […]
https://www.bleepingcomputer.com/news/security/new-carbonato-malware-uses-ai-agents-to-hijack-exposed-docker-hosts/ - Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
The Hacker News • 2026-09-24 11:10 • thehackernews.com
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus’s own software to gain root access, the highest level of control over an Android phone.OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not
https://thehackernews.com/2026/09/unpatched-oneplus-flaws-let-installed.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.