Breaking News – Cyber Threats – 2026-09-25 13:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-25 13:00 PDT
- Elementor WordPress flaw lets attackers create admin accounts
BleepingComputer • 2026-09-25 11:13 • www.bleepingcomputer.com
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. […]
https://www.bleepingcomputer.com/news/security/elementor-wordpress-flaw-lets-attackers-create-admin-accounts/ - CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
BleepingComputer • 2026-09-25 10:24 • www.bleepingcomputer.com
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. […]
https://www.bleepingcomputer.com/news/security/cisa-warns-of-sharepoint-wso2-adobe-commerce-flaws-exploited-in-attacks/ - Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
BleepingComputer • 2026-09-25 09:00 • www.bleepingcomputer.com
Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it’s offering up to $250 in free usage credits, so more users can give it a try. […]
https://www.bleepingcomputer.com/news/artificial-intelligence/anthropic-rolls-out-up-to-250-in-free-claude-code-credits-but-only-for-cloud-sessions/ - OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
BleepingComputer • 2026-09-25 07:54 • www.bleepingcomputer.com
OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it’s unclear when it’ll begin rolling out. […]
https://www.bleepingcomputer.com/news/artificial-intelligence/openai-is-preparing-a-500-chatgpt-pro-max-plan-with-faster-codex/ - With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
BleepingComputer • 2026-09-25 07:51 • www.bleepingcomputer.com
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent identities. […]
https://www.bleepingcomputer.com/news/security/with-the-rise-of-ai-agents-soc-2-should-adapt-or-risk-irrelevance/ - Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
The Hacker News • 2026-09-25 07:44 • thehackernews.com
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign.The affected GitHub Actions are listed below –
actions-cool/issues-helper
actions-cool/maintain-one-commentVisiting either of the repositories now shows the message: “Access to this
https://thehackernews.com/2026/09/compromised-github-actions-came-back.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.