Breaking News – Cyber Threats – 2026-09-26 08:00 PDT
Breaking News – Cyber Threats (last 6h)
Generated: 2026-09-26 08:00 PDT
- GitHub Actions re-enabled with Mini Shai-Hulud payload still active
BleepingComputer • 2026-09-26 07:19 • www.bleepingcomputer.com
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. […]
https://www.bleepingcomputer.com/news/security/github-actions-re-enabled-with-mini-shai-hulud-payload-still-active/ - OpenAI's AI agents accidentally uploaded user-provided images to third-party sites
BleepingComputer • 2026-09-26 05:28 • www.bleepingcomputer.com
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. […]
https://www.bleepingcomputer.com/news/artificial-intelligence/openais-ai-agents-accidentally-uploaded-user-provided-images-to-third-party-sites/ - Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
The Hacker News • 2026-09-26 04:46 • thehackernews.com
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally.The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in unauthenticated remote code execution.
The vulnerability was first exploited as a zero-day
https://thehackernews.com/2026/09/attackers-bypass-wafs-to-exploit-oracle.html - Zero Trust for AI Agents Starts With Fixing Zero Visibility
The Hacker News • 2026-09-26 03:30 • thehackernews.com
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could promise, a string of recent incidents, including a widely discussed intrusion at Hugging Face during an evaluation of OpenAI agents, has spurred organizations to
https://thehackernews.com/2026/09/zero-trust-for-ai-agents-starts-with.html - Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
The Hacker News • 2026-09-26 02:55 • thehackernews.com
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site.The cross-site request forgery (CSRF) vulnerability, which has yet to be assigned a CVE identifier, carries a CVSS score of 8.8 out of 10.0. It only affects versions
https://thehackernews.com/2026/09/elementor-csrf-flaw-lets-attackers-take.html
Sources: BleepingComputer, The Hacker News, KrebsOnSecurity, SANS ISC, CISA.