← Back to Blog
Security News
Security News — 15 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 6 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 15 September 2026 · 19 items.
Government & Critical Vulnerability Advisories
CISA Cybersecurity Advisories15 Sep
Developed by the National Institute of Standards and Technology (NIST) and CISA, this interagency report provides federal agencies and cloud service providers with guidelines to protect the identity assertions, access tokens, and cryptogra…
Read at source →
CISA Cybersecurity Advisories15 Sep
View CSAF Summary Successful exploitation of these vulnerabilities could grant full administrative control of the device, allowing an attacker to view live and recorded surveillance, alter device configurations, and use the device as a net…
Read at source →
CISA Cybersecurity Advisories15 Sep
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access privileged management functions or send arbitrary SMS messages through the connected GSM modem. The following versions of mySCADA myPRO Ma…
Read at source →
CISA Cybersecurity Advisories15 Sep
View CSAF Summary Schneider Electric is aware of a vulnerability in its SCADAPack x70 products. The SCADAPack 47x, SCADAPack 47xi, SCADAPack 47xd, SCADAPack 470R and SCADAPack 57x products are Remote Terminal Units that provide communicati…
Read at source →
Independent Investigative Journalism & Breaking News
BleepingComputer15 Sep
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild. [...]
Read at source →
BleepingComputer15 Sep
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account. [...]
Read at source →
Dark Reading15 Sep
You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.
Read at source →
Dark Reading15 Sep
The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and…
Read at source →
The Hacker News15 Sep
Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334. Active since at le…
Read at source →
Dark Reading15 Sep
The full-service malware-as-a-service (MaaS) platform offers a Windows implant, command-and-control (C2) infrastructure, and an operator panel for comprehensive remote access.
Read at source →
BleepingComputer15 Sep
CenterPoint Energy disclosed a breach compromising some customers' personal information after an attacker leaked data allegedly stolen from the utility company. [...]
Read at source →
The Hacker News15 Sep
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malw…
Read at source →
The Hacker News15 Sep
Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family,…
Read at source →
BleepingComputer15 Sep
A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems. [...]
Read at source →
The Hacker News15 Sep
With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators can move just as swiftly a…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)15 Sep
I have not done this type of diary in a while: What traffic will you see from a system on boot, before a user logs in? I just took a quick look at macOS 27 "Golden Gate" to see what traffic you should expect. Here are some of the highlight…
Read at source →
SANS Internet Storm Center (Handler Diary)15 Sep
Read at source →
Security Executive, Architecture & Policy
Schneier on Security15 Sep
This essay was written with Cindy Cohn, and originally appeared in Lawfare . One of the many legacies of the terrorist attacks of Sept. 11 is the government-wide shift from targeted surveillance—such as individual wiretaps or pen register/…
Read at source →
Schneier on Security15 Sep
Really interesting story about Harvest, a specialized code breaking computer built in the 1960s by IBM for the NSA.
Read at source →