← Back to Blog
Security News
Security News — 19 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 5 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 19 September 2026 · 12 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Critical CVEs19 Sep
CVSS 9.4 CRITICAL OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project wr…
Read at source →
CVEDatabase - Critical CVEs19 Sep
CVSS 8.6 HIGH A weakness has been identified in Totolink A3002MU Hh-B20211125.1046. Affected by this issue is the function formWsc of the file /boafrm/formWsc. This manipulation of the argument localPin causes command injection. The attack…
Read at source →
CVEDatabase - Critical CVEs19 Sep
CVSS 9.3 CRITICAL A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. Affected by this vulnerability is the function formWlWds of the file /boafrm/formWlWds. The manipulation of the argument submit-url results in buf…
Read at source →
Independent Investigative Journalism & Breaking News
The Hacker News19 Sep
Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with…
Read at source →
BleepingComputer19 Sep
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension. The Prompt Forcing technique earned over…
Read at source →
BleepingComputer19 Sep
A joint law enforcement advisory warns that the North Korean hacking group WaterPlum compromised at least 30,000 devices worldwide from December 2025 through July 2026 and transferred more than $10.7 million in stolen cryptocurrency to Nor…
Read at source →
BleepingComputer19 Sep
The ShinyHunters extortion gang breached the Clop (aka Cl0p) ransomware operation's data leak site, defacing the Tor site and allegedly stealing server data and the private keys for its onion service. [...]
Read at source →
The Hacker News19 Sep
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure a…
Read at source →
The Hacker News19 Sep
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investiga…
Read at source →
BleepingComputer19 Sep
AI actress Tilly Norwood went viral after glitching into Chinese on Piers Morgan Uncensored last night. Her "Talking Tilly" video call service face-scans every caller for an 18+ age check, senses callers' moods during calls, and shuts down…
Read at source →
The Hacker News19 Sep
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CV…
Read at source →
Security Executive, Architecture & Policy
Daniel Miessler19 Sep
A charcoal sketch of a small purple sorting machine taking in a flood of envelopes, dropping most into bins, and sending two glowing envelopes up a narrow ramp to a large engine behind it/images/jev-decision-gate.webp/images/jev-decision-g…
Read at source →