A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 12 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 22 September 2026 · 33 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Recent CVEs22 Sep
CVSS 7.5 HIGH GNU Emacs 28.1 through 31.1 allows arbitrary code execution upon opening a file, because an untrusted value of read-symbol-shorthands affects the intern and unintern functions. This affects the default configuration; no parti…
Read at source →
CVEDatabase - Recent CVEs22 Sep
CVSS 6.5 MEDIUM Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to enforce a request body size limit during CSRF validation of plugin requests which allows an authenticated user to exhaust…
Read at source →
CVEDatabase - Recent CVEs22 Sep
CVSS 5.5 MEDIUM Mattermost versions 11.9.x <= 11.9.1, 11.8.x <= 11.8.5, 11.7.x <= 11.7.10, 11.10.x <= 11.10.1 fail to apply the internal-connection filter to OAuth endpoint requests, which allows a System Administrator to make the server i…
Read at source →
CVEDatabase - Recent CVEs22 Sep
CVSS 7.2 HIGH OpenClaw iOS before 2026.8.11 logs complete agent deep-link URLs including persistent bearer keys to unified logs as public diagnostic data. Attackers who obtain diagnostic archives can recover unrotated keys and replay them…
Read at source →
CVEDatabase - Critical CVEs22 Sep
CVSS 9.3 CRITICAL LTSecurity LTK3500SF contains a hard-coded credentials vulnerability where root and guest account passwords are stored as reversible hashes in /etc/shadow, recoverable using dictionary-based cracking tools. Attackers can…
Read at source →
CVEDatabase - Critical CVEs22 Sep
CVSS 9.8 CRITICAL SolarWinds Observability Self-Hosted was found to be affected by an unauthenticated remote code execution vulnerability due to the insufficient integrity checks. Installations configured in a non-default and non-secure co…
Read at source →
CVEDatabase - Critical CVEs22 Sep
CVSS 9.6 CRITICAL · Vendor: Adobe Adobe Experience Manager Forms JEE is affected by a Server-Side Request Forgery (SSRF) vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to…
Read at source →
CVEDatabase - Critical CVEs22 Sep
CVSS 9.1 CRITICAL · Vendor: Adobe Adobe Experience Manager Forms JEE is affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileg…
Read at source →
CISA Current Activity22 Sep
CISA has added four new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active exploitation. CVE-2026-85102 Check Point Multiple Products Improper Certificate Validation Vulnerability CVE-2026-93…
Read at source →
CISA Cybersecurity Advisories22 Sep
View CSAF Summary Industrial Edge Management contains an authentication bypass vulnerability that could allow an unauthenticated remote attacker to perform full account takeover by resetting user credentials without completing email verifi…
Read at source →
CISA Cybersecurity Advisories22 Sep
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to hijack session cookies and issue state-changing requests as an operator which would allow the attacker to control the programmable logic controller…
Read at source →
CISA Cybersecurity Advisories22 Sep
View CSAF Summary Successful exploitation of this vulnerability could result in a system crash, a DoS, or memory corruption, which could lead to code execution on the victim system. The following versions of lwIP (Lightweight IP) are affec…
Read at source →
CISA Cybersecurity Advisories22 Sep
View CSAF Summary The products listed below contain a denial of service vulnerability that could allow an attacker to force the devices into protection mode under certain conditions. This disables remote connectivity functions (Web Access)…
Read at source →
Independent Investigative Journalism & Breaking News
BleepingComputer22 Sep
Security researchers developed an attack that lets hackers with privileged access register a rogue external MFA provider that steals users' passwords during legitimate login attempts. [...]
Read at source →
BleepingComputer22 Sep
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1.8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2.2 million people. [...]
Read at source →
Dark Reading22 Sep
More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.
Read at source →
BleepingComputer22 Sep
A Chinese-speaking threat actor has been exploiting vulnerabilities in ZyXEL GS1900 Smart Managed Switches and WordPress to steal sensitive data from 996 devices and more than 18,500 records stored in backend databases. [...]
Read at source →
Dark Reading22 Sep
Microsoft seized 50 websites and disabled more than 150 domains as part of a coordinated disruption effort against a phishing-as-a-service platform targeting Microsoft 365 accounts.
Read at source →
BleepingComputer22 Sep
The ShinyHunters extortion gang claims it breached FBI systems using a new Oracle PeopleSoft zero-day vulnerability, gaining access to internal services and stealing sensitive data on employees and job applicants. [...]
Read at source →
The Hacker News22 Sep
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service t…
Read at source →
The Hacker News22 Sep
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. T…
Read at source →
The Hacker News22 Sep
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harves…
Read at source →
Dark Reading22 Sep
Threat actors stole 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.
Read at source →
Dark Reading22 Sep
As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.
Read at source →
The Hacker News22 Sep
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. Distric…
Read at source →