← Back to Blog
Security News
Security News — 23 September 2026
A daily, automatically-compiled digest of the cyber security stories that broke in the last 24 hours, drawn from 9 trusted feeds. Each entry is a short excerpt — follow the link to read the full article at its original publisher. Compiled 23 September 2026 · 22 items.
Government & Critical Vulnerability Advisories
CVEDatabase - Critical CVEs23 Sep
CVSS 9.3 CRITICAL Laravel-Mediable 7.0.0 before 7.0.2 contains an incomplete patch for CVE-2026-49972 in which the .pht extension is absent from the forbidden_extensions blocklist in config/mediable.php. The blocklist introduced to address…
Read at source →
CVEDatabase - Critical CVEs23 Sep
CVSS 9.8 CRITICAL · Vendor: IBM IBM Concert 1.0.0 through 3.0.0 references or accesses memory after it has been freed. This allows an attacker who can influence program execution or input may exploit this condition to corrupt memory, cause…
Read at source →
CVEDatabase - Critical CVEs23 Sep
CVSS 9.8 CRITICAL · Vendor: IBM IBM Concert 1.0.0 through 3.0.0 is vulnerable to a buffer overflow, caused by improper bounds checking. A local user could overflow the buffer and execute arbitrary code on the system.
Read at source →
CVEDatabase - Critical CVEs23 Sep
CVSS 9.8 CRITICAL · Vendor: IBM IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote attacker can supply specially crafted input that is incorporated into OS commands, resulting in arbitrary command execution on the underlying…
Read at source →
CISA Cybersecurity Advisories23 Sep
Introduction The Federal Bureau of Investigation (FBI) and Cybersecurity and Infrastructure Security Agency (CISA)—hereafter referred to as the “authoring agencies”—have published this fact sheet to highlight considerations for critical in…
Read at source →
Primary Threat Research & Vendor Intelligence
Microsoft Security Blog23 Sep
We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together. The post Reimagining the SOC for the agentic era in Microsoft Defender appeared fi…
Read at source →
Independent Investigative Journalism & Breaking News
BleepingComputer23 Sep
The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell commands. [...]
Read at source →
BleepingComputer23 Sep
A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]
Read at source →
Dark Reading23 Sep
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
Read at source →
Dark Reading23 Sep
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
Read at source →
BleepingComputer23 Sep
Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway product. [...]
Read at source →
BleepingComputer23 Sep
Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]
Read at source →
The Hacker News23 Sep
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector fo…
Read at source →
The Hacker News23 Sep
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run…
Read at source →
The Hacker News23 Sep
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick,…
Read at source →
Dark Reading23 Sep
The United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.
Read at source →
Dark Reading23 Sep
Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.
Read at source →
The Hacker News23 Sep
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser password…
Read at source →
Blue Team, Incident Response & Detection Engineering
SANS Internet Storm Center (Handler Diary)23 Sep
Introduction
Read at source →
SANS Internet Storm Center (Handler Diary)23 Sep
Read at source →
Red Team, Bug Bounty & Exploit Research
PortSwigger Research23 Sep
How many bugs have you missed because you didn’t send quite enough HTTP requests? Turbo Intruder now supports HTTP/3, can comfortably exceed 100,000 requests per second over Wi-Fi, and auto-tunes for
Read at source →
Security Executive, Architecture & Policy
Schneier on Security23 Sep
New paper: “ Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .” Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language mo…
Read at source →