Security news
Latest security news
Today · Wed, 16 Sept 2026
- Critical ScreenConnect flaw now actively exploited in attacks
Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).
BleepingComputer - Cyber-Attacks Cost Organizations $52,000 on Average
Hiscox highlighted the huge financial and operational costs of cyber-attacks, with the average cost of an incident at $52,000
Infosecurity Magazine - Ministry of Justice apologizes after court staff accessed Southport victims' files
Sensitive personal data was involved, but there is no evidence it was shared with third parties
The Register - Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping
OPSWAT researchers find two zero-days in TP-Link cameras
Infosecurity Magazine - Windows Server 2022 reaches end of mainstream support next month
Microsoft has reminded customers that Windows Server 2022 will reach the end of mainstream support next month and enter extended support until October 2031.
BleepingComputerMicrosoft, Windows - Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
Infosecurity MagazinePalo Alto, Sophos - NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
Infosecurity Magazine - Google fixes actively exploited Android zero-day on Pixel devices
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.
BleepingComputerGoogle, Android - Mythos has made 2026 patching hell. It might make 2027 a breeze
Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner
The Register - Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over
The Hacker NewsWordPress
About this news
- 1,241
- Stories
- 31
- Added in the last 24 hours
- 17
- Critical in the last 7 days
- 4
- Reported by several outlets