Security news

Latest security news

174 of 1,256 storiesTopic: MalwareClear all

Yesterday · Tue, 15 Sept 2026

  1. BambooToken Malware Uses MQTT to Control Windows and Linux Systems

    Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging malware family, codenamed BambooToken, is assessed to be active since at least February 2023 and put to use in attacks targeting organizations across Asia and South America.

    The Hacker NewsWindows, Linux
  2. BambooToken malware controls Windows and Linux systems via MQTT

    A previously unknown malware framework called BambooToken, active since at least 2023, is now using the Message Queuing Telemetry Transport (MQTT) protocol to communicate with Windows and Linux systems.

    BleepingComputerWindows, Linux
  3. Hackers target WordPress sites via third-party WooCommerce plugin

    Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.

    BleepingComputerWordPress
  4. China spy chief points at US AI models in cyber threat warning

    China's spy chief identified Anthropic’s Claude Mythos and OpenAI’s GPT-5.5-Cyber as signs of what he called a “disruptive upgrade” in cyber capabilities, increasing the speed and potential weaponization of vulnerability discovery and malware development.

    The Record
  5. CVE-2026-76461: Critical Cisco Secure Email Gateway Vulnerability Exploited in the Wild

    Overview On September 14, 2026, Cisco published a security advisory for CVE-2026-76461 , a critical SQL injection vulnerability affecting Cisco AsyncOS Software for Cisco Secure Email Gateway. The vulnerability has a reported CVSS v3.1 base score of 9.8 and could allow an unauthenticated, remote attacker to execute arbitrary commands with root privileges on an affected appliance. Cisco Secure Email Gateway, formerly known as IronPort Email Security Appliance, is an enterprise email security product that inspects inbound and outbound email for threats including phishing, malware, spam, and business email compromise. Because affected gateways process externally delivered email as part of their normal operation, exploitation does not require access to an administrative interface or authentication. An attacker can reportedly trigger the vulnerability by sending a specially crafted email through a vulnerable gateway. CVE-2026-76461 was added to CISA's Known Exploited Vulnerabilities ( KEV ) catalog on the same day as the vendor disclosed the vulnerability, indicating that CVE-2026-76461 was exploited as a zero-day prior to disclosure. Cisco noted that their PSIRT became aware of active

    CriticalUsed in attacksRapid7 BlogCisco
  6. HBO Max’s verified Reddit account hijacked to spread malware

    Cybercriminals used HBO Max’s verified Reddit account to run 108 malicious ads that tricked people into installing information stealers.

    Malwarebytes Labs
  7. Hacked HBO Max Reddit Account Used for Malware Delivery via ClickFix Attack

    Ads led to a ClickFix page designed to trick macOS and Windows users into installing malware.

    SecurityWeekWindows
  8. China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

    A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called GRIMWEDGE. Volexity, which is tracking the threat cluster under the moniker UTA0560, said the activity targeted multiple non-governmental organizations (NGOs) on September 1, 2026. "The

    The Hacker NewsGoogle, Microsoft, Windows

Mon, 14 Sept 2026

  1. HBO Max Reddit account compromised to serve ClickFix attacks

    Part of a 'massive 48-hour malvertising blitz' targeting macOS and Windows machines with malware

    The RegisterWindows
  2. 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

    The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.

    Dark ReadingCisco

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets