Security news

Latest security news

70 of 1,256 storiesTopic: Nation StateClear all

Today · Wed, 16 Sept 2026

  1. Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers

    Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, according to multiple reports from Kaspersky. The cybersecurity vendor said it has identified attacks mounted by NightEagle (aka APT-Q-95), a threat actor known to be active since at least 2023, that involve new techniques for persistence and lateral movement.

    The Hacker News
  2. Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

    Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over

    The Hacker NewsWordPress

Yesterday · Tue, 15 Sept 2026

  1. Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

    Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's intelligence service uses to spy on dissidents, journalists, and activists around the world. The malware is controlled via the Telegram messaging app and can copy a target's emails and chat messages, take screenshots, and activate the microphone to record

    The Hacker NewsWindows
  2. Hackers target WordPress sites via third-party WooCommerce plugin

    Hackers are actively exploiting a critical vulnerability in the WooCommerce Wholesale Lead Capture premium plugin for WordPress to upload a PHP backdoor.

    BleepingComputerWordPress

Mon, 14 Sept 2026

  1. 'Sandworm' Chains Cisco Vulnerabilities to Deploy Cyclops Blink

    The notorious Russian threat group is spreading an upgraded version of the botnet malware, which the FBI disrupted in 2022.

    Dark ReadingCisco
  2. ⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

    AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines on their own. That is not a great combination. The rest of the week is more familiar: old bugs still working, fresh exploit chains, exposed systems, weak defaults, and simple paths that should have been harder to abuse. A few of

    The Hacker NewsPaperCut
  3. Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

    The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.

    SecurityWeekWindows

Sun, 13 Sept 2026

  1. Hackers exploit Tencent app flaw to deploy GrayRabbit malware

    Threat actors linked to a China-aligned espionage group are exploiting a critical vulnerability (CVE-2026-51990) in Tencent's Sogou Input Method for Windows to deploy the GrayRabbit backdoor.

    BleepingComputerWindows

Sat, 12 Sept 2026

  1. BlueMoon Exploit Kit Chains Recent Chrome, Windows Zero-Days

    Multiple espionage-motivated threat actors have adopted BlueMoon in opportunistic, rushed deployments.

    SecurityWeekWindows, Chrome

Fri, 11 Sept 2026

  1. Hackers abused Claude to extract secrets from 1.8M Android apps

    Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes.

    BleepingComputerAndroid

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets