Security news

Latest security news

Today · Wed, 16 Sept 2026

  1. Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution

    A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under active exploitation. The vulnerability in question is CVE-2026-89026 (CVSS v3.1 score: 9.8/CVSS v4.0 score: 9.3), which can allow an unauthenticated remote attacker to execute arbitrary operating system (OS) commands by taking advantage of a hard-coded

    CriticalThe Hacker News
  2. PHP Webshell Campaign Targets WordPress Through Critical WooCommerce Plugin Bug

    Attackers are exploiting a critical flaw in a third-party WooCommerce plugin to upload PHP webshells

    Infosecurity MagazineWordPress
  3. Attacker Hijacks AI Coding Assistant Session, Spreads Shai-Hulud Across About 100 Repositories

    Mandiant says an attacker hijacked an active AI coding-assistant session at an unnamed software-as-a-service provider and later spread Shai-Hulud across about 100 internal code repositories. Before the repository spread, the assistant recommended software that the attacker had poisoned, and the recommendation was accepted. The worm stole repository secrets and source code for the

    The Hacker News
  4. Parallels Desktop Flaw Lets Non-Admin Mac Users Gain Root, but Intel Macs Can't Install Fix

    Parallels Desktop for Mac has a flaw that lets an ordinary local account run code as root, the highest level of access on a Mac, software company JFrog said this week. The attack needs code already running on the machine as a normal user, so it does not work over the network. JFrog says the fix is in Parallels Desktop 27, a version that Intel Macs cannot install. Yuval Moravchick, who leads

    The Hacker NewsIntel
  5. Google Patches Pixel Modem Flaw Amid Signs of Limited Targeted Exploitation

    Google has disclosed that a high-severity security flaw in its Pixel Cellular Modem has come under exploitation in the wild. The vulnerability, tracked as CVE-2026-58704 (CVSS score: 8.0), is a privilege escalation flaw. "In Cellular Modem, there is a possible permission bypass due to a logic error in the code," according to a description of the bug in the NIST National Vulnerability Database

    CriticalUsed in attacksThe Hacker NewsGoogle
  6. Threat Intelligence Alone Won't Close the Exploitation Gap

    A leaked credential shows up in a criminal marketplace, or a vulnerability gets a disclosure advisory, and either one can be weaponized against a real target before most security teams have triaged the alert. Attackers are combining that kind of intelligence with AI-assisted exploitation to accelerate the path from exposure to breach faster than most security programs are built to react.

    The Hacker News
  7. Critical ScreenConnect flaw now actively exploited in attacks

    Attackers now exploit a critical-severity ConnectWise ScreenConnect vulnerability in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA).

    BleepingComputer
  8. Acronis cPanel Backup Plugin Vulnerability Exploited in Targeted Attacks

    Acronis has warned that a high-severity security flaw in its Backup plugin for cPanel and Web Host Manager (WHM) deployments has been exploited in the wild. The vulnerability, tracked as CVE-2026-87886 (CVSS score: 7.8), is described as a case of local privilege escalation due to insecure file permissions. It affects the following versions - Acronis Backup plugin for cPanel & WHM (Linux

    The Hacker NewsLinux
  9. Zero-Day Flaw in TP-Link Cameras Enables Eavesdropping

    OPSWAT researchers find two zero-days in TP-Link cameras

    Infosecurity Magazine
  10. Google fixes actively exploited Android zero-day on Pixel devices

    Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.

    BleepingComputerGoogle, Android

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets