Security news

Latest security news

Today · Wed, 16 Sept 2026

  1. Mythos has made 2026 patching hell. It might make 2027 a breeze

    Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner

    The Register
  2. Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

    Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over

    The Hacker NewsWordPress
  3. Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

    A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication

    The Hacker News

Yesterday · Tue, 15 Sept 2026

  1. Acronis warns of actively exploited flaw in its cPanel backup plugin

    Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild.

    BleepingComputerLinux
  2. Microsoft Issues Emergency Fixes After Massive Patch Tuesday

    You can't make an omelet without breaking a few eggs, and you can't patch nearly 1,000 CVEs without a few glitches.

    Dark ReadingMicrosoft
  3. Black Hat USA 2026 | The 'Breaking' News: The OpenAI–Hugging Face Incident

    The 'Breaking' News: The OpenAI–Hugging Face Incident - A Technical Reconstruction and Its Implications for AI At this Black Hat USA 2026 talk, OpenAI security engineers and researchers will reconstruct the OpenAI-Hugging Face incident and examine its implications for AI security, cyber resilience, and alignment. Throughout the session, they will share insights that address key topics raised by the Black Hat Review Board, including model safeguards, evaluation and containment practices, defensive use cases for AI, and the broader implications of increasingly autonomous systems for the cybersecurity community. The session will trace the models' attack path, including how frontier models are sandboxed during evaluations, how the models exploited a zero-day vulnerability to gain internet access, and how they identified and leveraged a remote code execution path on Hugging Face infrastructure. Drawing on the joint investigation, the speakers will explain how the activity was detected, contained, and investigated. They will also discuss the changes OpenAI is making to strengthen evaluation environments, containment controls, and monitoring capabilities, as well as the role AI systems pl

    Dark Reading
  4. Docker security advisory (AV26-925)

    Serial Number: AV26-925 Date: September 15, 2026 As of September 15, 2026, Docker is affected by a vulnerability in the following product: Docker Sandboxes Prior to 0.43.0 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Docker sbx-releases Docker security announcements

    Canadian Centre for Cyber SecurityDocker
  5. Mozilla security advisory (AV26-924)

    Serial Number: AV26-924 Date: September 15, 2026 As of September 15, 2026, Mozilla is affected by vulnerabilities in the following products: Firefox ESR Versions prior to 115.41 Versions prior to 140.16 Versions prior to 153.3 Firefox Versions prior to 156 The Cyber Centre encourages users and administrators to review the provided web links and apply any necessary updates as they become available. Security Vulnerabilities fixed in Firefox 156 — Mozilla Security Vulnerabilities fixed in Firefox ESR 115.41 — Mozilla Security Vulnerabilities fixed in Firefox ESR 140.16 — Mozilla Security Vulnerabilities fixed in Firefox ESR 153.3 — Mozilla Mozilla Foundation Security Advisories — Mozilla

    Canadian Centre for Cyber SecurityFirefox
  6. Cisco email security boxes can be rooted by... an email

    Attackers already exploiting the critical flaw, and Cisco warns they may be able to cover their tracks once they're in

    The RegisterCisco

About this news

1,256
Stories
41
Added in the last 24 hours
19
Critical in the last 7 days
4
Reported by several outlets