Security news
Latest security news
Today · Wed, 16 Sept 2026
- Major Cyber Threat Detection Vendors Shift from MITRE to UK Testing Program
A group of cyber threat detection providers, including CrowdStrike, Palo Alto Networks and Sophos, have joined SE Labs’ PIVOT program
Infosecurity MagazinePalo Alto, Sophos - NCSC and Allies Warn of Iranian Spyware Campaign
The UK’s National Cyber Security Centre says Iranian Chosen Brick spyware is designed to snoop on dissidents
Infosecurity Magazine - Google fixes actively exploited Android zero-day on Pixel devices
Google has released the September 2026 security patches to address 110 vulnerabilities affecting its Pixel devices, including one zero-day flaw actively exploited in targeted attacks.
BleepingComputerGoogle, Android - Mythos has made 2026 patching hell. It might make 2027 a breeze
Gartner sees huge amounts of technical debt paid down, and better scanning that could make software safer sooner
The Register - Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells
Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. "This vulnerability can be leveraged by unauthenticated attackers to upload arbitrary files, including PHP backdoors, and achieve remote code execution," Wordfence said. The WordPress security company said it has blocked over
The Hacker NewsWordPress - Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens
A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is a case of improper verification of a cryptographic signature that could result in account takeover. Hacktron Team has been credited with discovering and reporting the flaw. "JWT authentication
The Hacker News
Yesterday · Tue, 15 Sept 2026
- The vulnpocalypse rains iBugs down on Apple with record-setting number of patches
September Patch Tuesday part 2?
The RegisterApple - Acronis warns of actively exploited flaw in its cPanel backup plugin
Acronis disclosed a high-severity Linux local privilege escalation vulnerability in its backup plugin for cPanel, WebHost Manager (WHM), and Plesk that may be exploited in the wild.
BleepingComputerLinux - Malcious Admin Menu Editor Pro plugin backdoors 1,500 WordPress sites
Malicious versions of the Admin Menu Editor Pro plugin for WordPress have been distributed to more than 200 customers after a threat actor compromised the maintainer's website and pushed updates that created a hidden user account.
BleepingComputerWordPress - Microsoft Commits to Sweeping AI Privacy Rules for Students. Will Other Tech Giants Follow?
Microsoft agreed to adopt guardrails and privacy standards for its AI in schools, as negotiated with the American Federation of Teachers.
SecurityWeekMicrosoft
About this news
- 1,256
- Stories
- 42
- Added in the last 24 hours
- 19
- Critical in the last 7 days
- 4
- Reported by several outlets