China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

15/09/2026 0 Comments 0 tags

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called

Cisco Secure Email Gateway Flaw Exploited in the Wild, Enables Root Command Execution

15/09/2026 0 Comments 0 tags

Cisco has warned that a new critical vulnerability impacting AsyncOS Software for Cisco Secure Email Gateway has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-76461, carries

Telegram Desktop Flaw Lets Hidden JavaScript Exfiltrate Messages From HTML Exports

14/09/2026 0 Comments 0 tags

A flaw in Telegram Desktop let a bot’s message plant hidden JavaScript inside chats that users exported to HTML files, security researchers at ExPatch said in a writeup published on September 12.

3BB Attacker Used MeshCentral Backdoor for Root Access, Targeted Subscriber Credentials

14/09/2026 0 Comments 0 tags

An attacker was operating inside the network of 3BB, one of Thailand’s largest broadband providers, and maintained remote control of internal machines using a legitimate management tool called MeshCentral, threat

WordPress Adds Automated Plugin Reviews to Block High-Risk Updates Before Distribution

14/09/2026 0 Comments 0 tags

WordPress has announced it’s launching an automated security review for every release of a plugin before it’s distributed through the WordPress.org update API so as to analyze it for potential

Red Heron Exploits Gitea RCE to Compromise 13 Organizations Across Six Countries

14/09/2026 0 Comments 0 tags

A Chinese threat actor tracked as Red Heron has been attributed to the rapid exploitation of a recently disclosed security vulnerability in Gitea to compromise internet-facing instances as part of

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

14/09/2026 0 Comments 0 tags

Researchers have disclosed a new hardware attack, called DDRop, that breaks the memory protection in Intel and AMD confidential computing by silently dropping writes to a server’s memory, so the

⚡ Weekly Recap: Rogue AI Agents, WeChat Worm, PaperCut Attacks, AI Espionage, and Rootkits

14/09/2026 0 Comments 0 tags

AI keeps showing up in the wrong places. Attackers are using it to speed up exploits, test defenses, and automate more of the job. Some models are also crossing lines

AI Changed the Exposure Problem. Validation Needs to Change With It.

14/09/2026 0 Comments 0 tags

There’s a lot of noise around AI and cybersecurity right now. What’s actually important is far simpler, if often lost in the hubbub. Vulnerability discovery is getting faster and happening

Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users

14/09/2026 0 Comments 0 tags

A malicious cross-store Twitch browser extension has leaked OAuth tokens associated with nearly 31,000 users to proxy servers operated by a Russian commercial bot service. The extension, named “Twitch Enhanced