CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild

19/09/2026 0 Comments 0 tags

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

CrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub Repositories

19/09/2026 0 Comments 0 tags

An attacker copied about 170 of CrowdSec’s private GitHub repositories on May 22 using the account of an employee who had just left, CrowdSec said on September 18. The French security

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

18/09/2026 0 Comments 0 tags

A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

18/09/2026 0 Comments 0 tags

A flaw in four widely used AI coding agents lets someone who controls a plugin’s code repository swap the plugin an agent installs for a malicious one, even when the

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

18/09/2026 0 Comments 0 tags

In July 2025, someone registered a domain that used to belong to a content delivery network.  The CDN had been wound down years earlier, and the domain it served assets

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

18/09/2026 0 Comments 0 tags

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

18/09/2026 0 Comments 0 tags

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

18/09/2026 0 Comments 0 tags

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

18/09/2026 0 Comments 0 tags

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits

Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer

18/09/2026 0 Comments 0 tags

A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. “The developer likely