Active Exploitation Attempts Target WSO2 API Manager JWT Bypass With Forged Admin Tokens

16/09/2026 0 Comments 0 tags

A critical security flaw in WSO2 API Manager has come under active exploitation in the wild, according to findings from watchTowr. The vulnerability, tracked as CVE-2026-5430 (CVSS score: 9.8/10.0), is

Attackers Exploit WooCommerce Wholesale Lead Capture Flaw to Plant PHP Web Shells

16/09/2026 0 Comments 0 tags

Threat actors are exploiting a critical security flaw in WooCommerce Wholesale Lead Capture, a premium WordPress plugin that has more than 6,000 active installs. “This vulnerability can be leveraged by

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

15/09/2026 0 Comments 0 tags

Cybersecurity researchers have shed light on a previously undocumented Brazilian banking malware operation that delivers a toolkit called KREMLIN. Elastic Security Labs is tracking the activity under the moniker REF9334.

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

15/09/2026 0 Comments 0 tags

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran’s intelligence service uses to spy on dissidents, journalists, and

BambooToken Malware Uses MQTT to Control Windows and Linux Systems

15/09/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a multi-platform campaign that uses the Message Queueing Telemetry Transport (MQTT) protocol as a communication channel to control Windows and Linux systems. The emerging

Mass-Scanning Campaign Exploits Vite Flaw to Extract Cloud Credentials From Exposed Dev Servers

15/09/2026 0 Comments 0 tags

Cybersecurity researchers have disclosed details of a mass-scanning campaign that has targeted Vite deployments siphon sensitive data. The first is an automated effort aimed at internet-exposed Vite development servers that’s

Attack Chains, Not Just Attack Surfaces: Why Testing Individual Techniques Misses the Point

15/09/2026 0 Comments 0 tags

Introduction Security teams have gotten pretty good at testing against what can hurt them. Can this EDR agent catch this payload? Will my organization fail the phishing simulation? Does this

Human Attacker Exploits Marimo RCE, Reaches SSH Bastion in Eight Seconds

15/09/2026 0 Comments 0 tags

With artificial intelligence (AI) shrinking the window between vulnerability discovery and exploitation and lowering the barrier to entry for bad actors, new findings from Sysdig show that skilled human operators

LiteSpeed Enterprise Flaw Could Let One Hosting Account Gain Root Access on a Shared Server

15/09/2026 0 Comments 0 tags

A critical vulnerability in LiteSpeed Web Server Enterprise could let a low-privilege website user gain root access on a shared-hosting server, cPanel warned in an advisory published on September 14. On

China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE

15/09/2026 0 Comments 0 tags

A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and Microsoft Windows to deliver a malicious JavaScript backdoor called