Cyber Security News
Start. Stay. Grow.
Curated daily. The latest hacks, breaches, and cyber trends—humanized.
Daily cyber brief
Hacking Editorial Brief — September 18, 2026
AI Exploitation Used in OpenAI Breach and ClickFix Campaign Spreads via Marketing Platform
Security researchers successfully breached OpenAI's internal systems using Anthropic's Claude AI software, demonstrating practical exploitation of AI capabilities against a rival organization. The incident highlights the emerging use of large language models as active tools in offensive operations, not merely reconnaissance assets. Separately, a compromise at Brevo, an online marketing vendor, became the distribution vector for a widespread ClickFix-style malware campaign on Monday. The attack leveraged Brevo's infrastructure to deploy malicious payloads across numerous client websites simultaneously, exploiting the trust relationships inherent in third-party marketing platforms. ClickFix attacks typically trick users into running PowerShell commands disguised as legitimate technical fixes, making the marketing platform compromise particularly effective for social engineering at scale.
TrickBot Founder Surfaces on Russian Ballot and Extortion Campaigns Target FinTech
German police publicly identified Vitaly Kovalev, 38, as a founder of TrickBot, the organized cybercrime group behind ransomware attacks that disrupted U.S. hospitals. Despite being wanted by Interpol, Kovalev now appears on the federal candidate list for Russia's New People party, underscoring the protection afforded to cybercriminals operating within Russian borders. In ongoing extortion activity, hackers demanded $3 million from Revolut within 24 hours, threatening to publish customer data if payment is not made. The fintech firm joins a growing list of financial technology companies facing targeted data theft and ransom demands. Additionally, Iran-linked Handala Hack has been attributed to HEAVYGRAM, a Telegram-based surveillance backdoor capable of stealing passwords and conducting persistent monitoring of compromised devices.
Sources: Forbes · PC Mag · Meduza · AML Intelligence · The Hacker News
Around the Web
Last Updated: N/A

Hacks + Heists
Hackers Used Anthropic's Claude to Break Into OpenAI - WSJ
The hack demonstrates the complexity of defending corporate secrets in the age of AI hacking, said Joshua Saxe, the chief technology officer with ...
Read more →Hackers breach Flock camera data, share findings with media
WASHINGTON (TNND) — Hackers removed a Flock camera, breached the data and shared findings with media outlets. Wired and 404 Media found that the ...
Read more →Video shows Coast Guard, FBI boarding oil vessel suspected of being hacked by Iran
Iranian state media claims hackers had control of the ship's propellers, raising concern that these giant vessels could be used as weapons. Nicole
Read more →KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
... Hacker News. "Malicious browser extensions bypass Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs...
Read more →How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying - WSJ
Internal company materials show AI being used to make stolen foreign government data digestible for police, targeting Russia, Pakistan and others.
Read more →
Big Cyber
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
"At this time, there is no indication that this vulnerability has been exploited in the wild," the notice said. The U.S. Cybersecurity and ...
Read more →What Companies Actually Need as Cybersecurity Risks Rise - WSJ
But according to one cybersecurity CEO, having the right technology for defense isn't necessarily the problem. It's the humans who need to step up— .....
Read more →Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's ...
Read more →Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
Chinese threat actors linked to UNC3569 are actively exploiting CVE-2026-51990 in Tencent's Sogou Input Method to deploy the GrayRabbit backdoor for c...
Read more →
Hard Tech
React2Shell (CVE-2025-55182)
A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...
Read more →Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer
We discovered three vulnerabilities that when chained together, allow for complete remote compromise:
Read more →Check Point - Wrong Check Point (CVE-2024-24919)
Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...
Read more →Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...
Read more →Loading...
The Cybersecurity Chronicles
‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.
Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.
Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Stay Updated with Cyber Security News
Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.
Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.