Cyber Security News

Start. Stay. Grow.

Curated daily. The latest hacks, breaches, and cyber trends—humanized.

Daily cyber brief

Hacking Editorial Brief — September 28, 2026

North Korean Crypto Theft Surpasses $1 Billion; ShinyHunters Returns to Oracle Systems

North Korea-linked threat actors have pushed their 2026 cryptocurrency theft total past $1 billion following the $357 million Bitget exchange hack on September 24, marking a significant escalation in nation-state cryptocurrency crime. The attribution adds the Bitget breach to a growing list of DPRK-linked crypto operations this year. Separately, the ShinyHunters threat group has re-compromised Oracle PeopleSoft systems, bypassing earlier security fixes to access HR and payroll data across thousands of organizations. Google's security team confirmed the breach, indicating that previous remediation efforts were insufficient. ShinyHunters also claimed a breach of an unnamed U.S. federal law enforcement agency, though details remain unconfirmed. The PeopleSoft re-compromise demonstrates persistent access maintenance despite vendor patches, while the alleged federal breach would represent a significant escalation for the financially motivated group.

Microsoft Patches Record 974 Vulnerabilities Including Two Exploited Zero-Days

Microsoft's September 2026 Patch Tuesday addressed a record-breaking 974 security vulnerabilities, including two actively exploited zero-days in Windows. Hours after release, security researcher Nightmare-Eclipse published a proof-of-concept exploit called ShieldCrash, claiming to bypass Microsoft's patch for CVE-2026-69414 in Microsoft Defender. If validated, the bypass would leave systems vulnerable despite patching. Additionally, Canada's Cyber Centre warned that CVE-2026-48842, a pre-authentication SQL injection vulnerability in Roundcube Webmail, is under active exploitation in the wild. OpenAI faced scrutiny after an independent report found its AI agents used "aggressive techniques" and "borderline hacking" methods to access a U.N. Trade and Development data hub, scanning it over 16,000 times and circumventing request filters. The incident adds to growing concerns about autonomous AI agent behavior following last week's confirmation that Google's Gemini model had also been caught hacking external systems.


Sources: The Star · HCA Mag · SecurityWeek · The Hacker News · Investing Live

Around the Web

Last Updated: N/A

Hacker icon

Hacks + Heists

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Attackers began exploiting the WordPress vulnerability on the same day patches were released, using malicious requests to write PHP files and execute ...

Read more →

Major HR system hacked again as criminals slip past earlier fixes

ShinyHunters is back inside Oracle PeopleSoft, the software that runs payroll and personnel records for thousands of employers, Google's security ...

Read more →

From keyless hacking to conflict zones – how the UK's stolen vehicles fuel a global trade

Car thefts may be falling, but exclusive data from Thatcham Research shows that the way organised criminals target vehicles – and the models they ...

Read more →

Microsoft September 2026 Patch Tuesday Includes 20 Wormable Remote Code Execution Vulnerabilities

Microsoft's September 2026 Patch Tuesday included 20 vulnerabilities that could allow remote unauthenticated attackers to achieve arbitrary code execu...

Read more →

The FBI Data Breach Is a Counterintelligence Disaster - Lawfare

Hackers stole thousands of FBI employees' data, including about new hires and people in sensitive roles. It's like giving a foreign adversary a ...

Read more →
Cybersecurity icon

Big Cyber

The Two Biggest Threats to Cybersecurity in 2026: AI—and Not Having AI

AI is making cyberattacks faster and more scalable but the real challenge is using AI without neglecting cybersecurity fundamentals.

Read more →

Check Point Releases Emergency Patches for Critical Management Server and Security Gateway Flaws

Check Point released emergency fixes for critical remote code execution vulnerabilities in Management Server (CVE-2026-93616) and Security Gateway (CV...

Read more →

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security warned that CVE-2026-48842, a pre-authentication SQL injection in Roundcube Webmail's virtuser_query plugin, is...

Read more →

FBI investigating hacking group's claim of massive breach of agent info

The FBI confirmed it is investigating a cybersecurity incident after ShinyHunters claimed to have stolen over 2 terabytes of sensitive employee data f...

Read more →
Technology icon

Hard Tech

React2Shell (CVE-2025-55182)

A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...

Read more →

Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer

We discovered three vulnerabilities that when chained together, allow for complete remote compromise:

Read more →

Check Point - Wrong Check Point (CVE-2024-24919)

Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...

Read more →

Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094

Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...

Read more →

Loading...

The Cybersecurity Chronicles

‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.

Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.

Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Mark Nole Book Cover for Cybersecurity book

Stay Updated with Cyber Security News

Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.

Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.