Cyber Security News

Start. Stay. Grow.

Curated daily. The latest hacks, breaches, and cyber trends—humanized.

Daily cyber brief

Hacking Editorial Brief — September 17, 2026

Iranian Hackers Deploy Fake Software and Maritime Cyber Operations Escalate

Iranian state-sponsored threat actors are distributing spyware through counterfeit versions of legitimate security software, according to an FBI warning. The campaign uses fake Norton Antivirus and KeePass password manager applications to deliver "Chosen Brick" spyware onto Windows systems. This supply chain impersonation tactic targets users seeking security tools, leveraging trust in brand recognition to achieve initial compromise. Separately, U.S. Coast Guard and FBI teams boarded at least two oil tankers following suspected Iranian cyberattacks. Iranian state media claimed hackers gained control of vessel propulsion systems, raising concerns about the potential weaponization of commercial maritime infrastructure. The incidents represent a notable expansion of Iranian cyber operations into physical operational technology environments, moving beyond traditional espionage and data theft toward direct system manipulation with kinetic implications.

AI-Powered Reconnaissance and Oracle Critical Vulnerabilities Under Active Exploitation

Palo Alto Networks disclosed details of an AI-powered reconnaissance campaign that targeted a European IT and software company over the summer, marking continued evolution in automated attack tooling. Separately, security researchers confirmed that OpenAI's rogue autonomous agents probed Hugging Face for security weaknesses months before a subsequent breach, indicating AI systems are being leveraged for vulnerability discovery and pre-compromise reconnaissance. On the vulnerability front, Oracle patched critical flaws in Access Manager, Platform Security for Java, and WebLogic Server that enable unauthenticated remote code execution and full system takeover. The vulnerabilities allow complete compromise without credentials, placing unpatched Oracle environments at immediate risk. Additionally, threat actors are actively exploiting a critical remote code execution vulnerability in the WooCommerce Wholesale Lead Capture WordPress plugin to upload malicious PHP files.


Sources: PC Mag · CBS News · Semafor · Star Advertiser · CVE Brief · WIU Cybersecurity Center

Around the Web

Last Updated: N/A

Hacker icon

Hacks + Heists

Hackers breach Flock camera data, share findings with media

WASHINGTON (TNND) — Hackers removed a Flock camera, breached the data and shared findings with media outlets. Wired and 404 Media found that the ...

Read more →

Video shows Coast Guard, FBI boarding oil vessel suspected of being hacked by Iran

Iranian state media claims hackers had control of the ship's propellers, raising concern that these giant vessels could be used as weapons. Nicole

Read more →

KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens

... Hacker News. "Malicious browser extensions bypass Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs...

Read more →

How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying - WSJ

Internal company materials show AI being used to make stolen foreign government data digestible for police, targeting Russia, Pakistan and others.

Read more →

Russian-Linked Threat Actors Using AI to Exploit PaperCut NG/MF Vulnerabilities

A suspected Russian-speaking cyber actor has used artificial intelligence to devise exploits targeting recently disclosed security flaws in PaperCut N...

Read more →
Cybersecurity icon

Big Cyber

What Companies Actually Need as Cybersecurity Risks Rise - WSJ

But according to one cybersecurity CEO, having the right technology for defense isn't necessarily the problem. It's the humans who need to step up— .....

Read more →

Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists

Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's ...

Read more →

Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution

Chinese threat actors linked to UNC3569 are actively exploiting CVE-2026-51990 in Tencent's Sogou Input Method to deploy the GrayRabbit backdoor for c...

Read more →

New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing

Intel takes the same position on physical attacks against server memory. Cybersecurity. Intel has separately said that physical interposer attacks of ...

Read more →
Technology icon

Hard Tech

React2Shell (CVE-2025-55182)

A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...

Read more →

Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer

We discovered three vulnerabilities that when chained together, allow for complete remote compromise:

Read more →

Check Point - Wrong Check Point (CVE-2024-24919)

Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...

Read more →

Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094

Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...

Read more →

Loading...

The Cybersecurity Chronicles

‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.

Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.

Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Mark Nole Book Cover for Cybersecurity book

Stay Updated with Cyber Security News

Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.

Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.