Cyber Security News
Start. Stay. Grow.
Curated daily. The latest hacks, breaches, and cyber trends—humanized.
Daily cyber brief
Hacking Editorial Brief — September 16, 2026
Microsoft Ships Record 972 CVEs in September Patch Tuesday, Two Zero-Days Under Active Exploit
Microsoft released its largest security update on record, addressing 972 vulnerabilities in September's Patch Tuesday cycle. Among them are two actively exploited zero-day elevation of privilege flaws and 113 rated critical. The scale of disclosed vulnerabilities represents a significant spike in Microsoft's security posture reporting, though the company has not publicly attributed the active exploits to specific threat actors or disclosed exploitation scope. Organizations running Microsoft environments face an unusually large remediation surface this month, with immediate patching priorities centered on the two known-exploited flaws. The sheer volume suggests either improved internal discovery processes or an accumulation of third-party researcher submissions.
Critical WSO2 API Manager Flaw Under Active Exploitation; Iranian APT Uses Medical Imaging in Social Engineering
A critical authentication bypass vulnerability in WSO2 API Manager (CVE-2026-5430) is being actively exploited in the wild, enabling account takeover through improper JWT cryptographic signature verification. The flaw affects enterprise API management infrastructure and requires immediate patching. Separately, the UK's National Cyber Security Centre confirmed that Iranian state-sponsored actors are using fabricated MRI scan results as social engineering lures to compromise targets deemed enemies of the regime. The medical imagery tactic marks a shift toward exploiting sensitive health contexts to establish credibility and urgency in spear-phishing campaigns. Meanwhile, ShinyHunters claimed a breach of Florida's DMV system, asserting theft of 200,000 records, though state officials disputed the password-reset method cited by the group.
Sources: CrowdStrike · WIU Cybersecurity Center · The Record · Fox News
Around the Web
Last Updated: N/A

Hacks + Heists
KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens
... Hacker News. "Malicious browser extensions bypass Chromium integrity mechanisms by manipulating Secure Preferences and regenerating required HMACs...
Read more →How a Chinese Hacking Firm Tapped AI to Supercharge Cyber-Spying - WSJ
Internal company materials show AI being used to make stolen foreign government data digestible for police, targeting Russia, Pakistan and others.
Read more →Russian-Linked Threat Actors Using AI to Exploit PaperCut NG/MF Vulnerabilities
A suspected Russian-speaking cyber actor has used artificial intelligence to devise exploits targeting recently disclosed security flaws in PaperCut N...
Read more →CISA Confirms Ransomware Gangs Abusing Microsoft SharePoint RCE Vulnerability
CISA confirmed that ransomware gangs have begun actively exploiting a high-severity Microsoft SharePoint remote code execution vulnerability since ear...
Read more →China-Linked Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy GRIMWEDGE
A Chinese threat actor has been attributed to a spear-phishing campaign that exploits recently patched security flaws in Google Chrome and ...
Read more →
Big Cyber
Iranian Hackers Use Telegram-Controlled Malware to Spy on Dissidents and Journalists
Cybersecurity agencies in the United States, the United Kingdom, and the Netherlands have detailed a Windows malware that they say Iran's ...
Read more →Chinese Hackers Exploit Critical Tencent Software Flaw for One-Click Code Execution
Chinese threat actors linked to UNC3569 are actively exploiting CVE-2026-51990 in Tencent's Sogou Input Method to deploy the GrayRabbit backdoor for c...
Read more →New DDRop Attack Breaks Intel TDX and AMD SEV-SNP Confidential Computing
Intel takes the same position on physical attacks against server memory. Cybersecurity. Intel has separately said that physical interposer attacks of ...
Read more →Passkey phishing attack, Anthropic's report, airline cyber loophole - CISO Series
Airlines compliance with new cybersecurity regulations means fewer passenger conveniences. Starting next month, airlines whose flights are canceled or...
Read more →
Hard Tech
React2Shell (CVE-2025-55182)
A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...
Read more →Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer
We discovered three vulnerabilities that when chained together, allow for complete remote compromise:
Read more →Check Point - Wrong Check Point (CVE-2024-24919)
Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...
Read more →Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...
Read more →Loading...
The Cybersecurity Chronicles
‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.
Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.
Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Stay Updated with Cyber Security News
Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.
Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.