Cyber Security News
Start. Stay. Grow.
Curated daily. The latest hacks, breaches, and cyber trends—humanized.
Daily cyber brief
Hacking Editorial Brief — September 14, 2026
China-Aligned Actors Exploit Tencent Input Method Flaw to Deploy GrayRabbit Malware
A China-aligned espionage group is actively exploiting CVE-2026-51990, a critical vulnerability in Tencent's Sogou Input Method application, to deploy GrayRabbit malware on compromised systems. The campaign targets the widely deployed Chinese language input software, enabling attackers to establish persistent access on affected endpoints. Separately, APT31 has been observed deploying the previously undocumented BlueMoon exploit kit, which chains vulnerabilities in Microsoft Windows and Google Chrome to compromise targets. The toolkit represents a shift toward modular, multi-stage exploit chains by advanced persistent threat groups focused on espionage operations. A Russian-speaking threat actor has also been attributed to exploiting PaperCut NG/MF vulnerabilities using AI-assisted techniques to breach hundreds of instances of the print management software.
Malicious Twitch Extension Exfiltrates OAuth Tokens From 31,000 Users
A malicious browser extension distributed through Twitch, identified as JeetBot, successfully exfiltrated OAuth tokens from nearly 31,000 users by transmitting credentials to operator-controlled proxy infrastructure. The campaign targeted Twitch users seeking additional platform functionality, harvesting authentication tokens that could enable account takeover and unauthorized access to linked services. Firefox version 85.8.7 now blocks the malicious behavior, though the scope of compromised accounts and potential downstream impact remains under investigation. The incident highlights ongoing risks associated with third-party browser extensions in gaming and streaming ecosystems.
Microsoft September Patch Tuesday Addresses Record 974 Flaws Including Two Exploited Zero-Days
Microsoft's September 2026 Patch Tuesday addressed 974 vulnerabilities, a record-breaking figure that includes two actively exploited zero-day flaws: CVE-2026-81963 and CVE-2026-85880. The volume represents a substantial increase from the 966 vulnerabilities disclosed in initial reporting and underscores escalating complexity across Microsoft's product stack. Both zero-days were under active exploitation at the time of disclosure, though Microsoft has not publicly attributed the campaigns or detailed exploitation scope.
Sources: Bleeping Computer · The Hacker News · The Hacker News · The Hacker News · Bleeping Computer
Around the Web
Last Updated: N/A

Hacks + Heists
Malicious Twitch Browser Extension Leaks OAuth Tokens From Nearly 31,000 Users
JeetBot's Twitch extension sent OAuth tokens from nearly 31000 users to operator-controlled proxies; Firefox 85.8.7 stops the behavior.
Read more →North Korean Hackers Exploit Windows Zero-Day in Operation Dream Job
North Korean hackers have been actively exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies.
Read more →Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection
Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an ...
Read more →Ukrainian hacker gets four years in US prison over Conti ransomware attacks
A Ukrainian national was sentenced to four years in a U.S. prison for his role in the notorious Conti ransomware operation, which targeted more ...
Read more →Anthropic blocks 'malicious use' of AI that could develop biological weapons - BBC
The revelations in Anthropic's threat intelligence report come after a former top researcher at the company warned of the risks of AI to humanity.
Read more →
Big Cyber
Passkey phishing attack, Anthropic's report, airline cyber loophole - CISO Series
Airlines compliance with new cybersecurity regulations means fewer passenger conveniences. Starting next month, airlines whose flights are canceled or...
Read more →Cybersecurity stocks get a jolt on gloomy AI warnings from CEOs of Anthropic and OpenAI
Shares of top cybersecurity names popped in pre-market trading amid fresh warnings from the biggest names in AI within the past two days. Okta (OKTA) ...
Read more →ID verification giant IDScan confirms data breach with more than 150 million driver's licenses stolen
IDScan confirmed a data breach involving theft of driver's licenses and other government-issued identification documents from its cloud storage.
Read more →Internet Archive Breach Exposes 31 Million Files
Attackers breached the Internet Archive's systems in September 2026, exposing over 31 million files including email addresses and usernames, with invo...
Read more →
Hard Tech
React2Shell (CVE-2025-55182)
A 10.0 critical severity vulnerablility affecting server-side use of React.js, tracked as CVE-2025-55182 in React.js and CVE-2025-66478 specifically f...
Read more →Breaking Into a Brother (MFC-J1010DW): Three Security Flaws in a Seemingly Innocent Printer
We discovered three vulnerabilities that when chained together, allow for complete remote compromise:
Read more →Check Point - Wrong Check Point (CVE-2024-24919)
Gather round, gather round - it’s time for another blogpost tearing open an SSLVPN appliance and laying bare a recent in-the-wild exploited bug. This ...
Read more →Backdoor in XZ Utils allows RCE: everything you need to know - CVE-2024-3094
Detect and mitigate CVE-2024-3094, a critical supply chain compromise, affecting XZ Utils Data compression library. Organizations should patch urgentl...
Read more →Loading...
The Cybersecurity Chronicles
‘The Cybersecurity Chronicles: 2024‘ pulls back the curtain on the digital threats that shaped our world last year, revealing the human stories behind the headlines. From art galleries frozen by ransomware to prison tablets hacked with a minus sign, from British Library archivists racing to protect centuries of knowledge to Spotify users meticulously curating their digital identities – these stories illuminate how cybersecurity touches every aspect of modern life.
Author Mark Nole weaves together intimate portraits of the people on all sides of the digital battlefield: the defenders working through sleepless nights to protect critical infrastructure, the victims grappling with stolen identities and lost savings, and even the attackers themselves, operating from nondescript offices with project management software and performance metrics.
Through detailed reporting and narrative storytelling, Nole reveals how 2024 became the year when cybersecurity stopped being just a technical problem and emerged as a fundamentally human challenge. Whether you’re a security professional or simply someone trying to understand our increasingly digital world, these chronicles offer an unprecedented look at how technology shapes – and sometimes betrays – our trust, our privacy, and our lives.

Stay Updated with Cyber Security News
Get the latest cybersecurity headlines, breaking news, and expert insights delivered directly to your inbox. Stay ahead of threats and informed about the digital landscape.
Join thousands of cybersecurity professionals and enthusiasts. No spam, just valuable insights.