CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks - The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2.
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware - Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign . The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/maintain-one-comment...
News alert: SCOUTz gives MSPs security evidence to help turn prospects into customers - PHOENIX, Sept. 24, 2026, CyberNewswire — SCOUTz , a prospect intelligence platform built for managed service provider (MSP) security sales, is now available in open beta. The platform gives an MSP dated evidence about a prospect’s environment before the first meeting and keeps that evidence attached...
Kiteworks urges 6-hour server shutdown over potential zero-day attacks - Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack.
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions - A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today and ordered to pay nearly $300,000 in restitution to victims. One...
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells - Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could result in...
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild - The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions...
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions - A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone. OnePlus told him the...
Ukrainian ransomware developer jailed for nearly 13 years - A court in Zurich has sentenced a Ukrainian man to 12 years and nine months in prison, and banned him from Switzerland for ten years, for developing ransomware that blackmailed companies around the world. Read more in my article on the Hot for Security blog.