LIVE · cybersecurity feed
Live wire
CVE-2026-9055 · WordPress Amelia Plugin Flaw Exploited Before CVE PublicationCVE-2026-46331 · Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEVCVE-2026-84434 · CVE-2026-84434 Exploited Before Publication, No Patch WindowCVE-2024-4405 · Malicious Extensions Hijack AI Browser Agents via Prompt ForcingCVE-2026-58138 · Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCVE-2025-39682 · CISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildBrevo Supply-Chain Attack Infected Over 100,000 WebsitesPublic Exploits Released for Linux Kernel Root Privilege FlawsIn Other News: Ransomware Developer Sentenced, Plugin4Shell AI Attack, Critical SAP FlawCisco alerts customers to second actively exploited zero-day in as many days
vulnerability

SECURITY AFFAIRS MALWARE NEWSLETTER ROUND 115

Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Gray Rabbits and the Tale of a One-Click Backdoor Red Heron exploits Gitea n-day flaw in multinational campaign, exposing new Linux rootkit Malicious Twitch Browser Extension Exposes 30,000 Users’ OAuth Tokens to Russian Bot […]

zeroday.news ·

CenterPoint Energy, a Texas-based utility provider, has confirmed a data breach following claims by an unnamed hacker of having stolen 7.49 million customer records. The company acknowledged the incident but did not immediately provide details on the scope or nature of the compromised data.

The confirmation from CenterPoint Energy comes amidst a broader landscape of cybersecurity incidents affecting critical infrastructure. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) recently added several vulnerabilities to its Known Exploited Vulnerabilities catalog, including flaws in Acronis Backup, Cisco ISE, Google Pixel, and Cisco Secure Email Gateway. These additions highlight ongoing threats to various systems, from enterprise solutions to mobile devices.

Other recent attacks include a supply-chain compromise targeting Brevo, which reportedly infected over 100,000 websites with WordPress backdoors and Clickfix malware. Separately, the Gyazo image-sharing service experienced a data breach exposing 23 million user records. Financial institutions have also been targeted, with Revolut reporting a data leak potentially linked to compromised Italian government accounts.

Malware developments continue to pose significant risks. Researchers have identified "RatHat," a new AI-powered mobile threat that leverages Android accessibility features to target credentials and bank accounts. Another notable discovery is "BambooToken," malware that utilizes the MQTT protocol to evade detection. Additionally, the "SilkParasite" infrastructure has been linked to the "SpiceRAT" malware, which has been observed targeting energy and government entities across Central Asia.

The threat landscape also includes state-sponsored activities, such as "Chosen Brick," identified as Iranian surveillance malware. Iranian cyber operations have also been noted for targeting dissidents, activists, and journalists.

In response to these evolving threats, security researchers are developing new detection methods. These include "Delphi Scanner" for static malware detection via API sequence modeling, "ALIBI" for adversarial legitimacy injection against large language model (LLM) malware analyzers, and frameworks for metamorphic malware detection and uncertainty-aware zero-day botnet detection for IoT networks.

Law enforcement efforts are also underway, with the "NightmareStresser" DDoS-for-hire service recently taken offline as part of a global crackdown. Despite these efforts, the continuous emergence of new vulnerabilities and sophisticated attack techniques underscores the persistent challenges in cybersecurity.

vulnerabilitymalwarenation-state
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-9055critical

WordPress Amelia Plugin Flaw Exploited Before CVE Publication

A critical privilege escalation vulnerability in the WordPress Amelia plugin was exploited before its official CVE publication. CISA has not yet added it to its Known Exploited Vulnerabilities catalog.

CVE-2026-46331high

Linux Kernel Flaw Exploited After 71 Days, Not on CISA KEV

A Linux kernel vulnerability, CVE-2026-46331, has been confirmed as exploited, but remains absent from the US federal CISA Known Exploited Vulnerabilities (KEV) catalogue.

CVE-2026-84434high

CVE-2026-84434 Exploited Before Publication, No Patch Window

A critical vulnerability, CVE-2026-84434, was reported as exploited on September 18, 2026, one day before its official publication. This flaw has no patch window and is listed in the VulnCheck KEV but not in CISA KEV or EUVD.

vulnerability

Claude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained Flaws

Three researchers at the security firm Hacktron used Anthropic's Claude Opus 5 to chain two flaws and take over the ChatGPT and Codex accounts of several OpenAI employees, then reach an internal OpenAI code repository. The chain began with a bug in the software that runs OpenAI's public help forum and moved through a weakness in OpenAI's own login system. This was security research,

malware

Malicious npm packages evade install-script defenses at runtime

An ongoing npm malware campaign involving the 'indexed-btree' package shows how threat actors bypass supply chain defenses by hiding malicious code in a package's normal runtime behavior rather than in installation scripts. [...]

nation-state

AI Hallucinations Nearly Triggered a US-China Military Confrontation

An AI-generated intelligence report falsely identified weapons on a Chinese ship, nearly triggering a US military operation during the Iran war. According to CNN, four sources familiar with the episode say an intelligence report circulated through the military claiming a Chinese vessel in the Middle East was carrying components for a nuclear weapons program. The […]