Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and macOS.

According … Continue reading Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI→

Posted in Uncategorized

New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

A flaw in cPanel’s CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take “full control of the server,” the company said on September 22.

A second bug in the WP Toolkit plugin, used to install and… Continue reading New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control→

Posted in Uncategorized

Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests

Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior.

Opus 5.5, per Anthropic, is a “major step up from Opus 5,… Continue reading Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests→

Posted in Uncategorized

Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

A use-after-free in the Linux kernel’s AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22.

The flaw, tracked as CVE-2026-80521 (CVSS sco… Continue reading Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape→

Posted in Uncategorized

F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says.

The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization… Continue reading F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers→

Posted in Uncategorized

Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites.

The attacks, detected on September 3 and 4, 2026, involved the chaining of t… Continue reading Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware→

Posted in Uncategorized

Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said.

The risk applies when an app puts values an attacker cont… Continue reading Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input→

Posted in Uncategorized

ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency.

“We have compromised the FBI. We hold very sensitive d… Continue reading ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants→

Posted in Uncategorized

Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

Attackers exploited a previously unknown flaw in Check Point’s Security Management Server in a handful of targeted attacks on July 23, the company said.

The flaw, CVE-2026-93616, allows an attacker who can access the server’s web service to run s… Continue reading Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks→

Posted in Uncategorized