Google has released its September 2026 security update for Pixel devices, addressing 110 vulnerabilities. The patches include a high-severity Android zero-day that attackers may already be exploiting in limited, targeted operations. The company is urging all owners of supported Pixel devices to install the update as soon as it becomes available. Pixel Zero-Day Affects Cellular…
Acronis has disclosed a high-severity privilege escalation vulnerability affecting its backup integrations for cPanel, WebHost Manager and Plesk. The company says attackers may already be exploiting the security flaw in limited, targeted attacks. The vulnerability affects Linux servers and allows a low-privileged attacker to gain additional permissions. Acronis has released security updates and recommends installing…
A previously undocumented malware framework named BambooToken is using the MQTT messaging protocol to control compromised Windows and Linux systems. Researchers have identified infections across several industries, including finance, legal services, hospitality and software development. The campaign has operated since at least 2023. However, its operators began adding MQTT-based command-and-control capabilities to variants developed between…
Hackers are actively exploiting a critical WooCommerce plugin flaw to upload PHP backdoors to WordPress websites. Security researchers have recorded more than 100,000 attacks targeting vulnerable installations. The security issue affects the premium WooCommerce Wholesale Lead Capture plugin. Successful exploitation can give attackers full control of a website. Critical Vulnerability Enables File Uploads The vulnerability,…
Hackers are compromising internet-connected cameras to infiltrate corporate networks, conduct espionage and launch distributed denial-of-service attacks. Belgium’s cybersecurity agency warns that hacked IP cameras can provide an entry point to far more valuable internal systems. IP Cameras Become Corporate Entry Points The Centre for Cybersecurity Belgium has warned that threat actors are actively compromising IP…
Iranian-linked hackers are using Chosen Brick spyware to monitor dissidents, activists and journalists worldwide. The Windows malware exploits Telegram infrastructure to steal messages, files, screenshots and microphone recordings. Security agencies in the United States, the United Kingdom and the Netherlands have now issued a joint warning about the campaign. In one attack, the hackers even…
A security researcher has demonstrated how an Android app with no permissions can gain root access on flagship phones from several major manufacturers. The attack bypasses the operating system’s sandbox and gives the app almost complete control of the device. The vulnerabilities affect software and kernel drivers added by phone manufacturers. Therefore, the researcher says…
Cisco has released patches for a critical Secure Email Gateway vulnerability that attackers have exploited as a zero-day. The flaw allows unauthenticated remote attackers to run commands with root privileges. The company urged customers to install the security updates immediately. Meanwhile, US federal agencies must patch affected systems by September 17. Attackers Exploit Cisco Email…
Microsoft has released emergency Windows updates to resolve Remote Desktop Services failures caused by its September 2026 security patches. The out-of-band releases also address some Hyper-V and USB audio problems. Affected systems experienced failed Remote Desktop connections, sign-in errors and unresponsive servers. However, the new patches do not fix every reported audio issue. September Updates…
A browser extension with more than 30,000 installations has exposed users’ Twitch OAuth tokens to a commercial bot service. The extension remained available through the official Chrome and Firefox stores at the time of reporting. Security researchers found that Twitch Enhanced Viewer | JeetBot extracts authentication data from Twitch requests. It then sends the credentials…