Category: Cyber Security


  • Google Fixes Actively Exploited Pixel Zero-Day

    Google has released its September 2026 security update for Pixel devices, addressing 110 vulnerabilities. The patches include a high-severity Android zero-day that attackers may already be exploiting in limited, targeted operations. The company is urging all owners of supported Pixel devices to install the update as soon as it becomes available. Pixel Zero-Day Affects Cellular…

  • Acronis Backup Flaw Exploited in Targeted Attacks

    Acronis has disclosed a high-severity privilege escalation vulnerability affecting its backup integrations for cPanel, WebHost Manager and Plesk. The company says attackers may already be exploiting the security flaw in limited, targeted attacks. The vulnerability affects Linux servers and allows a low-privileged attacker to gain additional permissions. Acronis has released security updates and recommends installing…

  • BambooToken Malware Controls Windows and Linux Systems via MQTT

    A previously undocumented malware framework named BambooToken is using the MQTT messaging protocol to control compromised Windows and Linux systems. Researchers have identified infections across several industries, including finance, legal services, hospitality and software development. The campaign has operated since at least 2023. However, its operators began adding MQTT-based command-and-control capabilities to variants developed between…

  • Hackers Exploit WooCommerce Plugin Flaw to Hijack WordPress Sites

    Hackers are actively exploiting a critical WooCommerce plugin flaw to upload PHP backdoors to WordPress websites. Security researchers have recorded more than 100,000 attacks targeting vulnerable installations. The security issue affects the premium WooCommerce Wholesale Lead Capture plugin. Successful exploitation can give attackers full control of a website. Critical Vulnerability Enables File Uploads The vulnerability,…

  • Hacked IP Cameras Give Attackers Access to Corporate Networks

    Hackers are compromising internet-connected cameras to infiltrate corporate networks, conduct espionage and launch distributed denial-of-service attacks. Belgium’s cybersecurity agency warns that hacked IP cameras can provide an entry point to far more valuable internal systems. IP Cameras Become Corporate Entry Points The Centre for Cybersecurity Belgium has warned that threat actors are actively compromising IP…

  • Iranian Hackers Use Chosen Brick Spyware Against Dissidents

    Iranian-linked hackers are using Chosen Brick spyware to monitor dissidents, activists and journalists worldwide. The Windows malware exploits Telegram infrastructure to steal messages, files, screenshots and microphone recordings. Security agencies in the United States, the United Kingdom and the Netherlands have now issued a joint warning about the campaign. In one attack, the hackers even…

  • Android OEM Flaws Give Unprivileged Apps Root Access

    A security researcher has demonstrated how an Android app with no permissions can gain root access on flagship phones from several major manufacturers. The attack bypasses the operating system’s sandbox and gives the app almost complete control of the device. The vulnerabilities affect software and kernel drivers added by phone manufacturers. Therefore, the researcher says…

  • Cisco Email Flaw Gives Attackers Root Access

    Cisco has released patches for a critical Secure Email Gateway vulnerability that attackers have exploited as a zero-day. The flaw allows unauthenticated remote attackers to run commands with root privileges. The company urged customers to install the security updates immediately. Meanwhile, US federal agencies must patch affected systems by September 17. Attackers Exploit Cisco Email…

  • Emergency Windows Updates Fix RDS and Hyper-V Failures

    Microsoft has released emergency Windows updates to resolve Remote Desktop Services failures caused by its September 2026 security patches. The out-of-band releases also address some Hyper-V and USB audio problems. Affected systems experienced failed Remote Desktop connections, sign-in errors and unresponsive servers. However, the new patches do not fix every reported audio issue. September Updates…

  • Twitch Extension Exposes OAuth Tokens From 30,000 Users

    A browser extension with more than 30,000 installations has exposed users’ Twitch OAuth tokens to a commercial bot service. The extension remained available through the official Chrome and Firefox stores at the time of reporting. Security researchers found that Twitch Enhanced Viewer | JeetBot extracts authentication data from Twitch requests. It then sends the credentials…