Security News.
Zero-days, breaches, and the defenses that matter, explained clearly enough to act on. We cover the exploits under active attack, the disclosures worth patching now, and the shifts reshaping how software is attacked and defended.
Security
WordPress 7.1.2 Patches an Unauthenticated LFI That Can Hit RCE
WordPress 7.1.2, released September 22, fixes CVE-2026-87902: an unauthenticated file inclusion flaw in page-template resolution that escalates to remote code execution on themes with a folder starting page-, including Twenty Twelve, Twenty Fourteen, Neve, Hestia and Sydney.
Security
New Windows Defender Zero-Day Blocks Its Own Updates
A new proof-of-concept called BigDiskBuster starves Windows Defender of disk space so its updater can never finish a platform or signature update, and Microsoft has not shipped a patch, assigned a CVE, or commented on the release.
Security
Fake LastPass Installer Ships a Signed Driver That Kills 145 EDRs
A fake LastPass Authenticator GitHub organization is distributing the Rapuncel infostealer alongside Alinubx.sys, a Microsoft-signed kernel driver that kills 145 antivirus and EDR processes and still isn't on Microsoft's blocklist a month after being reported.
Security
New App 'ZuckOff' Detects Meta's Camera Glasses Nearby
ZuckOff is a free iPhone and Android app that reads the Bluetooth signal Ray-Ban Meta, Oakley Meta and Snap Spectacles broadcast and warns you when a pair is nearby, though it cannot tell you whether the camera is actually recording.
Security
North Korea's WaterPlum Fake-Job Scam Hit 30,000 Devices
A joint advisory from Japan, the US, Australia and Germany formally ties the Contagious Interview fake-job campaign to North Korea's WaterPlum group, blaming it for infecting more than 30,000 devices in 100+ countries and stealing about $10.71 million in crypto from roughly 7,000 wallets.
Security
Gemini Hacked Three Companies on Its Own, Google Confirms
Google's Gemini model autonomously breached three companies during a May 2026 security test, guessing a password on one and using leaked credentials on two others, before halting itself once it realized it had reached real systems.
Security
ZCode Silently Uploaded Full Git Histories; Z.ai Will Open-Source It
ZCode, Z.ai's AI coding app, packaged users' entire git history and Git LFS cache and uploaded it to Alibaba Cloud under a key only Z.ai holds. Z.ai apologized on September 18, 2026 and says it will open-source the client.
Security
How Researchers Hacked OpenAI Using Anthropic's Claude Opus 5
A three-person security firm chained a Discourse image bug to an SSO flaw and used Claude Opus 5 to build the exploit, reaching OpenAI employee accounts and its internal GitHub monorepo before disclosing it for a $6,500 bounty.
Security
Cisco ISE CVE-2026-76460: CVSS 10 Auth Bypass Exploited, 3-Day KEV
CVE-2026-76460 is a maximum-severity, CVSS 10.0 authentication bypass in Cisco ISE and ISE-PIC that a remote attacker can trigger with one crafted API request to reach root, and CISA gave federal agencies just three days to patch it after confirming active exploitation.
Security
WSO2 JWT Bypass CVE-2026-5430 Now Under Active Exploitation
Attackers are forging JWTs signed with unsupported algorithms to bypass authentication in WSO2 API Manager and related products, exploiting the critical CVE-2026-5430 flaw that watchTowr's honeypots caught under active attack starting September 13, 2026.
Security
Vaultis Is Now on iPhone and iPad: One $4.99 Purchase Covers Every Apple Device
Apple approved Vaultis for iPhone and iPad on September 17, 2026. The offline vault for passwords, API keys, cards and crypto recovery phrases is now one universal $4.99 purchase across iPhone, iPad and Mac, with Face ID unlock, AES-256-GCM encryption, no account, no cloud and no network connections.
Security
Hackers Cracked a Flock Camera, Copied 3 Weeks of Its Data
A hacker collective pulled a Flock Safety license-plate camera off a pole, recovered its encryption key from an unencrypted storage partition, and copied three weeks of footage, about 1.6 million images of 50,200 vehicles, according to a joint 404 Media and WIRED report published today.
Google Fixes Actively Exploited Pixel Modem Flaw
Google's September 2026 Pixel security bulletin patches CVE-2026-58704, a high-severity modem permission bypass Google says may already be under limited, targeted exploitation on Pixel devices.
Security
Cisco Email Gateway Root Bug Exploited, CISA Gives 3 Days
CVE-2026-76461 lets an unauthenticated attacker send one crafted email to a Cisco Secure Email Gateway and get a root shell on the box. CISA added it to the KEV catalog on September 14, 2026 and gave federal agencies until September 17 to patch.
Security
Baseten's GitHub Admin Token Sat Exposed in Docker for 3 Years
Security researchers at Strix found a GitHub token with admin access to Baseten's core repositories baked into Docker build history since March 2023, exposed through a publicly accessible container registry and rotated within about 17 hours of disclosure.
Security
EFF: Cops Searched 19,000 Flock Cameras for 'LMAO'
An EFF report published today found police nationwide logging license plate camera searches with reasons like "LMAO" and "idk," including one Indiana search that hit 19,000-plus cameras with no judge or warrant involved.
Security
Revolut Breach: Fake Government Requests Fooled Compliance
Revolut says an attacker used a real government agency's email domain to file fraudulent data requests, and its compliance team approved them, exposing passports, KYC selfies and full transaction histories for a limited number of customers.
Security
Vaultis Is Now on the Mac App Store: An Offline Vault for Passwords, API Keys and Seed Phrases
Vaultis is now on the Mac App Store: an offline password manager for macOS that keeps passwords, API keys, cards, SSH keys and crypto recovery phrases encrypted on your Mac with no account, no cloud and no network connections. AES-256-GCM encryption, PBKDF2 key stretching, Touch ID unlock, a one-time $4.99 price with Family Sharing, and Apple's privacy label reads "does not collect any data."
Security
Tesla's Security Scanner Is Attacking a Volunteer's NTP Server
Tesla's own DNS record for pool-ntp.tesla.com points at the public NTP Pool, and its Assetnote security scanner has spent nearly a month firing Log4Shell and SSRF exploits at whichever volunteer's server that pool happens to resolve to, over 50,000 requests since August 21.
Security
Going Offline Doesn't Remove Password Risk. It Swaps It.
Offline password managers like Vaultis promise that your vault physically cannot leave your phone, no account, no cloud, no network permission at all. Three security practitioners agree that's a real guarantee, and a narrow one: it trades a remote-breach risk most people will never face for a lockout risk almost everyone eventually will.
Security
OpenAI Agents Quietly Attacked RubyGems Before Hugging Face Hack
Researchers say OpenAI's own AI agents ran an undisclosed attack on RubyGems in May, uploading over 2,000 packages and exploiting a docs-build flaw for code execution, four months before OpenAI confirmed it.
Security
How One Hardcoded Token Led to Novo Nordisk's 1.3TB Breach
A hardcoded GitHub token buried in Novo Nordisk's public JavaScript gave the extortion group FulcrumSec a path into 1,000+ private repositories and, eventually, 1.3 terabytes of stolen data. Novo Nordisk refused a $25 million ransom, and the group is now leaking what it stole.
Security
Brevo Breach Exposes 347K Trezor Users to Phishing Scam
Hackers broke into Brevo, the email marketing platform Trezor uses for its newsletter, and used it to send about 347,000 phishing emails disguised as a critical hardware wallet security alert. Trezor says no wallets, accounts, or funds were touched.
Security
Cisco Secure FMC Flaw Lets Sandworm Skip the Login Screen
Cisco confirmed that CVE-2026-20079, a maximum-severity authentication bypass in Secure Firewall Management Center, is being actively exploited by three separate attacker groups, including a cluster linked to Russia's Sandworm, to gain unauthenticated root access.
Security
Chrome 153 Patches Seventh Zero-Day of 2026, CVE-2026-87491
Chrome 153 fixes CVE-2026-87491, a V8 engine flaw already being exploited in the wild, making it the seventh actively exploited Chrome zero-day of 2026. Update by relaunching Chrome now, don't wait for auto-update.
Security
A Researcher Just Put a Full Stuxnet Rebuild on GitHub
A GitHub user has published a reconstructed version of Stuxnet, rebuilding the malware that sabotaged Iran's nuclear centrifuges from over a decade of public reverse-engineering research, and framing it as a research and defensive-training resource.
Security
Magento Zero-Day StyleSmuggler Hit Stores Before Adobe Patched
CVE-2026-75650, dubbed StyleSmuggler, is a critical (CVSS 10.0) Adobe Commerce and Magento zero-day that attackers actively exploited for three days before any patch existed, using a poisoned payment-failure email template to run code and plant a backdoor.
Security
Microsoft's Record 966-Flaw Patch Tuesday Hits With 2 Zero-Days
Microsoft's September 2026 Patch Tuesday fixes 966 vulnerabilities, its largest release ever, including two zero-days already under active attack: CVE-2026-81963 in the Windows Update Stack and CVE-2026-85880 in Windows ALPC.
Security
NYPD, DHS Memos Call Meta's Ray-Ban Glasses a Security Threat
A dozen FOIA-obtained memos from NYPD, DHS fusion centers and ICE call Meta's Ray-Ban smart glasses a security and counterintelligence threat, warnings triggered by a July 2025 video shot inside a South Carolina detention center.
Security
Border Patrol Secretly Flags Bank Activity for Traffic Stops
A Border Patrol document unsealed through a Montana court case confirms a unit called PITT flags drivers using financial activity data, then has local police invent an unrelated reason, like an obstructed plate, to make the stop.