Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

ShinyHunters leaks Questel data taken through a vishing call into Microsoft 365

The extortion group ShinyHunters published data stolen from Questel, a French intellectual-property software and services firm, after a voice phishing call gave attackers access to a Sales SharePoint site in its Microsoft 365 environment. The group claimed more than 21 million records, but the published corpus verified out to about 1.2 million real email addresses, along with names, employers, job titles, physical addresses, and phone numbers, mostly corporate contacts from sales and marketing. Questel confirmed the unauthorized access but has not endorsed the larger figure. It is the same voice-phishing-into-connected-cloud pattern, and the same inflated-claim behavior, seen in other recent ShinyHunters cases.

Check
Harden identity and help desk processes against voice phishing, since a single tricked employee gave attackers access to a cloud collaboration site, and be skeptical of headline record counts in extortion claims.
Affected
Questel corporate contacts whose names, employers, titles, addresses, and phone numbers were leaked, about 1.2 million email addresses; the detailed business profiles support convincing targeted phishing despite the inflated original claim.
Fix
Adopt phishing-resistant authentication, train staff against vishing, tightly control access to Microsoft 365 sites like SharePoint, monitor for unusual data access, and verify breach claims before treating attacker figures as fact.

Critical WordPress plugin and theme flaws let unauthenticated attackers seize sites

Researchers at Wordfence and Patchstack disclosed a cluster of critical WordPress vulnerabilities, most scored 9.8, that let unauthenticated attackers take over sites or run code. In the WPMU DEV Dashboard plugin, CVE-2026-76581 is a single-sign-on authentication bypass that can hand an attacker an administrator session. The Avada theme's CVE-2026-18431 allows arbitrary file writes that lead to remote code execution. In the Pods plugin, CVE-2026-19598 lets an attacker escalate to administrator or overwrite any user's password, while TranslatePress's CVE-2026-19632 exposes the raw administrator password-reset link. Each independently enables full site compromise, and a separate GiveWP flaw in the same batch was covered earlier.

Check
Inventory your WordPress sites for the WPMU DEV Dashboard, Avada, Pods, and TranslatePress components, and update each to its patched version now, prioritizing internet-facing and multi-author sites.
Affected
Sites running vulnerable versions of WPMU DEV Dashboard, Avada, Pods, or TranslatePress (CVE-2026-76581, CVE-2026-18431, CVE-2026-19598, CVE-2026-19632); unauthenticated attackers can gain admin access, reset passwords, or execute code.
Fix
Patch every affected plugin and theme, audit for unexpected admin accounts, changed passwords, and new PHP files, front sites with a web application firewall, and rotate credentials on any exposed site.

TerminalFix tricks users with fake CAPTCHAs into pasting a backdoor command

A social-engineering campaign dubbed TerminalFix uses fake Cloudflare CAPTCHA pages, often served from compromised websites, to trick visitors into copying and running a malicious PowerShell command in their terminal. It is a refined take on the ClickFix technique, tuned to make complex scripts run more reliably, and it deploys a reverse-tunnel backdoor through a multi-stage chain involving DLL sideloading, hiding payloads inside images, and an outbound WebSocket connection for command and control. The campaign has hit organizations across several sectors. The core deception is simple to teach against: a legitimate CAPTCHA never asks you to paste and run commands in a terminal or Run dialog.

Check
Warn users that no real CAPTCHA ever asks them to paste commands into a terminal, and treat any such prompt as an attack, closing the page and reporting it.
Affected
Users lured to compromised or malicious sites showing fake CAPTCHA verification; following the prompt to run a PowerShell command installs a reverse-tunnel backdoor that gives attackers remote access to the device.
Fix
Enforce application control and PowerShell script-block logging, monitor for anomalous outbound WebSocket traffic and DLL sideloading, restrict who can run scripts, and train users to recognize fake CAPTCHA and ClickFix lures.

Trusted browser extensions turned into crypto stealers through ownership handoffs

Researchers at Socket detailed a long-running campaign, active since early 2024, in which Chrome and Edge extensions delivered an extensible malware framework of sixteen modules to steal cryptocurrency, credentials, session tokens, and browsing data, and to inject ClickFix lures. Notably, several extensions started out legitimate and were only weaponized later, after their original developers handed over control and new owners pushed malicious automatic updates. One extension reached seventy thousand users before removal. The malware ran from the extension's background worker, opened an encrypted connection to its servers, and displayed fake wallet-recovery pages on real crypto sites to capture recovery phrases.

Check
Audit installed Chrome and Edge extensions, remove unneeded ones, and recognize that a once-safe extension can turn malicious through an update after its ownership changes, silently and without a new prompt.
Affected
Users of the affected Chrome and Edge extensions, especially crypto holders; the framework steals wallet recovery phrases, credentials, session cookies, and browsing data, and can prompt users into running attacker commands.
Fix
Restrict extension installs through browser policy, review extension permissions, keep crypto wallets off browsers used for general work, monitor for the campaign's indicators, and move funds if a compromised extension was installed.

CISA flags exploited ownCloud flaw that lets attackers read and delete files

CISA added a critical ownCloud flaw to its exploited-vulnerabilities catalog after attackers used it to steal data from a research organization. Tracked as CVE-2023-49105 and scored 9.8, the WebDAV authentication-bypass bug lets an unauthenticated attacker who knows a victim's username read, modify, or delete that user's files when no signing key is configured, which is the platform's default. Disclosed back in November 2023, it affects ownCloud Server core versions 10.6.0 through 10.13.0 and was fixed in 10.13.1, yet unpatched instances remain exposed nearly two years later. Public exploit code exists, and CISA set a short deadline for federal agencies, underscoring that long-standing self-hosted flaws keep getting weaponized.

Check
Upgrade ownCloud Server to 10.13.1 or later now, or configure a signing key as a mitigation, and review WebDAV access logs for unusual file reads, changes, or deletions.
Affected
Organizations running ownCloud Server 10.6.0 through 10.13.0 without a signing key, the default (CVE-2023-49105); an unauthenticated attacker knowing a username can read, alter, or delete that user's files, and exploitation is active.
Fix
Patch to 10.13.1, set a signing key, restrict and monitor exposed WebDAV services, investigate for unauthorized file access or deletion, and treat any long-unpatched ownCloud instance as a likely target.

Critical GiveWP WordPress flaw lets unauthenticated attackers run server commands

A critical flaw in GiveWP, a WordPress donation and fundraising plugin installed on more than 100,000 sites, lets an unauthenticated attacker run commands on the hosting server. Tracked as CVE-2026-82222, it chains three weaknesses: an unsafe PHP deserialization helper, a donation flow that stores attacker-controlled serialized objects, and a gadget chain in bundled libraries that turns that into system command execution. Although exploitation normally needs an account, an exposed registration action lets an attacker create one even when registration is disabled, making it effectively unauthenticated. It affects versions up to 4.16.7.1 and is fixed in 4.16.7.2, which blocks serialized data during donation processing.

Check
Update the GiveWP plugin to 4.16.7.2 across all WordPress sites now, and check for unexpected accounts, files, or processes on servers running the donation plugin.
Affected
WordPress sites running GiveWP up to 4.16.7.1 (CVE-2026-82222); an attacker can chain PHP object injection into system command execution, and a registration bypass makes exploitation effectively unauthenticated even with signups disabled.
Fix
Patch the plugin, put a web application firewall in front of the site, scan for web shells and unauthorized files, and review hosting accounts and logs on donation-enabled sites.

Bluetooth flaw gives root on Unitree humanoid robots and can spread between them

A researcher disclosed two root remote code execution chains in the Unitree G1 humanoid robot, one reachable over Bluetooth from nearby without any pairing. Tracked as CVE-2026-76639 and CVE-2026-76640, the Bluetooth chain abuses a gap in Unitree's cloud service, which handed over another robot's key material to any free account without checking ownership, then used a buffer overflow in the Wi-Fi provisioning code to run code as root on the robot's control computer. The researcher demonstrated that a compromised robot can spread the exploit to another within Bluetooth range, making it wormable. There is no confirmed fixed firmware for the on-robot flaws, though the cloud ownership check was tightened.

Check
Owners of Unitree G1 robots should watch for firmware updates addressing these flaws, keep the robots off untrusted networks, and be aware that a nearby compromised unit could attack others over Bluetooth.
Affected
Unitree G1 humanoid robots (CVE-2026-76639, CVE-2026-76640); an attacker within Bluetooth range can chain a cloud key-recovery gap and a buffer overflow to gain root, and the exploit can spread robot to robot.
Fix
Isolate robots on segmented networks, limit physical and radio proximity by untrusted parties, apply firmware fixes when a confirmed release appears, and treat cyber-physical devices as full computers requiring patching.

Cluster of 19 Chrome and Edge extensions steal wallets and drain crypto

Researchers at Socket found a coordinated cluster of nineteen browser extensions, eighteen for Chrome and one for Edge, published over the past six months with code to steal cryptocurrency wallet secrets, drain funds, harvest credentials, and inject code into targeted websites. The extensions share code and tradecraft, suggesting a single campaign that may have run even longer. Because a browser extension can read and alter the pages a user visits, a malicious one that reaches a crypto user can quietly capture recovery phrases or redirect transactions. This continues a steady pattern of wallet-draining extensions slipping into official browser stores under the guise of useful tools.

Check
Review the browser extensions installed across your users, remove unknown or wallet-related ones from this cluster, and remind crypto users that a single malicious extension can drain their funds.
Affected
Users who installed any of the nineteen malicious Chrome or Edge extensions, especially cryptocurrency holders; the extensions steal wallet secrets, drain funds, harvest credentials, and can tamper with the websites users visit.
Fix
Restrict extension installation through browser policy, allowlist trusted publishers, audit installed extensions periodically, keep crypto wallets off browsers used for general browsing, and treat any exposed wallet as compromised.

Cosmos EVM flaw exploited across blockchains sharing the same vulnerable code

Cosmos Labs warned that attackers are actively exploiting a flaw in its Cosmos EVM module, the component that gives Cosmos blockchains Ethereum compatibility, and urged affected chains to halt their validators. The bug lies in how the module handles state during nested transactions, letting an attacker manipulate balance and ownership tracking to move funds without authorization. Because many independent chains share the same module code, the weakness is systemic: separate chains were hit in the days before the ecosystem-wide warning, suggesting attackers generalized one exploit across the shared codebase. A patch existed from earlier in the year, but new exploitation shows the risk persists. It echoes supply-chain risk applied to blockchain infrastructure.

Check
Operators of chains built on the Cosmos EVM module should follow Cosmos Labs' guidance, apply the latest patched module, and pause validators if advised until confirmed safe.
Affected
Blockchains built on the vulnerable Cosmos EVM module; incorrect state handling during nested execution lets attackers manipulate balances and ownership to steal funds, and shared code exposes many chains at once.
Fix
Update to the patched Cosmos EVM module, monitor for abnormal precompile calls and unauthorized transfers, coordinate with the ecosystem on halts, and recognize shared blockchain modules concentrate risk across every chain.

McKesson discloses breach as ShinyHunters claims 284 million patient records

Healthcare and pharmaceutical distribution giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, which the extortion group ShinyHunters claims exposed 284 million patient records. The group told reporters it broke in by voice-phishing two employees, then extracted data from the company's Salesforce and Snowflake environments, the same connected-app looting pattern it has used elsewhere. It claims deeply sensitive medical data was taken and says a roughly 55 million dollar ransom went unanswered. McKesson confirmed the incident in a regulatory filing but has not verified what was stolen, and the record count, like past ShinyHunters claims, may be inflated.

Check
Watch McKesson's official channels for confirmed details before acting on the 284 million figure, and if notified as affected, be alert to healthcare-themed phishing and identity theft using real medical details.
Affected
Patients and partners whose data McKesson handles, pending confirmation of scope; ShinyHunters claims names, Social Security numbers, and sensitive medical records were taken via phished access to Salesforce and Snowflake.
Fix
For organizations, harden connected SaaS like Salesforce and Snowflake against voice-phishing-led access with phishing-resistant authentication and tighter session controls, and verify large breach claims before treating headline numbers as confirmed.