Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

Stolen Cloudflare key let attackers poison Brevo scripts on 100,000 sites

Attackers stole a Cloudflare API key from marketing platform Brevo and used it to inject malicious code into the scripts that Brevo's customers embed on their own websites, affecting more than 100,000 sites. The key was long-lived, had full account permissions, and was hardcoded in application source code, which let the attackers create a Cloudflare Worker that modified Brevo's forms, widget, and loader scripts at the network edge for about five and a half hours. Visitors saw a fake verification page with ClickFix instructions to run a command on Windows, and on WordPress sites where an admin was logged in, the script tried to silently install a backdoor plugin.

Check
Keep API keys out of source code, replace long-lived full-permission keys with scoped short-lived credentials in a secrets manager, and review third-party scripts your sites embed for unexpected changes or injected content.
Affected
Websites embedding Brevo's scripts and their visitors during the incident; a stolen key let attackers modify those trusted scripts at the edge to push ClickFix malware and a WordPress backdoor plugin.
Fix
Scope and rotate API keys, store them outside code, constrain embedded third-party scripts with subresource integrity and content security policy, monitor for edge content changes, and teach users to reject paste-a-command prompts.

RatHat Android malware turns on wireless debugging to control phones and survive removal

Researchers at Zimperium documented RatHat, an Android banking trojan that gains deep control of a phone by abusing its own debugging tools. After tricking the user into granting accessibility permissions, it uses automated taps to enable wireless debugging, reads the on-screen pairing code, and connects to the phone's local debugging service to get shell-level access with no computer attached. It then drops components that disable security apps, open a hidden tunnel to the attacker, and restore the malware even after uninstall, intercepting the removal screen with a fake error. RatHat also uses a generative-AI engine to read the screen and navigate on its own, making it more adaptable than scripted malware.

Check
Warn users not to sideload apps from links, ads, or third-party stores, not to grant accessibility to unexpected apps, and to watch if developer options or wireless debugging turn on by themselves.
Affected
Android users who sideload apps disguised as streaming, browser, or banking software and grant accessibility; RatHat then enables wireless debugging to gain shell access, steal banking data, and persist beyond uninstallation.
Fix
Restrict sideloading and accessibility grants through mobile device management, deploy mobile threat detection, keep Google Play Protect enabled, and on infected phones expect a factory reset may be needed for full removal.

Attacker hijacks an AI coding session and spreads Shai-Hulud to 100 repositories

Mandiant reported that an attacker hijacked a developer's active AI coding-assistant session at a software company and used it to spread the self-replicating Shai-Hulud worm across about 100 internal code repositories. The chain started when the AI assistant recommended a piece of software the attacker had poisoned, and the developer accepted the suggestion. Using the live session, the attacker installed an infostealer through a poisoned PyPI package and stole GitHub access tokens, then unleashed the worm, which stole repository secrets and source code. The attacker also poisoned a package in the company's own namespace, so a second developer's pull caused a reinfection. It shows AI-recommended dependencies as a new poisoning path.

Check
Check dependencies that an AI assistant recommends against cryptographic checksums and an approved allowlist before installing them, and keep API keys and long-lived OAuth tokens out of reach of coding-assistant extensions.
Affected
Development teams using AI coding assistants that install dependencies with the developer's credentials; a poisoned recommendation or hijacked session can plant an infostealer, steal tokens, and spread a worm through repositories.
Fix
Route dependency traffic through internal repositories, verify AI-suggested packages before use, scope tokens the assistant can reach, monitor for worm-like package activity, and treat a compromised coding session as a supply-chain incident.

One malicious extension can hijack the built-in AI in several browsers

Researchers at Forever Security showed that a single malicious browser extension can hijack the AI assistant built into several AI-enabled browsers, including Chrome, Edge, Comet, Opera Neon, and Claude in Chrome. The core problem is that putting an AI agent inside the browser reopens a privilege-escalation path browsers normally work to close, letting a low-privilege extension reach a high-privilege part of the browser. Two of the findings received identifiers, one in Chrome, patched in January, and one in Edge, patched in July, while the others were fixed through bug bounties without dates. There is no evidence of real-world use yet, and each method still requires the user to install the extension.

Check
Update Chrome, Edge, and other AI-enabled browsers to their latest versions, review installed extensions and remove untrusted ones, and restrict extension installation through browser policy where possible.
Affected
Users of browsers with a built-in AI assistant who install a malicious extension; it can escalate from its low privileges to the high-privilege in-browser AI agent, controlling the assistant and its access.
Fix
Keep AI-enabled browsers updated, enforce extension allowlisting by policy, limit what the built-in AI agent can access, and treat the in-browser AI assistant as a privilege boundary extensions must not reach.

Exploited Issabel PBX flaw uses a shared hardcoded key to run commands unauthenticated

Attackers are exploiting a critical flaw in Issabel Framework, the web interface for the open-source Asterisk-based phone system. Tracked as CVE-2026-89026 and scored 9.8, the flaw stems from a hardcoded token-signing key that is identical across every installation, so an unauthenticated attacker can forge a valid access token, call the system's call-origination endpoint, and make Asterisk run arbitrary operating-system commands. Researchers at VulnCheck flagged it, and the Shadowserver Foundation first saw exploitation on September 9. A patch released on August 1 replaces the shared key with a unique per-installation key. Exposed, unpatched phone systems should be treated as urgent given the low barrier to attack.

Check
Update Issabel Framework to the patched version that replaces the shared signing key, and take the phone system's web interface off the public internet, restricting it to trusted management networks.
Affected
Organizations running internet-exposed Issabel Framework phone systems (CVE-2026-89026); because the signing key is identical everywhere, an unauthenticated attacker can forge a token and run operating-system commands, and exploitation is underway.
Fix
Patch to remove the hardcoded key, restrict and monitor access to the PBX web and management interfaces, hunt for forged-token requests and unexpected command execution, and rotate credentials if compromise is suspected.

Parallels Desktop flaw lets a normal Mac user become root, stranding Intel Macs

Researchers at JFrog disclosed a flaw in Parallels Desktop, which runs Windows and Linux virtual machines on a Mac, that lets a non-administrator user gain root on the Mac itself. Tracked as CVE-2026-90894 and named ParaShells, the issue is that Parallels' root-level background service listens on a socket that was left world-writable, so any program running as a normal user can connect to it and escalate to root. It needs code already running locally, not network access. The fix is in Parallels Desktop 27, but Intel Macs cannot install that version, leaving those users without a patch. Apple-silicon users should update to the latest release on that line.

Check
Update Parallels Desktop to 27.0.1 or later on Apple-silicon Macs; on Intel Macs, which cannot install the fix, limit who can run code locally and consider alternatives until a fix is available.
Affected
Mac users running Parallels Desktop below version 27 (CVE-2026-90894); a non-admin local user can reach the world-writable service socket to gain root, and Intel Macs cannot install the fixed version.
Fix
Patch Apple-silicon Macs to the latest Parallels release, restrict local code execution on Intel Macs that cannot update, monitor for unexpected privilege escalation, and weigh alternative virtualization for unpatchable systems.

Acronis cPanel backup plugin flaw exploited to escalate privileges on hosting servers

Acronis warned that a flaw in its Backup plugin for cPanel and WebHost Manager is being exploited in limited, targeted attacks. Tracked as CVE-2026-87886 and scored 7.8, it is an insecure-file-permissions issue that lets a low-privilege user who already has local access, such as a compromised hosting account, escalate their privileges on the Linux server. From there, an attacker could reach backup data, system files, and other customers' accounts on shared hosting. Acronis's backup add-ons are widely used by web hosts and managed service providers, so the flaw has broad reach. A fix is available, and a related Plesk extension is affected though not yet under attack.

Check
Update the Acronis Backup plugin for cPanel and WHM to the fixed version immediately, and update the Plesk extension too, then review shared servers for signs of privilege escalation and unauthorized access.
Affected
Web hosts and managed service providers running the Acronis Backup plugin for cPanel and WHM (CVE-2026-87886); an attacker with a foothold can escalate privileges to reach backups, system files, and tenants' data.
Fix
Patch the backup plugin and extension, tighten file permissions and account isolation on shared hosting, monitor for privilege escalation and backup access, and treat a compromised hosting account as a server-wide risk.

CenterPoint Energy breach traced to an external API with no authentication

Texas utility CenterPoint Energy confirmed that an unauthorized party obtained customer personal information through an external-facing system. A threat actor claimed on a cybercrime forum to have pulled about 7.49 million records, including names, addresses, account and billing details, and partial Social Security numbers, through a company API that lacked authentication, rate limiting, and web-application-firewall protection. CenterPoint confirmed the incident in a regulatory filing but not the record count, and said energy services were unaffected. It is a textbook example of an exposed API being scraped at scale: without authentication and throttling, a public endpoint hands attackers a bulk export of customer data. The investigation is ongoing.

Check
Inventory external-facing APIs and confirm each one enforces authentication, authorization, rate limiting, and monitoring, and test them for endpoints that return customer data to unauthenticated callers.
Affected
About 7.49 million CenterPoint customers, per the attacker's claim, whose personal, account, and partial Social Security data may have been scraped; unauthenticated, unthrottled external APIs let attackers bulk-export such data with ease.
Fix
Require authentication and rate limiting on every external API, put them behind a web application firewall, monitor for bulk or anomalous access, and treat customer-data endpoints as high-value assets to test.

Exploited Cisco email gateway flaw lets a crafted email run commands as root

Cisco warned that attackers are exploiting a critical zero-day in its Secure Email Gateway appliances that lets them run commands as root just by sending a crafted email. Tracked as CVE-2026-76461 and scored 9.8, the flaw is a SQL injection in the appliance's email-parsing logic, so an unauthenticated attacker needs no access to the management interface at all. It affects physical and virtual gateways in any configuration, and Cisco confirmed it was exploited as a zero-day before disclosure. CISA added it to its exploited-vulnerabilities catalog with a three-day federal deadline. Because successful attacks grant root, intruders can erase their own tracks, so Cisco urges inspecting mail logs for suspicious activity.

Check
Patch Cisco Secure Email Gateway appliances immediately given active exploitation, and inspect mail and network logs for suspicious SQL statements and signs of compromise, despite the risk that root access erased indicators.
Affected
Organizations running physical or virtual Cisco Secure Email Gateway appliances in any configuration (CVE-2026-76461); an unauthenticated attacker can send a crafted email to run commands as root, exploited in the wild.
Fix
Apply the fixed AsyncOS releases now, hunt for compromise using Cisco's indicators while assuming a rooted device may hide them, and apply the four other critical email-gateway fixes shipped the same day.

Attackers forge admin tokens through a WSO2 API Manager JWT bypass flaw

Attackers are exploiting a JWT authentication-bypass flaw in WSO2 products, including its widely used API Manager and Identity Server. Tracked as CVE-2026-5430 and rated 9.8, the flaw is an algorithm-confusion bug: the token validator accepts JWTs signed with algorithms other than the ones it is configured to trust, so an attacker can craft a forged token that passes validation. That lets them mint tokens as an administrator and take over the deployment, gaining control over the APIs and identities the platform manages. Because WSO2 sits at the center of API and identity infrastructure, a takeover can cascade to everything behind the gateway. Active exploitation attempts have been observed against exposed instances.

Check
Apply WSO2's fixes for the JWT authentication-bypass flaw across API Manager, Identity Server, and other affected products, and keep the Carbon management console and admin interfaces off the public internet.
Affected
Organizations running affected WSO2 products such as API Manager or Identity Server (CVE-2026-5430); an attacker can forge a JWT with an unsupported algorithm to bypass authentication, become an administrator, and take over.
Fix
Patch to fixed WSO2 versions, restrict management interfaces to trusted networks, enforce strict JWT algorithm validation, monitor for forged-token and anomalous admin activity, and rotate keys and tokens if compromise is suspected.