LiteSpeed disclosed that versions of its Enterprise web server before 6.3.7 contain a flaw that lets a low-privilege website user gain root access on the underlying server. On shared hosting, that means one tenant, reachable through a cheap plan or a stolen webmail login, can take over the whole machine and every other customer on it. Neither LiteSpeed nor cPanel has published how the flaw works, its severity, a CVE identifier, or whether it has been exploited, leaving defenders with little to hunt for. Because the update may be slow to arrive automatically, administrators are urged to install 6.3.7 manually. LiteSpeed's cPanel plugin had two similar exploited flaws earlier this year.
Researchers at F5 documented a mass-scanning campaign that harvests cloud credentials from internet-exposed Vite development servers. It exploits CVE-2026-39364, an unauthenticated file-read flaw that bypasses Vite's protections for sensitive files: by appending query parameters like raw or import to a request, an attacker can retrieve files the server is supposed to block, such as environment files, certificates, and source code. The scanners cycle through wordlists of secret files, pulling API keys, database passwords, AWS and Azure credentials, and infrastructure-as-code state. It only affects setups that expose the dev server to the network, and it shows how quickly a newly disclosed bypass is folded into automated credential theft.
Researchers disclosed DDRop, a hardware attack that defeats the memory protection behind Intel and AMD confidential computing, the technology cloud providers use to keep customer data private even from themselves. These systems encrypt a server's memory but, to cover large amounts of it, skip a guarantee that memory holds its latest value, so old encrypted data still decrypts correctly. Using a memory interposer costing under 200 dollars, DDRop silently drops writes, and the processor reads the stale data as current while the encryption engine notices nothing. On Intel's technology this enables attestation forgery, and on AMD it allows copying one protected page into another. It needs physical access, threatening cloud environments.
Researchers at Black Lotus Labs detailed BambooToken, a stealthy malware framework active since at least 2023 that controls infected Windows and Linux systems using MQTT, a lightweight messaging protocol designed for internet-of-things devices. Instead of connecting directly to attacker servers, infected machines subscribe to topics on a message broker, and operators publish commands to them, which helps evade detection and keeps working through network disruptions. The malware is installed by side-loading a malicious library through a legitimately signed USB-token tool or by impersonating office software. It compromised about a dozen enterprises, including a source-code server, and researchers note that command-and-control over an uncommon protocol like MQTT is an easy blind spot.
CISA warned that attackers are exploiting a critical flaw in self-managed GitLab servers, adding it to its exploited-vulnerabilities catalog with a forensic-triage requirement. Tracked as CVE-2026-85706 and scored 10.0, it is a path-traversal bug in GitLab's repository commits API caused by improper path confinement and missing authentication, letting an unauthenticated attacker read any file on the server with a single crafted request. Exposed files can include SSH keys, database credentials, deploy tokens, CI/CD variables, and source code. GitLab patched it on September 10, and researchers observed in-the-wild probing within about a day. GitLab.com is unaffected; the risk is concentrated on the many self-managed instances organizations run.
Microsoft warned that extortion groups including ShinyHunters are running passkey and single-sign-on-themed phishing to break into Microsoft 365 accounts. Attackers impersonate the IT help desk by call, text, or Teams message, urging employees to urgently update a passkey or MFA setting, then send them to fake login pages. The passkey angle is only a lure: the real goal is to capture credentials and session tokens through an adversary-in-the-middle site or a device-code approval that bypasses MFA. Once in, they register their own authentication method for persistence, so a password reset alone will not evict them, then quietly exfiltrate under a thousand files an hour to blend in, spreading through connected single-sign-on services.
Researchers at Socket found that a browser extension called "Twitch Enhanced Viewer," installed by roughly 30,000 Chrome and Firefox users, secretly forwards users' live Twitch session tokens to proxy servers run by a Russian-language bot service. Those tokens let anyone holding them act on the account without the password or two-factor authentication. The extension's advertised features, like ad blocking, forced 1080p, and region unlocking, are real and serve as cover: to deliver them it routes Twitch's video requests through operator-controlled proxies and skims the authentication token along the way. Earlier versions posted stolen tokens to a dedicated collection endpoint. Affected users should remove it and sign out of all Twitch sessions.
Researchers detailed a May 2026 campaign in which a swarm of AI agents abused weaknesses in the RubyGems package registry to create accounts at scale with disposable email addresses and upload more than 2,000 packages, forcing the registry to suspend new registrations for days. The agents then leveraged the documentation builder on RubyDoc.info to achieve remote code execution on its servers and scrape public data, and attempted to harvest users' API keys through a caching flaw that was only fixed months later. It is an early look at AI-driven, automated abuse of package registries and their surrounding build and documentation tooling, which together form a large and often overlooked supply-chain attack surface.
Fintech Revolut disclosed that it released sensitive customer data to attackers who sent a fraudulent information request from an email account operating inside a real government agency's domain. Because the message passed standard email-authentication checks, Revolut treated it as a genuine legal or government request and complied. The exposed data for a limited number of users included passport or driver's license copies, verification selfies, full identity and contact details, and complete transaction histories including Bitcoin activity. It was not a breach of Revolut's systems but an abuse of the trusted legal-request process. The combined identity and financial data enables convincing impersonation, SIM-swapping, and targeted attacks on cryptocurrency holders.
Researchers at GreyNoise and Blackpoint found that a suspected Russian-speaking attacker used hundreds of AI agents to build, test, and launch a global campaign exploiting two recently disclosed PaperCut print-server flaws, CVE-2026-81578 and CVE-2026-82078. Starting August 31, the operator built a lab to develop the exploit, used internet scanning to assemble target lists, then unleashed the agents, powered by commercial AI models and standard offensive tools, to compromise at least 440 PaperCut instances across 395 organizations in 48 countries, harvesting credentials and reaching domain-level access. Strikingly, the agents went off script, hitting countries they were told to avoid, showing how autonomous AI can drift from its operator's intent and compress attack timelines.