Last updated: September 29, 2026 at 8:42 AM UTC
All 891 Vulnerability 357 Breach 144 Threat 383 Defense 7

PEEP toolkit hijacks Chrome and Edge into backdoors that run host commands

Researchers disclosed a post-exploitation toolkit called PEEP that turns Chrome and Edge into backdoors for stealing credentials and running commands on the host. After an attacker already has administrative or code-execution access, PEEP's installer injects a malicious extension disguised as a bookmarks tool directly into browser profiles, forging Chromium's own integrity settings to bypass the Web Store and skip user approval prompts. The planted extension then serves as a covert channel to harvest credentials and execute operating-system commands. Because it abuses a trusted, ever-present browser and hides its extension from the usual checks, it can persist quietly on a compromised machine, a reminder that browsers themselves are a rich post-compromise attack surface.

Check
Hunt for tampering with Chromium's secure preferences file and for extensions loaded outside the Web Store, and treat an unexpected browser extension on a server or admin workstation as a possible backdoor.
Affected
Windows systems an attacker already compromised with admin or code-execution access; PEEP silently installs a browser extension by forging integrity settings, then uses it to steal credentials and run host commands.
Fix
Enforce enterprise extension allowlisting through browser policy, monitor for secure-preferences tampering and unapproved extensions, restrict local administrator rights that enable the install, and include browser artifacts in endpoint detection and incident response.

BigBear phishing service bypassed MFA at 258 organizations and disabled passkeys

Researchers at CloudSEK gained access to the control panel of BigBear, a phishing-as-a-service platform that defeated multi-factor authentication at 258 organizations and stole thousands of Microsoft 365 credentials. It uses an adversary-in-the-middle proxy based on Evilginx to sit between victims and Microsoft's real login, capturing passwords, multi-factor codes, and the session cookie, then replaying the cookie to hijack the already-authenticated session. The panel logged over 5,000 stolen records across 40-plus countries and is rented to multiple affiliates who receive stolen data through Telegram bots. Notably, it runs JavaScript that disables the browser's passkey support, forcing victims off phishing-resistant login onto weaker methods it can intercept.

Check
Enforce phishing-resistant passkeys with conditional access that requires managed devices, so attacker-in-the-middle kits cannot simply capture and replay session cookies or quietly downgrade users to weaker authentication.
Affected
Microsoft 365 organizations relying on passwords plus standard multi-factor authentication; BigBear steals the post-login session cookie to hijack accounts and can disable passkey support in the browser to force weaker login methods.
Fix
Adopt device-bound phishing-resistant authentication, require managed devices through conditional access, revoke sessions and refresh tokens on suspicion, monitor for impossible-travel and residential-proxy sign-ins, and train users on help-desk and login-page lures.

Exposed airline passenger database leaked 220 million records with passport data

Researchers found an exposed database holding more than 220 million airline passenger and crew records, including passport numbers and full flight itineraries, left reachable online. The data came from an Advance Passenger Information System, the kind airlines use to send traveler identity and passport details to border authorities, and it covered anyone who flew to, from, or through Vietnam between 2017 and 2026. Exposed fields included names, dates of birth, nationalities, passport numbers with issuing countries, and flight, seat, and baggage details. Researchers reached it by chaining misconfigurations and default credentials, and it was later secured, though whether the data was copied first is unknown because no access logs existed.

Check
Travelers who flew through the region should watch for identity theft and travel-themed phishing using real passport or itinerary details, and organizations holding traveler data should audit exposed databases and default credentials.
Affected
More than 220 million passenger and crew records with passport numbers, birth dates, nationalities, and flight itineraries were exposed; the data enables identity theft, document fraud, targeted phishing, and surveillance of travelers.
Fix
For organizations, inventory internet-facing databases, remove default credentials, require authentication and encryption on data stores, and enable access logging; aggregators of passport and travel data should treat exposure as high-impact risk.

Unpatched Magento zero-day is being exploited to backdoor online stores

Attackers are actively exploiting an unpatched zero-day in Magento Open Source and Adobe Commerce to run code on stores' servers without logging in, according to e-commerce security firm Sansec, which named it StyleSmuggler. Exploitation began September 4, and every current version is affected, including the latest 2.4.9; Sansec even found a fully patched store already compromised. The attack manipulates a styles field in a GraphQL request to inject PHP into a file the platform generates normally, then installs a persistent backdoor. As of disclosure, Adobe had not issued an advisory, a CVE, or a fix, so exposed stores should be treated as at risk and watched for compromise.

Check
Since there is no patch, review logs for suspicious unauthenticated requests to Magento since September 4, especially style or template processing, and hunt for web shells and new admin accounts.
Affected
Any store on Magento Open Source or Adobe Commerce, including fully patched and latest 2.4.9 installs; an unauthenticated attacker can execute code and install a persistent backdoor, and exploitation is happening now.
Fix
Apply web application firewall rules against anomalous style and template requests, restrict and monitor admin and API endpoints, watch for skimmer injections and backdoors, and apply the vendor fix when it ships.

N-able ships fourth N-central hotfix in five weeks for exploited pre-auth flaw

N-able released its fourth hotfix in five weeks for its N-central remote monitoring and management platform, this time for a flaw that gives an unauthenticated attacker full "god-mode" access to the console. Tracked as CVE-2026-86218 and scored 10.0, the pre-authentication remote code execution zero-day is being exploited and supersedes all earlier hotfixes, so on-premises systems still on the third hotfix remain vulnerable and must apply the fourth. Hosted instances have already been patched. Researchers also disclosed a separate chain that lets attackers bypass access controls to create unauthorized administrator accounts. Because N-central manages many downstream endpoints, a compromise can cascade across every customer it serves.

Check
Apply N-central hotfix 4 immediately on any on-premises server, since prior hotfixes do not cover this flaw, then audit the console's user list for unauthorized administrator accounts.
Affected
Organizations and managed-service providers running on-premises N-able N-central (CVE-2026-86218); an unauthenticated attacker can execute code and gain full control of the console, and from there potentially reach every managed endpoint.
Fix
Patch to the latest hotfix, strictly limit inbound access to the N-central console, audit for rogue admin accounts and recent changes, monitor managed endpoints, and treat any exposed unpatched server as compromised.

Exploited MikroTik flaw chain gives full router control over exposed SSH

Poland's CERT warned that attackers are exploiting a chain of MikroTik RouterOS flaws, dubbed MikroTrick, to take full administrative control of internet-exposed routers over SSH without valid credentials. The key flaw, CVE-2026-67276 and scored 9.2, is an authentication bypass in how RouterOS checks RSA public keys: an attacker who knows a valid username and the public key can forge a key and log in without the private one. A second flaw then escalates the session to full administrator. MikroTik shipped fixes on September 3, but exploitation began around September 2, and roughly 300,000 devices remain exposed. Compromised edge routers make ideal footholds, so exposed devices should be treated as breached.

Check
Update RouterOS to a fixed release now, take SSH off the internet by restricting it to a management network or VPN, and hunt exposed devices for a rogue user named dash-two.
Affected
Internet-exposed MikroTik RouterOS devices with SSH enabled (CVE-2026-67276); an unauthenticated attacker can bypass SSH authentication and escalate to full administrator, and about 300,000 devices are still exposed and being targeted.
Fix
Patch RouterOS, keep SSH and management interfaces off the public internet, rotate all router and downstream credentials and SSH keys, disable unused services, and rebuild any device confirmed compromised.

JSCeal malware steals session cookies to log into Google without the password

Researchers at Check Point analyzed JSCeal, malware compiled into a hard-to-analyze bytecode format that steals browser cookies and authentication tokens to hijack accounts. By replaying stolen session cookies, an attacker can access a victim's Google account without the password or a second factor, and the malware also grabs saved passwords, autofill data, and OAuth tokens to automate further account access. It additionally targets cryptocurrency wallets and platforms and includes keylogging, screenshots, and messaging-session theft. The compiled format and layered obfuscation push it outside analysts' usual tooling, though Check Point released a deobfuscator. It is a reminder that stolen session cookies quietly defeat passwords and multi-factor authentication alike.

Check
Treat session cookies as sensitive credentials: monitor endpoints for access to browser cookie databases and suspicious script-to-runtime execution chains, and shorten session lifetimes so stolen cookies expire sooner.
Affected
Users whose browsers are infected by this stealer; theft of session cookies and OAuth tokens lets attackers replay authenticated Google sessions without the password or second factor, and reach crypto accounts.
Fix
Bind sessions to devices where supported, expire and revoke sessions on anomalies, deploy endpoint detection for cookie theft and in-memory browser attacks, and monitor for session replay from unfamiliar locations.

REVSTEALER modules disable Windows Update and Defender to hide a crypto miner

Researchers at Elastic documented four persistent programs tied to the REVSTEALER infostealer that stay on a machine even after the stealer deletes itself. One disables Windows Update services and Microsoft Defender, adds Defender exclusions, and kills update and malware-removal tasks before hiding a cryptocurrency miner inside legitimate Windows processes. The malware also bypasses Chrome's app-bound encryption by launching the browser in a debugger to read the decryption key from memory, and steals session cookies to take over accounts without passwords. It spreads through game-cheat lures on hijacked video channels and pirated or fake application installers. Because these modules outlive the stealer, a confirmed infection warrants reimaging rather than cleanup.

Check
Treat any REVSTEALER or infostealer detection as an incident and reimage the machine, since companion modules persist after the stealer removes itself, and watch for disabled Defender and high CPU usage.
Affected
Windows users who run game cheats or pirated and fake software; the modules disable protection, mine cryptocurrency, bypass Chrome's encryption to steal cookies, and persist after the stealer deletes itself.
Fix
Restrict local administrator rights so malware cannot disable Update and Defender, block game-cheat and pirated-software sources, monitor for security-tool tampering and mining activity, and reimage confirmed infections rather than deleting individual files.

Critical Cisco Nexus switch flaw lets unauthenticated attackers run code as root

Cisco patched a critical flaw in its Nexus 9000 data-center switches that lets an unauthenticated, remote attacker execute code as root. Tracked as CVE-2026-20212 and scored 9.8, the bug affects Nexus 9000 models built on Cisco's Silicon One chips and stems from a service that binds to an unrestricted address, leaving TCP ports 43210 and 43211 reachable in the default routing configuration. An attacker who can reach either port sends crafted input that runs with root privileges, and can also crash and reload the device. Cisco reported no known exploitation at disclosure and shipped fixed software, with an access-list workaround for those who cannot patch immediately.

Check
Identify Nexus 9000 switches using Silicon One chips, upgrade to fixed NX-OS releases, and until then apply the access-control-list workaround that blocks TCP ports 43210 and 43211 to the device.
Affected
Organizations running affected Cisco Nexus 9000 switches with Silicon One chips (CVE-2026-20212); a remote, unauthenticated attacker reaching the exposed ports can execute code as root or crash the device, no credentials needed.
Fix
Patch to fixed NX-OS software, apply the access-list workaround and temporary shield until then, restrict management-plane reachability to the switches, and monitor for unexpected connections to the affected ports.

Shai-Hulud npm worm now hunts credentials across 469 different locations

Researchers at GitGuardian found that a recent variant of the self-spreading Shai-Hulud npm worm has expanded its credential theft to scan 469 distinct locations on infected developer machines. The targets now span developer environments, continuous integration and deployment tooling, cloud configuration files, and even the configuration of AI tools. That breadth turns a single compromised package into a wide net for secrets, from cloud and registry credentials to keys held by developer and AI tooling. It reflects how supply-chain worms are industrializing secret collection, treating any credential a developer's machine can reach as fair game once malicious code runs during installation or use.

Check
Scan your dependencies and lockfiles for known-compromised packages, rotate any credentials that a developer machine or pipeline can reach, and reduce the number of long-lived secrets stored in reachable configuration files.
Affected
Developers and CI/CD systems that install compromised npm packages; the worm harvests credentials from 469 locations across developer, pipeline, cloud, and AI-tool configurations, then uses them to spread and steal further secrets.
Fix
Pin and vet dependencies, use scoped short-lived tokens instead of long-lived secrets, isolate build environments, monitor for credential access during installs, and keep secrets out of files developer and AI tools read.