⚠️ VULNERABILITY DISCLOSURE 11[−]
6 SepUnpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online StoresAttackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store's server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, w…THEHACKERNEWS.COM
6 SepWhen hackers control the clock.The accurate timing data from spacecraft has become an invaluable tool for nearly every critical infrastructure sector and a greater target for malicious actors. Host Maria Varmazis and Andy Davis, Global Research Director at the NCC Group, discuss the importance of timin…THECYBERWIRE.COM
6 SepThe vulnerable clock in space.This week on T-Minus: Space-Cyber Briefing: we explore the role of timing in space and how vital these systems are for everyday functionality. Given their importance, attackers have become increasingly aware of how to exploit these systems.THECYBERWIRE.COM
6 SepWeek in review: Claude accounts compromised through infostealer, Patch Tuesday forecastHere’s an overview of some of last week’s most interesting news, articles, interviews and videos: Anthropic locks out Claude users after infostealers hijack login sessions Anthropic has started locking users out of their Claude accounts due to their login sessions having been com…HELPNETSECURITY.COM
6 SepSecurity Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITIONA new round of the weekly Security Affairs newsletter has arrived! Every week, the best security articles from Security Affairs are free in your email box. Enjoy a new round of the weekly SecurityAffairs newsletter, including international press. PaperCut Flaws Exploited in Attac…SECURITYAFFAIRS.COM
6 SepAttackers Hijack MikroTik Routers Through Internet-Exposed SSH Without AuthenticationAttackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska's attack warning, published on September 5. Successful at…THEHACKERNEWS.COM
6 SepNYS Comptroller DiNapoli releases more municipal cybersecurity auditsNew York State Comptroller DiNapoli recently released some municipal audits, three of which concerned cybersecurity. The following are excerpts from the public versions of the audits. Town of Wilton – Cybersecurity (2026M-48) Audit Period January 1, 2024 – August 8, 2025 Understa…DATABREACHES.NET
6 SepNatural Resources Wales confirms data breach due to human errorNation.Cymru reports: Sensitive personal information relating to current and former Natural Resources Wales employees has been exposed in a data breach. The public body said a spreadsheet containing employee information had been inadvertently published on its website, potentially…DATABREACHES.NET
6 SepUS offers $10 million for info on Iranian allegedly behind cyberattacks on critical infrastructureJonathan Greig reports: A $10 million reward has been posted by the State Department for information on the whereabouts of senior Iranian official Amir Yaryab. Yaryab allegedly leads the Islamic Revolutionary Guard Corps’ (IRGC) Cyber-Electronic Command (CEC). U.S. officials accu…DATABREACHES.NET
6 SepYour MikroTik Router May Already Be Compromised: Look for SSH User “-2”MikroTik RouterOS SSH zero-day (MikroTrick chain) under active exploitation since Sept 2. Patch to 7.24.2, 7.23.5, or 6.49.21 immediately and check logs. Anyone running a MikroTik router with SSH exposed to the internet should treat it as compromised until proven otherwise. The p…SECURITYAFFAIRS.COM
6 SepCritical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this point, assume compromise. Attackers have been adding new accounts to affected devices to maintain access …ISC.SANS.EDU
🔥 INCIDENT REPORTING 1[−]
6 SepWeekly Update 520: The Unscripted EditionPresently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSite I've started playing around with YouTube's "create video thumbnail", which hopefully will give me back a bit of tim…TROYHUNT.COM
🕵️ THREAT INTELLIGENCE 1[−]
6 SepAttackers conceal phishing lures using invisible Unicode charactersThreat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. [...]BLEEPINGCOMPUTER.COM
🌐 CYBER THREAT LANDSCAPE 1[−]
6 SepSECURITY AFFAIRS MALWARE NEWSLETTER ROUND 113Security Affairs Malware newsletter includes a collection of the best articles and research on malware in the international landscape Malware Newsletter Hackers Steal Claude Login Sessions With Infostealer Malware to Hijack Accounts Fire Ant Evolves: From Hypervisors to Trusted I…SECURITYAFFAIRS.COM
📡 INFOSEC NEWS 3[−]
6 SepFour REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto MinerElastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Windows Update and Microsoft Defender before…THEHACKERNEWS.COM
6 SepAI Agents Hijacked German Wiki to Cheat, OpenAI Delayed DisclosureAI agents secretly took over a 25-year-old German wiki for two months to cheat on tests, and OpenAI sat on the news until reporters found it first OpenAI finally admitted this weekend that a swarm of its own AI agents hijacked a German programming wiki earlier this year, turning …SECURITYAFFAIRS.COM
6 SepChatGPT Astra is now rolling out to $20 Plus subscriptionOpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there's no word on when free users will get access.. [...]BLEEPINGCOMPUTER.COM