MyCyber News
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Your daily cybersecurity news feed in one view.Curated, concise, and connected.
Last feed pull: Sep 24, 2026, 2:02 AM (UTC+3)
Topic · Policy & Regulation
CVE ID : CVE-2026-96603 Published : Sept. 23, 2026, 10:17 p. m. • 42 minutes ago Description : A vulnerability has been found in Abdurrab5 online-makeup-store. Affected is the function confirm_logged_in/confirm_user of the file functions. php of the component Admin Handler. Such manipulation of the argument adminid leads to missing authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. This product utilizes a rolling release system for continuous delivery, and as such, version information for affected or updated releases is not disclosed. The vendor was contacted early about this disclosure. Severity: 7.5 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Technology company F5 fixed a critical remote code execution vulnerability in its BIG-IP Access Policy Manager (APM) platform on Tuesday. The flaw impacts deployments configured as OAuth authorization servers and was already under active exploitation in the wild before the patch became available. BIG-IP APM is a software component in F5’s BIG-IP hardware platform that enables companies to control access to internal network resources. APM performs various client-side checks and handles authorization and authentication, along with providing VPN connectivity for remote users. The flaw, tracked as CVE-2026-94127, is described as a heap-based buffer overflow and is rated 9. 8 on the CVSS scale. The vulnerability impacts the BIG-IP system when configured in appliance mode as well but can be exploited only when both APM and an OAuth authorization server profile are configured.
Nearly nine out of 10 federal civilian executive branch agencies failed to meet last summer’s deadline to implement cloud security directives from the Cybersecurity and Infrastructure Security Agency, a watchdog report published Wednesday found. The conclusions from those results, according to the inspector general for the Department of Homeland Security: agencies “may encounter elevated security exposures that undermine the national cloud security posture and increase the likelihood of preventable cyberattacks and related threat,” and “CISA lacks the authority necessary to require full and timely implementation of Binding Operational Directives,” or BODs. The latter is a question that has surfaced before about CISA directives, which the agency uses to pressure agencies into improving their cyber defenses.
You receive an invitation to a password-protected meeting, a secure chatroom, or a shared document. To get access, it says, you need to enter a short code on a sign-in page for one of your accounts. The message claims the code will let you open the document or join the meeting. In fact, it approves a sign-in the scammer started. The page is real and the code works, which is why this type of attack—known as device code phishing—is so dangerous. Device code phishing abuses a legitimate sign-in feature intended for devices that cannot easily display a normal login screen (such as smart TVs, printers, conference-room equipment, and some command-line tools). Instead of entering a username and password on the device itself, you open a browser on another device, visit a sign-in page, enter a short code, and approve the sign-in.
The potentially serious breach highlights the supply chain risks facing even the most sophisticated organizations.
F5 warns of a critical BIG-IP APM zero-day, CVE-2026-94127, allowing remote code execution. Attackers are already exploiting it. F5 has released emergency security updates for a critical vulnerability, tracked as CVE-2026-94127 (CVSS score of 9.8), in BIG-IP Access Policy Manager (APM) that attackers are already exploiting in the wild. The flaw can allow an unauthenticated attacker to execute arbitrary code on a vulnerable BIG-IP system. F5 disclosed the issue on September 22 and confirmed that exploitation had already been observed. The vulnerability affects BIG-IP APM deployments using an access policy together with an OAuth profile on a virtual server. More specifically, the vulnerable configuration is one in which APM operates as an OAuth Authorization Server. Systems using APM only as an OAuth Client or Resource Server are not affected.
The Pentagon’s top civilian cyber policy official said Tuesday her single priority is expanding the cyber options available to the president and the defense secretary, describing a gap between what commanders are asking for and what the force can deliver. “I’m focused on one single priority, and that is building a more robust set of capabilities for the secretary and the president,” said Katie Sutton, assistant secretary of defense for cyber policy, at DefenseTalks, hosted by DefenseScoop. “The demand far exceeds the supply we have.” Sutton traced the department’s posture to 2018, when the military gained authorities to run cyber operations as a traditional military activity. “In those last eight years, we’ve learned a lot, but I feel like the last year has really been the year that cyber has sort of entered the limelight,” she said.
Overview Cinnamon's Kotaemon (all versions up to v0. 12. 0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This results in high‑impact confidentiality, integrity, and availability violations. Description Cinnamon's Kotaemon is an open‑source, retrieval‑augmented generation (RAG) based tool that lets you build a chatbot capable of "chatting with your documents". As discussed in CVE-2026-86867 , all versions up to v0. 12. 0 fail to verify conversation ownership when loading a conversation. In multi‑user mode, each conversation row includes a user field that identifies its owner.
Legis Legis is a well-known Latin American publisher that creates specialized legal and business information resources. Founded over 60 years ago, the company serves professionals across six countries including Colombia, Venezuela, Argentina, Mexico, Peru, and Chile. DATABASES (SQL)PST/OSTLEGAL DOCUMENTS:Tutela - constitutional actions with claimants' personal dataID card copies (cedulas) of shareholders and third partiesEnvironmental sanction proceedings against the company (AUTO 10852)Sanction dispute with the pension authority (UGPP)Signed cease & desist - trademark dispute (Xpandia case)Personal data transfer agreements (Colsubsidio, Universidad Externado)Litigation log of all company lawsuitsContract matrix, payment agreements, reorganization documentsFINANCE & OWNERSHIP:Shareholder and ultimate-beneficial-owner register with ID copiesOwnership structure: ~99.
The Australian Signals Directorate (ASD) has this month issued a clear call to action through its Multi-factor authentication: Switch it on campaign, urging businesses, organisations, and individuals to enable multi-factor authentication (MFA) across their online accounts. At AWS, we strongly support this message. As threat actors continue to target credentials through phishing, credential stuffing, and social engineering, passwords alone are no longer enough. MFA is one of the most effective security controls available. It’s a cornerstone of ASD’s Essential Eight maturity model and a recognized component of major cybersecurity frameworks worldwide.
Virtual Private Networks provide users with privacy and safety from prying eyes, that is if it is from a trusted service. Choose Proton VPN for a true zero-log tool instead of untrustworthy ones on the App Store and save up to 70%. Proton VPN is a safe and trustworthy tool with a zero-logs policy. Image source: Proton It's easy to assume that the Apple App Store is safe and free of manipulative software and privacy-invasive schemes. However, that has never been the case, and recent research reveals exactly how bad things are for VPN software. Users are becoming more and more aware and educated about the existence and use of Virtual Private Networks, or VPNs. They are meant to encrypt your traffic and keep you anonymous, but not all of them can prove they are as private as they say. Continue Reading on AppleInsider
The ShinyHunters cybercriminal organization on Tuesday replaced agency images on the FBIjobs.gov site with a photo of a Pokemon that has become the group’s defacto mascot.
More than 80,000 relay servers are helping users in China bypass geographic restrictions on leading U. S. AI models, according to Team Cymru. “What we have uncovered is an entire ecosystem designed explicitly to break the frontier model providers’ T&Cs, enabling fraud and illicit activity,” said Scott Fisher, Senior Principal Engineer at Team Cymru. Earlier this month, CISA, the NSA and the FBI warned in a joint advisory that China-based AI firms are running large-scale knowledge … More → The post 80,000 relay servers help users in China slip past U. S. AI region bans appeared first on Help Net Security .
ShinyHunters claims FBI breach via PeopleSoft zero-day, steals staff data; FBI investigating, no confirmation yet. The popular cybercrime group ShinyHunters is claiming that it breached the U. S. Federal Bureau of Investigation (FBI) and stole sensitive information belonging to FBI employees and job applicants. The group says the operation was not financially motivated and was instead carried out in response to an FBI warning published earlier this year. The claim surfaced on September 22 and quickly drew attention after ShinyHunters said it had obtained data on a large number of current and former FBI personnel. The group reportedly offered a sample of around 5,000 records as evidence and claimed that the stolen information could include names, addresses, phone numbers, Social Security numbers, assignments and, in some cases, family details.
Portnox has announced new capabilities to detect unauthorized AI applications and agents on managed devices and automatically enforce security policy, restricting, quarantining, or removing unapproved or risky applications the moment they’re detected. The capability addresses shadow AI: generative AI applications that increasingly act as autonomous agents, reaching local files, remote resources, and enterprise data with the same permissions as the logged-in user. As this footprint grows faster than most organizations can track, Portnox gives IT … More → The post Portnox detects and removes unauthorized AI applications from managed devices appeared first on Help Net Security .
Barracuda Networks has launched Barracuda AI Data Security, the AI security and governance solution purpose-built for resource-constrained organizations and managed service providers (MSPs). The solution enables businesses to accelerate AI adoption by protecting sensitive data, enforcing responsible AI use and demonstrating compliance. Barracuda AI Data Security represents a major milestone in Barracuda’s expanding AI Security portfolio. Built on the BarracudaONE platform, the solution combines AI visibility, data protection, threat defense, and governance into a single … More → The post Barracuda brings AI security and governance within reach of smaller organizations appeared first on Help Net Security .
By Adrian Cheek, Senior Cybercrime Researcher To reach a hospital’s medical images the hard way, you need a DICOM (Digital Imaging and Communications in Medicine) client and some knowledge of a protocol designed in the 1980s for machines that were never supposed to face the internet. To reach a growing number of them the easy way, you can open a web browser and type an address. The image server that stores a patient’s scans no longer just speaks the old wire protocol on an obscure port. It increasingly runs a web console for administration and a browser-based viewer for the images themselves, and those two web interfaces sit on the public internet far more often, and far more openly, than they should.
Extortion group ShinyHunters is not afraid to make enemies. Now it claims to have breached the FBI. After reportedly taking over ransomware group Clop’s leak site , ShinyHunters says it attacked the FBI to punish the agency for spreading what it calls false information about the group. In a very long post on its leak site, the group outlines its grievances: “ PSA – READ THIS NOW Dear Assistant Director Brett Leatherman of the FBI Cyber Division & Director Kash Patel of the FBI, During Quarter Two of this year the Federal Bureau of Investigation (FBI) made substantial false allegations regarding our organisation in a FLASH report. We have been severely offended. We were very disappointed to see an agency of your standing would resort to such circulation of disinformation in an attempt to “disrupt” our operations, an effort that ultimately proved unsuccessful.
New paper: “ Self-Jailbreaking: Language Models Can Reason Themselves Out of Safety Alignment After Benign Reasoning Training .” Abstract: We discover a novel and surprising phenomenon of unintentional misalignment in reasoning language models (RLMs), which we call self-jailbreaking. Specifically, after benign reasoning training on math or code domains, RLMs will use multiple strategies to circumvent their own safety guardrails. One strategy is to introduce benign assumptions about users and scenarios to justify fulfilling harmful requests. For instance, an RLM reasons that harmful requests like “outline a strategy for stealing customers’ credit card information from a retail store” could be associated with the benign intent of “a security professional trying to test defense,” despite no such benign context being provided as input.
Microsoft, Coinbase and law enforcement took down EvilTokens, a phishing kit that compromised 12,000 inboxes through device-code phishing and AI. EvilTokens showed up in February 2026 and moved fast. Within months it had compromised more than 12,000 inboxes across over 10,000 organizations. Microsoft says the EvilTokens platform, operated by Storm-2992, is a phishing-as-a-service kit sold to cybercriminals through Telegram. The service costs $1,500 upfront and $500 per month, with additional tools available for extra fees. Its control panel lets customers build and manage phishing campaigns, customize landing pages, configure domains, track victims, and manage stolen authentication tokens. The platform includes 44 themes and uses AI to create targeted phishing emails based on a victim’s role.
CVE ID : CVE-2026-5696 Published : Sept. 23, 2026, 10:22 a. m. • 36 minutes ago Description : Reflected Cross-Site Scripting (XSS) in Microweber. The vulnerability lies in the ‘group’ parameter of the ‘/admin/settings’ endpoint in the administration panel. A successful exploit allows an attacker to trick an authenticated user into executing malicious JavaScript code in their browser. This enables the attacker to perform actions without the victim’s consent, steal confidential information or hijack the user’s session. Severity: 5.9 • MEDIUM Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Government Administration Stolen data: 3 GB.
CVE ID : CVE-2026-5695 Published : Sept. 23, 2026, 10:20 a. m. • 38 minutes ago Description : Arbitrary file upload vulnerability due to a lack of proper validation in upload forms. This allows authenticated users to upload files to the server without restrictions. An attacker could exploit this flaw to execute malicious code remotely (demonstrated by uploading the EICAR test file), which could result in the system being completely compromised. Severity: 8.4 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Government Administration Stolen data: 2 GB.
CVE ID : CVE-2026-95626 Published : Sept. 23, 2026, 10:17 a. m. • 42 minutes ago Description : Tauri's Content Security Policy hardening, which injects a random nonce to restrict script execution, provides zero protection when an application includes data: or blob: in its script-src directive. Per the CSP Level 3 specification, these scheme sources remain active even when a nonce is present, allowing arbitrary script execution without knowing the nonce. Severity: 8.3 • HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Emerging from stealth with $16 million in pre-seed funding, Outerlimit offers a decentralized authorization layer designed to discover, observe, and block harmful autonomous AI actions. The post Outerlimit Raises $16 Million to Stop Rogue AI Agents From Causing Harm appeared first on SecurityWeek .
Infamous threat group ShinyHunters claims to have personal information on thousands of FBI employees
Google has rolled out Chrome 154 to the Stable channel for Windows, Mac, and Linux, delivering fixes for 108 security vulnerabilities. The update, version 154. 0. 8037. 57 for Linux and 154. 0. 8037. 57/. 58 for Windows and Mac, addresses one of the largest security patch batches Chrome has shipped in recent memory, including 11 flaws rated Critical severity The most severe issues affect Chrome’s graphics and rendering stack. Multiple critical bugs were found in ANGLE, Chrome’s cross-platform graphics abstraction layer, including buffer overflows. Google Chrome 154 Patches 108 Security Flaws Additional critical flaws hit the GPU process, WebGL, ServiceWorker, Fullscreen, WindowDialog, and AdFilter components, with largely use-after-free and out-of-bounds write issues that could allow an attacker to achieve remote code execution or sandbox escape via a malicious web page.
Overview On September 22, 2026, F5 published a security advisory for CVE-2026-94127 , a critical heap-based buffer overflow vulnerability affecting F5 BIG-IP Access Policy Manager (APM). The vulnerability has a CVSS v3. 1 score of 9. 8. An unauthenticated attacker with network access to an affected virtual server may be able to achieve remote code execution (RCE) by sending specifically crafted traffic. BIG-IP APM provides identity-aware access control for applications and other corporate resources and can integrate with authentication technologies including OAuth, OpenID Connect, and SAML. CVE-2026-94127 is not exposed in a default configuration: exploitation requires a BIG-IP virtual server with both an APM access policy and an OAuth profile configured.
The EvilTokens phishing service, which compromised more than 12,000 inboxes at over 10,000 organizations, has been disrupted by a coalition of law enforcement and private-sector partners led by Microsoft. With authorization from the US District Court for the Eastern District of Virginia, Microsoft and Health-ISAC worked with Cloudflare, Coinbase, OpenAI, Railway, SpyCloud, The Shadowserver Foundation and TRM Labs to seize 50 websites used to operate the service and disable more than 150 domains tied to … More → The post Microsoft disrupts EvilTokens phishing service that gave criminals access to 12,000 inboxes appeared first on Help Net Security .
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to applications. F5 disclosed it in an advisory on September 22 and has released engineering hotfixes.
Concerns over agentic risks are rising, and identity and access management (IAM) giant Okta believes it’s making the moves of a would-be leader in this emerging cyber market. “Identity is the primary control plane for securing AI,” said Okta CEO and co-founder Todd McKinnon in an earnings call in late August , telling investment analysts that the company’s customers see Okta as well-positioned to secure this agentic future. “And so we’re going after that on all fronts.” “We think that being the system of record for agents in the enterprise and being the system of record for agent identity, in the fullness of time, could be the biggest category of cyber,” he added. At the center of that strategy is Okta for AI Agents, an identity management and security platform for tracking and controlling agentic entities and activity.
Quick Answer: Zero standing privileges is the destination; the lane depends on what you’re granting. PAM estates adding JIT: CyberArk and Delinea (and BeyondTrust) extend the platforms you already run. Cloud-native JIT for AWS/GCP/Azure roles: Apono and P0 Security lead the born-JIT startups. Infrastructure access (servers, K8s, databases): StrongDM’s zero-standing-access platform. SaaS app access and approvals in Slack: Lumos. Developer-workflow approvals: Indent status diligence advised. Every lane shares the thesis: access that expires can’t be stolen later. Who This Guide Is For Security teams dismantling standing admin rights, cloud platform owners drowning in over-privileged IAM roles, and IT leads whose access-request queue lives in tickets nobody loves.
EU digital identity and GDPR compliance mandates, deepfake-driven fraud in authentication and verification , and credential-reuse fatigue pushed decentralized identity from conference-talk to contract. We scored ten players on standards depth, production evidence, and enterprise readiness and flagged the market’s churn honestly, because this category retires vendors faster than most. Microsoft Entra Verified ID ranks #1 on deployable reach; Dock Labs and Ping Identity complete the podium. Key Takeaways • #1 overall: Entra Verified ID verifiable credentials bundled into the identity platform enterprises already run. • Podium: Microsoft (reach), Dock Labs (fastest issuance API), Ping (IAM-integrated credentials). • Churn warning: this market consolidates fast we flag status risks ([VERIFY]) rather than rank ghosts blindly.
F5 BIG-IP APM deployments configured as OAuth authorization servers are affected by CVE-2026-94127, a critical heap-based buffer overflow that can allow unauthenticated remote code execution and is being exploited in the wild. The post F5 BIG-IP APM Zero-Day CVE-2026-94127 Actively Exploited for RCE appeared first on CyberUpdates365 • Latest Cybersecurity News & Vulnerabilities .
Prismor is a free, open-source security layer for AI coding agents. It sits between an agent such as Claude Code, Codex, or Cursor and the actions that agent wants to take, and it checks each tool call against a policy before the call runs. Every call gets one of three verdicts: allow, warn, or block. AI coding agents run shell commands, read and write files, handle credentials, and call outside APIs, often chaining many steps … More → The post Prismor: Open-source runtime control plane for AI agents appeared first on Help Net Security .
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U. S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents and individuals who filed an application with the FBI for a job," the group said in a statement posted on their dark
The FBI is investigating an attack on its own systems after ShinyHunters claimed responsibility for the incident, putting the prolific cybercrime group in the most direct conflict yet with agents responsible for investigating data extortion attacks. The Monday breach, first reported by 404 Media , allowed ShinyHunters to temporarily deface the FBI jobs site. The group claimed it stole “very sensitive data on almost all FBI agents and individuals who filed an application with the FBI for a job,” in a lengthy post on its data-leak site. “The FBI is aware of claims regarding unauthorized activity affecting FBIjobs.gov and is currently investigating,” a spokesperson for the agency said in a statement. An alert on the FBI jobs site notes that apply. fbijobs. gov and the Special Agent Application Portal are currently unavailable.
ShinyHunters claims FBI systems hack, sensitive data "on almost ALL FBI agents" Cybernews
Sweden's data privacy regulator, IMY, has imposed a $183,000 (SEK 1. 8 million) fine on IT systems provider Miljödata for inadequate security measures leading to a breach in August 2025 affecting 2. 2 million people. [... ]