IT News Analysis

// AI-powered news analysis

Latest Top 10 Articles

1
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify the lure and the delivery method. "Where earlier variants embedded their payload key material directly in the JXA source, it now fetches a purpose-built decryption utility and completes a key exchange with the server before the payload can be unwrapped," security researcher Thijs Xhaflaire said in an analysis. "Without the server's cooperation, the payload cannot be recovered statically." A second major change is the choice of the decoy itself. While previous versions observed in July and August 2026 were observed using fake websites masquerading as Maccy, Scoppr, and Nancy Clipboard, victims are now lured through a bogus website ("wavel[.]app") advert...

Sep 25, 2026
3
The SOC Doesn't Need to Start Over with Every Alert

The SOC Doesn't Need to Start Over with Every Alert

Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like this. An attacker lands on a low-privilege cloud account, and the first try at privilege escalation goes nowhere. That dead end used to cost hours of documentation reading, permission checks, and script debugging, and plenty of operators simply got stuck. With a model in the loop, the error gets explained, the script gets fixed, and a fresh enumeration path is under test within minutes. No step in that sequence is a new capability. Together they strip time, skill, and cost out of the unglamorous middle of an intrusion, the research and troubleshooting that sit between intent and outcome. What the threat reporting shows The public record traces the arc. In early 2025, Google's Threat Intelligence Group found state-backed actors treating generative AI as a prod...

Sep 25, 2026
4
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.  "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet said in a post shared on X. "Bitget's cold wallets and the overwhelming majority of platform assets remain secure and unaffected." The company emphasized that customer account balances remain accurate, and deposits and trading continue to operate normally. However, withdrawals have been temporarily suspended out of an abundance of caution while a "comprehensive security review" is underway. Bitget did not disclose any details on how the attack took place, but said it has enlisted the help of Google-owned Mandiant and SlowMist for a third-party investigation. "Bitget Wallet operates as a self-custodial wallet on a completely separate and independent infrastruc...

Sep 25, 2026
5
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roundcube Webmail versions 1.6.x before 1.6.16 and 1.7.x before 1.7.1. The issue stems from a preg_replace() backslash escape bypass that allows attackers to inject arbitrary SQL statements without authentication. "Unauthenticated attackers can inject SQL into Roundcube's database backend through the virtuser_query plugin, potentially exposing mail account credentials and stored messages," SentinelOne said . Patches for the vulnerability were released by Roundcube in May 2026 as part of 1.6.16 and 1.7.1. In an update shared this week, the Cyber Centre said the security flaw is being actively exploited in the wild, citing open-source reporting. No additional details of the exploitation ac...

Sep 25, 2026
6
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier containers had used and given up, not from any live workload, and an attacker could not choose whose data they got,  according to Cloudflare . The company has fixed the flaw across its service and says customers need to do nothing. Cloudflare Containers runs customers' programs inside containers on servers shared by many accounts, and Cloudflare, not the customer, picks the server. Cloudflare Sandboxes, which runs on Containers and is sold as a safe place to run untrusted code, including code written by AI agents, was affected too. The flaw was reported on September 4 by Oren Yomtov of the security firm Accomplish , through Cloudflare's bug bounty program. The problem was in how the shared disks were set up. Each container gets a ...

Sep 25, 2026
8
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities ( KEV ) catalog, based on evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-5430 (CVS score: 9.8) - A path traversal vulnerability in  WSO2 API Control Plane, API Manager, Traffic Manager and Universal Gateway that could allow unrestricted file upload and lead to remote code execution. CVE-2026-71362 (CVSS score: 9.1) - An incorrect authorization vulnerability in  Adobe Commerce and Magento that could allow an attacker to leverage this vulnerability to gain elevated access to sensitive resources without any user interaction. The addition of CVE-2026-5430 to the KEV comes a little over a week after watchTowr said it's seeing in-the-wild exploitation efforts against its honeypots since at least September 13, 2026. "We captured forged JW...

Sep 25, 2026
9
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats,  chained two flaws in OnePlus's own software  to gain root access, the highest level of control over an Android phone. OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not said which. OnePlus confirmed both flaws in May. In the same reply, the company told Moorats that it alone decides when to make a flaw public and warned that publishing without its permission could result in legal liability. He published on September 24 anyway, when OnePlus had released no fix. OnePlus set out its position in the reply,  which Moorats published in full . It said a fix was scheduled, but claimed "the exclusive final right of vulnerability disclosure," and told him that even after a fix ships, researchers may not publish full technical details on their own. The comp...

Sep 24, 2026
10
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI tools leak more than expected. Fake prompts look real enough. And some attacks barely need an exploit at all — just one weak setting or one person doing what the screen tells them. Nothing here looks especially dramatic. That is what makes it useful. The threats change every week. Subscribe, and we’ll alert you when each new ThreatsDay Bulletin is out.

Sep 24, 2026

Get a summary by Chaplin or Kilmister Get a summary