Why “We Patched #WordPress Last Week” Is Not Enough: WordPress has urgently released v7.1.2 for a critical core #vulnerability: an unauthenticated attacker can make template resolution include a chosen local PHP file and in some conditions, achieve RCE:
👇
https://thehackernews.com/2026/09/wordpress-issues-patch-for-critical.html
Sam Stepanyan
🐘
https://twitter.com/securestep9
#OWASP London Chapter Leader(@OWASPLondon@infosec.exchange). Application Security (#AppSec) Architect & Consultant. OWASP Global Board Member. OWASP Nettacker Project co-leader. #CISSP
#OWASP GenAI Security Project publishes the "project Crosswalk" - an open-source resource which maps AI risks to compliance requirements from 25 regulatory frameworks NIST, ISO, #MITRE ATLAS, the EU #AI Act and others:
#AISecurity
👇
https://genai.owasp.org/resource/genai-security-industry-framework-crosswalk/
Fintech company #Revolut has disclosed a #databreach after sharing KYC customer PII data (names, addresses, scanned passports, driving licenses, photos, IBAN bank account numbers & statements) with a threat actor impersonating a government agency:
👇
https://www.bleepingcomputer.com/news/security/revolut-discloses-data-breach-exposing-financial-info-passports/
#WordPress admin clicks a link. WordPress clicks Install.
“Click2Shell” abuses the admin’s logged-in session to silently install an attacker-chosen theme. Chain it with a vulnerable theme: server-side PHP execution.
Patch WordPress core to 7.1.1 now! 👇
https://thehackernews.com/2026/09/new-wordpress-click2shell-flaw-forces.html
#WordPress “Comment2Shell” turns anonymous stored #XSS vulnerability into server code execution when an admin views the comment.
It abuses the admin session to upload a malicious plugin. Patch now!
👇
https://idnsec.com/research/comment2shell-zero-click-pre-auth-xss-to-rce-in-wordpress-core/
#Microsoft #Copilot #Cowork Sandbox Bypass #Vulnerability Gives Attackers Remote Control:
#AISecurity
https://www.promptarmor.com/resources/microsoft-copilot-cowork-sandbox-bypass
This is what modern #AgenticCybercrime looks like.
ShinyHunters-linked group used Claude in an automated pipeline that decompiled & scanned 1.8M Android APKs for hardcoded secrets.
#AI-assisted cybercrime is moving from prompts to scalable workflows.
👇
https://www.bleepingcomputer.com/news/security/hackers-abused-claude-to-extract-secrets-from-18m-android-apps/
#AI: Zero-click Grok and Gemini chat history theft possible using cryptographic context injection technique that bypasses AI safety filters - demonstrated by @Adversa_AI:
#AISecurity
👇
https://securityaffairs.com/197717/hacking/zero-click-grok-chat-history-theft-adversa-ai-demonstrates-cryptographic-context-injection.html
#HuggingFace built an interactive replay of the #OpenAI agent that breached them: Anatomy of a frontier-lab agent intrusion.
It includes 17,613 logged attacker actions across the 4.5-day campaign, with the live command stream. Fascinating to watch: 📽️
👇
https://huggingface-anatomy-of-frontier-lab-model-intrusion.static.hf.space/index.html
Manchester Airports Group #databreach was caused by the API keys simply #hardcoded in the front-end JavaScript files - something I see a lot recently in AI vibe-coded applications and in the pre-AI era in poorly coded applications which visibly look & work fine before a pentest:
#ChatGPT: With the release of Workspace Agents, ChatGPT was vulnerable to a #CSRF attack enabling a single link to create a malicious insider in your organisation (dubbed #AgentForger by Zenity)
#AISecurity:
👇
https://labs.zenity.io/p/agentforger-part-1-chatgpt-cross-site-agent-forgery
#AirportBreach: Used Wi-Fi or booked parking, lounge or FastTrack at #Stansted, #Manchester or #EastMidlands Airport? Attackers breached and accessed data of 8.7mln airport customers including emails, phone numbers, postcodes and vehicle registrations:
👇
https://www.theguardian.com/business/2026/aug/27/uk-airports-operator-cyber-attack-customer-data-accessed
Top AIs invent same fake #PyPl and #npm package names. Research reveals that #slopsquatting remains a threat to developers using #AI to aid coding (#vibecoding):
👇
https://www.infoworld.com/article/4200884/top-ais-invent-same-fake-pypl-and-npm-package-names.html
#Linux: a 13-year-old Linux kernel flaw dubbed #OVSWrap lets local users gain root privileges on most Linux distributions. CVE-2026-64531 vulnerability is in the Linux kernel’s Open vSwitch datapath:
#PrivilegeEscalation
👇
Imagine finding a master key that can create the keys to access almost every Azure Cosmos DB instance on the planet. That's essentially what #CosmosEscape achieved.
One of the most fascinating recent cloud security bugs:
#CloudSecurity
👇
https://www.wiz.io/blog/cosmosescape-taking-over-every-database-in-azure-cosmos-db
#AI: Tracebit has published an interesting research on “context bombs” - injected text snippets designed to intentionally trigger an AI model’s safety guardrails and make an adversarial AI agent refuse to continue an attack:
#AISecurity
👇
https://tracebit.com/blog/context-bombs-stopping-ai-attackers-in-their-tracks
A 16-year-old flaw in #Linux KVM hypervisor dubbed "#Januscape" (CVE-2026-53359) is a Use-After-Free vulnerability which allows guest VMs to escape to the host:
The fix was merged into the mainline Linux kernel on June 19, 2026:
👇
https://thehackernews.com/2026/07/16-year-old-linux-kvm-flaw-lets-guest.html
#Python: Attackers Planted a #Telegram-Powered Backdoor #Malware Across Fake 'pyrogram' Packages on #PyPI:
* pyrogram-navy
* pyrogram-styled
* sepgram
* pyrogram-kelra
...and others - check out the @CheckmarxZero blog post for more details:
👇
https://checkmarx.com/zero-post/operation-navy-ghost-pyrogram-telegram-supplychain-attack/
A supply-chain attack became a #databreach.
Malicious TanStack npm packages stole a GitHub token from an ex-CrowdSec employee whose access remained active. Attackers copied ~170 private repos and exposed data on 83 users and 51 potential investors:
👇
https://thehackernews.com/2026/09/crowdsec-says-tanstack-npm-attack-led.html
If you want to present a talk at the #OWASP Global AppSec USA 2026 Conference in San Francisco - you have just a few days left to submit your talk - the #CFP is still open:
👇
https://sessionize.com/owasp-global-appsec-us-2026-cfp-SF/
#Mikrotik - if you are using Mikrotik routers you should immediately upgrade to the latest version due to the undisclosed security #vulnerability in RouterOS.
Fixes included in versions:
* 7.25 beta 3
* 7.24.2
* 7.23.4
* 6.49.21
Vendor advisory:
https://mikrotik.com/supportsec/september-2026-vulnerability/
#NextJS: Two Critical Vulnerabilities in NextJS allow unauthenticated #RCE: one through crafted AVIF images, another via path traversal on Windows (CVE-2026-75604).
Upgrade your NextJS immediately to v15.5.24 or 16.3.3!:
👇
https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html
#Telegram: Montenegro-owned top-level-domain '.me' registry suspends Telegram's short link domain 't[.]me' causing all Telegram links including channel invite links to stop working. Telegram now has switched to 'telegram[.]me' domain, but millions of old links remain broken:
👇
https://cryptobriefing.com/telegram-tme-domain-suspended-dns/
#JFrog #Artifactory: Attackers are already exploiting critical auth bypass CVE-2026-82329 (CVSS 9.8) to mint admin tokens. Compromising your organisation's artifact repository could poison builds and trigger #SoftwareSupplyChain attacks - patch now!
👇
https://www.csoonline.com/article/4217534/exploited-jfrog-artifactory-bug-puts-software-supply-chain-on-alert.html
Coding Agent Horror Stories: The 29 Million #Secret Problem - great blog post story by Docker:
👇
https://www.docker.com/blog/coding-agent-horror-stories-the-29-million-secret-problem/
#AsyncAPI packages were compromised with Miasama RAT #Malware on #NPM:
* @asyncapi/generator@3.3.1
* @asyncapi/generator-helpers@1.1.1
* @asyncapi/generator-components@0.7.1
#SoftwareSupplyChainSecurity
👇
https://www.stepsecurity.io/blog/compromised-next-branch-pushes-malicious-asyncapi-generator-generator-helpers-and-generator-components-to-npm
#WhatsApp: German law enforcement agencies are using features built into apps such as WhatsApp, Signal, #Telegram to monitor people’s messages without breaking their #encryption or installing spyware on the phones - see Netzpolitik report:
👇
https://cybernews.com/privacy/police-telegram-whatsapp-signal-surveillance-linked-devices
OWASP Nettacker v0.4.1 released:
#Microsoft patched a Critical #Windows DNS Server Remote Code Execution (#RCE) #vulnerability in September Patch Tuesday:
🔴 CVE-2026-69730
⚠️ CVSS: 9.8
🌐 Unauthenticated remote attack (use-after-free)
Patch your DNS servers!
👇
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-69730
#NPM: two hijacked npm packages:
- html-to-gutenberg
- fetch-page-assets and a cluster of Go packages use VS Code Tasks to deploy #Python Infostealer #malware: #SoftwareSupplyChainSecurity 👇 https://thehackernews.com/2026/06/hijacked-npm-and-go-packages-use-vs.html
#AI: Zscaler ThreatLabz has published a research paper on malicious websites that impersonate legitimate services and use Indirect Prompt Injection to poison SEO & manipulate AI Agents & AI-driven workflows - a fascinating read:
#AISecurity
👇
https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-web-content-targets-ai-agents

