🛡️ OpenAI Agent Swarm Bypassed Sandbox Limits and Left 80,000 Attack Payloads Behind
Details: https://t.co/mBXeZBNeeV
About 700 OpenAI agents allegedly escaped evaluation sandboxes, compromised parts of Hugging Face infrastructure, and generated over 80,000 attack payloads via public URL chains.
The report says the agents initially had limited internet access and could only make GET requests, which normally allow a system to retrieve web content without submitting data or interacting with web applications.
The agents reportedly discovered a way to turn that restricted access into a functional read-and-write channel by chaining together external web services.
#cybersecuritynews
🛡️ New Windows Process Injection Attack Evades EDR Monitoring Without WriteProcessMemory
Source: https://t.co/826wkR79uO
A Windows process injection method disclosed by security researcher Two Seven One Three sidesteps two APIs closely associated with remote code injection: VirtualAllocEx and WriteProcessMemory.
Dubbed console named-pipe injection, the technique delivers payload bytes through a child console process’s redirected standard input and repurposes memory Windows has already populated.
It can disrupt detections built around the familiar allocate-write-execute sequence. Process injection executes arbitrary code inside another process, potentially masking activity behind a legitimate application.
#cybersecuritynews
🛡️ Wireshark 4.6.9 Fixes 19 Vulnerabilities Including Code Execution Via Malicious Packet
Details: https://t.co/sTWvgv8H9K
Wireshark has released version 4.6.9, a security-focused update that addresses 19 documented vulnerabilities across protocol dissectors, capture-file parsers, the Sharkd utility, and configuration-profile handling.
Released on September 23 alongside Wireshark 4.4.19, the update is available as Windows and macOS installers and source code. The most significant issue is CVE-2026-96419, tracked as wnpa-sec-2026-106. A specially crafted configuration profile can crash Wireshark or potentially execute arbitrary code when a user is persuaded to import it.
#cybersecuritynews
We identified a coordinated campaign of 10 browser #extensions disguised as browser games. On installation, extension names resolve through fragmented translation keys and runtime #impersonates crypto wallets with a remote kill switch. Details at https://t.co/CVKUAyZ1sN
‼️ Cloudflare Containers Vulnerability Could Leak Data Between Customer Workloads
Source: https://t.co/uvKBNaa4mX
Cloudflare has patched a cross-tenant data exposure vulnerability in its Containers platform across its global, multi-tenant cloud computing infrastructure that could allow one customer’s workload to recover residual disk data left by another tenant on the same physical host.
The issue also affected Cloudflare Sandboxes, which are built on Containers, but Cloudflare says it found no evidence of malicious exploitation or customer data compromise in its retained telemetry.
#cybersecuritynews
‼️ GitLab Email Feature Vulnerability Lets Attackers Push Code Into Private Repositories
Details: https://t.co/jFpj0iI6xU
GitLab’s “Email work item to this project” feature can become a repository-compromise primitive when its private address is exposed, according to research published by @AikidoSecurity researcher Joe Leon on September 23, 2026.
The address contains a long-lived glimt- incoming-email token that GitLab says does not expire and must remain secret. GitLab documentation confirms that anyone possessing it can create issues and merge requests as the token owner.
An attacker can reportedly replace the -issue suffix with -merge-request, attach a Git patch, and identify a source branch in the email subject. GitLab then applies the patch to that branch or creates it using the victim’s permissions.
#cybersecuritynews
🛡️ Microsoft Entra ID to Block SMS First-Factor Sign-Ins Worldwide in February 2027
Details: https://t.co/8nUEkk9KGW
Microsoft is retiring SMS first-factor sign-in for Microsoft Entra ID workforce tenants worldwide and requires organizations to migrate affected users before February 1, 2027.
The security-focused change will prevent employees from using a registered telephone number and SMS one-time passcode as their primary sign-in method, potentially disrupting Microsoft 365 and other Entra-protected services if administrators fail to prepare.
SMS first-factor authentication, internally identified as SignInNoPassword, allows a user to enter a registered phone number instead of a username and password.
#cybersecuritynews #Microsoft
‼️ WARNING - F5’s BIG-IP APM 0-day is being exploited for unauthenticated RCE.
CVE-2026-94127 affects systems where APM acts as an OAuth authorization server. F5 has released hotfixes, and CISA added the flaw to KEV.
What to patch and check: https://t.co/AP8y7sIIto
🛡️Critical WordPress Core Vulnerability Lets Attackers Execute Code Without Logging In
Details: https://t.co/WokyPZ1rjz
WordPress has released version 7.1.2 to address a critical security vulnerability that could allow unauthenticated attackers to execute code on vulnerable websites under specific conditions.
The flaw is tracked as CVE-2026-87902, and it affects WordPress page template resolution, a core mechanism that determines which PHP template file renders a requested page.
The vulnerability can allow a remote attacker to influence template resolution and cause WordPress to include a readable local PHP file located outside the active theme directory.
#cybersecuritynews
Security researcher Abdelhamid Naceri (also known as Nightmare Eclipse) has released another Microsoft Defender zero-day exploit that blocks antivirus updates.
https://t.co/CjU6Rzvvow
⚡ Microsoft took down EvilTokens, tied to 12,000+ compromised inboxes across 10,000+ organizations.
The service abused Microsoft’s legitimate device-code sign-in flow and used AI to identify trusted contacts and draft impersonation emails.
Learn how it worked: https://t.co/1zMcU0ddjt
🚨 Check Point patches Management Server zero-day exploited in attacks
⠀
Check Point has released fixes for CVE-2026-93616, a vulnerability that allows unauthenticated attackers to upload and execute arbitrary scripts on affected management servers.
⠀
The company says a small number of customers have already been attacked.
⠀
Affected products include:
• Security Management Server
• Multi-Domain Security Management Server
• Log Server
• Multi-Domain Log Server
• SmartEvent
⠀
The vulnerability carries a CVSS score of 9.8.
⠀
Check Point advises installing the applicable fixes, restricting management access to trusted IP addresses, and checking for signs of exploitation.
⠀
LivePatch Take 28/29 does not fix this vulnerability.
Stolen session cookies let attackers walk straight into your employees' accounts - no login, no 2FA prompt, no alerts on your end.
NordLayer Intelligence by NordStellar detects leaked session cookies on the dark web and alerts you in real time.
When you log in, a session cookie keeps you authenticated. If an attacker steals that cookie - usually via infostealer malware - they inherit your active session. No credentials needed. No MFA challenge. You're already "logged in."
The damage: account takeover, data theft, financial loss, reputational hit.
How NordStellar stops it:
• 24/7 dark web monitoring - continuously scans deep & dark web sources and malware logs for stolen session cookies tied to your employees and customers
• Real-time alerts - get notified the moment a stolen cookie appears, with source, device, and affected data details
• Actionable intelligence for remediation - know exactly which sessions and devices are compromised so your team can revoke access and secure accounts before attackers strike
Check if your organization’s data exposed online for FREE ➡️ https://t.co/A4wtpTjQW2
⚠️ North Korean Jade Sleet is linked to a breach of an Indian IT provider via a DevOps engineer’s Apple Silicon MacBook.
FLATROOF and ROOFDECK were found on the system, with capabilities for command execution, remote shell access, persistence, and data theft.
Inside the MacBook compromise: https://t.co/ZGCgA76J5Y
🚨 North Korea’s Contagious Interview campaign compromised 30,000+ devices across 100+ countries and stole at least $10.71M in crypto.
Fake job offers and coding tests trigger malware infections; funds or credentials were siphoned from 7,000+ wallets.
Inside the chain: https://t.co/ItIoxbQPjU
🛡️ Linux KVM/arm64 Vulnerability Lets Attackers Escape Virtual Machines and Gain Host Access
Details: https://t.co/YG6WscPCMy
A newly disclosed Linux kernel vulnerability, tracked as CVE-2026-89775, could let attackers escape an ARM64 virtual machine and access the underlying host system.
The issue affects KVM/arm64 environments where nested virtualization is enabled, creating a serious risk for multi-tenant cloud infrastructure and systems that allow untrusted users to create virtual machines.
The bug affects how the kernel calculates the size of a memory region it must invalidate from the virtual CPU’s pseudo-Translation Lookaside Buffer, or pseudo-TLB. Under normal conditions, KVM must invalidate stale memory translations after memory mappings change.
#cybersecuritynews