Device Code Vishing Attacks Target Microsoft Entra Accounts!
Hackers are exploiting the OAuth device authorization flow to trick users into entering legitimate Microsoft device codes, allowing attackers to gain access to Microsoft Entra accounts — even bypassing MFA.
This sophisticated vishing technique targets identity systems and connected services like Microsoft 365.
Protect your organization with advanced identity security solutions from AGT.
https://t.co/5Bh06BEMCp
Source: BleepingComputer
#CyberSecurity #IdentitySecurity
‼️ Apple patched a new CoreGraphics flaw that may have been exploited in targeted iOS attacks.
CVE-2026-86950 can trigger arbitrary code execution when a maliciously crafted file is processed. Fixes are available for affected older iOS, iPadOS, and macOS releases.
Read: https://t.co/RueCsj3Xpk
FBI and Dutch Police Arrested Alleged ShinyHunters Hackers Group Leader
Details: https://t.co/KPcfcpKxht
FBI Director Kash Patel has announced the arrest of an alleged leader of ShinyHunters, the cyber-extortion group linked to attacks across the United States, the Netherlands, and other countries.
Dutch police detained the 24-year-old Amsterdam suspect on September 15 under Dutch law, with FBI investigators supporting the operation and pursuing leads. Patel described the detainee as “one of the alleged leaders” of ShinyHunters and thanked Dutch police and private-sector partners for sharing information, emphasizing that the investigation remains active.
#cybersecuritynews
⚠️ Pentagon Data Breach - Hackers Reportedly Accessed 3 Million People's Sensitive Data
Details: https://t.co/a5aBZRhhac
The Pentagon has confirmed a major data breach involving a Defense Manpower Data Center (DMDC) information system, exposing sensitive personal information belonging to more than three million people.
The incident affected 2.76 million living individuals and approximately 294,000 deceased people, placing one of the Department of Defense’s most important personnel repositories under renewed scrutiny.
A small number of unauthorized users accessed the DMDC system between October 2025 and July 2026. The intrusion was linked to a security vulnerability in a file-sharing system, which allowed outsiders to reach files stored on an affected server.
#cybersecuritynews
🚨 Critical Apple CoreGraphics Zero-Day Vulnerability Actively Exploited in Attacks
Details: https://t.co/vi7ImgPtPF
Apple has released iOS 26.7.1 and iPadOS 26.7.1 to fix a critical zero-day vulnerability that it says may have been exploited in an extremely sophisticated attack against specifically targeted individuals.
The security issue, tracked as CVE-2026-86950, affects the CoreGraphics framework, a fundamental Apple component responsible for rendering graphics, images, and documents across iPhones and iPads.
Successful exploitation could allow attackers to execute arbitrary code on a vulnerable device by convincing a victim to process a maliciously crafted file. Apple released the updates on September 28, 2026, and urged users to install them as soon as possible.
#cybersecuritynews
‼️ URGENT - WordPress issues patch a new critical flaw (CVE-2026-87902) that requires no account and can lead to code execution on some servers.
Versions 4.7.0 through 7.1.1 are affected.
Here's how the flaw works: https://t.co/7zcWyMyHR4
🛡️ Multiple VLC Media Player Flaws Allow Attackers to Corrupt or Read Heap Memory
Details: https://t.co/QtPQODla3y
Two security vulnerabilities in VLC Media Player could allow attackers to corrupt heap memory or disclose sensitive data from a victim’s memory.
The flaws, tracked as CVE-2026-56711 and CVE-2026-73324, affect VLC Media Player versions 3.0.0 through 3.0.23 and require a victim to open a specially crafted media file or playlist entry.
An attacker can exploit the flaw using a crafted PNG image with oversized width and height values in its IHDR header. VLC’s image demuxer checks the input file size but does not properly validate declared image dimensions.
#cybersecuritynews
‼️ Hackers Chain Chrome and Windows Zero-Days in New BlueMoon Exploit Kit Attacks
Details: https://t.co/6TEZSWTuoY
Multiple espionage-motivated threat actors have rapidly adopted a newly discovered exploit kit that chains Chrome browser and Microsoft Windows vulnerabilities to deploy backdoors and surveillance tools against government, defense, and commercial targets worldwide. BlueMoon exploits three vulnerabilities in sequence.
The first is a type-confusion flaw; this is followed by a V8 sandbox escape, and the final stage leverages a Windows kernel local privilege escalation flaw.
#cybersecuritynews
‼️ Check Point patched two critical VPN certificate flaws, CVE-2026-85102 and CVE-2026-85103, that could allow unauthenticated RCE under specific, undisclosed conditions.
Both carry CVSS 9.8 scores.
What’s affected and how to fix it: https://t.co/6eJGipbZ2o
⚠️ ALERT - Google patched a new actively exploited Chrome V8 zero-day.
CVE-2026-87491 lets crafted HTML execute arbitrary code inside Chrome’s sandbox. Google has not said how it’s being weaponized or who is behind it.
Read: https://t.co/MG32DeTMiV
Chrome 153 Fixes 230 Vulnerabilities, Including One 0-Day Exploited in the Wild
Details: https://t.co/2tqKH04lZj
Google has rolled out Chrome 153 to the stable channel for Windows, Mac, and Linux, shipping as version 153.0.8010.36 on Linux and 153.0.8010.36/.37 on Windows and Mac.
The update will reach users over the coming days and weeks and includes 230 security fixes, one of the largest patch batches in recent Chrome release history.
The most critical issue in this release is CVE-2026-87491, a Medium-severity out-of-bounds write vulnerability in V8, Chrome’s JavaScript and WebAssembly engine. Google has confirmed that an exploit for this flaw already exists in the wild, making immediate updates essential for all users.
#cybersecuritynews
🚨 Critical Chrome 0-Day Vulnerability Actively Exploited in the Wild |
Source: https://t.co/KcoTh9AsWR
Google has released an emergency Chrome security update that fixes a critical zero-day vulnerability already being exploited in real-world attacks.
The flaw, tracked as CVE-2026-85046, affects the V8 JavaScript and WebAssembly engine used by Chrome to process web content.
The company confirmed that it is aware of an exploit for the vulnerability existing in the wild. While Google did not disclose details about the attacks, affected targets, or the threat actors behind the activity, the active exploitation notice makes immediate patching important for all Chrome desktop users.
#cybersecuritynews
⚡ Apple fixed an iOS bug where deleted notifications stayed stored on devices.
The flaw let message data persist after apps like Signal were removed. It surfaced after forensic extraction. The patch now clears and prevents retention.
🔗 Details → https://t.co/ybkDLPpaGT
Microsoft warns that some Windows domain controllers are entering restart loops after installing the April 2026 security updates.
https://t.co/6ImZhwIIwz
⚠️ EU's New Age Verification App Can Be Hacked Within 2 Minutes
Source: https://t.co/Z7K6BNlxao
The European Commission's newly launched Digital Age Verification App, unveiled on April 14, 2026, to protect minors from harmful online content, has already been compromised, with UK-based security consultant Paul Moore demonstrating a full authentication bypass in under two minutes.
During app setup, users are prompted to create a PIN. The app then encrypts this PIN and stores it in a local configuration file called shared_prefs on the user's device.
Researchers identified two critical architectural flaws: the encrypted PIN is stored locally but is not cryptographically tied to the identity vault that holds actual verification credentials, and the encryption itself serves no meaningful security purpose given its editable nature.
#cybersecuritynews #EU #Ageverification