HN · BleepingComputer · Krebs · Dark Reading · SANS · THN Intel · Unit 42 · Security.com
📰 Cybersecurity News Headlines
Top stories from leading cybersecurity publications as of September 17, 2026.
-
Anthropic wants Claude to analyze your bank account and financial data
— Bleeping Computer
Anthropic is testing a new personal finance feature called "Claude Money" that will allow you to connect your bank accounts directly to Cla… -
AI Security Spending Jumps as Fear Outpaces Proof of Value
— Dark Reading
CISOs are not waiting for AI to prove its cybersecurity value before investing in the technology. Is it the right move? -
Windows 11 KB5124008 update breaks domain trust for some users
— Bleeping Computer
Microsoft is investigating reports that the Windows 11 KB5124008 security update is breaking domain trust relationships on some enterprise s… -
Iranian hackers use CHOSEN BRICK Windows malware to spy on targets
— Bleeping Computer
Government agencies are warning that Iranian state-linked hackers are using a Windows malware strain named CHOSEN BRICK to target dissidents… -
Scans Targeting Hospitality Applications, (Wed, Sep 16th)
— SANS ISC
Earlier today, I noted an odd request showing up in our "First Seen" report: -
Data Broker Radaris Loses Domains in Privacy Fight
— Krebs on Security
The consumer data broker Radaris.com has long had a reputation for ignoring requests to remove personal information from its vast empire of … -
Fighting Your Dragons Through Tough Tech Times
— Dark Reading
Cybersecurity industry veteran Hal Pomeranz gives a pep talk on career anxiety and self-doubt and shares how to build meaningful connections… -
BragJack Attack Can Turn a Browser's Agentic AI Against It
— Dark Reading
A new type of attack hijacks the AI assistant built directly into various browsers to access sensitive information, execute malicious action… -
Attackers Exploit Issabel Framework Flaw Enabling Unauthenticated OS Command Execution
— The Hacker News
A critical security flaw in Issabel Framework, a web-based framework for the open-source unified communications PBX software, has come under… -
Three Threat Groups Target Russian Enterprises With Backdoors, Ransomware, and Wipers
— The Hacker News
Enterprises in Russia have emerged as the target of three threat activity clusters tracked as NightEagle, Hacking Cat, and Toy Ghouls, accor… -
One Extension Could Hijack AI Assistants Across Chrome, Comet, Edge, Opera Neon and Claude
— The Hacker News
Security researchers at Forever Security have shown that one ordinary browser extension could take control of the AI assistants built into… -
Atomic macOS (AMOS) Stealer Activity
— Unit 42
Modern macOS malware uses deceptive setup guides to steal credentials and sensitive user data. Learn how to identify and block these threats…
🪲 NVD — Last 20 Scored Vulnerabilities
Latest scored CVEs from the National Vulnerability Database (15148 in last 30 days).
Critical: 0 · High: 6 · Medium: 14 · Low: 0. View full dashboard →
-
CVE-2026-61596
— CVSS 7.1 (HIGH)
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, djust's per-object authorization (`get_object` + `has_object_permission`, ADR-017) wa⦠-
CVE-2026-61589
— CVSS 6.3 (MEDIUM)
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, the WebSocket `handle_mount` and `ViewRuntime._build_request` rebuild an `HttpRequest⦠-
CVE-2026-61588
— CVSS 6.5 (MEDIUM)
djust provides Phoenix LiveView-style reactive server-side rendering for Django with Rust-powered performance. Prior to version 1.0.7, when a Django `Model` instance is assigned to a public view attribute, djust serializ⦠-
CVE-2026-92599
— CVSS 7.5 (HIGH)
joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and >=18.0.0 <18.2.6 are vulnerable to regular expression denial of service in the `Joi.string().isoDate()` validation rule. One of the regular expressions the ⦠-
CVE-2026-92598
— CVSS 6.5 (MEDIUM)
Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encoding international domain names, causing the domain resolver to compute a different Punycode A-label than standards-compliant parsers. Attackers can cr⦠-
CVE-2026-92597
— CVSS 6.5 (MEDIUM)
Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments in email addresses: in lib/addressparser, a comment closed immediately before a non-break character causes the tokenizer to concatenate the atoms surr⦠-
CVE-2026-92596
— CVSS 7.5 (HIGH)
Nodemailer before 9.1.0 contains a quadratic time complexity vulnerability in the addressparser component that allows remote attackers to cause denial of service by supplying a crafted comma-separated address list. Attac⦠-
CVE-2026-92595
— CVSS 5.9 (MEDIUM)
Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do not honor the `disableFileAccess` and `disableUrlAccess` sandbox options when message content is resolved through the public plugin API `MailMessage.res⦠-
CVE-2026-92594
— CVSS 7.5 (HIGH)
Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authorize the GraphQL draftCreator and revisionCreator fields: instead of requiring the user-data scope enforced by Gql::canQueryUsers() (usergroups.*:read),⦠-
CVE-2026-92593
— CVSS 8.8 (HIGH)
Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirectUrl() -> View::renderObjectTemplate() sink remained unsandboxed, and the same fix commit added a se⦠-
CVE-2026-92592
— CVSS 8.8 (HIGH)
Craft CMS 4.8.0 through 4.18.5 and 5.0.0 through 5.10.12 sign an authenticated user's attacker-controlled license-shun cookie with the same key and format used to validate signed redirect parameters, because the HMAC sig⦠-
CVE-2026-92591
— CVSS 5.9 (MEDIUM)
Craft CMS 5.0.0 through 5.10.12 treats a database connection failure as meaning that Craft is not installed, which makes anonymous installer actions — including install/validate-site — reachable on an installed produ⦠-
CVE-2026-92590
— CVSS 5.4 (MEDIUM)
Craft CMS versions from 5.7.0 before 5.10.13 contain a stored cross-site scripting vulnerability in the Generated Fields feature that disables Twig autoescaping and fails to encode cached values. Content editors can inje⦠-
CVE-2026-92589
— CVSS 4.3 (MEDIUM)
Craft CMS 5.0.0 through 5.10.12 (fixed in 5.10.13) contains a broken access control flaw in the nested-elements reorder endpoint. When an authenticated control panel user with viewEntries and viewPeerEntries (but without⦠-
CVE-2026-92588
— CVSS 4.4 (MEDIUM)
n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request ⦠-
CVE-2026-92587
— CVSS 5.0 (MEDIUM)
n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its workin⦠-
CVE-2026-92586
— CVSS 4.3 (MEDIUM)
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to verify video access permissions in the set_api_comment function, allowing authenticated users to post comments on password-protected and grou⦠-
CVE-2026-92585
— CVSS 4.3 (MEDIUM)
AVideo through 29.0 (commit c3edcc274c389816d434acadac07ee78eaf330c1) fails to validate video access permissions in the API like endpoint, allowing logged-in users to vote on password-protected and group-restricted video⦠-
CVE-2026-92584
— CVSS 6.1 (MEDIUM)
AVideo through 29.0 (current revision e01e41ecc) contains a stored cross-site scripting vulnerability. The unauthenticated view-counter endpoint objects/videoAddViewCount.json.php reaches VideoStatistic::save(), which wr⦠-
CVE-2026-92583
— CVSS 6.5 (MEDIUM)
AVideo through 29.0 contains a race condition in the enforceRateLimit() function that fails to atomically increment rate limit counters, allowing attackers to bypass all rate limits including login brute-force protectionâ¦
Source: NVD CVE API 2.0
Generated by CryptXNet.ai Threat Intelligence Platform · September 17, 2026 · Sources: The Hacker News, Bleeping Computer, Krebs on Security, Dark Reading, SANS ISC, THN Threat Intel, Unit 42, Security.com
Leave a Comment