Skip to content
September 2026 Page 10

September 2026

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

Swati KhandelwalSep 22, 2026Vulnerability / Web Security A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published… 

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

A malicious npm package named “indexed-btree” has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls.… 

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

Ravie LakshmananSep 22, 2026Malware / Cyber Espionage The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. “SideCopy campaign operations… 

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor

Swati KhandelwalSep 22, 2026Vulnerability / Artificial Intelligence Malware already running on a Mac can quietly take over Meta’s Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has… 

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session

Swati KhandelwalSep 22, 2026Vulnerability / Web Security A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that… 

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access

Ravie LakshmananSep 22, 2026Vulnerability / Endpoint Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing…