Skip to content
Bitget Says Suspected North Korean Hackers Stole 1.6M After Backend Compromise

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Ravie LakshmananSep 25, 2026Cryptocurrency / Cybercrime Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.  “At 18:31 UTC on September 24, 2026, Bitget’s security systems identified… 

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Ravie LakshmananSep 25, 2026Vulnerability / Email Security The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS… 

Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data

Cloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk Data

Swati KhandelwalSep 25, 2026Cloud Security / Vulnerability A flaw in Cloudflare Containers let a paying customer read data that other customers’ containers had left behind on the same server, Cloudflare and the researchers who found… 

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

Ravie LakshmananSep 25, 2026Vulnerability / Web Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV)… 

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

Swati KhandelwalSep 24, 2026Vulnerability / Mobile Security A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained… 

AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

Ravie LakshmananSep 24, 2026Hacking News / Cybersecurity News This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked… 

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

The “third-party[.]com” domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. “third-party[.]com has been a generic documentation placeholder for… 

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. “When a visitor interacts with… 

Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted…