Below I’ve curated cyber security news from the world-wide-web – the lefthand column is from “The Hacker News” website and on the right is news from “Security Week”. Both are top cyber security news sites. In the very least this shows that threats are daily and they are very real.
Hacker News
- Microsoft Takes Down EvilTokens Device-Code...by info@thehackernews.com (The Hacker News) on September 22, 2026 at 5:03 pm
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the […]
- Critical Bifrost AI Gateway Flaw Lets Attackers...by info@thehackernews.com (The Hacker News) on September 22, 2026 at 4:41 pm
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw, tracked as CVE-2026-90898 (CVSS score: 9.8), affects all […]
- Researcher Drops BigDiskBuster Zero-Day PoC That...by info@thehackernews.com (The Hacker News) on September 22, 2026 at 4:14 pm
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhamid […]
- AI Agents Are Rewriting the Rules of Lateral...by info@thehackernews.com (The Hacker News) on September 22, 2026 at 12:30 pm
Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try several ways to complete a task. A deterministic application […]
- New CVSS 10.0 VeloCloud Orchestrator Flaw...by info@thehackernews.com (The Hacker News) on September 22, 2026 at 12:29 pm
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker with no login access to privilege internal functions and […]
- DORA Year Two: Can Your SOC Actually See the...by info@thehackernews.com (The Hacker News) on September 22, 2026 at 11:45 am
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing third-party service providers, updating contract clauses, and […]
- New Linux Kernel Flaw Gives ARM64 KVM Guests...by info@thehackernews.com (The Hacker News) on September 22, 2026 at 11:38 am
A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775, allows a guest to read and write host kernel memory, and the […]
- SharePoint Flaw Initially Listed as Spoofing by...by info@thehackernews.com (The Hacker News) on September 22, 2026 at 11:17 am
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber Security researcher Dinh Ho Anh Khoa. The flaw, […]
- Malicious npm Package indexed-btree Hid Its...by info@thehackernews.com (The Hacker News) on September 22, 2026 at 9:38 am
A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexed-btree is a malicious npm package […]
- SideCopy Broadens India Targeting to Academia...by info@thehackernews.com (The Hacker News) on September 22, 2026 at 7:52 am
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage the abuse of […]
WordPress News
- WordPress 7.1.2 Releaseby John Blackbourn on September 22, 2026 at 2:01 pm
This security release features a fix for a critical severity security vulnerability. Because this is a security release, it is recommended that you update your sites immediately. You can download WordPress 7.1.2 from WordPress.org, or visit your WordPress Dashboard, click “Updates”, and then […]
- WordPress Takes Its Turn Leading the Open Website...by Mary Hubbard on September 21, 2026 at 2:28 pm
I’m happy to announce that I am now serving as president of the Open Website Alliance (OWA), representing the WordPress Foundation. The Alliance brings together the community organizations behind Drupal, Joomla!, TYPO3, and WordPress to advocate for open source and share practices that benefit […]
- WordPress 7.1.1 Maintenance and Security Releaseby Aaron Jorbin on September 17, 2026 at 7:53 pm
This security and maintenance release features 17 bug fixes on Core, 19 bug fixes for the Block Editor, and 11 security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can download WordPress 7.1.1 from WordPress.org, or visit your WordPress […]
- Students Built 108 Websites in Two Weeks in...by Destiny Kanno on September 7, 2026 at 11:19 pm
In July, students at two campuses in Kishoreganj, Bangladesh, built 108 websites. In eastern Uganda, a workshop that arrived to find no electricity at the school ran anyway, for more than 100 learners, because a former student had asked for it. In Costa Rica, three university students taught a […]
- WordPress Signs the Open Weights and American AI...by Mary Hubbard on August 27, 2026 at 5:00 pm
We’re proud to announce that WordPress has signed Open Weights and American AI Leadership, an open letter asking US policymakers to not place early restrictions on open weight AI models. These are artificial intelligence models that anyone can download, inspect, modify, and run on their own […]
- AI Creates Opportunity While Artists Ship at...by Nicholas Garofalo on August 20, 2026 at 5:51 am
WordCamp US (WCUS) 2026 just wrapped up after 4 days at the Phoenix Convention Center in Phoenix, Arizona. Over 1,100 people from around the world registered to attend, and thousands more watched online through livestreams. Contributor Day and Showcase Day opened the week before two main […]
- WordPress 7.1 “Mary Lou”by annezazu on August 19, 2026 at 11:33 pm
WordPress 7.1, “Mary Lou,” is here—celebrating the pioneering jazz pianist, composer, and arranger Mary Lou Williams and her spirit of reinvention and collaboration. This release brings a more flexible, responsive, and collaborative WordPress experience, with new responsive styling controls, […]
- Introducing the WordPress Browser Extensionby Jake Goldman on August 13, 2026 at 4:29 pm
The official WordPress Browser Extension is now available for Google Chrome and Chromium-based browsers in the Chrome Web Store and for Safari on macOS in the Mac App Store. This new open source extension lets logged-in site users easily hide the admin bar while keeping its most helpful shortcuts […]
- WordPress 7.0.4 Releaseby John Blackbourn on August 12, 2026 at 2:45 pm
WordPress 7.0.4 is now available WordPress 7.0.4 is now available which features a security fix. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.4 by downloading it from WordPress.org, or visiting your site’s Dashboard […]
- WordPress 7.0.3 releaseby John Blackbourn on August 6, 2026 at 6:55 pm
WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. You can update to WordPress 7.0.3 by downloading it from WordPress.org, or visiting your site’s […]
















