ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New Stories

The Hacker News

Overview

This week, cybersecurity experts reported significant vulnerabilities and incidents affecting various systems and tools. Over 800 flaws have been patched, indicating that many software products are at risk if not updated. Additionally, there are concerns about insider threats, particularly regarding SIM swapping, which can compromise personal accounts and sensitive information. Attackers are employing both new tactics and exploiting existing weaknesses, which suggests that the security environment remains challenging for organizations and individuals alike. As technology evolves, so do the methods used by cybercriminals, making it crucial for users to stay vigilant and proactive about their security measures.

Key Takeaways

  • Affected Systems: Various software products and services, particularly those with outdated vulnerabilities or weak logins.
  • Action Required: Regularly update software, apply patches, and strengthen login credentials to mitigate risks.
  • Timeline: Ongoing since recent weeks

Original Article Summary

Attackers keep finding new keys. The funny part is that defenders keep inventing where to store them. This week, those keys sit in AI tools, exposed services, old bugs, weak logins, and software sold like a monthly subscription. Some attacks use new tricks. Others just reuse what was already lying around. Both work often enough. So the threat landscape is not getting cleaner. It is just

Impact

Various software products and services, particularly those with outdated vulnerabilities or weak logins.

Exploitation Status

The exploitation status is currently unknown. Monitor vendor advisories and security bulletins for updates.

Timeline

Ongoing since recent weeks

Remediation

Regularly update software, apply patches, and strengthen login credentials to mitigate risks.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Coverage

Early Scattered Spider member pleads guilty to cybercrime spree

CyberScoop

Ahmed Elbadawy, a member of the cybercrime group known as Scattered Spider, has pleaded guilty to participating in a series of cybercrimes that allowed him to amass significant wealth. Prosecutors have indicated they are pursuing the forfeiture of approximately $17.6 million in virtual currencies, along with luxury vehicles, jewelry, and designer bags linked to his illegal activities. This case exemplifies the ongoing challenges law enforcement faces in tackling organized cybercrime. The financial proceeds from such crimes not only enrich the perpetrators but also fund further illicit activities, making it crucial for authorities to act decisively against such networks. The resolution of this case could have implications for how similar crimes are prosecuted in the future.

Sep 18, 2026

MFA Won't Save You From OAuth Consent Abuse

darkreading

The article discusses the limitations of Multi-Factor Authentication (MFA) in protecting against OAuth consent abuse. While MFA adds an extra layer of security, it doesn't address the need for proper governance of OAuth protocols, which can lead to unauthorized access when users mistakenly grant permissions. Companies must implement least-privilege scopes and actively monitor consent to ensure that users are not giving away more access than necessary. Additionally, quick revocation of permissions is crucial in mitigating potential breaches. This issue is particularly relevant as OAuth is widely used across various applications, making proper management essential to safeguard user data.

Sep 18, 2026

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

The Hacker News

A security researcher has made public exploit code for four vulnerabilities in the Linux kernel that allow local users to gain root access, which is the highest level of control on a computer. These vulnerabilities have been patched in recent updates, meaning that systems with the latest kernel versions are not at risk. However, machines running older versions of the kernel could be vulnerable, putting them at potential risk of exploitation. Users and administrators are strongly advised to update their systems to the latest kernel version to prevent unauthorized access. The release of this exploit code increases the urgency for users to ensure their systems are secure, as it makes it easier for attackers to leverage these flaws if they remain unpatched.

Sep 18, 2026

Researchers use AI to find widespread software decoder flaw

CyberScoop

Researchers have identified a significant software decoder flaw that was able to grant attackers remote code execution privileges. This vulnerability, which has since been patched, put user accounts and production environments at risk, affecting major platforms like Meta's product suite and an OpenAI software repository. The ability for attackers to exploit this flaw raises serious concerns about the security of widely used software components. Organizations that rely on these products should ensure they have implemented the necessary patches to protect their systems. This incident serves as a reminder of the ongoing challenges in software security and the need for vigilant monitoring and updates.

Sep 18, 2026

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

The Hacker News

WordPress has patched several vulnerabilities in its core software, including a serious flaw that could let attackers install themes from the official WordPress.org directory without user consent. This vulnerability, dubbed Click2Shell by researchers at pwn.ai, specifically affects logged-in administrators who click on a specially crafted link. While the flaw requires user interaction to exploit, it poses significant risks as it could lead to unauthorized code execution on compromised sites. Website owners using WordPress should ensure they update their installations promptly to protect against potential exploitation. The discovery of this vulnerability emphasizes the ongoing need for vigilance in web application security.

Sep 18, 2026

Gyazo server flaw exploited to steal 23.6 million user records

BleepingComputer

Gyazo, a popular image-sharing platform, has confirmed a significant data breach due to a vulnerability in its server. Hackers exploited this flaw to access and steal approximately 23.6 million user records, which raises serious concerns about data privacy and security for those affected. The breach likely includes sensitive information that could be used for identity theft or other malicious purposes. This incident serves as a reminder for users to be vigilant about their online security and for companies to prioritize robust security measures. Gyazo has not yet released specific details on how they plan to address this vulnerability or secure their systems moving forward.

Sep 18, 2026